BiGetPhysicalDriveName
INT64 __stdcall BiGetPhysicalDriveName(WCHAR *DeviceName, WCHAR **PhysicalDriveName){
WCHAR v2;
int v4;
int VolumeDiskExtentsInformation;
wchar_t *Buffer;
WCHAR *PoolWithTag;
WCHAR *v8;
struct _UNICODE_STRING DestinationString;
struct _IO_STATUS_BLOCK IoStatusBlock;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
UNICODE_STRING FileHandle;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
*(_QWORD *)&FileHandle.Length = 0i64;
FileHandle.Buffer = 0i64;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, DeviceName, v2);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
IoStatusBlock = 0i64;
v4 = ZwOpenFile(&FileHandle, (PWCHAR)0x80100000i64);
if( v4 >= 0 )
{
VolumeDiskExtentsInformation = BiGetVolumeDiskExtentsInformation(
*(VOID **)&FileHandle.Length,
(_VOLUME_DISK_EXTENTS **)&FileHandle.Buffer);
Buffer = FileHandle.Buffer;
v4 = VolumeDiskExtentsInformation;
if( VolumeDiskExtentsInformation >= 0 )
{
if( *(_DWORD *)FileHandle.Buffer == 1 )
{
PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, 0x3Eui64, 0x4B444342ui64);
v8 = PoolWithTag;
if( PoolWithTag )
{
v4 = RtlStringCbPrintfW(PoolWithTag, 0x3Eui64, (WCHAR *)L"\\??\\PhysicalDrive%lu");
if( v4 < 0 )
ExFreePoolWithTag(v8, 0x4B444342u);
else
*PhysicalDriveName = v8;
}
else
{
v4 = -1073741670;
}
}
else
{
v4 = -1073741637;
}
}
if( Buffer )
ExFreePoolWithTag(Buffer, 0x4B444342u);
}
if( *(_QWORD *)&FileHandle.Length )
ZwClose(*(HANDLE *)&FileHandle.Length);
return(unsigned int)v4;
}Referenced by:
BiCreatePartitionDevice
BiGetDriveLayoutBlock