RtlpQueryRegistryValues

UINT8 __fastcall RtlpQueryRegistryValues(_KTRAP_FRAME *TrapFrame, _KEXCEPTION_FRAME *ExceptionFrame){
  _RTL_QUERY_REGISTRY_TABLE *v2; 
  VOID *v3; 
  VOID *v4; 
  _RTL_QUERY_REGISTRY_TABLE *v5; 
  unsigned int v6; 
  int v8; 
  int RegistryHandle; 
  WCHAR v10; 
  int v11; 
  _KEXCEPTION_FRAME *v12; 
  INT64 *v13; 
  __int64 v14; 
  INT64 *v15; 
  __int64 v16; 
  int v17; 
  ULONG v18; 
  unsigned int Flags; 
  const WCHAR *Name; 
  int v21; 
  int v22; 
  UINT8 v23; 
  __int64 v24; 
  int v25; 
  int v26; 
  __int64 v27; 
  int v28; 
  UINT64 Length; 
  PULONG ResultLength; 
  PULONG ResultLengtha; 
  UINT64 Environment; 
  HANDLE KeyHandle; 
  HANDLE Handle; 
  UINT64 PAllocLength; 
  struct _UNICODE_STRING ValueName; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  VOID *Context; 
  INT64 pStatus; 
  UINT8 ValidateKeyTrust; 
  Context = v3;
  v4 = v3;
  v5 = v2;
  v6 = 0;
  Handle = 0i64;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  LODWORD(Environment) = 0;
  v8 = (int)TrapFrame;
  DestinationString = 0i64;
  ValueName = 0i64;
  RegistryHandle = RtlpGetRegistryHandle((UINT64)TrapFrame, (const WCHAR *)ExceptionFrame, 0, &Handle);
  LODWORD(pStatus) = RegistryHandle;
  if( RegistryHandle < 0 )
    return RegistryHandle;
  v11 = v8 & 0x40000000;
  if( v11 )
    v12 = 0i64;
  else
    v12 = ExceptionFrame;
  RtlInitUnicodeString(&DestinationString, (PCWSTR)v12, v10);
  PAllocLength = 136i64;
  LODWORD(v14) = RtlpAllocDeallocQueryBuffer(&PAllocLength, 0i64, v13, (INT64)&pStatus);
  v16 = v14;
  if( v14 )
  {
    LOBYTE(v17) = pStatus;
    v18 = 134;
    *(_DWORD *)(v14 + 8) = 0;
    KeyHandle = Handle;
LABEL_6:
    if( !v5->QueryRoutine && (v5->Flags & 0x21) == 0 )
    {
LABEL_8:
      if( Handle && !v11 )
        ZwClose(Handle);
      if( KeyHandle && KeyHandle != Handle )
        ZwClose(KeyHandle);
      RtlpAllocDeallocQueryBuffer(0i64, (PVOID)v16, v15, 0i64);
      LOBYTE(RegistryHandle) = v17;
      return RegistryHandle;
    }
    Flags = v5->Flags;
    if( (Flags & 0x20) != 0 && (!v5->Name || (Flags & 1) != 0 || v5->QueryRoutine) )
    {
LABEL_76:
      LOBYTE(v17) = 13;
      goto LABEL_8;
    }
    if( (Flags & 3) != 0 && KeyHandle != Handle )
    {
      ZwClose(KeyHandle);
      KeyHandle = Handle;
      Flags = v5->Flags;
    }
    Name = v5->Name;
    if( (Flags & 1) != 0 )
    {
      if( !Name )
        goto LABEL_76;
      RtlInitUnicodeString(&DestinationString, Name, (WCHAR)v15);
      ObjectAttributes.RootDirectory = Handle;
      ObjectAttributes.Length = 48;
      ObjectAttributes.ObjectName = &DestinationString;
      ObjectAttributes.Attributes = 576;
      *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
      v17 = ZwOpenKey(&KeyHandle, 0x2000000u, &ObjectAttributes);
      if( v17 < 0 )
        goto LABEL_8;
      if( !v5->QueryRoutine )
        goto LABEL_31;
    }
    else
    {
      if( Name )
      {
        RtlInitUnicodeString(&ValueName, Name, (WCHAR)v15);
        while( 1 )
        {
          v21 = v6++;
          if( v21 > 4 )
          {
            DbgPrint("RtlpQueryRegistryValues: Miscomputed buffer size at line %d\n", 1276i64);
            goto LABEL_8;
          }
          v17 = ZwQueryValueKey(KeyHandle, &ValueName, KeyValueFullInformation, (PVOID)v16, v18, (PULONG)&Environment);
          if( v17 == -2147483643 )
            v17 = -1073741789;
          LODWORD(pStatus) = v17;
          if( v17 < 0 )
          {
            if( v17 == -1073741772 )
            {
              v23 = ValidateKeyTrust;
              *(_DWORD *)(v16 + 4) = 0;
              *(_DWORD *)(v16 + 12) = 0;
              LODWORD(Environment) = v18;
              v17 = RtlpCallQueryRegistryRoutine(
                      KeyHandle,
                      v5,
                      (_KEY_VALUE_FULL_INFORMATION *)v16,
                      &Environment,
                      v4,
                      ResultLength,
                      v23);
              LODWORD(pStatus) = v17;
            }
            if( v17 != -1073741789 )
              goto LABEL_36;
          }
          else
          {
            if( *(_DWORD *)(v16 + 4) == 7 )
            {
              *(_WORD *)((unsigned int)Environment + v16) = 0;
              *(_DWORD *)(v16 + 12) += 2;
            }
            LODWORD(Environment) = v18;
            v22 = RtlpCallQueryRegistryRoutine(
                    KeyHandle,
                    v5,
                    (_KEY_VALUE_FULL_INFORMATION *)v16,
                    &Environment,
                    v4,
                    ResultLength,
                    ValidateKeyTrust);
            LODWORD(pStatus) = v22;
            v17 = v22;
            if( v22 != -1073741789 )
            {
              v6 = 0;
              if( v22 < 0 )
                goto LABEL_8;
              if( (v5->Flags & 0x40) != 0 )
                ZwDeleteValueKey(KeyHandle, &ValueName);
LABEL_31:
              if( v17 >= 0 )
              {
                ++v5;
                goto LABEL_6;
              }
              goto LABEL_8;
            }
          }
          v17 = Environment + 10;
          PAllocLength = (unsigned int)Environment + 10i64;
          LODWORD(v24) = RtlpAllocDeallocQueryBuffer(&PAllocLength, (PVOID)v16, v15, (INT64)&pStatus);
          v16 = v24;
          if( !v24 )
          {
            LOBYTE(v17) = pStatus;
            goto LABEL_8;
          }
          v18 = v17 - 2;
          *(_DWORD *)(v24 + 8) = 0;
          LOBYTE(v17) = pStatus;
        }
      }
      if( (Flags & 8) != 0 )
      {
        v17 = v5->QueryRoutine(0i64, 0, 0i64, 0, v4, v5->EntryContext);
        goto LABEL_31;
      }
    }
    v25 = 0;
    while( 1 )
    {
      LODWORD(Length) = v18;
      v17 = ZwEnumerateValueKey(KeyHandle, v6, KeyValueFullInformation, (VOID *)v16, Length, &Environment);
      if( v17 == -2147483643 )
        v17 = -1073741789;
      LODWORD(pStatus) = v17;
      if( v17 == -2147483622 )
      {
        if( v6 || (v5->Flags & 4) == 0 )
        {
          v6 = 0;
          v17 = 0;
        }
        else
        {
          v17 = -1073741772;
          v6 = 0;
        }
        v4 = Context;
        goto LABEL_31;
      }
      if( v17 >= 0 )
      {
        LODWORD(Environment) = v18;
        v17 = RtlpCallQueryRegistryRoutine(
                KeyHandle,
                v5,
                (_KEY_VALUE_FULL_INFORMATION *)v16,
                &Environment,
                Context,
                ResultLengtha,
                ValidateKeyTrust);
        LODWORD(pStatus) = v17;
      }
      if( v17 == -1073741789 )
      {
        v26 = Environment + 10;
        PAllocLength = (unsigned int)Environment + 10i64;
        LODWORD(v27) = RtlpAllocDeallocQueryBuffer(&PAllocLength, (PVOID)v16, v15, (INT64)&pStatus);
        v16 = v27;
        if( !v27 )
          goto LABEL_75;
        *(_DWORD *)(v27 + 8) = 0;
        v18 = v26 - 2;
        v28 = v25;
        --v6;
        ++v25;
        if( v28 > 4 )
        {
          DbgPrint("RtlpQueryRegistryValues: Miscomputed buffer size at line %d\n", 1457i64);
LABEL_75:
          v17 = pStatus;
          v4 = Context;
LABEL_36:
          v6 = 0;
          goto LABEL_31;
        }
      }
      else
      {
        if( v17 < 0 )
          goto LABEL_8;
        v25 = 0;
        if( (v5->Flags & 0x40) != 0 )
        {
          ValueName.Buffer = (wchar_t *)(v16 + 20);
          ValueName.Length = *(_WORD *)(v16 + 16);
          ValueName.MaximumLength = *(_WORD *)(v16 + 16);
          if( ZwDeleteValueKey(KeyHandle, &ValueName) >= 0 )
            --v6;
        }
      }
      ++v6;
    }
  }
  if( !v11 )
    ZwClose(Handle);
  LOBYTE(RegistryHandle) = pStatus;
  return RegistryHandle;
}

