CmpCmdRenameHive
NTSTATUS __stdcall CmpCmdRenameHive(
PVOID Handle,
_OBJECT_NAME_INFORMATION *OldName,
_UNICODE_STRING *NewName,
UINT64 NameInfoLength,
UINT8 ReplaceIfExists){
NTSTATUS result;
UINT8 *PoolWithTag;
UINT8 *v9;
NTSTATUS v10;
struct _IO_STATUS_BLOCK IoStatusBlock;
UINT64 ReturnLength;
LODWORD(ReturnLength) = NameInfoLength;
IoStatusBlock = 0i64;
if( !OldName
|| (result = ZwQueryObject(Handle, ObjectNameInformation, OldName, NameInfoLength, &ReturnLength), result >= 0) )
{
PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, NewName->Length + 24i64, 0x20204D43ui64);
v9 = PoolWithTag;
if( PoolWithTag )
{
*((_QWORD *)PoolWithTag + 1) = 0i64;
*PoolWithTag = ReplaceIfExists;
*((_DWORD *)PoolWithTag + 4) = NewName->Length;
memmove(PoolWithTag + 20, (UINT8 *)NewName->Buffer, NewName->Length);
v10 = ZwSetInformationFile(Handle, &IoStatusBlock, v9, (unsigned int)NewName->Length + 24, FileRenameInformation);
ExFreePoolWithTag(v9, 0);
return v10;
}
else
{
return -1073741670;
}
}
return result;
}Referenced by:
CmReplaceKey
CmpFlushBackupHive