EtwpTraceSystemInitialization
VOID __stdcall EtwpTraceSystemInitialization(){
REGHANDLE v0;
_LOADER_PARAMETER_BLOCK *v1;
_LOADER_PARAMETER_EXTENSION *Extension;
_HV_PARTITION_PRIVILEGE_MASK v3;
__int64 v4;
char v5;
REGHANDLE v6;
__int64 p_CodeSize;
__int64 v8;
__int64 *p_SoftRestartTime;
int v10;
int v11;
int v12;
int v13;
int v14;
int v15;
int v16;
int v17;
int v18;
int v19;
__int64 v20;
_LARGE_INTEGER v21;
__int64 v22;
_HV_X64_HYPERVISOR_FEATURES HvFeaturesOut;
INT64 v24[2];
int VersionInformation;
_DWORD VersionInformation_4[71];
_EVENT_DATA_DESCRIPTOR UserData;
__int64 *v28;
__int64 v29;
unsigned int *p_SoftRestartCount;
__int64 v31;
int *v32;
__int64 v33;
_DWORD *v34;
__int64 v35;
int *v36;
__int64 v37;
_LARGE_INTEGER *v38;
__int64 v39;
_EVENT_DATA_DESCRIPTOR v40;
int *v41;
__int64 v42;
int *v43;
__int64 v44;
int *v45;
__int64 v46;
int *v47;
__int64 v48;
int *v49;
__int64 v50;
int *v51;
__int64 v52;
__int64 *v53;
__int64 v54;
_HV_X64_HYPERVISOR_FEATURES *p_HvFeaturesOut;
__int64 v56;
int *v57;
__int64 v58;
int *v59;
__int64 v60;
_EVENT_DATA_DESCRIPTOR v61;
int *v62;
__int64 v63;
int *v64;
__int64 v65;
memset(VersionInformation_4, 0i64, 0x118u);
v13 = NtBuildQfe;
v14 = InitSafeBootMode;
*(_OWORD *)v24 = 0i64;
VersionInformation = 284;
if( RtlGetVersion((_OSVERSIONINFOW *)&VersionInformation) >= 0 )
{
v21 = KeBootTime;
if( *(&stru_140C00F40 + 1820) > 5u && tlgKeywordOn((__int64)&stru_140C00F40 + 7280, 0x800000000000i64) )
{
v15 = VersionInformation_4[0];
HvFeaturesOut.PartitionPrivileges = v3;
v41 = &v15;
LOBYTE(v10) = v4 != 0;
v16 = VersionInformation_4[1];
v42 = 4i64;
v43 = &v16;
v17 = VersionInformation_4[2];
v45 = &v17;
v47 = &v18;
v19 = v13;
v49 = &v19;
LOWORD(v11) = VersionInformation_4[68];
v51 = &v11;
LODWORD(v20) = v14;
v53 = &v20;
p_HvFeaturesOut = &HvFeaturesOut;
v12 = dword_140C508A0;
v57 = &v12;
v59 = &v10;
v44 = 4i64;
v46 = 4i64;
v18 = 1;
v48 = 4i64;
v50 = 4i64;
v52 = 2i64;
v54 = 4i64;
v56 = 8i64;
v58 = 4i64;
v60 = 1i64;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&stru_140C00F40 + 7280,
(unsigned __int8 *)word_14002BAD2,
0i64,
0i64,
0xCu,
&v40);
}
if( HviIsHypervisorVendorMicrosoft() )
{
HviGetHardwareFeatures((INT64)v24);
HvFeaturesOut = 0i64;
HviGetHypervisorFeatures(&HvFeaturesOut);
if( *(&stru_140C00F40 + 1820) > 5u )
{
if( tlgKeywordOn((__int64)&stru_140C00F40 + 7280, 0x400000000000i64) )
{
LOBYTE(v10) = v5;
v12 = (LODWORD(v24[0]) >> 10) & 0xF;
v63 = 4i64;
v62 = &v12;
v65 = 1i64;
v64 = &v10;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&stru_140C00F40 + 7280,
(unsigned __int8 *)byte_14002BA9D,
0i64,
0i64,
4u,
&v61);
}
}
}
if( *(&ExBootDevicesRemovedEvent + 380) )
{
*(_QWORD *)&UserData.Size = 4i64;
UserData.Ptr = (unsigned __int64)VersionInformation_4;
v29 = 4i64;
v28 = (__int64 *)&VersionInformation_4[1];
v31 = 4i64;
p_SoftRestartCount = &VersionInformation_4[2];
v33 = 4i64;
v32 = &v13;
v34 = &VersionInformation_4[68];
v36 = &v14;
v38 = &v21;
v35 = 2i64;
v37 = 4i64;
v39 = 8i64;
EtwWriteEx(*(&ExBootDevicesRemovedEvent + 380), &KernelSystemStart, 0i64, 0, 0, 0, 7u, &UserData);
v0 = *(&ExBootDevicesRemovedEvent + 380);
if( EtwEventEnabled(*(&ExBootDevicesRemovedEvent + 380), &BootPerformanceData) )
{
*(_QWORD *)&UserData.Size = 264i64;
UserData.Ptr = (unsigned __int64)&EtwBootPerfData;
EtwWriteEx(v0, &BootPerformanceData, 0i64, 0, 0, 0, 1u, &UserData);
}
v1 = KeLoaderBlock_0;
Extension = KeLoaderBlock_0->Extension;
if( (Extension->_bf_84 & 0x100) != 0 || Extension->LoaderPerformanceData.CleanupVsmTime )
{
v6 = *(&ExBootDevicesRemovedEvent + 380);
if( EtwEventEnabled(*(&ExBootDevicesRemovedEvent + 380), &VsmPerformanceData) )
{
*(_QWORD *)&UserData.Size = 8i64;
UserData.Ptr = (unsigned __int64)&Extension->LoaderPerformanceData.CleanupVsmTime;
p_CodeSize = (__int64)&v1->Extension->MiniExecutive.CodeSize;
v29 = 64i64;
v28 = (__int64 *)p_CodeSize;
EtwWriteEx(v6, &VsmPerformanceData, 0i64, 0, 0, 0, 2u, &UserData);
}
}
if( (*(&ExBootDevicesRemovedEvent + 1112) & 4) != 0 )
{
LODWORD(v8) = RtlGetSystemTimePrecise();
v22 = v8;
p_SoftRestartTime = &KeLoaderBlock_0->Extension->SoftRestartTime;
*(_QWORD *)&UserData.Size = 8i64;
UserData.Ptr = (unsigned __int64)p_SoftRestartTime;
v28 = &v22;
v29 = 8i64;
p_SoftRestartCount = &KeLoaderBlock_0->Extension->SoftRestartCount;
v31 = 4i64;
EtwWriteEx(*(&ExBootDevicesRemovedEvent + 380), &SoftBootInfo, 0i64, 0, 0, 0, 3u, &UserData);
}
}
}
}Referenced by:
EtwpInitialize