EtwpLogger

void __fastcall EtwpLogger(PVOID StartContext){
  __int64 v1; 
  _EJOB *v2; 
  unsigned int v3; 
  int v4; 
  UINT64 v5; 
  UINT8 v6; 
  UINT8 v7; 
  int v8; 
  int Logfile; 
  EVENT_DESCRIPTOR *v10; 
  bool v11; 
  int v12; 
  EVENT_DESCRIPTOR *v13; 
  int v14; 
  UINT64 v15; 
  const _GUID *v16; 
  NTSTATUS v17; 
  UNICODE_STRING *v18; 
  INT64 v19; 
  int i; 
  int v21; 
  EVENT_DESCRIPTOR *v22; 
  UINT64 v23; 
  IRP *WaitMode; 
  INT64 Alertable; 
  PLARGE_INTEGER Timeout; 
  PVOID Object[2]; 
  _EJOB *v28; 
  v1 = *((_QWORD *)StartContext + 1);
  *(_QWORD *)(v1 + 48) = KeGetCurrentThread();
  v2 = PsAttachSiloToCurrentThread(*(_EJOB **)StartContext);
  v28 = v2;
  KeSetActualBasePriorityThread((__int64)KeGetCurrentThread(), 15);
  KeSetEvent((PRKEVENT)(v1 + 472), 0);
  Object[1] = (PVOID)(v1 + 520);
  Object[0] = (PVOID)(v1 + 496);
  if( !*(_DWORD *)(v1 + 336) )
    goto LABEL_53;
  do
  {
    v3 = 0;
    KeWaitForMultipleObjects(
      (_BYTE *)((unsigned int)(*(_DWORD *)(v1 + 224) != 0) + 1),
      Object,
      WaitAny,
      Executive,
      0,
      0,
      0i64,
      0i64);
    if( v4 == 1 )
    {
      EtwpResetFlushTimer(v1, 0);
      KeResetEvent((VOID *)(v1 + 496), v5, v6, v7, WaitMode);
      v3 = 1;
    }
    if( EtwpFileSystemReady )
      _InterlockedOr((volatile signed __int32 *)(v1 + 832), 4u);
    EtwpAdjustFreeBuffers((_WMI_LOGGER_CONTEXT *)v1);
    v8 = *(_DWORD *)(v1 + 836) & 4;
    if( v8 )
    {
      if( *(_DWORD *)(v1 + 224) )
        EtwpResetFlushTimer(v1, 1);
      v3 = 1;
    }
    if( (*(_DWORD *)(v1 + 832) & 4) == 0 )
    {
      EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, v3);
      continue;
    }
    if( (*(_DWORD *)(v1 + 836) & 0x80u) != 0 )
    {
      _InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFF7F);
      if( *(_QWORD *)(v1 + 816) )
        EtwpFinalizeHeader(v1, 1);
    }
    if( (*(_DWORD *)(v1 + 12) & 0x100) != 0 )
      _InterlockedOr((volatile signed __int32 *)(v1 + 832), 8u);
    else
      _InterlockedAnd((volatile signed __int32 *)(v1 + 832), 0xFFFFFFF7);
    if( (*(_DWORD *)(v1 + 832) & 8) != 0 )
    {
      Logfile = EtwpRealtimeCreateLogfile((_WMI_LOGGER_CONTEXT *)v1);
      if( Logfile < 0 )
        goto LABEL_48;
      EtwpRealtimeUpdateConsumers(v1);
      EtwpRealtimeFlushSavedBuffers((_WMI_LOGGER_CONTEXT *)v1);
      if( *(_DWORD *)(v1 + 360) && *(_DWORD *)(v1 + 440) )
        EtwpRequestFlushTimer(v1, 0);
    }
    if( (*(_DWORD *)(v1 + 836) & 0x40) != 0 )
    {
      _InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFBF);
      EtwpRealtimeNotifyConsumers((_WMI_LOGGER_CONTEXT *)v1);
    }
    if( (*(_DWORD *)(v1 + 836) & 8) != 0 )
    {
      EtwpRealtimeDisconnectAllConsumers((_WMI_LOGGER_CONTEXT *)v1);
      _InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFF7);
      *(_DWORD *)(v1 + 56) = 0;
      KeSetEvent((PRKEVENT)(v1 + 472), 0);
    }
    if( (*(_DWORD *)(v1 + 836) & 3) != 0 )
    {
      v11 = 1;
      if( (*(_DWORD *)(v1 + 836) & 2) != 0 )
        v11 = *(_QWORD *)(v1 + 816) == 0i64;
      v12 = EtwpCreateLogFile((_WMI_LOGGER_CONTEXT *)v1, 1u);
      *(_DWORD *)(v1 + 56) = v12;
      Logfile = v12;
      if( v12 < 0 )
      {
        v14 = *(_DWORD *)(v1 + 12);