Referenced by:

EtwStartAutoLogger
EtwpEnableAutoLoggerProvider
EtwpGetAutoLoggerEventNameFilter
EtwpGetAutoLoggerLevelKwFilter
EtwpGetAutoLoggerProviderFilter
EtwpGetPmcCpuHierarchyRegistry
EtwpLoadMicroarchitecturalProfileGroup
EtwpLoadMicroarchitecturalProfileSource
ExpGetNumberOfInitialSessionsFromRegistry
ExpPcwDisabledStatus
IopQueryPassiveInterruptRegistryOptions
PerfDiagpUpdatePerfDiagLoggerEnableFlags
PiCreateDriverSwDeviceCallback
PiDevCfgClearDeviceMigrationNode
PiDevCfgConfigureDevice
PiDevCfgQueryDeviceMigrationNode
PiDevCfgQueryDriverConfiguration
PiDevCfgQueryDriverNode
PiDrvDbQuerySystemPathWin32
PpmRegisterSpmSettings
PspQueryForwardersEnabled
PspSiloGetMultiUserTsFromRegistry
PspSiloGetSuiteMaskStringFromRegistry
RtlQueryRegistryValues
RtlQueryRegistryValuesEx
RtlSetActiveTimeBias
RtlpQueryTimeZoneInformationWorker
RtlpUpdateDynamicTimeZones
SmKmRegParamsLoad
SshpQueryRegistryValues
VRegSetup
WmipGetGuidSecurityDescriptor
WmipQueryWmiDataBlock