IoRegisterPlugPlayNotification

NTSTATUS __stdcall IoRegisterPlugPlayNotification(
        IO_NOTIFICATION_EVENT_CATEGORY EventCategory,
        ULONG EventCategoryFlags,
        PVOID EventCategoryData,
        PDRIVER_OBJECT DriverObject,
        PDRIVER_NOTIFICATION_CALLBACK_ROUTINE CallbackRoutine,
        PVOID Context,
        PVOID *NotificationEntry){
  NTSTATUS result; 
  __int32 v11; 
  __int32 v12; 
  __int32 v13; 
  NTSTATUS restarted; 
  _GUID *PoolWithTag; 
  PCWSTR v16; 
  PCWSTR *v17; 
  _FAST_MUTEX *v18; 
  _GUID *v19; 
  __int64 *v20; 
  __int64 **v21; 
  __int128 v22; 
  WCHAR v23; 
  int v24; 
  WCHAR *v25; 
  const WCHAR *i; 
  _EJOB *CurrentServerSilo; 
  int SessionIdFromSymbolicName; 
  _GUID **v29; 
  struct _DMA_ADAPTER *v30; 
  ULONG v31; 
  PCWSTR SourceString; 
  struct _UNICODE_STRING DestinationString; 
  int v34; 
  GUID v35; 
  __int128 v36; 
  int v37; 
  UNICODE_STRING *SymbolicLinkName; 
  LODWORD(SourceString) = EventCategoryFlags;
  *NotificationEntry = 0i64;
  result = ObReferenceObjectByPointerWithTag(DriverObject, 0, IoDriverObjectType, 0, 0x4E706E50u);
  if( result >= 0 )
  {
    v11 = EventCategory - 1;
    if( v11 )
    {
      v12 = v11 - 1;
      if( v12 )
      {
        v13 = v12 - 1;
        if( v13 )
        {
          if( v13 != 1 )
          {
            restarted = -1073741585;
            goto LABEL_33;
          }
          restarted = PiRegisterKernelSoftRestartNotification(
                        (INT64)DriverObject,
                        CallbackRoutine,
                        (INT64)Context,
                        (CHAR **)NotificationEntry);
          goto LABEL_13;
        }
        SourceString = 0i64;
        restarted = PnpGetRelatedTargetDevice((PFILE_OBJECT)EventCategoryData, &SourceString);
        if( restarted < 0 )
          goto LABEL_33;
        PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x70ui64, 0x43706E50ui64);
        if( PoolWithTag )
        {
          restarted = PnpInitializeNotifyEntry(
                        (__int64)PoolWithTag,
                        3,
                        (unsigned __int64)CallbackRoutine,
                        (__int64)Context,
                        (__int64)DriverObject,
                        (__int64)&PnpTargetDeviceNotifyLock);
          if( restarted < 0 )
          {
            ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
            v30 = (struct _DMA_ADAPTER *)*((_QWORD *)SourceString + 4);
          }
          else
          {
            v16 = SourceString;
            *(_QWORD *)&PoolWithTag[5].Data1 = EventCategoryData;
            *(_QWORD *)PoolWithTag[5].Data4 = *((_QWORD *)v16 + 4);
            restarted = PnpDeferNotification((__int64)PoolWithTag);
            if( restarted >= 0 )
            {
              KeAcquireGuardedMutex(&PnpTargetDeviceNotifyLock);
              v17 = (PCWSTR *)*((_QWORD *)v16 + 60);
              if( *v17 == v16 + 236 )
              {
                *(_QWORD *)&PoolWithTag->Data1 = v16 + 236;
                v18 = &PnpTargetDeviceNotifyLock;
                *(_QWORD *)PoolWithTag->Data4 = v17;
                *v17 = (PCWSTR)PoolWithTag;
                *((_QWORD *)v16 + 60) = PoolWithTag;
LABEL_11:
                KeReleaseGuardedMutex(v18);
LABEL_12:
                *NotificationEntry = PoolWithTag;
                goto LABEL_13;
              }
              goto LABEL_47;
            }
            ExFreePoolWithTag(PoolWithTag, 0x43706E50u);
            v30 = (struct _DMA_ADAPTER *)*((_QWORD *)v16 + 4);
          }
          HalPutDmaAdapter(v30);
LABEL_13:
          if( restarted >= 0 )
            return restarted;
LABEL_33:
          ObfDereferenceObjectWithTag(DriverObject, 0x4E706E50ui64);
          return restarted;
        }
        HalPutDmaAdapter(*((PADAPTER_OBJECT *)SourceString + 4));
LABEL_38:
        restarted = -1073741670;
        goto LABEL_33;
      }
      PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x60ui64, 0x44706E50ui64);
      if( !PoolWithTag )
        goto LABEL_38;
