IopBootLog

VOID __stdcall IopBootLog(UNICODE_STRING *LogEntry, UINT8 Loaded){
  UNICODE_STRING *v4; 
  PUNICODE_STRING v5; 
  UNICODE_STRING *v6; 
  WCHAR v7; 
  WCHAR v8; 
  unsigned __int16 Length; 
  wchar_t *Data; 
  WCHAR v11; 
  WCHAR v12; 
  UINT64 DataSize; 
  struct _UNICODE_STRING DestinationString; 
  UNICODE_STRING Source; 
  UNICODE_STRING v16; 
  UNICODE_STRING KeyName; 
  struct _UNICODE_STRING ValueName; 
  wchar_t pszDest[256]; 
  char v20; 
  *(_QWORD *)&DestinationString.Length = 0x1000000i64;
  DestinationString.Buffer = (wchar_t *)&v20;
  KeyName = 0i64;
  ValueName = 0i64;
  v16 = 0i64;
  Source = 0i64;
  if( qword_140D2C030 )
  {
    ExAcquireResourceExclusiveLite((ERESOURCE *)&qword_140D2C030[4], 1u);
    v5 = qword_140D2C030;
    v6 = qword_140D2C030;
    if( !Loaded )
      v6 = qword_140D2C030 + 1;
    RtlCopyUnicodeString(&DestinationString, v6, v4);
    RtlInitUnicodeString(&Source, L" ", v7);
    RtlAppendUnicodeStringToString(&DestinationString, &Source);
    RtlAppendUnicodeStringToString(&DestinationString, LogEntry);
    RtlInitUnicodeString(&v16, L"\r\n", v8);
    RtlAppendUnicodeStringToString(&DestinationString, &v16);
    Length = DestinationString.Length;
    Data = DestinationString.Buffer;
    if( DestinationString.Length == DestinationString.MaximumLength )
    {
      Length = DestinationString.Length - 2;
      DestinationString.Length = Length;
      DestinationString.Buffer[(unsigned __int64)Length >> 1] = 0;
    }
    ++LODWORD(v5[10].Buffer);
    RtlStringCchPrintfW(pszDest, 0x100ui64, (WCHAR *)L"%d");
    RtlInitUnicodeString(&KeyName, pszDest, v11);
    RtlInitUnicodeString(&ValueName, &word_1407CF120, v12);
    if( BYTE4(qword_140D2C030[10].Buffer) )
    {
      IopBootLogToFile(&DestinationString);
    }
    else
    {
      *(_QWORD *)&Source.Length = 0i64;
      *(_QWORD *)&DestinationString.Length = 0i64;
      if( IopOpenRegistryKey(
             (PVOID *)&DestinationString,
             0i64,
             &CmRegistryMachineSystemCurrentControlSetControlBootLog,
             0xF003Fui64,
             1u) >= 0 )
      {
        if( IopOpenRegistryKey((PVOID *)&Source, *(PVOID *)&DestinationString.Length, &KeyName, 0xF003Fui64, 1u) >= 0 )
        {
          LODWORD(DataSize) = Length + 2;
          ZwSetValueKey(*(PVOID *)&Source.Length, &ValueName, 0i64, 1ui64, Data, DataSize);
          ZwClose(*(HANDLE *)&Source.Length);
        }
        ZwClose(*(HANDLE *)&DestinationString.Length);
      }
    }
    ExReleaseResourceLite((PERESOURCE)&qword_140D2C030[4]);
  }
}

Referenced by:

IopInitializeBootLogging
IopLoadDriver
PipCallDriverAddDevice