NtDeleteBootEntry
NTSTATUS __stdcall NtDeleteBootEntry(UINT64 Id){
int v1;
INT8 v3;
_ETHREAD *CurrentThread;
NTSTATUS EnvironmentVariable;
UINT64 Attributes;
UINT64 ValueLength;
wchar_t Dst[12];
v1 = Id;
if( dword_140C19650 != 2 )
return -1073741822;
if( (unsigned int)Id > 0xFFFF )
return -1073741811;
v3 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v3 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemEnvironmentPrivilege, v3) )
return -1073741727;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquireFastMutexUnsafe(&ExpEnvironmentLock);
swprintf_s(Dst, 9ui64, (WCHAR *)L"Boot%04X");
LODWORD(ValueLength) = 0;
EnvironmentVariable = IoGetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, &ValueLength, 0i64);
if( EnvironmentVariable != -1073741568 )
goto LABEL_11;
if( ((2 * ((v1 | (2 * v1)) & 0xC4444444)) & v1) != 0 )
{
swprintf_s(Dst, 9ui64, (WCHAR *)L"Boot%04x");
LODWORD(ValueLength) = 0;
EnvironmentVariable = IoGetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, &ValueLength, 0i64);
LABEL_11:
if( !EnvironmentVariable || EnvironmentVariable == -1073741789 )
{
LODWORD(Attributes) = 1;
EnvironmentVariable = IoSetEnvironmentVariableEx(Dst, (GUID *)&EfiBootVariablesGuid, 0i64, 0i64, Attributes);
}
}
ExReleaseFastMutexUnsafe(&ExpEnvironmentLock);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return EnvironmentVariable;
}Referenced by:
No references.