      restarted = PnpInitializeNotifyEntry(
                    (__int64)PoolWithTag,
                    2,
                    (unsigned __int64)CallbackRoutine,
                    (__int64)Context,
                    (__int64)DriverObject,
                    (__int64)&PnpDeviceClassNotifyLock);
      if( restarted < 0 )
        goto LABEL_33;
      v19 = PoolWithTag + 5;
      PoolWithTag[5] = *(_GUID *)EventCategoryData;
      restarted = PnpDeferNotification((__int64)PoolWithTag);
      if( restarted >= 0 )
      {
        KeAcquireGuardedMutex(&PnpDeviceClassNotifyLock);
        v20 = &PnpDeviceClassNotifyList[2
                                      * ((v19->Data1
                                        + *(_DWORD *)&PoolWithTag[5].Data2
                                        + *(_DWORD *)PoolWithTag[5].Data4
                                        + *(_DWORD *)&PoolWithTag[5].Data4[4])
                                       % 0xD)];
        v21 = (__int64 **)v20[1];
        if( *v21 == v20 )
        {
          *(_QWORD *)&PoolWithTag->Data1 = v20;
          *(_QWORD *)PoolWithTag->Data4 = v21;
          *v21 = (__int64 *)PoolWithTag;
          v20[1] = (__int64)PoolWithTag;
          KeReleaseGuardedMutex(&PnpDeviceClassNotifyLock);
          if( ((unsigned __int8)SourceString & 1) != 0 )
          {
            v22 = (__int128)*v19;
            SourceString = 0i64;
            DestinationString = 0i64;
            v37 = 0;
            v34 = 3145729;
            v35 = GUID_DEVICE_INTERFACE_ARRIVAL;
            v36 = v22;
            IopGetDeviceInterfaces(PoolWithTag + 5, 0i64, 0i64, 0, (WCHAR **)&SourceString, 0i64);
            restarted = v24;
            if( v24 < 0 )
              goto LABEL_33;
            v25 = (WCHAR *)SourceString;
            for( i = SourceString; *i; i += ((unsigned __int64)DestinationString.Length >> 1) + 1 )
            {
              LODWORD(SourceString) = 0;
              RtlInitUnicodeString(&DestinationString, i, v23);
              SymbolicLinkName = &DestinationString;
              CurrentServerSilo = PsGetCurrentServerSilo();
              if( *(_DWORD *)&PoolWithTag[1].Data2 != (unsigned int)PsGetServerSiloServiceSessionId(CurrentServerSilo) )
              {
                SessionIdFromSymbolicName = IopGetSessionIdFromSymbolicName(SymbolicLinkName);
                if( SessionIdFromSymbolicName != -1 && *(_DWORD *)&PoolWithTag[1].Data2 != SessionIdFromSymbolicName )
                  continue;
              }
              PnpNotifyDriverCallback((__int64)PoolWithTag, (__int64)&v34, &SourceString);
            }
            ExFreePoolWithTag(v25, 0);
          }
          goto LABEL_12;
        }
        goto LABEL_47;
      }
      v31 = 1148218960;
    }
    else
    {
      PoolWithTag = (_GUID *)ExAllocatePoolWithTag(PagedPool, 0x50ui64, 0x39706E50ui64);
      if( !PoolWithTag )
        goto LABEL_38;
      restarted = PnpInitializeNotifyEntry(
                    (__int64)PoolWithTag,
                    1,
                    (unsigned __int64)CallbackRoutine,
                    (__int64)Context,
                    (__int64)DriverObject,
                    (__int64)&PnpHwProfileNotifyLock);
      if( restarted < 0 )
        goto LABEL_33;
      restarted = PnpDeferNotification((__int64)PoolWithTag);
      if( restarted >= 0 )
      {
        KeAcquireGuardedMutex(&PnpHwProfileNotifyLock);
        v29 = (_GUID **)qword_140D2DB58;
        if( *(PVOID **)qword_140D2DB58 == &PnpProfileNotifyList )
        {
          *(_QWORD *)&PoolWithTag->Data1 = &PnpProfileNotifyList;
          v18 = &PnpHwProfileNotifyLock;
          *(_QWORD *)PoolWithTag->Data4 = v29;
          *v29 = PoolWithTag;
          qword_140D2DB58 = (__int64)PoolWithTag;
          goto LABEL_11;
        }
LABEL_47:
        __fastfail(3u);
      }
      v31 = 963669584;
    }
    ExFreePoolWithTag(PoolWithTag, v31);
    goto LABEL_13;
  }
  return result;
}

Referenced by:

HalpPostPnpInitialize
PoInitDriverServices
PopRegisterCoolingExtensionProtection
SbpWaitForVmbus
SmKmStoreFileCreate