WmipSendWmiIrp
NTSTATUS __stdcall WmipSendWmiIrp(
UINT8 MinorFunction,
UINT64 ProviderId,
VOID *DataPath,
UINT64 BufferLength,
VOID *Buffer,
_IO_STATUS_BLOCK *Iosb){
int v6;
unsigned int v8;
INT64 v10;
_IRP *Irp;
_IRP *v12;
NTSTATUS v13;
UINT64 BufferLengtha;
v6 = BufferLength;
v8 = ProviderId;
while( 1 )
{
LOBYTE(v10) = *(_BYTE *)(*(&ExBootDevicesRemovedEvent + 391) + 76i64) + 1;
Irp = (_IRP *)IoAllocateIrp(v10, 0);
v12 = Irp;
if( !Irp )
break;
--Irp->Tail.CurrentStackLocation;
--Irp->CurrentLocation;
LODWORD(BufferLengtha) = v6;
Irp->Tail.CurrentStackLocation->DeviceObject = (_DEVICE_OBJECT *)*(&ExBootDevicesRemovedEvent + 391);
Irp->Tail.Thread = (_ETHREAD *)KeGetCurrentThread();
Irp->AssociatedIrp.MasterIrp = (_IRP *)Buffer;
v13 = WmipForwardWmiIrp(Irp, MinorFunction, v8, DataPath, BufferLengtha, Buffer);
*Iosb = v12->IoStatus;
IoFreeIrp(v12);
if( v13 != -1073741160 )
return v13;
}
return -1073741670;
}Referenced by:
WmipDereferenceEvent
WmipDisableCollectionForRemovedGuid
WmipEnableCollectionForNewGuid
WmipProcessLegacyEtwCallback
WmipQueryAllData
WmipQuerySetExecuteSI
WmipRegisterOrUpdateDS
WmipSendEnableDisableRequest