NtGetMUIRegistryInfo

NTSTATUS __stdcall NtGetMUIRegistryInfo(UINT64 Flags, UINT64 *DataSize, VOID *Data){
  __int64 v5; 
  __int64 v6; 
  int v7; 
  _ETHREAD *CurrentThread; 
  char v9; 
  NTSTATUS v10; 
  unsigned int v12; 
  unsigned int Length; 
  HANDLE Handle; 
  struct _KEVENT *StartContext; 
  void *v16; 
  __int64 v17; 
  int v18; 
  int v19; 
  int v20; 
  int v21; 
  NTSTATUS v22; 
  int v23; 
  struct _KEVENT Event; 
  OBJECT_ATTRIBUTES ObjectAttributes; 
  char v26; 
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  memset(&Event, 0, sizeof(Event));
  Handle = 0i64;
  v23 = 0;
  v26 = 0;
  if( !*((_BYTE *)KeGetCurrentThread() + 562) || InitSafeBootMode )
    goto LABEL_46;
  if( !DataSize )
  {
    if( (Flags & 0xA) == 0 )
      goto LABEL_47;
    Length = 0;
    v5 = 0x7FFFFFFF0000i64;
    goto LABEL_11;
  }
  v5 = 0x7FFFFFFF0000i64;
  v6 = 0x7FFFFFFF0000i64;
  if( (unsigned __int64)DataSize < 0x7FFFFFFF0000i64 )
    v6 = (__int64)DataSize;
  Length = *(_DWORD *)v6;
  if( !*(_DWORD *)v6 )
  {
LABEL_11:
    if( Data )
      goto LABEL_47;
    goto LABEL_12;
  }
  if( !Data )
    goto LABEL_47;
LABEL_12:
  v7 = 1;
  if( (_DWORD)Flags )
    v7 = Flags;
  if( (v7 & 0xFFFFFFF4) != 0 )
    goto LABEL_47;
  if( !MUIRegistryLock )
  {
    v10 = MUIInitializeResourceLock(&MUIRegistryLock);
    if( (v10 & 0xC0000000) == -1073741824 )
      goto LABEL_27;
  }
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquireResourceExclusiveLite(MUIRegistryLock, 1u);
  v26 = 1;
  if( MUIRegistryInfo == (PVOID)-1i64 )
  {
    if( (v7 & 2) != 0 )
    {
      MUIRegistryInfo = 0i64;
      *(_DWORD *)MUIRegistryInfoSize = 0;
LABEL_45:
      v10 = 0;
      goto LABEL_27;
    }
LABEL_46:
    v10 = -1073741823;
    goto LABEL_27;
  }
  if( (v7 & 1) == 0 )
  {
    if( (v7 & 2) != 0 )
    {
      if( MUIRegistryInfo )
      {
        ExFreePoolWithTag(MUIRegistryInfo, 0);
        MUIRegistryInfo = 0i64;
        *(_DWORD *)MUIRegistryInfoSize = 0;
        if( (v7 & 8) != 0 )
          ++KUSER_SHARED_DATA.LangGenerationCount;
      }
      goto LABEL_45;
    }
    if( (v7 & 8) != 0 )
    {
      v12 = ++KUSER_SHARED_DATA.LangGenerationCount;
      if( MUIRegistryInfo )
        *((_DWORD *)MUIRegistryInfo + 3) = v12;
      goto LABEL_45;
    }
LABEL_47:
    v10 = -1073741811;
    goto LABEL_27;
  }
  v9 = 0;
  if( MUIRegistryInfo )
    goto LABEL_19;
  KeInitializeEvent(&Event, SynchronizationEvent, 0);
  StartContext = &Event;
  v16 = 0i64;
  v17 = 0i64;
  v18 = (unsigned __int16)PsInstallUILanguageId;
  v19 = 0;
  v20 = (unsigned __int16)PsMachineUILanguageId;
  v21 = 0;
  v22 = -1073741823;
  ObjectAttributes.Length = 48;
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.Attributes = 512;
  ObjectAttributes.ObjectName = 0i64;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  v10 = PsCreateSystemThreadEx(
          &Handle,
          0x1FFFFFui64,
          &ObjectAttributes,
          0i64,
          0i64,
          (PKSTART_ROUTINE)MUIRegistrySystemRoutine,
          &StartContext,
          0i64,
          0i64);
  if( v10 >= 0 )
  {
    ZwClose(Handle);
    v10 = KeWaitForSingleObject(&Event, Executive, 0, 0, 0i64);
    if( v10 >= 0 )
    {
      v10 = v22;
      if( v22 < 0 )
      {
LABEL_54:
        MUIRegistryInfo = (PVOID)-1i64;
        *(_DWORD *)MUIRegistryInfoSize = 0;
        goto LABEL_27;
      }
      MUIRegistryInfo = v16;
      *(_DWORD *)MUIRegistryInfoSize = v17;
      if( !HIDWORD(v17) )
        MUIBugCheck(32770i64);
      if( !v19 )
      {
        if( PsUILanguageComitted )
          MUIBugCheck(32769i64);
        MigrateOOBELanguageToInstallationLanguage();
      }
      if( !v21 )
        PsMachineUILanguageId = PsInstallUILanguageId;
    }
  }
  if( v10 < 0 )
    goto LABEL_54;
LABEL_19:
  if( Length )
  {
    if( Length < *(_DWORD *)MUIRegistryInfoSize )
    {
      v10 = -1073741789;
      goto LABEL_23;
    }
    v9 = 1;
  }
  v10 = 0;
LABEL_23:
  if( (unsigned __int64)DataSize < 0x7FFFFFFF0000i64 )
    v5 = (__int64)DataSize;
  *(_DWORD *)v5 = *(_DWORD *)v5;
  *(_DWORD *)DataSize = *(_DWORD *)MUIRegistryInfoSize;
  if( v9 )
  {
    ProbeForWrite(Data, Length, 1ui64);
    memset((INT64)Data, 0i64);
    memmove((UINT8 *)Data, (UINT8 *)MUIRegistryInfo, *(unsigned int *)MUIRegistryInfoSize);
  }
LABEL_27:
  if( v26 )
  {
    ExReleaseResourceLite(MUIRegistryLock);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  }
  return v10;
}

Referenced by:

No references.