NtRestoreKey

NTSTATUS __stdcall NtRestoreKey(PVOID KeyHandle, PVOID FileHandle, UINT64 Flags){
  char v3; 
  int v4; 
  INT8 v7; 
  _ETHREAD *CurrentThread; 
  NTSTATUS v9; 
  INT8 v10; 
  PVOID *v11; 
  NTSTATUS v12; 
  HANDLE v13; 
  NTSTATUS v14; 
  struct _DMA_ADAPTER *v15; 
  _ETHREAD *v16; 
  SLIST_ENTRY *v17; 
  SLIST_ENTRY *v18; 
  int v19; 
  HANDLE Handle; 
  PADAPTER_OBJECT DmaAdapter; 
  INT64 a6[2]; 
  SLIST_ENTRY *Argument[2]; 
  __int128 v25; 
  __int128 v26; 
  KAPC_STATE ApcState; 
  DmaAdapter = 0i64;
  Handle = 0i64;
  a6[1] = (INT64)a6;
  *(_OWORD *)Argument = 0i64;
  v3 = 0;
  a6[0] = (INT64)a6;
  v4 = Flags;
  v25 = 0i64;
  v26 = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  v7 = *((_BYTE *)KeGetCurrentThread() + 562);
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown) )
  {
    v9 = CmCheckNoTxContext();
    if( v9 < 0 )
    {
LABEL_27:
      ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
      KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
      return v9;
    }
    if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeRestorePrivilege, v7) )
    {
      v9 = -1073741727;
      goto LABEL_27;
    }
    if( v7 == 1 )
    {
      v12 = IoConvertFileHandleToKernelHandle(FileHandle, 1, 1ui64, 0, &Handle);
      v13 = Handle;
      v9 = v12;
      if( v12 < 0 )
      {
LABEL_24:
        if( v13 && v13 != FileHandle )
          ZwClose(v13);
        goto LABEL_27;
      }
    }
    else
    {
      v13 = FileHandle;
      Handle = FileHandle;
    }
    LOBYTE(v11) = v7;
    v14 = CmObReferenceObjectByHandle(KeyHandle, 0i64, v10, v11, (OBJECT_HANDLE_INFORMATION *)&DmaAdapter);
    v15 = DmaAdapter;
    v9 = v14;
    if( v14 < 0 )
    {
LABEL_22:
      if( v15 )
        HalPutDmaAdapter(v15);
      goto LABEL_24;
    }
    if( (LODWORD(DmaAdapter->DmaOperations->PutDmaAdapter) & 0x80u) != 0 )
    {
      v9 = -1073741790;
      goto LABEL_22;
    }
    v16 = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)v16 + 242);
    v17 = (SLIST_ENTRY *)DmaAdapter;
    v18 = (SLIST_ENTRY *)Handle;
    if( CmpCallBackCount && !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
    {
      Argument[0] = v17;
      Argument[1] = v18;
      LODWORD(v25) = v4;
      v19 = CmpCallCallBacksEx(RegNtPreRestoreKey, Argument, 0i64, 1, RegNtPostRestoreKey, 0i64, (INT64)a6);
      v9 = v19;
      if( v19 < 0 )
      {
        if( v19 == -1073740541 )
          v9 = 0;
LABEL_21:
        KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
        v15 = DmaAdapter;
        v13 = Handle;
        goto LABEL_22;
      }
      v3 = 1;
    }
    CmpAttachToRegistryProcess(&ApcState);
    v9 = CmRestoreKey(v17, v18, v4, v7);
    KiUnstackDetachProcess(&ApcState, 0i64);
    if( v3 )
      v9 = CmPostCallbackNotificationEx(RegNtPostRestoreKey, v17, (unsigned int)v9, (INT64)Argument, 0i64, (INT64)a6);
    goto LABEL_21;
  }
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  return -1073741431;
}

Referenced by:

No references.