EtwSetInformation
NTSTATUS __stdcall EtwSetInformation(
REGHANDLE RegHandle,
_EVENT_INFO_CLASS InformationClass,
PVOID EventInformation,
ULONG InformationLength){
NTSTATUS v4;
__int32 v5;
v4 = 0;
if( RegHandle )
{
v5 = InformationClass - 2;
if( v5 )
{
if( v5 != 1 )
return -1073741808;
if( EventInformation && InformationLength == 1 )
{
if( *(_BYTE *)EventInformation == 1 )
{
_InterlockedOr16((volatile signed __int16 *)(RegHandle + 98), 0x200u);
return v4;
}
if( !*(_BYTE *)EventInformation )
{
_InterlockedAnd16((volatile signed __int16 *)(RegHandle + 98), 0xFDFFu);
return v4;
}
}
}
else if( EventInformation && InformationLength - 3 <= 0x7FFC )
{
return EtwpSetProviderTraitsKm((_ETW_REG_ENTRY *)RegHandle, EventInformation, InformationLength);
}
return -1073741811;
}
return -1073741816;
}Referenced by:
BapdRegisterEtwProvider
BapdWriteEtwEvents
HvlpEtwRegister
PopDiagInitialize
PsDispatchIumService
TraceLoggingRegisterEx_EtwRegister_EtwSetInformation