WmipLegacyEtwWorker

VOID __stdcall WmipLegacyEtwWorker(VOID *Context){
  __int64 v2; 
  void **v3; 
  void ***v4; 
  void **v5; 
  int v6; 
  int v7; 
  UINT64 v8; 

  WmipReferenceEntry((INT64)Context);
  KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
  v2 = *((_QWORD *)Context + 16);
  v3 = (void **)(v2 + 24);
  if( !v2 )
    v3 = (void **)((char *)Context + 136);
  while( 1 )
  {
    v4 = (void ***)*v3;
    if( *v3 == v3 )
      break;
    if( v4[1] != v3 || (v5 = *v4, (*v4)[1] != v4) )
      __fastfail(3u);
    *v3 = v5;
    v5[1] = v3;
    KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
    v6 = *((_DWORD *)v4 + 4);
    if( v6 )
    {
      v7 = v6 - 1;
      if( v7 )
      {
        if( v7 == 1 )
          WmipProcessLegacyEtwCallback((__int64)v4, (__int64)Context);
      }
      else
      {
        KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
        v8 = *((_QWORD *)Context + 13);
        *((_QWORD *)Context + 13) = 0i64;
        KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
        if( v8 )
          EtwUnregister(v8);
      }
    }
    else
    {
      WmipProcessLegacyEtwRegister((tagGUIDENTRY *)Context, (UINT64)v4);
    }
    WmipUnreferenceEntry((__int64)&stru_140C00F40 + 4528, (volatile signed __int64 *)Context);
    ExFreePoolWithTag(v4, 0x70696D57u);
    KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
  }
  *((_DWORD *)Context + 4) &= ~0x10u;
  *((_QWORD *)Context + 16) = 0i64;
  KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
  WmipUnreferenceEntry((__int64)&stru_140C00F40 + 4528, (volatile signed __int64 *)Context);
}

Referenced by:

WmipAddDataSource