PopReadHiberbootGroupPolicy

NTSTATUS __stdcall PopReadHiberbootGroupPolicy(UINT8 *Hiberboot){
  WCHAR v1; 
  int v3; 
  WCHAR v4; 
  ULONG ResultLength; 
  void *KeyHandle; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int128 KeyValueInformation; 
  int v11; 
  KeyHandle = 0i64;
  ResultLength = 0;
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  *Hiberboot = 0;
  DestinationString = 0i64;
  RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System", v1);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = &DestinationString;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 576;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  v3 = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
  if( v3 >= 0 )
  {
    RtlInitUnicodeString(&DestinationString, (PCWSTR)L"HiberbootEnabled", v4);
    v11 = 0;
    KeyValueInformation = 0i64;
    v3 = ZwQueryValueKey(
           KeyHandle,
           &DestinationString,
           KeyValuePartialInformation,
           &KeyValueInformation,
           0x14u,
           &ResultLength);
    if( v3 >= 0 )
      *Hiberboot = BYTE12(KeyValueInformation);
    ZwClose(KeyHandle);
  }
  return v3;
}

Referenced by:

PopReadHiberbootPolicy