EtwpLogger
void __fastcall EtwpLogger(PVOID StartContext){
__int64 v1;
_EJOB *v2;
unsigned int v3;
int v4;
UINT64 v5;
UINT8 v6;
UINT8 v7;
int v8;
int Logfile;
EVENT_DESCRIPTOR *v10;
bool v11;
int v12;
EVENT_DESCRIPTOR *v13;
int v14;
UINT64 v15;
const _GUID *v16;
NTSTATUS v17;
UNICODE_STRING *v18;
INT64 v19;
int i;
int v21;
EVENT_DESCRIPTOR *v22;
UINT64 v23;
IRP *WaitMode;
INT64 Alertable;
PLARGE_INTEGER Timeout;
PVOID Object[2];
_EJOB *v28;
v1 = *((_QWORD *)StartContext + 1);
*(_QWORD *)(v1 + 48) = KeGetCurrentThread();
v2 = PsAttachSiloToCurrentThread(*(_EJOB **)StartContext);
v28 = v2;
KeSetActualBasePriorityThread((__int64)KeGetCurrentThread(), 15);
KeSetEvent((PRKEVENT)(v1 + 472), 0);
Object[1] = (PVOID)(v1 + 520);
Object[0] = (PVOID)(v1 + 496);
if( !*(_DWORD *)(v1 + 336) )
goto LABEL_53;
do
{
v3 = 0;
KeWaitForMultipleObjects(
(_BYTE *)((unsigned int)(*(_DWORD *)(v1 + 224) != 0) + 1),
Object,
WaitAny,
Executive,
0,
0,
0i64,
0i64);
if( v4 == 1 )
{
EtwpResetFlushTimer(v1, 0);
KeResetEvent((VOID *)(v1 + 496), v5, v6, v7, WaitMode);
v3 = 1;
}
if( EtwpFileSystemReady )
_InterlockedOr((volatile signed __int32 *)(v1 + 832), 4u);
EtwpAdjustFreeBuffers((_WMI_LOGGER_CONTEXT *)v1);
v8 = *(_DWORD *)(v1 + 836) & 4;
if( v8 )
{
if( *(_DWORD *)(v1 + 224) )
EtwpResetFlushTimer(v1, 1);
v3 = 1;
}
if( (*(_DWORD *)(v1 + 832) & 4) == 0 )
{
EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, v3);
continue;
}
if( (*(_DWORD *)(v1 + 836) & 0x80u) != 0 )
{
_InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFF7F);
if( *(_QWORD *)(v1 + 816) )
EtwpFinalizeHeader(v1, 1);
}
if( (*(_DWORD *)(v1 + 12) & 0x100) != 0 )
_InterlockedOr((volatile signed __int32 *)(v1 + 832), 8u);
else
_InterlockedAnd((volatile signed __int32 *)(v1 + 832), 0xFFFFFFF7);
if( (*(_DWORD *)(v1 + 832) & 8) != 0 )
{
Logfile = EtwpRealtimeCreateLogfile((_WMI_LOGGER_CONTEXT *)v1);
if( Logfile < 0 )
goto LABEL_48;
EtwpRealtimeUpdateConsumers(v1);
EtwpRealtimeFlushSavedBuffers((_WMI_LOGGER_CONTEXT *)v1);
if( *(_DWORD *)(v1 + 360) && *(_DWORD *)(v1 + 440) )
EtwpRequestFlushTimer(v1, 0);
}
if( (*(_DWORD *)(v1 + 836) & 0x40) != 0 )
{
_InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFBF);
EtwpRealtimeNotifyConsumers((_WMI_LOGGER_CONTEXT *)v1);
}
if( (*(_DWORD *)(v1 + 836) & 8) != 0 )
{
EtwpRealtimeDisconnectAllConsumers((_WMI_LOGGER_CONTEXT *)v1);
_InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFF7);
*(_DWORD *)(v1 + 56) = 0;
KeSetEvent((PRKEVENT)(v1 + 472), 0);
}
if( (*(_DWORD *)(v1 + 836) & 3) != 0 )
{
v11 = 1;
if( (*(_DWORD *)(v1 + 836) & 2) != 0 )
v11 = *(_QWORD *)(v1 + 816) == 0i64;
v12 = EtwpCreateLogFile((_WMI_LOGGER_CONTEXT *)v1, 1u);
*(_DWORD *)(v1 + 56) = v12;
Logfile = v12;
