IopInitializeBuiltinDriver

__int64 __fastcall IopInitializeBuiltinDriver(
        unsigned __int16 *a1,
        __int64 a2,
        int (__fastcall *a3)(_DRIVER_OBJECT *, _UNICODE_STRING *),
        __int64 a4,
        unsigned __int8 a5,
        struct _DRIVER_OBJECT **a6){
  void *v6; 
  unsigned __int16 *p_Length; 
  char v11; 
  int inserted; 
  char *v13; 
  PVOID *i; 
  IMAGE_NT_HEADERS *v15; 
  CHAR *Pool_1; 
  CHAR *v17; 
  __int64 v18; 
  unsigned __int64 v19; 
  UINT8 *v20; 
  __int64 v21; 
  UINT8 *v22; 
  UINT8 *v23; 
  unsigned __int16 v24; 
  unsigned __int16 v25; 
  CHAR *v26; 
  _UNICODE_STRING *v27; 
  PVOID v28; 
  __int16 v29; 
  UNICODE_STRING *v30; 
  int Image; 
  int v32; 
  UNICODE_STRING *v33; 
  PVOID *NewObject; 
  HANDLE KeyHandle; 
  HANDLE Handle; 
  PVOID Object; 
  PVOID v39; 
  int v40[2]; 
  __int64 v41; 
  unsigned __int16 *v42; 
  int v43; 
  int v44; 
  __int128 v45; 
  unsigned int PnpFlags; 
  UNICODE_STRING *KeyName; 
  KeyName = (UNICODE_STRING *)a2;
  v6 = 0i64;
  Handle = 0i64;
  Object = 0i64;
  p_Length = (unsigned __int16 *)a2;
  v40[1] = 0;
  *a6 = 0i64;
  v44 = 0;
  KeyHandle = 0i64;
  PnpFlags = 0;
  if( HeadlessGlobals && HeadlessGlobals[1] )
    HdlspKernelAddLogEntry(1ui64, (_UNICODE_STRING *)a1);
  v40[0] = 48;
  v41 = 0i64;
  v11 = *((_BYTE *)KeGetCurrentThread() + 562);
  v43 = 80;
  v42 = a1;
  v45 = 0i64;
  inserted = ObCreateObject(v11, IoDriverObjectType, (__int64)v40, 0, 0, 416, 0, 0, &Object);
  if( inserted >= 0 )
  {
    v13 = (char *)Object;
    memset((INT64)Object, 0i64);
    *((_QWORD *)v13 + 6) = v13 + 336;
    *((_QWORD *)v13 + 42) = v13;
    memset64(v13 + 112, (unsigned __int64)IopInvalidDeviceRequest, 0x1Cui64);
    *(_DWORD *)v13 = 22020100;
    *((_QWORD *)v13 + 11) = a3;
    inserted = ObInsertObject(v13, 0i64, 1ui64, 0i64, 0i64, &Handle);
    if( inserted >= 0 )
    {
      ObReferenceObjectByHandle(Handle, 0, IoDriverObjectType, 0, &v39, 0i64);
      for( i = (PVOID *)PsLoadedModuleList; i != &PsLoadedModuleList && a4; i = (PVOID *)*i )
      {
        if( RtlEqualString((STRING *)(a4 + 88), (STRING *)(i + 11), 1u) )
        {
          *((_QWORD *)v13 + 5) = i;
          break;
        }
      }
      InbvIndicateProgress();
      if( !a4
        || (v6 = *(void **)(a4 + 48),
            v15 = RtlImageNtHeader(v6),
            *((_QWORD *)v13 + 3) = v6,
            *((_DWORD *)v13 + 8) = v15->OptionalHeader.SizeOfImage,
            (v15->OptionalHeader.DllCharacteristics & 0x2000) == 0) )
      {
        *((_DWORD *)v13 + 4) |= 2u;
      }
      Pool_1 = IopVerifierExAllocatePool_1(NonPagedPoolNx, a1[1] + 2i64);
      v17 = Pool_1;
      if( Pool_1 )
      {
        *((_QWORD *)v13 + 8) = Pool_1;
        *((_WORD *)v13 + 29) = a1[1];
        *((_WORD *)v13 + 28) = *a1;
        memmove(*((UINT8 **)v13 + 8), *((UINT8 **)a1 + 1), a1[1]);
        *(_WORD *)&v17[2 * ((unsigned __int64)*a1 >> 1)] = 0;
      }
      v18 = *((_QWORD *)v13 + 6);
      if( p_Length )
      {
        v19 = *p_Length;
        if( (_WORD)v19 )
        {
          v20 = (UINT8 *)*((_QWORD *)p_Length + 1);
          v21 = -4i64;
          v22 = &v20[2 * (v19 >> 1)];
          if( *((_WORD *)v22 - 1) != 92 )
            v21 = -2i64;
          v23 = &v22[v21];
          v24 = 0;
          if( v23 != v20 )
          {
            while( *(_WORD *)v23 != 92 )
            {
              v24 += 2;
              v23 -= 2;
              if( v23 == v20 )
                goto LABEL_30;
            }
            v23 += 2;
          }
LABEL_30:
          v25 = v24 + 2;
          if( v23 != v20 )
            v25 = v24;
          Object = (PVOID)v25;
          v26 = IopVerifierExAllocatePool_1(NonPagedPoolNx, v25 + 2i64);
          v39 = v26;
