IopBootLogToFile
INT64 __stdcall IopBootLogToFile(PUNICODE_STRING String){
_ETHREAD *CurrentThread;
WCHAR v4;
_UNICODE_STRING *v5;
NTSTATUS v6;
ULONG Length;
UINT64 FileAttributes;
UINT64 ShareAccess;
UINT64 CreateDisposition;
UINT64 CreateOptions;
UINT64 EaLength;
struct _IO_STATUS_BLOCK IoStatusBlock;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int16 Buffer;
void *FileHandle;
union _LARGE_INTEGER ByteOffset;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
IoStatusBlock = 0i64;
FileHandle = 0i64;
Buffer = -257;
if( !qword_140D2C030 )
return 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquireResourceExclusiveLite((ERESOURCE *)&qword_140D2C030[4], 1u);
v5 = qword_140D2C030;
if( !qword_140D2C030[2].Buffer )
RtlInitUnicodeString(qword_140D2C030 + 2, L"\\SystemRoot\\ntbtlog.txt", v4);
LODWORD(EaLength) = 0;
LODWORD(CreateOptions) = 100;
LODWORD(CreateDisposition) = 3;
LODWORD(ShareAccess) = 1;
LODWORD(FileAttributes) = 128;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
ObjectAttributes.ObjectName = v5 + 2;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v6 = ZwCreateFile(
&FileHandle,
0x40000000ui64,
&ObjectAttributes,
&IoStatusBlock,
0i64,
FileAttributes,
ShareAccess,
CreateDisposition,
CreateOptions,
0i64,
EaLength);
if( v6 >= 0 )
{
if( IoStatusBlock.Information == 2 )
v6 = ZwWriteFile(FileHandle, 0i64, 0i64, 0i64, &IoStatusBlock, &Buffer, 2u, 0i64, 0i64);
if( v6 >= 0 )
{
Length = String->Length;
ByteOffset.QuadPart = -1i64;
v6 = ZwWriteFile(FileHandle, 0i64, 0i64, 0i64, &IoStatusBlock, String->Buffer, Length, &ByteOffset, 0i64);
}
ZwClose(FileHandle);
}
ExReleaseResourceLite((PERESOURCE)&qword_140D2C030[4]);
KeLeaveCriticalRegionThread((__int64)CurrentThread);
return(unsigned int)v6;
}Referenced by:
IopBootLog
IopCopyBootLogRegistryToFile