NtRestoreKey
NTSTATUS __stdcall NtRestoreKey(PVOID KeyHandle, PVOID FileHandle, UINT64 Flags){
char v3;
int v4;
INT8 v7;
_ETHREAD *CurrentThread;
NTSTATUS v9;
INT8 v10;
PVOID *v11;
NTSTATUS v12;
HANDLE v13;
NTSTATUS v14;
struct _DMA_ADAPTER *v15;
_ETHREAD *v16;
SLIST_ENTRY *v17;
SLIST_ENTRY *v18;
int v19;
HANDLE Handle;
PADAPTER_OBJECT DmaAdapter;
INT64 a6[2];
SLIST_ENTRY *Argument[2];
__int128 v25;
__int128 v26;
KAPC_STATE ApcState;
DmaAdapter = 0i64;
Handle = 0i64;
a6[1] = (INT64)a6;
*(_OWORD *)Argument = 0i64;
v3 = 0;
a6[0] = (INT64)a6;
v4 = Flags;
v25 = 0i64;
v26 = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
v7 = *((_BYTE *)KeGetCurrentThread() + 562);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown) )
{
v9 = CmCheckNoTxContext();
if( v9 < 0 )
{
LABEL_27:
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return v9;
}
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeRestorePrivilege, v7) )
{
v9 = -1073741727;
goto LABEL_27;
}
if( v7 == 1 )
{
v12 = IoConvertFileHandleToKernelHandle(FileHandle, 1, 1ui64, 0, &Handle);
v13 = Handle;
v9 = v12;
if( v12 < 0 )
{
LABEL_24:
if( v13 && v13 != FileHandle )
ZwClose(v13);
goto LABEL_27;
}
}
else
{
v13 = FileHandle;
Handle = FileHandle;
}
LOBYTE(v11) = v7;
v14 = CmObReferenceObjectByHandle(KeyHandle, 0i64, v10, v11, (OBJECT_HANDLE_INFORMATION *)&DmaAdapter);
v15 = DmaAdapter;
v9 = v14;
if( v14 < 0 )
{
LABEL_22:
if( v15 )
HalPutDmaAdapter(v15);
goto LABEL_24;
}
if( (LODWORD(DmaAdapter->DmaOperations->PutDmaAdapter) & 0x80u) != 0 )
{
v9 = -1073741790;
goto LABEL_22;
}
v16 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v16 + 242);
v17 = (SLIST_ENTRY *)DmaAdapter;
v18 = (SLIST_ENTRY *)Handle;
if( CmpCallBackCount && !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
{
Argument[0] = v17;
Argument[1] = v18;
LODWORD(v25) = v4;
v19 = CmpCallCallBacksEx(RegNtPreRestoreKey, Argument, 0i64, 1, RegNtPostRestoreKey, 0i64, (INT64)a6);
v9 = v19;
if( v19 < 0 )
{
if( v19 == -1073740541 )
v9 = 0;
LABEL_21:
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
v15 = DmaAdapter;
v13 = Handle;
goto LABEL_22;
}
v3 = 1;
}
CmpAttachToRegistryProcess(&ApcState);
v9 = CmRestoreKey(v17, v18, v4, v7);
KiUnstackDetachProcess(&ApcState, 0i64);
if( v3 )
v9 = CmPostCallbackNotificationEx(RegNtPostRestoreKey, v17, (unsigned int)v9, (INT64)Argument, 0i64, (INT64)a6);
goto LABEL_21;
}
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return -1073741431;
}Referenced by:
No references.