PopInitSystemSleeperThread
NTSTATUS __fastcall PopInitSystemSleeperThread(INT64 a1, _DWORD *a2){
NTSTATUS result;
OBJECT_ATTRIBUTES ObjectAttributes;
HANDLE Handle;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
Handle = 0i64;
a2[18] = a1;
KeInitializeEvent((_KEVENT *)a2, SynchronizationEvent, 0);
KeInitializeEvent((_KEVENT *)a2 + 1, SynchronizationEvent, 0);
KeInitializeEvent((_KEVENT *)a2 + 2, SynchronizationEvent, 0);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = 0i64;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 512;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
result = PsCreateSystemThreadEx(&Handle, 0i64, &ObjectAttributes, 0i64, 0i64, PopTransitionToSleep, a2, 0i64, 0i64);
if( result >= 0 )
{
ZwClose(Handle);
KeWaitForSingleObject(a2, Executive, 0, 0, 0i64);
return 0;
}
return result;
}Referenced by:
PopTransitionSystemPowerStateEx