NtSaveKeyEx

NTSTATUS __stdcall NtSaveKeyEx(VOID *KeyHandle, VOID *FileHandle, UINT64 Format){
  int v3; 
  char PreviousMode; 
  _ETHREAD *CurrentThread; 
  NTSTATUS v8; 
  INT8 v9; 
  PVOID *v10; 
  NTSTATUS v11; 
  VOID *v12; 
  INT64 v13; 
  INT64 v14; 
  _ETHREAD *v15; 
  CM_KEY_BODY *v16; 
  _SLIST_ENTRY *v17; 
  int v18; 
  UINT64 v19; 
  unsigned int v20; 
  unsigned int v21; 
  VOID *Handle; 
  PADAPTER_OBJECT DmaAdapter; 
  INT64 a6[2]; 
  _SLIST_ENTRY *Argument[2]; 
  __int128 v27; 
  __int128 v28; 
  _KAPC_STATE ApcState; 

  DmaAdapter = 0i64;
  Handle = 0i64;
  a6[1] = (INT64)a6;
  *(_OWORD *)Argument = 0i64;
  v3 = Format;
  a6[0] = (INT64)a6;
  v27 = 0i64;
  v28 = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  PreviousMode = KeGetCurrentThread()->PreviousMode;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  if( !ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132) )
  {
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
    return -1073741431;
  }
  v8 = CmCheckNoTxContext();
  if( v8 >= 0 )
  {
    if( SeSinglePrivilegeCheck(*(_QWORD *)&SeBackupPrivilege, PreviousMode) )
    {
      if( ((v3 - 1) & 0xFFFFFFFC) == 0 && v3 != 3 )
      {
        if( PreviousMode == 1 )
        {
          v11 = IoConvertFileHandleToKernelHandle(FileHandle, 1, 2ui64, 0, &Handle);
          v12 = Handle;
          v8 = v11;
          if( v11 < 0 )
          {
LABEL_20:
            if( v12 && v12 != FileHandle )
              ZwClose((_HANDLE)v12);
            goto LABEL_23;
          }
        }
        else
        {
          v12 = FileHandle;
          Handle = FileHandle;
        }
        LOBYTE(v10) = PreviousMode;
        v8 = CmObReferenceObjectByHandle(KeyHandle, 0i64, v9, v10, (OBJECT_HANDLE_INFORMATION *)&DmaAdapter);
        if( v8 >= 0 )
        {
          v15 = (_ETHREAD *)KeGetCurrentThread();
          --v15->Tcb.KernelApcDisable;
          v16 = (CM_KEY_BODY *)DmaAdapter;
          v17 = (_SLIST_ENTRY *)Handle;
          if( dword_140C5083C
            && !ExIsResourceAcquiredSharedLite((UINT64)&CmpRegistryLock, v13, v14)
            && (Argument[0] = (_SLIST_ENTRY *)v16,
                Argument[1] = v17,
                LODWORD(v27) = v3,
                v18 = CmpCallCallBacksEx(RegNtPreSaveKey, Argument, 0i64, 1, RegNtPostSaveKey, 0i64, (INT64)a6),
                v8 = v18,
                v18 < 0) )
          {
            if( v18 == -1073740541 )
              v8 = 0;
          }
          else
          {
            CmpAttachToRegistryProcess(&ApcState);
            if( v3 == 4 )
            {
              v20 = CmDumpKey((__int64)v16, (__int64)v17, PreviousMode);
            }
            else
            {
              v19 = 5i64;
              if( v3 != 2 )
                v19 = 3i64;
              v20 = CmSaveKey(v16, v17, v19);
            }
            v21 = v20;
            KiUnstackDetachProcess(&ApcState, 0i64);
            v8 = CmPostCallbackNotificationEx(
                   RegNtPostSaveKey,
                   (_SLIST_ENTRY *)v16,
                   v21,
                   (INT64)Argument,
                   0i64,
                   (INT64)a6);
          }
          KeLeaveCriticalRegionThread(KeGetCurrentThread());
          v12 = Handle;
        }
        if( DmaAdapter )
          HalPutDmaAdapter(DmaAdapter);
        goto LABEL_20;
      }
      v8 = -1073741811;
    }
    else
    {
      v8 = -1073741727;
    }
  }
LABEL_23:
  ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
  KeLeaveCriticalRegionThread(KeGetCurrentThread());
  return v8;
}

Referenced by:

NtSaveKey