PipGetDriverKsrGuid
INT64 __fastcall PipGetDriverKsrGuid(INT64 a1, GUID *a2){
UNICODE_STRING *v3;
NTSTATUS v4;
HANDLE v5;
int DriverKsrGuidRegistryValue;
__int128 v8;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
void *KeyHandle;
HANDLE Handle;
v3 = (UNICODE_STRING *)(*(_QWORD *)(a1 + 48) + 24i64);
KeyHandle = (void *)-1i64;
Handle = (HANDLE)-1i64;
v8 = 0i64;
v4 = PipOpenServiceEnumKeys(v3, 0x20019ui64, &Handle, 0i64, 0);
v5 = Handle;
DriverKsrGuidRegistryValue = v4;
if( v4 >= 0 )
{
*(&ObjectAttributes.Length + 1) = 0;
memset(&ObjectAttributes.Attributes + 1, 0, 20);
KeyHandle = 0i64;
*((_QWORD *)&v8 + 1) = L"Parameters";
LODWORD(v8) = 1441812;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&v8;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = Handle;
ObjectAttributes.Attributes = 576;
DriverKsrGuidRegistryValue = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( DriverKsrGuidRegistryValue >= 0 )
DriverKsrGuidRegistryValue = PipGetDriverKsrGuidRegistryValue(KeyHandle, a2);
}
if( KeyHandle != (void *)-1i64 )
{
ZwClose(KeyHandle);
KeyHandle = (void *)-1i64;
}
if( v5 != (HANDLE)-1i64 )
ZwClose(v5);
return(unsigned int)DriverKsrGuidRegistryValue;
}Referenced by:
IoReserveKsrPersistentMemory
PipGetPersistentMemory