PiDrvDbLoadHive
NTSTATUS __stdcall PiDrvDbLoadHive(UNICODE_STRING *HiveKeyPath, UNICODE_STRING *HiveFileName, PVOID *RootKeyHandle){
void **v3;
void **v4;
int v5;
UINT64 v7;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
OBJECT_ATTRIBUTES SourceFile;
v4 = v3;
*v3 = 0i64;
LODWORD(v7) = 0;
LODWORD(RootKeyHandle) = (unsigned int)RootKeyHandle | 0x80;
*(_OWORD *)&ObjectAttributes.Length = 0x30ui64;
*(_OWORD *)&SourceFile.Length = 0x30ui64;
ObjectAttributes.ObjectName = HiveKeyPath;
SourceFile.ObjectName = HiveFileName;
*(_QWORD *)&ObjectAttributes.Attributes = 576i64;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
*(_QWORD *)&SourceFile.Attributes = 576i64;
*(_OWORD *)&SourceFile.SecurityDescriptor = 0i64;
v5 = ZwLoadKeyEx(&ObjectAttributes, &SourceFile, (UINT64)RootKeyHandle, 0i64, 0i64, v7, 0i64, 0i64);
if( v5 >= 0 )
{
v5 = ZwOpenKey(v4, 0x2000000u, &ObjectAttributes);
if( v5 < 0 )
ZwUnloadKey2(&ObjectAttributes, 0i64);
}
return v5;
}Referenced by:
PiDrvDbLoadNodeWorkerCallback
PiDrvDbSetupNodeHive