EtwpLoadMicroarchitecturalProfileSource
NTSTATUS __stdcall EtwpLoadMicroarchitecturalProfileSource(WCHAR *Path, _KAFFINITY_EX *Source, WCHAR *Src){
unsigned int v6;
NTSTATUS result;
VOID **PoolWithTag;
VOID **v9;
int CpuVendor;
int v11;
int v12;
int v13;
int v14;
int v15;
int v16;
int v17;
int v18;
int v19;
int *v20;
int v21;
int *v22;
int v23;
int *v24;
int v25;
int *v26;
int v27;
int *v28;
int v29;
int *v30;
int v31;
int *v32;
int v33;
int *v34;
__int64 v35[63];
if( !Src )
return -1073741823;
v18 = 0;
v15 = 0;
v13 = 0;
v14 = 0;
v6 = wcsnlen(Src, 0xFEui64) + 1;
v16 = 0;
v11 = -1;
v12 = -1;
v17 = 0x10000;
memset(v35, 0i64, sizeof(v35));
v35[0] = (__int64)EtwpQueryRegistryCallback;
v35[3] = (__int64)&v19;
v35[2] = (__int64)L"Event";
v20 = &v11;
v35[10] = (__int64)&v21;
v35[9] = (__int64)L"Unit";
v22 = &v12;
v35[17] = (__int64)&v23;
v35[16] = (__int64)L"Interval";
v24 = &v17;
v35[24] = (__int64)&v25;
v35[23] = (__int64)L"AllowsHalt";
v26 = &v18;
v35[31] = (__int64)&v27;
v35[30] = (__int64)L"CMask";
v28 = &v13;
v35[38] = (__int64)&v29;
v35[37] = (__int64)L"EdgeDetect";
v30 = &v16;
v35[45] = (__int64)&v31;
v35[44] = (__int64)L"AnyThread";
LODWORD(v35[4]) = 4;
v19 = 4;
v35[7] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[11]) = 4;
v21 = 4;
v35[14] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[18]) = 4;
v23 = 4;
v35[21] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[25]) = 4;
v25 = 4;
v35[28] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[32]) = 4;
v27 = 4;
v35[35] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[39]) = 4;
v29 = 4;
v35[42] = (__int64)EtwpQueryRegistryCallback;
LODWORD(v35[46]) = 4;
v31 = 4;
v32 = &v15;
v35[49] = (__int64)EtwpQueryRegistryCallback;
v35[52] = (__int64)&v33;
LODWORD(v35[53]) = 4;
v35[51] = (__int64)L"CMaskInvert";
v33 = 4;
v34 = &v14;
LOBYTE(result) = RtlpQueryRegistryValues((_KTRAP_FRAME *)0x40000000, (_KEXCEPTION_FRAME *)Path);
if( result < 0 )
return result;
if( v11 == -1 || v12 == -1 )
return -1073741823;
PoolWithTag = ExAllocatePoolWithTag(1ui64, 2 * v6 + 184, 1350005829i64);
v9 = PoolWithTag;
if( !PoolWithTag )
return -1073741801;
wcsncpy_s((WCHAR *)PoolWithTag + 92, v6, Src, v6);
KeCopyAffinityEx((_KAFFINITY_EX *)(v9 + 2), Source);
CpuVendor = KiGetCpuVendor();
if( CpuVendor == 2 )
{
*(_BYTE *)v9 = v11;
*((_BYTE *)v9 + 1) = v12;
*((_BYTE *)v9 + 2) = v13;
*((_BYTE *)v9 + 3) = v14;
*((_BYTE *)v9 + 4) = v15;
*((_BYTE *)v9 + 5) = v16;
}
else if( CpuVendor == 1 )
{
*(_BYTE *)v9 = v11;
*((_BYTE *)v9 + 1) = v12;
}
*((_DWORD *)v9 + 2) = v17;
((void(__fastcall *)(__int64, _QWORD, VOID **))off_140C00A70[0])(20i64, 2 * v6 + 184, v9);
ExFreePoolWithTag(v9, 0x50777445u);
return 0;
}Referenced by:
EtwpLoadMicroarchitecturalProfileGroup