WmiTraceRundownNotify
NTSTATUS __stdcall WmiTraceRundownNotify(UINT64 LoggerId, UINT64 TraceClass){
int v2;
int Buffer[2];
UINT64 v5;
__int64 v6;
_WMIP_TRACE_DEVICE *DeviceListOut;
UINT64 DeviceCountOut;
v5 = LoggerId;
Buffer[1] = TraceClass;
DeviceListOut = 0i64;
LODWORD(DeviceCountOut) = 0;
v6 = 0x400000i64;
Buffer[0] = 2;
v2 = WmipBuildTraceDeviceList(0x400000ui64, &DeviceListOut, &DeviceCountOut);
if( v2 >= 0 )
{
v2 = WmipSendWmiIrpToTraceDeviceList(DeviceListOut, (unsigned int)DeviceCountOut, 0xCu, 0x18ui64, Buffer);
if( v2 >= 0 )
v2 = 0;
}
if( DeviceListOut )
WmipFreeTraceDeviceList(DeviceListOut, (unsigned int)DeviceCountOut);
return v2;
}Referenced by:
EtwpKernelTraceRundown
EtwpLogFileNameRundown
EtwpUpdateFileInfoDriverState