NtDeleteBootEntry

NTSTATUS __stdcall NtDeleteBootEntry(UINT64 Id){
  int v1; 
  INT8 v3; 
  _ETHREAD *CurrentThread; 
  NTSTATUS EnvironmentVariable; 
  UINT64 Attributes; 
  UINT64 ValueLength; 
  wchar_t Dst[12]; 
  v1 = Id;
  if( dword_140C19650 != 2 )
    return -1073741822;
  if( (unsigned int)Id > 0xFFFF )
    return -1073741811;
  v3 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v3 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemEnvironmentPrivilege, v3) )
    return -1073741727;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquireFastMutexUnsafe(&ExpEnvironmentLock);
  swprintf_s(Dst, 9ui64, (WCHAR *)L"Boot%04X");
  LODWORD(ValueLength) = 0;
  EnvironmentVariable = IoGetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, &ValueLength, 0i64);
  if( EnvironmentVariable != -1073741568 )
    goto LABEL_11;
  if( ((2 * ((v1 | (2 * v1)) & 0xC4444444)) & v1) != 0 )
  {
    swprintf_s(Dst, 9ui64, (WCHAR *)L"Boot%04x");
    LODWORD(ValueLength) = 0;
    EnvironmentVariable = IoGetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, &ValueLength, 0i64);
LABEL_11:
    if( !EnvironmentVariable || EnvironmentVariable == -1073741789 )
    {
      LODWORD(Attributes) = 1;
      EnvironmentVariable = IoSetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, 0i64, Attributes);
    }
  }
  ExReleaseFastMutexUnsafe(&ExpEnvironmentLock);
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  return EnvironmentVariable;
}

Referenced by:

No references.