          v27 = (_UNICODE_STRING *)(v18 + 24);
          if( v26 )
          {
            v28 = Object;
            v29 = (_WORD)Object + 2;
            *(_QWORD *)(v18 + 32) = v26;
            *(_WORD *)(v18 + 26) = v29;
            v27->Length = (unsigned __int16)v28;
            memmove((UINT8 *)v26, v23, (UINT64)v28);
            v30 = KeyName;
            *((_WORD *)v39 + ((unsigned __int64)v27->Length >> 1)) = 0;
            inserted = IopOpenRegistryKeyEx(&KeyHandle, 0i64, v30, 0xF003Fui64);
            if( inserted >= 0 )
            {
              inserted = PnpPrepareDriverLoading(v27, KeyHandle, v6, a5, &PnpFlags);
              NtClose(KeyHandle);
              if( inserted >= 0 )
              {
                p_Length = &KeyName->Length;
LABEL_38:
                if( (PnpFlags & 1) != 0 )
                  *((_DWORD *)v13 + 4) |= 0x100u;
                *((_QWORD *)v13 + 9) = &CmRegistryMachineHardwareDescriptionSystemName;
                VfDifCaptureDriverEntry((DRIVER_OBJECT *)v13);
                Image = KseDriverLoadImage(a4);
                inserted = Image;
                if( Image >= 0 )
                {
                  v32 = (*((__int64(__fastcall **)(char *, unsigned __int16 *))v13 + 11))(v13, p_Length);
                  inserted = v32;
                  if( v32 < 0 )
                  {
                    if( v32 == -1073741218 )
                    {
                      LODWORD(NewObject) = -1073741218;
                      DbgPrintEx(
                        0x65u,
                        3u,
                        "IOINIT: Built-in driver %wZ failed to initialize with status - 0x%lX\n",
                        a1,
                        NewObject);
                    }
                    else
                    {
                      LODWORD(NewObject) = v32;
                      DbgPrintEx(
                        0x65u,
                        0,
                        "IOINIT: Built-in driver %wZ failed to initialize with status - 0x%lX\n",
                        a1,
                        NewObject);
                    }
                  }
                  else
                  {
                    VfDifCaptureIoCallbacks((DRIVER_OBJECT *)v13);
                    KseShimDriverIoCallbacks((DRIVER_OBJECT *)v13, v33);
                  }
                }
                else
                {
                  LODWORD(NewObject) = Image;
                  DbgPrintEx(0x65u, 3u, "IOINIT: Built-in driver %wZ blocked with status - 0x%lX\n", a1, NewObject);
                }
              }
            }
          }
          else
          {
            *(_QWORD *)(v18 + 32) = 0i64;
            inserted = -1073741670;
            v27->Length = 0;
          }
          NtClose(Handle);
          if( inserted < 0 )
          {
            if( inserted != -1073741218 )
              PnpDriverLoadingFailed(0i64, (UNICODE_STRING *)(*((_QWORD *)v13 + 6) + 24i64));
            if( HeadlessGlobals && HeadlessGlobals[1] )
              HdlspKernelAddLogEntry(3ui64, 0i64);
            ObMakeTemporaryObject(v13);
            ObfDereferenceObjectWithTag(v13, 0x746C6644ui64);
          }
          else
          {
            IopReadyDeviceObjects((DRIVER_OBJECT *)v13);
            if( HeadlessGlobals && HeadlessGlobals[1] )
              HdlspKernelAddLogEntry(2ui64, 0i64);
            *a6 = (struct _DRIVER_OBJECT *)v13;
          }
          return(unsigned int)inserted;
        }
      }
      *(_DWORD *)(v18 + 24) = 0;
      *(_QWORD *)(v18 + 32) = 0i64;
      goto LABEL_38;
    }
  }
  if( HeadlessGlobals && HeadlessGlobals[1] )
    HdlspKernelAddLogEntry(3ui64, 0i64);
  return(unsigned int)inserted;
}

Referenced by:

PnpInitializeBootStartDriver