PopReadShutdownPolicy

INT64 __stdcall PopReadShutdownPolicy(){
  WCHAR v0; 
  INT64 result; 
  WCHAR v2; 
  ULONG ResultLength; 
  void *KeyHandle; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int128 KeyValueInformation; 
  int v8; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  KeyHandle = 0i64;
  ResultLength = 0;
  DestinationString = 0i64;
  v8 = 0;
  KeyValueInformation = 0i64;
  RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT", v0);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = &DestinationString;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 576;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  LODWORD(result) = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
  if( (int)result >= 0 )
  {
    RtlInitUnicodeString(&DestinationString, L"DontPowerOffAfterShutdown", v2);
    if( ZwQueryValueKey(
           KeyHandle,
           &DestinationString,
           KeyValuePartialInformation,
           &KeyValueInformation,
           0x14u,
           &ResultLength) >= 0
      && DWORD1(KeyValueInformation) == 4 )
    {
      PopShutdownPowerOffPolicy = BYTE12(KeyValueInformation) == 1;
    }
    LODWORD(result) = ZwClose(KeyHandle);
  }
  return result;
}

Referenced by:

PopTransitionSystemPowerStateEx