PopReadShutdownPolicy
INT64 __stdcall PopReadShutdownPolicy(){
WCHAR v0;
INT64 result;
WCHAR v2;
ULONG ResultLength;
void *KeyHandle;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int128 KeyValueInformation;
int v8;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
KeyHandle = 0i64;
ResultLength = 0;
DestinationString = 0i64;
v8 = 0;
KeyValueInformation = 0i64;
RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT", v0);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
LODWORD(result) = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( (int)result >= 0 )
{
RtlInitUnicodeString(&DestinationString, L"DontPowerOffAfterShutdown", v2);
if( ZwQueryValueKey(
KeyHandle,
&DestinationString,
KeyValuePartialInformation,
&KeyValueInformation,
0x14u,
&ResultLength) >= 0
&& DWORD1(KeyValueInformation) == 4 )
{
PopShutdownPowerOffPolicy = BYTE12(KeyValueInformation) == 1;
}
LODWORD(result) = ZwClose(KeyHandle);
}
return result;
}Referenced by:
PopTransitionSystemPowerStateEx