TtmpGetConfigOverride

CHAR __fastcall TtmpGetConfigOverride(INT64 a1, const WCHAR *a2, _DWORD *a3){
  WCHAR v5; 
  NTSTATUS v6; 
  ULONG ResultLength; 
  void *KeyHandle; 
  struct _UNICODE_STRING DestinationString; 
  struct _UNICODE_STRING ValueName; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int128 KeyValueInformation; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  KeyHandle = 0i64;
  ResultLength = 0;
  DestinationString = 0i64;
  ValueName = 0i64;
  KeyValueInformation = 0i64;
  RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Power", (WCHAR)a3);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = &DestinationString;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 576;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) >= 0
    && (RtlInitUnicodeString(&ValueName, a2, v5),
        v6 = ZwQueryValueKey(
               KeyHandle,
               &ValueName,
               KeyValuePartialInformation,
               &KeyValueInformation,
               0x10u,
               &ResultLength),
        ZwClose(KeyHandle),
        v6 >= 0)
    && *(_QWORD *)((char *)&KeyValueInformation + 4) == 0x400000004i64 )
  {
    *a3 = HIDWORD(KeyValueInformation);
    return 1;
  }
  else
  {
    *a3 = 0;
    return 0;
  }
}

Referenced by:

TtmpInitializeWatchdogTimeouts