RtlpOpenBaseImageFileOptionsKeyEx
NTSTATUS __fastcall RtlpOpenBaseImageFileOptionsKeyEx(_QWORD *a1, __int64 a2, __int64 a3, INT64 a4){
char PreviousMode;
unsigned int v6;
NTSTATUS result;
_OBJECT_ATTRIBUTES v8;
VOID *v9;
*(&v8.Attributes + 1) = 0;
v9 = 0i64;
PreviousMode = KeGetCurrentThread()->PreviousMode;
v6 = 1600;
*(_QWORD *)&v8.Length = 48i64;
v8.RootDirectory = 0i64;
if( PreviousMode != 1 )
v6 = 576;
v8.Attributes = v6;
*(_OWORD *)&v8.SecurityDescriptor = 0i64;
result = ZwOpenKey(
&v9,
9ui64,
&v8,
a4,
*(INT64 *)&v8.Length,
(INT64)v8.RootDirectory,
(INT64)&qword_140005A70,
*(INT64 *)&v8.Attributes);
if( result >= 0 )
{
*a1 = v9;
return 0;
}
return result;
}Referenced by:
RtlpOpenBaseImageFileOptionsKey