BiIsVolumePartitionInformationRetained
UINT8 __stdcall BiIsVolumePartitionInformationRetained(PWCHAR VolumeName){
WCHAR v1;
NTSTATUS v2;
bool v3;
struct _IO_STATUS_BLOCK IoStatusBlock;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
UNICODE_STRING FileHandle;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
*(_QWORD *)&FileHandle.Length = 0i64;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, VolumeName, v1);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
IoStatusBlock = 0i64;
v2 = ZwOpenFile(&FileHandle, (PWCHAR)0x80100000i64);
if( v2 >= 0 )
{
IoStatusBlock = 0i64;
v2 = ZwDeviceIoControlFile(
*(HANDLE *)&FileHandle.Length,
0i64,
0i64,
0i64,
&IoStatusBlock,
0x560028u,
0i64,
0,
0i64,
0);
}
v3 = v2 >= 0;
if( *(_QWORD *)&FileHandle.Length )
ZwClose(*(HANDLE *)&FileHandle.Length);
return v3;
}Referenced by:
BiConvertNtDeviceToBootEnvironment