PnpUnloadAttachedDriver

NTSTATUS __stdcall PnpUnloadAttachedDriver(DRIVER_OBJECT *DriverObject){
  bool v1; 
  _DRIVER_EXTENSION *DriverExtension; 
  unsigned int v4; 
  WCHAR *PoolWithTag; 
  WCHAR v6; 
  struct _UNICODE_STRING DestinationString; 
  v1 = DriverObject->DriverSection == 0i64;
  DriverExtension = DriverObject->DriverExtension;
  DestinationString = 0i64;
  if( v1 || DriverObject->DeviceObject )
    return 0;
  v4 = *(unsigned __int16 *)CmRegistryMachineSystemCurrentControlSetServices
     + 6
     + DriverExtension->ServiceKeyName.Length;
  PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v4, 0x65647050ui64);
  if( PoolWithTag )
  {
    RtlStringCbPrintfW(PoolWithTag, v4, (WCHAR *)L"%s\\%s");
    RtlInitUnicodeString(&DestinationString, PoolWithTag, v6);
    IopUnloadDriver(&DestinationString, 1u);
    ExFreePoolWithTag(DestinationString.Buffer, 0);
    return 0;
  }
  return -1073741670;
}

Referenced by:

PipCallDriverAddDevice
PnpRemoveLockedDeviceNode