NtCreateKeyTransacted
NTSTATUS __stdcall NtCreateKeyTransacted(
PVOID *KeyHandle,
UINT64 DesiredAccess,
_OBJECT_ATTRIBUTES *ObjectAttributes,
UINT64 TitleIndex,
_UNICODE_STRING *Class,
UINT64 CreateOptions,
PVOID TransactionHandle,
UINT64 *Disposition){
_ETHREAD *CurrentThread;
unsigned int v10;
bool v12;
KPROCESSOR_MODE v13;
NTSTATUS v14;
INT64 v15;
INT64 Trans;
NTSTATUS Key;
NTSTATUS v19;
INT64 v20;
PVOID Object;
PVOID v22;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v10 = DesiredAccess;
--*((_WORD *)CurrentThread + 242);
v12 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
if( !v12 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( !v12 )
return -1073741431;
v13 = *((_BYTE *)KeGetCurrentThread() + 562);
Object = 0i64;
v14 = ObReferenceObjectByHandle(TransactionHandle, 4u, CmRegistryTransactionType, v13, &Object, 0i64);
Trans = (INT64)Object;
Key = v14;
if( v14 == -1073741788 )
{
v22 = 0i64;
v19 = ObReferenceObjectByHandle(
TransactionHandle,
4u,
(POBJECT_TYPE)TmTransactionObjectType,
*((_BYTE *)KeGetCurrentThread() + 562),
&v22,
0i64);
Trans = (INT64)v22;
Key = v19;
LABEL_7:
if( Key >= 0 )
{
LODWORD(v20) = CreateOptions;
Key = CmCreateKey(KeyHandle, v10, ObjectAttributes, v15, Class, v20, Disposition, (_CM_TRANS_PTR)Trans);
}
goto LABEL_9;
}
if( v14 >= 0 )
{
Trans = (unsigned __int64)Object | 1;
goto LABEL_7;
}
LABEL_9:
if( Trans )
CmpTransDereferenceTransaction(Trans);
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return Key;
}Referenced by:
No references.