VrpPreOpenOrCreate
INT64 __fastcall VrpPreOpenOrCreate(INT64 a1, CHAR *a2){
UNICODE_STRING **v2;
_UNICODE_STRING *v5;
UNICODE_STRING *v6;
struct _UNICODE_STRING *v7;
UNICODE_STRING *v8;
int v9;
int v10;
int v11;
int v12;
UNICODE_STRING *PoolWithTag;
struct _UNICODE_STRING v14;
struct _UNICODE_STRING v15;
int v16;
UNICODE_STRING v17;
PADAPTER_OBJECT v18;
UNICODE_STRING v19;
int v21;
UNICODE_STRING *v22;
int Length;
__int64 Buffer;
char *v25;
UNICODE_STRING *v26;
int v27;
int v28;
PADAPTER_OBJECT DmaAdapter;
_UNICODE_STRING *NewKeyPath;
struct _UNICODE_STRING DestinationString;
PVOID P[2];
__int64 v33[2];
GUID ActivityId;
struct _EVENT_DATA_DESCRIPTOR v35;
int *v36;
__int64 v37;
__int64 v38;
int v39[2];
int *v40;
__int64 v41;
v2 = *(UNICODE_STRING ***)a1;
v28 = 0;
v5 = v2[1];
v6 = *v2;
v7 = 0i64;
v8 = v2[11];
DmaAdapter = 0i64;
DestinationString = 0i64;
NewKeyPath = v5;
*(_OWORD *)P = 0i64;
*(_OWORD *)v33 = 0i64;
ActivityId = 0i64;
EtwActivityIdControl(3u, &ActivityId);
if( !v6->Length || *v6->Buffer != 92 )
{
if( !v8 )
return 0;
VrpBuildKeyPath((UNICODE_STRING *)((unsigned __int64)&v8[1] & -(__int64)(v8 != 0i64)), *v2, &DestinationString);
v10 = v9;
if( v9 < 0 )
goto LABEL_15;
goto LABEL_5;
}
VrpBuildKeyPath(0i64, *v2, &DestinationString);
v10 = v21;
if( v21 >= 0 )
{
LABEL_5:
v27 = 0;
v11 = VrpTranslatePath((_UNICODE_STRING *)a2, NewKeyPath);
v10 = v11;
if( v11 == -1073741772 )
return 0;
if( v11 < 0 )
goto LABEL_15;
v12 = v28;
DmaAdapter[3].Size = NewKeyPath[3].MaximumLength;
PoolWithTag = (UNICODE_STRING *)ExAllocatePoolWithTag(PagedPool, 0x48ui64, 0x67655256ui64);
v7 = PoolWithTag;
if( !PoolWithTag )
{
v10 = -1073741670;
goto LABEL_21;
}
v14 = DestinationString;
v2[10] = PoolWithTag;
*(_QWORD *)&PoolWithTag->Length = v2[1];
PoolWithTag[1] = **v2;
v15 = *v2[14];
v16 = v27;
v7[3] = v14;
*(_DWORD *)&v7[4].Length = v12;
v17 = *(UNICODE_STRING *)v33;
v7[2] = v15;
*(_DWORD *)(a1 + 8) = v16;
v18 = DmaAdapter;
v19 = *(UNICODE_STRING *)P;
v7->Buffer = (wchar_t *)a2;
v2[1] = (UNICODE_STRING *)v18;
**v2 = v19;
*v2[14] = v17;
}
if( v10 >= 0 )
return(unsigned int)v10;
LABEL_15:
if( v10 == -1073740541 )
{
if( (unsigned int)CallbackContext > 5 )
{
v22 = (UNICODE_STRING *)&EmptyUnicodeString;
if( (*v2)->Buffer )
v22 = *v2;
Length = v22->Length;
Buffer = (__int64)v22->Buffer;
v36 = v39;
v25 = byte_140023258;
v27 = -1073740541;
LABEL_25:
v38 = Buffer;
v39[0] = Length;
v40 = &v27;
v37 = 2i64;
v39[1] = 0;
v41 = 4i64;
tlgWriteTransfer_EtwWriteTransfer((__int64)&CallbackContext, (unsigned __int8 *)v25, &ActivityId, 0i64, 5u, &v35);
goto LABEL_26;
}
goto LABEL_26;
}
LABEL_21:
if( (unsigned int)CallbackContext > 2 )
{
v26 = (UNICODE_STRING *)&EmptyUnicodeString;
if( (*v2)->Buffer )
v26 = *v2;
Length = v26->Length;
Buffer = (__int64)v26->Buffer;
v36 = v39;
v25 = &byte_140023297;
v27 = v10;
goto LABEL_25;
}
LABEL_26:
if( v7 )
ExFreePoolWithTag(v7, 0x67655256u);
if( P[1] )
ExFreePoolWithTag(P[1], 0x67655256u);
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
if( DestinationString.Buffer )
ExFreePoolWithTag(DestinationString.Buffer, 0x67655256u);
return(unsigned int)v10;
}Referenced by:
VrpRegistryCallback