BiUnloadHiveByName

NTSTATUS __stdcall BiUnloadHiveByName(PWCHAR KeyName, UINT64 KeyNameSize, UINT8 ForceUnload){
  UINT64 v4; 
  WCHAR *PoolWithTag; 
  WCHAR *v6; 
  WCHAR v7; 
  int v8; 
  NTSTATUS v9; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES KeyObjectAttributes; 
  __int64 v13; 
  *(&KeyObjectAttributes.Length + 1) = 0;
  *(&KeyObjectAttributes.Attributes + 1) = 0;
  v13 = 0i64;
  v4 = (unsigned int)(KeyNameSize + 38);
  DestinationString = 0i64;
  PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v4, 0x4B444342ui64);
  v6 = PoolWithTag;
  if( !PoolWithTag )
    return -1073741670;
  swprintf_s(PoolWithTag, v4 >> 1, (WCHAR *)L"%s\\%s");
  RtlInitUnicodeString(&DestinationString, v6, v7);
  KeyObjectAttributes.RootDirectory = 0i64;
  KeyObjectAttributes.ObjectName = &DestinationString;
  KeyObjectAttributes.Length = 48;
  KeyObjectAttributes.Attributes = 576;
  *(_OWORD *)&KeyObjectAttributes.SecurityDescriptor = 0i64;
  v8 = BiAcquirePrivilege(0x12u, (__int64)&v13);
  if( v8 >= 0 )
  {
    if( ForceUnload )
      v9 = ZwUnloadKey2(&KeyObjectAttributes, 1ui64);
    else
      v9 = ZwUnloadKey(&KeyObjectAttributes);
    v8 = v9;
    BiReleasePrivilege((__int64)&v13);
  }
  ExFreePoolWithTag(v6, 0x4B444342u);
  return v8;
}

Referenced by:

BiAddStoreFromFile
BiUnloadHiveByHandle