CmpCmdRenameHive

NTSTATUS __stdcall CmpCmdRenameHive(
        PVOID Handle,
        _OBJECT_NAME_INFORMATION *OldName,
        _UNICODE_STRING *NewName,
        UINT64 NameInfoLength,
        UINT8 ReplaceIfExists){
  NTSTATUS result; 
  UINT8 *PoolWithTag; 
  UINT8 *v9; 
  NTSTATUS v10; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  UINT64 ReturnLength; 
  LODWORD(ReturnLength) = NameInfoLength;
  IoStatusBlock = 0i64;
  if( !OldName
    || (result = ZwQueryObject(Handle, ObjectNameInformation, OldName, NameInfoLength, &ReturnLength), result >= 0) )
  {
    PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, NewName->Length + 24i64, 0x20204D43ui64);
    v9 = PoolWithTag;
    if( PoolWithTag )
    {
      *((_QWORD *)PoolWithTag + 1) = 0i64;
      *PoolWithTag = ReplaceIfExists;
      *((_DWORD *)PoolWithTag + 4) = NewName->Length;
      memmove(PoolWithTag + 20, (UINT8 *)NewName->Buffer, NewName->Length);
      v10 = ZwSetInformationFile(Handle, &IoStatusBlock, v9, (unsigned int)NewName->Length + 24, FileRenameInformation);
      ExFreePoolWithTag(v9, 0);
      return v10;
    }
    else
    {
      return -1073741670;
    }
  }
  return result;
}

Referenced by:

CmReplaceKey
CmpFlushBackupHive