BiUnloadHiveByName
NTSTATUS __stdcall BiUnloadHiveByName(PWCHAR KeyName, UINT64 KeyNameSize, UINT8 ForceUnload){
UINT64 v4;
WCHAR *PoolWithTag;
WCHAR *v6;
WCHAR v7;
int v8;
NTSTATUS v9;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES KeyObjectAttributes;
__int64 v13;
*(&KeyObjectAttributes.Length + 1) = 0;
*(&KeyObjectAttributes.Attributes + 1) = 0;
v13 = 0i64;
v4 = (unsigned int)(KeyNameSize + 38);
DestinationString = 0i64;
PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v4, 0x4B444342ui64);
v6 = PoolWithTag;
if( !PoolWithTag )
return -1073741670;
swprintf_s(PoolWithTag, v4 >> 1, (WCHAR *)L"%s\\%s");
RtlInitUnicodeString(&DestinationString, v6, v7);
KeyObjectAttributes.RootDirectory = 0i64;
KeyObjectAttributes.ObjectName = &DestinationString;
KeyObjectAttributes.Length = 48;
KeyObjectAttributes.Attributes = 576;
*(_OWORD *)&KeyObjectAttributes.SecurityDescriptor = 0i64;
v8 = BiAcquirePrivilege(0x12u, (__int64)&v13);
if( v8 >= 0 )
{
if( ForceUnload )
v9 = ZwUnloadKey2(&KeyObjectAttributes, 1ui64);
else
v9 = ZwUnloadKey(&KeyObjectAttributes);
v8 = v9;
BiReleasePrivilege((__int64)&v13);
}
ExFreePoolWithTag(v6, 0x4B444342u);
return v8;
}Referenced by:
BiAddStoreFromFile
BiUnloadHiveByHandle