IopBootLogToFile

NTSTATUS __stdcall IopBootLogToFile(_UNICODE_STRING *String){
  INT64 v1; 
  _ETHREAD *CurrentThread; 
  _UNICODE_STRING *v5; 
  int v6; 
  ULONG Length; 
  UINT64 FileAttributes; 
  UINT64 ShareAccess; 
  UINT64 CreateDisposition; 
  UINT64 CreateOptions; 
  UINT64 EaLength; 
  _IO_STATUS_BLOCK IoStatusBlock; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int16 Buffer; 
  VOID *FileHandle; 
  _LARGE_INTEGER ByteOffset; 

  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  IoStatusBlock = 0i64;
  FileHandle = 0i64;
  Buffer = -257;
  if( !qword_140D2C030 )
    return 0;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  ExAcquireResourceExclusiveLite((UINT64)&qword_140D2C030[4], 1, v1);
  v5 = qword_140D2C030;
  if( !qword_140D2C030[2].Buffer )
    RtlInitUnicodeString(qword_140D2C030 + 2, L"\\SystemRoot\\ntbtlog.txt");
  LODWORD(EaLength) = 0;
  LODWORD(CreateOptions) = 100;
  LODWORD(CreateDisposition) = 3;
  LODWORD(ShareAccess) = 1;
  LODWORD(FileAttributes) = 128;
  ObjectAttributes.Length = 48;
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.Attributes = 576;
  ObjectAttributes.ObjectName = v5 + 2;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  v6 = ZwCreateFile(
         &FileHandle,
         0x40000000ui64,
         &ObjectAttributes,
         &IoStatusBlock,
         0i64,
         FileAttributes,
         ShareAccess,
         CreateDisposition,
         CreateOptions,
         0i64,
         EaLength);
  if( v6 >= 0 )
  {
    if( IoStatusBlock.Information == 2 )
      v6 = ZwWriteFile((_HANDLE)FileHandle, 0, 0i64, 0i64, &IoStatusBlock, &Buffer, 2u, 0i64, 0i64);
    if( v6 >= 0 )
    {
      Length = String->Length;
      ByteOffset.QuadPart = -1i64;
      v6 = ZwWriteFile((_HANDLE)FileHandle, 0, 0i64, 0i64, &IoStatusBlock, String->Buffer, Length, &ByteOffset, 0i64);
    }
    ZwClose((_HANDLE)FileHandle);
  }
  ExReleaseResourceLite((PERESOURCE)&qword_140D2C030[4]);
  KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
  return v6;
}

Referenced by:

IopBootLog
IopCopyBootLogRegistryToFile