TtmpGetConfigOverride
CHAR __fastcall TtmpGetConfigOverride(INT64 a1, const WCHAR *a2, _DWORD *a3){
WCHAR v5;
NTSTATUS v6;
ULONG ResultLength;
void *KeyHandle;
struct _UNICODE_STRING DestinationString;
struct _UNICODE_STRING ValueName;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int128 KeyValueInformation;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
KeyHandle = 0i64;
ResultLength = 0;
DestinationString = 0i64;
ValueName = 0i64;
KeyValueInformation = 0i64;
RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Power", (WCHAR)a3);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) >= 0
&& (RtlInitUnicodeString(&ValueName, a2, v5),
v6 = ZwQueryValueKey(
KeyHandle,
&ValueName,
KeyValuePartialInformation,
&KeyValueInformation,
0x10u,
&ResultLength),
ZwClose(KeyHandle),
v6 >= 0)
&& *(_QWORD *)((char *)&KeyValueInformation + 4) == 0x400000004i64 )
{
*a3 = HIDWORD(KeyValueInformation);
return 1;
}
else
{
*a3 = 0;
return 0;
}
}Referenced by:
TtmpInitializeWatchdogTimeouts