PiDevCfgLogDeviceStarted
void __fastcall PiDevCfgLogDeviceStarted(__int64 a1){
INT64 v2;
WCHAR v3;
wchar_t *Buffer;
char v5;
wchar_t *v6;
int v7;
int v8;
const WCHAR *v9;
const WCHAR *v10;
const WCHAR *v11;
const WCHAR *v12;
CHAR v13;
unsigned __int16 Length;
unsigned int v15;
__int64 v16;
unsigned __int16 v17;
unsigned int v18;
__int64 v19;
const WCHAR *LogString;
const WCHAR *v21;
INT64 v22;
const WCHAR *v23;
const WCHAR *v24;
CHAR v25;
const WCHAR *v26;
const WCHAR *v27;
const WCHAR *v28;
const WCHAR *v29;
CHAR v30;
UINT64 v31;
struct _UNICODE_STRING DestinationString;
UNICODE_STRING v33;
struct _UNICODE_STRING UnicodeString;
UNICODE_STRING v35;
INT64 v36[2];
INT64 result;
int v38;
INT64 *v39;
int v40;
int v41;
const DEVPROPKEY *v42;
int v43;
struct _UNICODE_STRING *p_UnicodeString;
int v45;
int v46;
const DEVPROPKEY *v47;
int v48;
UNICODE_STRING *v49;
int v50;
int v51;
const DEVPROPKEY *v52;
int v53;
struct _UNICODE_STRING *p_DestinationString;
int v55;
int v56;
const DEVPROPKEY *v57;
int v58;
UNICODE_STRING *v59;
int v60;
int v61;
*(_QWORD *)&UnicodeString.Length = 0i64;
UnicodeString.Buffer = 0i64;
*(_QWORD *)&v35.Length = 0i64;
v35.Buffer = 0i64;
*(_QWORD *)&DestinationString.Length = 0i64;
DestinationString.Buffer = 0i64;
*(_QWORD *)&v33.Length = 0i64;
v33.Buffer = 0i64;
*(_OWORD *)v36 = 0i64;
if( (byte_140C130BA & 0x18) == 24 )
{
memset((INT64)&result, 0i64);
LODWORD(v31) = 5;
v45 = 6;
v43 = 18;
result = (INT64)&DEVPKEY_Device_ClassGuid;
v48 = 18;
v39 = v36;
v50 = 6;
v42 = &DEVPKEY_Device_DriverInfPath;
v55 = 6;
p_UnicodeString = &UnicodeString;
v47 = &DEVPKEY_Device_Service;
v49 = &v35;
v52 = &DEVPKEY_Device_LowerFilters;
p_DestinationString = &DestinationString;
v57 = &DEVPKEY_Device_UpperFilters;
v59 = &v33;
v60 = 6;
v2 = *(_QWORD *)(a1 + 48);
v38 = 13;
v40 = 16;
v53 = 8210;
v58 = 8210;
if( (int)PiDevCfgQueryObjectProperties(8210i64, v2, 1ui64, 0i64, (INT64)&result, v31) >= 0 )
{
if( v41 < 0 )
*(_OWORD *)v36 = 0i64;
if( v46 < 0 )
RtlInitUnicodeString(&UnicodeString, 0i64, v3);
if( v51 < 0 )
RtlInitUnicodeString(&v35, 0i64, v3);
if( v56 < 0 )
RtlInitUnicodeString(&DestinationString, 0i64, v3);
if( v61 < 0 )
RtlInitUnicodeString(&v33, 0i64, v3);
Buffer = DestinationString.Buffer;
v5 = 32;
if( DestinationString.Buffer )
{
Length = DestinationString.Length;
if( DestinationString.Length > 4u )
{
v15 = 0;
if( (unsigned __int64)DestinationString.Length >> 1 != 2 )
{
v16 = 0i64;
do
{
if( !Buffer[v16] )
{
Buffer[v16] = 32;
Buffer = DestinationString.Buffer;
Length = DestinationString.Length;
}
v16 = ++v15;
}
while( v15 < ((unsigned __int64)Length >> 1) - 2 );
}
DestinationString.Length = Length - 2;
}
}
v6 = v33.Buffer;
if( v33.Buffer )
{
v17 = v33.Length;
if( v33.Length > 4u )
{
v18 = 0;
if( (unsigned __int64)v33.Length >> 1 != 2 )
{
v19 = 0i64;
do
{
if( !v6[v19] )
{
v6[v19] = 32;
v6 = v33.Buffer;
v17 = v33.Length;
}
v19 = ++v18;
}
while( v18 < ((unsigned __int64)v17 >> 1) - 2 );
}
v33.Length = v17 - 2;
}
}
v7 = *(_DWORD *)(a1 + 396);
v8 = v7 & 0x6000;
if( (v7 & 0x6000) == 0 )
PipIsDevNodeDNStarted((_DEVICE_NODE *)a1);
if( v8 || !(unsigned int)PipIsDevNodeDNStarted((_DEVICE_NODE *)a1) )
{
if( (v7 & 0x2000) != 0 && *(_DWORD *)(a1 + 404) == 14 )
{
if( ((unsigned __int8)v5 & (unsigned __int8)byte_140C130BA) != 0 )
{
PnpGetLogString(&v33);
PnpGetLogString(&DestinationString);
LogString = PnpGetLogString(&v35);
McTemplateK0zzjzzzdd_EtwWriteTransfer(
v22,
(const EVENT_DESCRIPTOR *)KMPnPEvt_DeviceStart_RebootRequired,
(INT64)v23,
*(const WCHAR **)(a1 + 48),
v24,
(INT64)v36,
LogString,
v21,
v23,
14,
v25);
}
}
else if( (byte_140C130BA & 0x10) != 0 )
{
PnpGetLogString(&v33);
PnpGetLogString(&DestinationString);
v26 = PnpGetLogString(&v35);
McTemplateK0zzjzzzdd_EtwWriteTransfer(
*(unsigned int *)(a1 + 404),
(const EVENT_DESCRIPTOR *)KMPnPEvt_DeviceStart_Failure,
(INT64)v28,
*(const WCHAR **)(a1 + 48),
v29,
(INT64)v36,
v26,
v27,
v28,
*(_DWORD *)(a1 + 404),
v30);
}
}
else if( (byte_140C130BA & 8) != 0 )
{
PnpGetLogString(&v33);
PnpGetLogString(&DestinationString);
v9 = PnpGetLogString(&v35);
McTemplateK0zzjzzzdd_EtwWriteTransfer(
*(unsigned int *)(a1 + 404),
&KMPnPEvt_DeviceStart_Success,
(INT64)v11,
*(const WCHAR **)(a1 + 48),
v12,
(INT64)v36,
v9,
v10,
v11,
*(_DWORD *)(a1 + 404),
v13);
}
}
}
RtlFreeAnsiString(&UnicodeString);
RtlFreeAnsiString(&v35);
RtlFreeAnsiString(&DestinationString);
RtlFreeAnsiString(&v33);
}Referenced by:
PpDevCfgTraceDeviceStart