NtClose

NTSTATUS __fastcall NtClose(UINT64 a1){
  UINT64 v1; 
  char PreviousMode; 
  _ETHREAD *CurrentThread; 
  char v4; 
  _EPROCESS *Process; 
  PEPROCESS v6; 
  _HANDLE_TABLE *ObjectTable; 
  _HANDLE_TABLE_ENTRY *v8; 
  _HANDLE_TABLE_ENTRY *v9; 
  NTSTATUS v10; 
  VOID *v12; 
  UINT8 HandleExceptionsPermanent; 
  UINT8 HandleExceptionsOn; 

  v1 = a1;
  PreviousMode = KeGetCurrentThread()->PreviousMode;
  if( (MmVerifierData & 0x100) != 0 && !PreviousMode && !ObpIsKernelHandle((PVOID)a1, 0) )
    VfCheckUserHandle(v12);
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v4 = 0;
  Process = CurrentThread->Tcb.ApcState.Process;
  HandleExceptionsPermanent = 0;
  if( ObpIsKernelHandle((PVOID)v1, PreviousMode) )
  {
    ObjectTable = HandleTable;
    v1 ^= 0xFFFFFFFF80000000ui64;
    v6 = PsInitialSystemProcess;
  }
  else
  {
    v6 = Process;
    if( KeGetCurrentThread()->ApcStateIndex != 1 )
    {
      ObjectTable = Process->ObjectTable;
      if( ObjectTable != HandleTable )
        goto LABEL_5;
      return -1073741816;
    }
    ObjectTable = ObReferenceProcessHandleTable(Process);
    if( !ObjectTable )
      return -1073741816;
    v4 = 1;
  }
LABEL_5:
  --CurrentThread->Tcb.KernelApcDisable;
  if( (v1 & 0x3FC) != 0 )
  {
    v8 = ExpLookupHandleTableEntry(ObjectTable, (_EXHANDLE)v1);
    v9 = v8;
    if( v8 )
    {
      if( ExLockHandleTableEntry(ObjectTable, v8) )
      {
        v10 = ObCloseHandleTableEntry(ObjectTable, v9, v6, (PVOID)v1, PreviousMode, 0);
        goto LABEL_9;
      }
    }
  }
  KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
  if( v1 >= 0xFFFFFFFFFFFFFFFAui64 || v1 == 0 )
    goto LABEL_14;
  ExQueryHandleExceptionsPermanency(ObjectTable, &HandleExceptionsOn, &HandleExceptionsPermanent);
  if( (ObjectTable->Flags & 0x10) != 0 && HandleExceptionsPermanent )
    ExHandleLogBadReference(ObjectTable, (VOID *)v1, PreviousMode);
  if( !PreviousMode )
  {
    if( (CurrentThread->CrossThreadFlags & 1) == 0 && Process->Peb && (_BYTE)KdDebuggerEnabled )
      KeBugCheckEx(0x93u, (PVOID)v1, (PVOID)1, 0i64, 0i64);
    goto LABEL_14;
  }
  if( (NtGlobalFlag & 0x400000) == 0 && !Process->DebugPort && !ObjectTable->DebugInfo )
  {
LABEL_14:
    v10 = -1073741816;
    if( v1 + 6 <= 5 )
      v10 = 0;
    goto LABEL_9;
  }
  if( KeGetCurrentThread()->ApcStateIndex == 1 )
    v10 = -1073741816;
  else
    v10 = KeRaiseUserException(3221225480i64);
LABEL_9:
  if( v4 )
    ExReleaseRundownProtection(&v6->RundownProtect);
  return v10;
}

Referenced by:

AdtpInitializeDriveLetters
AdtpObjsInitialize
AlpcpAcceptConnectPort
AlpcpConnectPort
CreateSystemRootLink
EtwpSetCoverageSamplerInformation
ExpInitializeCallbacks
ExpWatchLicenseInfoWork
ExpWatchProductTypeInitialization
FsRtlInitializeSmssEvent
InitSafeBoot
IopApplySystemPartitionProt
IopConnectLinkTrackingPort
IopInitCrashDumpRegCallback
IopInitializeBuiltinDriver
IopProtectSystemPartition
IsMachineLanguageListInMutableLocation
NtCreateRegistryTransaction
NtOpenRegistryTransaction
NtSecureConnectPort
ObInitSystem
PfSnGetPrefetchInstructions
PfSnGetSectionObject
PfSnIsVolumeMounted
PfSnOpenVolumesForPrefetch
PfSnPopulateReadList
PfSnPrefetchMetadata
PfpFileBuildReadSupport
PfpPrefetchPrivatePages
PfpReadSupportCleanup
PfpSourceGetPrefetchSupport
PfpVolumeOpenAndVerify
PopEtEnergyTrackerCreate
RtlCreateSystemVolumeInformationFolder
RtlQueryValidationRunlevel
RtlpLoadLanguageConfigList
RtlpMuiRegLoadInstalledFromKey
RtlpRemovePendingDeleteLanguages
RtlpSysVolTakeOwnership
SepAdtInitializeAuditingOptions
SepRmCallLsa