PopReadHiberbootGroupPolicy
NTSTATUS __stdcall PopReadHiberbootGroupPolicy(UINT8 *Hiberboot){
WCHAR v1;
int v3;
WCHAR v4;
ULONG ResultLength;
void *KeyHandle;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int128 KeyValueInformation;
int v11;
KeyHandle = 0i64;
ResultLength = 0;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
*Hiberboot = 0;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System", v1);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v3 = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( v3 >= 0 )
{
RtlInitUnicodeString(&DestinationString, (PCWSTR)L"HiberbootEnabled", v4);
v11 = 0;
KeyValueInformation = 0i64;
v3 = ZwQueryValueKey(
KeyHandle,
&DestinationString,
KeyValuePartialInformation,
&KeyValueInformation,
0x14u,
&ResultLength);
if( v3 >= 0 )
*Hiberboot = BYTE12(KeyValueInformation);
ZwClose(KeyHandle);
}
return v3;
}Referenced by:
PopReadHiberbootPolicy