PnpUnloadAttachedDriver
NTSTATUS __stdcall PnpUnloadAttachedDriver(DRIVER_OBJECT *DriverObject){
bool v1;
_DRIVER_EXTENSION *DriverExtension;
unsigned int v4;
WCHAR *PoolWithTag;
WCHAR v6;
struct _UNICODE_STRING DestinationString;
v1 = DriverObject->DriverSection == 0i64;
DriverExtension = DriverObject->DriverExtension;
DestinationString = 0i64;
if( v1 || DriverObject->DeviceObject )
return 0;
v4 = *(unsigned __int16 *)CmRegistryMachineSystemCurrentControlSetServices
+ 6
+ DriverExtension->ServiceKeyName.Length;
PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v4, 0x65647050ui64);
if( PoolWithTag )
{
RtlStringCbPrintfW(PoolWithTag, v4, (WCHAR *)L"%s\\%s");
RtlInitUnicodeString(&DestinationString, PoolWithTag, v6);
IopUnloadDriver(&DestinationString, 1u);
ExFreePoolWithTag(DestinationString.Buffer, 0);
return 0;
}
return -1073741670;
}Referenced by:
PipCallDriverAddDevice
PnpRemoveLockedDeviceNode