RtlQueryRegistryValueWithFallback

NTSTATUS __stdcall RtlQueryRegistryValueWithFallback(
        HANDLE PrimaryHandle,
        HANDLE FallbackHandle,
        PUNICODE_STRING ValueName,
        ULONG ValueLength,
        PULONG ValueType,
        PVOID ValueData,
        PULONG ResultLength){
  ULONG Length; 
  UINT8 *PoolWithTag; 
  int v12; 
  ULONG v14; 
  v14 = 0;
  if( __PAIR128__((unsigned __int64)PrimaryHandle, (unsigned __int64)FallbackHandle) == 0 )
    return -1073741811;
  Length = ValueLength + 16;
  if( ValueLength >= 0xFFFFFFF0 )
    return -1073741675;
  PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, Length, 0x6D6C7472ui64);
  if( !PoolWithTag )
    return -1073741801;
  v12 = -1073741772;
  if( PrimaryHandle )
  {
    v12 = ZwQueryValueKey(PrimaryHandle, ValueName, KeyValuePartialInformation, PoolWithTag, Length, &v14);
    if( v12 != -1073741772 )
      goto LABEL_8;
  }
  if( FallbackHandle )
  {
    v12 = ZwQueryValueKey(FallbackHandle, ValueName, KeyValuePartialInformation, PoolWithTag, Length, &v14);
LABEL_8:
    if( (int)(v12 + 0x80000000) < 0 || v12 == -2147483643 )
    {
      *ResultLength = *((_DWORD *)PoolWithTag + 2);
      if( ValueType )
        *ValueType = *((_DWORD *)PoolWithTag + 1);
      if( v12 >= 0 )
        memmove((UINT8 *)ValueData, PoolWithTag + 12, *((unsigned int *)PoolWithTag + 2));
    }
  }
  ExFreePoolWithTag(PoolWithTag, 0);
  return v12;
}

Referenced by:

EtwpGetGuidSecurityDescriptor