PopOpenThermalLoggingKey

INT64 __fastcall PopOpenThermalLoggingKey(CHAR a1, PVOID *a2, WCHAR a3){
  int PersistedStateLocation; 
  WCHAR v5; 
  int v6; 
  UINT64 CreateOptions; 
  void *KeyHandle; 
  UINT64 v10; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  WCHAR SourceString[264]; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  KeyHandle = 0i64;
  DestinationString = 0i64;
  if( a1 )
  {
    RtlInitUnicodeString(
      &DestinationString,
      L"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Power\\LastThermalEvent",
      a3);
    v6 = 1;
  }
  else
  {
    LODWORD(CreateOptions) = 520;
    PersistedStateLocation = RtlGetPersistedStateLocation(
                               (WCHAR *)L"ThermalLogging",
                               0i64,
                               L"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Power",
                               0i64,
                               SourceString,
                               CreateOptions,
                               &v10);
    if( PersistedStateLocation < 0 )
      return(unsigned int)PersistedStateLocation;
    RtlInitUnicodeString(&DestinationString, SourceString, v5);
    v6 = 0;
  }
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = &DestinationString;
  LODWORD(CreateOptions) = v6;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 576;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  PersistedStateLocation = ZwCreateKey(&KeyHandle, 0x2001Fui64, &ObjectAttributes, 0i64, 0i64, CreateOptions, 0i64);
  if( PersistedStateLocation >= 0 )
    *a2 = KeyHandle;
  return(unsigned int)PersistedStateLocation;
}

Referenced by:

PopThermalHandlePreviousShutdown
PopThermalWriteShutdownToRegistry