NtOpenRegistryTransaction

NTSTATUS __stdcall NtOpenRegistryTransaction(
        PVOID *TransactionHandle,
        UINT64 DesiredAccess,
        _OBJECT_ATTRIBUTES *ObjectAttributes){
  DWORD v4; 
  _ETHREAD *CurrentThread; 
  bool v7; 
  int v8; 
  char v9; 
  __int64 v10; 
  void *Handle[5]; 
  v4 = DesiredAccess;
  Handle[0] = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  v7 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
  if( !v7 )
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  if( v7 )
  {
    v9 = *((_BYTE *)KeGetCurrentThread() + 562);
    if( v9 == 1 )
    {
      v10 = 0x7FFFFFFF0000i64;
      if( (unsigned __int64)TransactionHandle < 0x7FFFFFFF0000i64 )
        v10 = (__int64)TransactionHandle;
      *(_QWORD *)v10 = 0i64;
    }
    else
    {
      *TransactionHandle = 0i64;
    }
    v8 = ObOpenObjectByName((__int64)ObjectAttributes, (__int64)CmRegistryTransactionType, v9, 0i64, v4, 0i64, Handle);
    if( v8 >= 0 )
    {
      *TransactionHandle = Handle[0];
      Handle[0] = 0i64;
      v8 = 0;
    }
  }
  else
  {
    v8 = -1073741431;
  }
  if( Handle[0] )
    NtClose(Handle[0]);
  if( v7 )
  {
    ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  }
  return v8;
}

Referenced by:

No references.