IopBootLogToFile
NTSTATUS __stdcall IopBootLogToFile(_UNICODE_STRING *String){
INT64 v1;
_ETHREAD *CurrentThread;
_UNICODE_STRING *v5;
int v6;
ULONG Length;
UINT64 FileAttributes;
UINT64 ShareAccess;
UINT64 CreateDisposition;
UINT64 CreateOptions;
UINT64 EaLength;
_IO_STATUS_BLOCK IoStatusBlock;
_OBJECT_ATTRIBUTES ObjectAttributes;
__int16 Buffer;
VOID *FileHandle;
_LARGE_INTEGER ByteOffset;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
IoStatusBlock = 0i64;
FileHandle = 0i64;
Buffer = -257;
if( !qword_140D2C030 )
return 0;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquireResourceExclusiveLite((UINT64)&qword_140D2C030[4], 1, v1);
v5 = qword_140D2C030;
if( !qword_140D2C030[2].Buffer )
RtlInitUnicodeString(qword_140D2C030 + 2, L"\\SystemRoot\\ntbtlog.txt");
LODWORD(EaLength) = 0;
LODWORD(CreateOptions) = 100;
LODWORD(CreateDisposition) = 3;
LODWORD(ShareAccess) = 1;
LODWORD(FileAttributes) = 128;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
ObjectAttributes.ObjectName = v5 + 2;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v6 = ZwCreateFile(
&FileHandle,
0x40000000ui64,
&ObjectAttributes,
&IoStatusBlock,
0i64,
FileAttributes,
ShareAccess,
CreateDisposition,
CreateOptions,
0i64,
EaLength);
if( v6 >= 0 )
{
if( IoStatusBlock.Information == 2 )
v6 = ZwWriteFile((_HANDLE)FileHandle, 0, 0i64, 0i64, &IoStatusBlock, &Buffer, 2u, 0i64, 0i64);
if( v6 >= 0 )
{
Length = String->Length;
ByteOffset.QuadPart = -1i64;
v6 = ZwWriteFile((_HANDLE)FileHandle, 0, 0i64, 0i64, &IoStatusBlock, String->Buffer, Length, &ByteOffset, 0i64);
}
ZwClose((_HANDLE)FileHandle);
}
ExReleaseResourceLite((PERESOURCE)&qword_140D2C030[4]);
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
return v6;
}Referenced by:
IopBootLog
IopCopyBootLogRegistryToFile