PipGetDriverKsrGuid

INT64 __fastcall PipGetDriverKsrGuid(INT64 a1, GUID *a2){
  UNICODE_STRING *v3; 
  NTSTATUS v4; 
  HANDLE v5; 
  int DriverKsrGuidRegistryValue; 
  __int128 v8; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  void *KeyHandle; 
  HANDLE Handle; 
  v3 = (UNICODE_STRING *)(*(_QWORD *)(a1 + 48) + 24i64);
  KeyHandle = (void *)-1i64;
  Handle = (HANDLE)-1i64;
  v8 = 0i64;
  v4 = PipOpenServiceEnumKeys(v3, 0x20019ui64, &Handle, 0i64, 0);
  v5 = Handle;
  DriverKsrGuidRegistryValue = v4;
  if( v4 >= 0 )
  {
    *(&ObjectAttributes.Length + 1) = 0;
    memset(&ObjectAttributes.Attributes + 1, 0, 20);
    KeyHandle = 0i64;
    *((_QWORD *)&v8 + 1) = L"Parameters";
    LODWORD(v8) = 1441812;
    ObjectAttributes.ObjectName = (_UNICODE_STRING *)&v8;
    ObjectAttributes.Length = 48;
    ObjectAttributes.RootDirectory = Handle;
    ObjectAttributes.Attributes = 576;
    DriverKsrGuidRegistryValue = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
    if( DriverKsrGuidRegistryValue >= 0 )
      DriverKsrGuidRegistryValue = PipGetDriverKsrGuidRegistryValue(KeyHandle, a2);
  }
  if( KeyHandle != (void *)-1i64 )
  {
    ZwClose(KeyHandle);
    KeyHandle = (void *)-1i64;
  }
  if( v5 != (HANDLE)-1i64 )
    ZwClose(v5);
  return(unsigned int)DriverKsrGuidRegistryValue;
}

Referenced by:

IoReserveKsrPersistentMemory
PipGetPersistentMemory