WmipSendWmiIrpToTraceDeviceList
NTSTATUS __stdcall WmipSendWmiIrpToTraceDeviceList(
_WMIP_TRACE_DEVICE *DeviceList,
UINT64 DeviceCount,
UINT8 MinorFunction,
UINT64 BufferLength,
VOID *Buffer){
int v5;
__int64 v6;
NTSTATUS v8;
__int16 v9;
char v10;
INT64 v11;
_IRP *Irp;
_CCHAR v13;
UINT16 v14;
UINT64 BufferLengtha;
v5 = BufferLength;
v6 = (unsigned int)DeviceCount;
v8 = 0;
KeWaitForSingleObject((UINT64)&ExBootDevicesRemovedEvent + 3072, 0, 0, 0, 0i64);
v9 = *(char *)(*(&ExBootDevicesRemovedEvent + 391) + 76i64);
v10 = v9 + 1;
KeReleaseMutex((_KMUTANT *)((char *)&ExBootDevicesRemovedEvent + 3072), 0);
LOBYTE(v11) = v9 + 1;
Irp = (_IRP *)IoAllocateIrp(v11, 0);
if( !Irp )
return -1073741670;
if( (_DWORD)v6 )
{
v14 = 72 * v9 + 280;
do
{
LOBYTE(v13) = v10;
IoInitializeIrp(Irp, v14, v13);
--Irp->Tail.CurrentStackLocation;
--Irp->CurrentLocation;
LODWORD(BufferLengtha) = v5;
Irp->Tail.CurrentStackLocation->DeviceObject = (_DEVICE_OBJECT *)*(&ExBootDevicesRemovedEvent + 391);
Irp->Tail.Thread = (_ETHREAD *)KeGetCurrentThread();
WmipForwardWmiIrp(
Irp,
MinorFunction,
*(unsigned int *)(*(_QWORD *)DeviceList + 56i64),
0i64,
BufferLengtha,
Buffer);
DeviceList += 4;
--v6;
}
while( v6 );
v8 = 0;
}
IoFreeIrp(Irp);
return v8;
}Referenced by:
WmiSetNetworkNotify
WmiTraceRundownNotify