NtOpenRegistryTransaction
NTSTATUS __stdcall NtOpenRegistryTransaction(
PVOID *TransactionHandle,
UINT64 DesiredAccess,
_OBJECT_ATTRIBUTES *ObjectAttributes){
DWORD v4;
_ETHREAD *CurrentThread;
bool v7;
int v8;
char v9;
__int64 v10;
void *Handle[5];
v4 = DesiredAccess;
Handle[0] = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v7 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
if( !v7 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( v7 )
{
v9 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v9 == 1 )
{
v10 = 0x7FFFFFFF0000i64;
if( (unsigned __int64)TransactionHandle < 0x7FFFFFFF0000i64 )
v10 = (__int64)TransactionHandle;
*(_QWORD *)v10 = 0i64;
}
else
{
*TransactionHandle = 0i64;
}
v8 = ObOpenObjectByName((__int64)ObjectAttributes, (__int64)CmRegistryTransactionType, v9, 0i64, v4, 0i64, Handle);
if( v8 >= 0 )
{
*TransactionHandle = Handle[0];
Handle[0] = 0i64;
v8 = 0;
}
}
else
{
v8 = -1073741431;
}
if( Handle[0] )
NtClose(Handle[0]);
if( v7 )
{
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}
return v8;
}Referenced by:
No references.