        if( (v14 & 8) != 0 )
        {
          if( EtwEventEnabled(
                 EtwpEventTracingProvRegHandle,
                 (EVENT_DESCRIPTOR *)&ETW_EVENT_SWITCH_TO_NEW_FILE_FAILED,
                 v13) )
          {
            LODWORD(Timeout) = v14;
            LODWORD(Alertable) = Logfile;
            EtwpEventWriteTemplateAdmin(
              v15,
              &ETW_EVENT_SWITCH_TO_NEW_FILE_FAILED,
              v16,
              (const _UNICODE_STRING *)(v1 + 152),
              (const _UNICODE_STRING *)(v1 + 168),
              Alertable,
              (const UINT64)Timeout);
          }
        }
      }
      KeSetEvent((PRKEVENT)(v1 + 472), 0);
      if( Logfile < 0 && v11 )
        goto LABEL_48;
    }
    Logfile = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, v3);
    if( (*(_DWORD *)(v1 + 836) & 1) != 0 && Logfile >= 0 && !v3 )
      Logfile = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64);
    if( (*(_DWORD *)(v1 + 836) & 0x1000) != 0 )
    {
      _InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFEFFF);
      if( *(_QWORD *)(v1 + 816) )
      {
        v17 = EtwpFinalizeHeader(v1, 0);
        Logfile = v17;
        if( v17 >= 0 )
        {
          ZwClose(*(HANDLE *)(v1 + 816));
          *(_QWORD *)(v1 + 816) = 0i64;
        }
        else
        {
          *(_DWORD *)(v1 + 56) = v17;
        }
      }
    }
    if( v8 )
    {
      _InterlockedAnd((volatile signed __int32 *)(v1 + 836), 0xFFFFFFFB);
      *(_DWORD *)(v1 + 56) = Logfile;
      KeSetEvent((PRKEVENT)(v1 + 472), 0);
    }
    if( Logfile < 0 )
    {
LABEL_48:
      if( EtwEventEnabled(EtwpEventTracingProvRegHandle, (EVENT_DESCRIPTOR *)&ETW_EVENT_SESSION_END_FAILED, v10) )
        EtwpEventWriteTemplateSessionEnd((UNICODE_STRING *)(v1 + 168), v18, v19, v1 + 152, v1 + 168);
      *(_DWORD *)(v1 + 56) = Logfile;
      EtwpStopLoggerInstance((_WMI_LOGGER_CONTEXT *)v1);
    }
  }
  while( *(_DWORD *)(v1 + 336) );
  v2 = v28;
LABEL_53:
  for( i = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64);
        ;
        i = EtwpFlushActiveBuffers((_WMI_LOGGER_CONTEXT *)v1, 1ui64) )
  {
    v21 = i;
    if( i < 0 )
      break;
    if( i == 259 )
    {
      if( (*(_DWORD *)(v1 + 832) & 8) == 0 || (v21 = 0, *(_QWORD *)(v1 + 376)) )
        v21 = -1073741823;
      break;
    }
    if( *(int *)(v1 + 248) <= 0 || *(_DWORD *)(v1 + 248) <= *(_DWORD *)(v1 + 244) )
      break;
    KeWaitForSingleObject((PVOID)(v1 + 496), Executive, 0, 0, (PLARGE_INTEGER)&EtwpOneSecond);
  }
  if( *(_QWORD *)(v1 + 816) )
  {
    EtwpFinalizeHeader(v1, 0);
    ZwClose(*(HANDLE *)(v1 + 816));
    *(_QWORD *)(v1 + 816) = 0i64;
  }
  if( *(_QWORD *)(v1 + 376) )
  {
    EtwpRealtimeSaveState((_WMI_LOGGER_CONTEXT *)v1);
    ZwClose(*(HANDLE *)(v1 + 376));
    *(_QWORD *)(v1 + 376) = 0i64;
  }
  *(_DWORD *)(v1 + 56) = v21;
  KeSetEvent((PRKEVENT)(v1 + 472), 0);
  if( v21 < 0 && EtwEventEnabled(EtwpEventTracingProvRegHandle, (EVENT_DESCRIPTOR *)&ETW_EVENT_STOP_TRACE, v22) )
    EtwpEventWriteTemplateSession(v23, &ETW_EVENT_STOP_TRACE, (_WMI_LOGGER_CONTEXT *)v1);
  EtwpFreeLoggerContext((_WMI_LOGGER_CONTEXT *)v1);
  PsDetachSiloFromCurrentThread(v2);
  PsTerminateSystemThread((unsigned int)v21);
}

Referenced by:

No references.