PopInitSystemSleeperThread

NTSTATUS __fastcall PopInitSystemSleeperThread(INT64 a1, _DWORD *a2){
  NTSTATUS result; 
  OBJECT_ATTRIBUTES ObjectAttributes; 
  HANDLE Handle; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  Handle = 0i64;
  a2[18] = a1;
  KeInitializeEvent((_KEVENT *)a2, SynchronizationEvent, 0);
  KeInitializeEvent((_KEVENT *)a2 + 1, SynchronizationEvent, 0);
  KeInitializeEvent((_KEVENT *)a2 + 2, SynchronizationEvent, 0);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = 0i64;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 512;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  result = PsCreateSystemThreadEx(&Handle, 0i64, &ObjectAttributes, 0i64, 0i64, PopTransitionToSleep, a2, 0i64, 0i64);
  if( result >= 0 )
  {
    ZwClose(Handle);
    KeWaitForSingleObject(a2, Executive, 0, 0, 0i64);
    return 0;
  }
  return result;
}

Referenced by:

PopTransitionSystemPowerStateEx