if( v12 < 0 )
{
v14 = *(_DWORD *)(v1 + 12);
if( (v14 & 8) != 0 )
{
if( EtwEventEnabled(
EtwpEventTracingProvRegHandle,
(EVENT_DESCRIPTOR *)&ETW_EVENT_SWITCH_TO_NEW_FILE_FAILED,
v13) )
{
LODWORD(Timeout) = v14;
LODWORD(Alertable) = Logfile;
EtwpEventWriteTemplateAdmin(
v15,
&ETW_EVENT_SWITCH_TO_NEW_FILE_FAILED,
v16,
(const _UNICODE_STRING *)(v1 + 152),
(const _UNICODE_STRING *)(v1 + 168),
Alertable,
(const UINT64)Timeout);
}
}
}
KeSetEvent((PRKEVENT)(v1 + 472), 0);
if( Logfile < 0 && v11 )
goto LABEL_48;
}
Logfile = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, v3);
if( (*(_DWORD *)(v1 + 836) & 1) != 0 && Logfile >= 0 && !v3 )
Logfile = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64);
if( (*(_DWORD *)(v1 + 836) & 0x1000) != 0 )
{
_InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFEFFF);
if( *(_QWORD *)(v1 + 816) )
{
v17 = EtwpFinalizeHeader(v1, 0);
Logfile = v17;
if( v17 >= 0 )
{
ZwClose(*(HANDLE *)(v1 + 816));
*(_QWORD *)(v1 + 816) = 0i64;
}
else
{
*(_DWORD *)(v1 + 56) = v17;
}
}
}
if( v8 )
{
_InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFFB);
*(_DWORD *)(v1 + 56) = Logfile;
KeSetEvent((PRKEVENT)(v1 + 472), 0);
}
if( Logfile < 0 )
{
LABEL_48:
if( EtwEventEnabled(EtwpEventTracingProvRegHandle, (EVENT_DESCRIPTOR *)&ETW_EVENT_SESSION_END_FAILED, v10) )
EtwpEventWriteTemplateSessionEnd((UNICODE_STRING *)(v1 + 168), v18, v19, v1 + 152, v1 + 168);
*(_DWORD *)(v1 + 56) = Logfile;
EtwpStopLoggerInstance((_WMI_LOGGER_CONTEXT *)v1);
}
}
while( *(_DWORD *)(v1 + 336) );
v2 = v28;
LABEL_53:
for( i = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64);
;
i = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64) )
{
v21 = i;
if( i < 0 )
break;
if( i == 259 )
{
if( (*(_DWORD *)(v1 + 832) & 8) == 0 || (v21 = 0, *(_QWORD *)(v1 + 376)) )
v21 = -1073741823;
break;
}
if( *(int *)(v1 + 248) <= 0 || *(_DWORD *)(v1 + 248) <= *(_DWORD *)(v1 + 244) )
break;
KeWaitForSingleObject((PVOID)(v1 + 496), Executive, 0, 0, (PLARGE_INTEGER)&EtwpOneSecond);
}
if( *(_QWORD *)(v1 + 816) )
{
EtwpFinalizeHeader(v1, 0);
ZwClose(*(HANDLE *)(v1 + 816));
*(_QWORD *)(v1 + 816) = 0i64;
}
if( *(_QWORD *)(v1 + 376) )
{
EtwpRealtimeSaveState((_WMI_LOGGER_CONTEXT *)v1);
ZwClose(*(HANDLE *)(v1 + 376));
*(_QWORD *)(v1 + 376) = 0i64;
}
*(_DWORD *)(v1 + 56) = v21;
KeSetEvent((PRKEVENT)(v1 + 472), 0);
if( v21 < 0 && EtwEventEnabled(EtwpEventTracingProvRegHandle, (EVENT_DESCRIPTOR *)&ETW_EVENT_STOP_TRACE, v22) )
EtwpEventWriteTemplateSession(v23, &ETW_EVENT_STOP_TRACE, (_WMI_LOGGER_CONTEXT *)v1);
EtwpFreeLoggerContext((_WMI_LOGGER_CONTEXT *)v1);
PsDetachSiloFromCurrentThread(v2);
PsTerminateSystemThread((unsigned int)v21);
}Referenced by:
No references.