SepSecureBootCorrectBcd
INT64 __fastcall SepSecureBootCorrectBcd(){
void *v0;
int updated;
GUID *PoolWithTag;
unsigned int v3;
unsigned __int16 *v4;
unsigned int v5;
PVOID v6;
_DWORD *v7;
__int64 v8;
unsigned int v10;
SIZE_T NumberOfBytes;
PVOID ObjectHandle;
VOID *StoreHandle;
ObjectHandle = 0i64;
v0 = 0i64;
v10 = 0;
LODWORD(NumberOfBytes) = 0;
StoreHandle = 0i64;
updated = BiAcquireBcdSyncMutant(0);
if( updated >= 0 )
{
updated = BiOpenSystemStore(&StoreHandle, 0i64);
BiReleaseBcdSyncMutant(0);
v0 = StoreHandle;
}
else
{
BiLogMessage();
}
if( updated >= 0 )
{
StoreHandle = (VOID *)1;
updated = BcdEnumerateObjects((__int64)v0, &StoreHandle, 0i64, (unsigned int *)&NumberOfBytes, &v10);
if( updated == -1073741789 )
{
PoolWithTag = (GUID *)ExAllocatePoolWithTag(PagedPool, (unsigned int)NumberOfBytes, 0x62536553ui64);
if( PoolWithTag )
{
updated = BcdEnumerateObjects((__int64)v0, &StoreHandle, PoolWithTag, (unsigned int *)&NumberOfBytes, &v10);
if( updated >= 0 )
{
v3 = 0;
if( v10 )
{
while( 1 )
{
NumberOfBytes = (SIZE_T)PoolWithTag + 24 * v3;
updated = BcdOpenObject(v0, (GUID *)NumberOfBytes, &ObjectHandle);
if( updated < 0 )
break;
v4 = (unsigned __int16 *)qword_140CF4AF8;
v5 = 0;
v6 = ObjectHandle;
if( *((_WORD *)qword_140CF4AF8 + 18) )
{
do
{
v7 = (_DWORD *)(qword_140CF9DA8 + 12i64 * v5);
if( !*v7 || *v7 == *(_DWORD *)(*(_QWORD *)(NumberOfBytes + 16) + 4i64) )
{
v8 = *(unsigned __int16 *)((unsigned int)v7[2] + qword_140CF9DA0);
if( ((v8 & 0x20) == 0 || (dword_140C54384 & 4) != 0)
&& ((v8 & 0x40) == 0 || (dword_140C54384 & 0x10) != 0) )
{
updated = SepSecureBootUpdateBcdDataForRule(qword_140CF9DA8 + 12i64 * v5, v6, v8);
if( updated < 0 )
goto LABEL_24;
v4 = (unsigned __int16 *)qword_140CF4AF8;
}
}
++v5;
}
while( v5 < v4[18] );
}
BcdCloseObject(v6);
v6 = 0i64;
++v3;
ObjectHandle = 0i64;
if( v3 >= v10 )
goto LABEL_24;
}
v6 = ObjectHandle;
LABEL_24:
if( v6 )
BcdCloseObject(v6);
}
}
ExFreePoolWithTag(PoolWithTag, 0x62536553u);
}
else
{
updated = -1073741801;
}
}
}
if( v0 )
BcdCloseStore(v0);
return(unsigned int)updated;
}Referenced by:
NtFilterBootOption