PopReadSystemAwayModePolicy

NTSTATUS __stdcall PopReadSystemAwayModePolicy(){
  bool v0; 
  NTSTATUS result; 
  WCHAR v2; 
  ULONG ResultLength; 
  HANDLE KeyHandle; 
  struct _UNICODE_STRING DestinationString; 
  __int128 KeyValueInformation; 
  int v7; 
  KeyHandle = 0i64;
  ResultLength = 0;
  v0 = 0;
  v7 = 0;
  DestinationString = 0i64;
  KeyValueInformation = 0i64;
  if( byte_140C23D12 )
    v0 = dword_140C002F0 != 0;
  result = PopOpenPowerKey(&KeyHandle);
  if( result >= 0 )
  {
    if( byte_140C23D12 )
    {
      RtlInitUnicodeString(&DestinationString, L"AwayModeEnabled", v2);
      if( ZwQueryValueKey(
             KeyHandle,
             &DestinationString,
             KeyValuePartialInformation,
             &KeyValueInformation,
             0x14u,
             &ResultLength) >= 0
        && *(_QWORD *)((char *)&KeyValueInformation + 4) == 0x400000004i64
        && HIDWORD(KeyValueInformation) )
      {
        v0 = 1;
      }
    }
    result = ZwClose(KeyHandle);
  }
  byte_140C23D10 = v0;
  return result;
}

Referenced by:

PopIssueActionRequest