WmipLegacyEtwWorker
VOID __stdcall WmipLegacyEtwWorker(VOID *Context){
__int64 v2;
void **v3;
void ***v4;
void **v5;
int v6;
int v7;
UINT64 v8;
WmipReferenceEntry((INT64)Context);
KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
v2 = *((_QWORD *)Context + 16);
v3 = (void **)(v2 + 24);
if( !v2 )
v3 = (void **)((char *)Context + 136);
while( 1 )
{
v4 = (void ***)*v3;
if( *v3 == v3 )
break;
if( v4[1] != v3 || (v5 = *v4, (*v4)[1] != v4) )
__fastfail(3u);
*v3 = v5;
v5[1] = v3;
KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
v6 = *((_DWORD *)v4 + 4);
if( v6 )
{
v7 = v6 - 1;
if( v7 )
{
if( v7 == 1 )
WmipProcessLegacyEtwCallback((__int64)v4, (__int64)Context);
}
else
{
KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
v8 = *((_QWORD *)Context + 13);
*((_QWORD *)Context + 13) = 0i64;
KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
if( v8 )
EtwUnregister(v8);
}
}
else
{
WmipProcessLegacyEtwRegister((tagGUIDENTRY *)Context, (UINT64)v4);
}
WmipUnreferenceEntry((__int64)&stru_140C00F40 + 4528, (volatile signed __int64 *)Context);
ExFreePoolWithTag(v4, 0x70696D57u);
KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
}
*((_DWORD *)Context + 4) &= ~0x10u;
*((_QWORD *)Context + 16) = 0i64;
KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
WmipUnreferenceEntry((__int64)&stru_140C00F40 + 4528, (volatile signed __int64 *)Context);
}Referenced by:
WmipAddDataSource