PopInitializePowerButtonHold
VOID __fastcall PopInitializePowerButtonHold(INT64 a1){
WCHAR v1;
UINT64 v2;
void *KeyHandle;
UINT64 v4;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
WCHAR SourceString[264];
KeyHandle = 0i64;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
DestinationString = 0i64;
if( (_DWORD)a1 )
{
if( (_DWORD)a1 == 1 )
{
LODWORD(v2) = 520;
if( (int)RtlGetPersistedStateLocation(
(WCHAR *)L"PowerButtonBugcheckSettings",
0i64,
L"\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\POWER",
0i64,
SourceString,
v2,
&v4) >= 0 )
{
RtlInitUnicodeString(&DestinationString, SourceString, v1);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(&KeyHandle, 0x11u, &ObjectAttributes) >= 0 )
{
*(_QWORD *)PopPowerButtonBugcheckWatchWorkItem = 0i64;
qword_140C206D0 = (__int64)PopPowerButtonBugcheckWatchCallback;
qword_140C206D8 = (__int64)KeyHandle;
PopPowerButtonBugcheckConfigure(KeyHandle);
}
}
}
}
else
{
PopAcpiPdttSupportEnabled = 0;
PopPowerButtonBugcheckConfig = 0;
PopPowerButtonBugcheckLock = 0i64;
memset((INT64)&qword_140C205E8, 0i64);
memset((INT64)&PopPowerButtonTriageBlock, 0i64);
dword_140C20730 = 0;
dword_140C20734 = 0;
PopPowerButtonHold = 0i64;
qword_140C20740 = (__int64)&PopBlackBoxEntries;
LODWORD(PopPowerButtonTriageBlock) = 2;
dword_140C20748 = 22;
PopInitializeWorkItem((INT64)&qword_140C20670, (INT64)PopPowerButtonWorkCallback, 0i64);
}
}Referenced by:
PoInitSystem