IopBootLogToFile

INT64 __stdcall IopBootLogToFile(PUNICODE_STRING String){
  _ETHREAD *CurrentThread; 
  WCHAR v4; 
  _UNICODE_STRING *v5; 
  NTSTATUS v6; 
  ULONG Length; 
  UINT64 FileAttributes; 
  UINT64 ShareAccess; 
  UINT64 CreateDisposition; 
  UINT64 CreateOptions; 
  UINT64 EaLength; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int16 Buffer; 
  void *FileHandle; 
  union _LARGE_INTEGER ByteOffset; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  IoStatusBlock = 0i64;
  FileHandle = 0i64;
  Buffer = -257;
  if( !qword_140D2C030 )
    return 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquireResourceExclusiveLite((ERESOURCE *)&qword_140D2C030[4], 1u);
  v5 = qword_140D2C030;
  if( !qword_140D2C030[2].Buffer )
    RtlInitUnicodeString(qword_140D2C030 + 2, L"\\SystemRoot\\ntbtlog.txt", v4);
  LODWORD(EaLength) = 0;
  LODWORD(CreateOptions) = 100;
  LODWORD(CreateDisposition) = 3;
  LODWORD(ShareAccess) = 1;
  LODWORD(FileAttributes) = 128;
  ObjectAttributes.Length = 48;
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.Attributes = 576;
  ObjectAttributes.ObjectName = v5 + 2;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  v6 = ZwCreateFile(
         &FileHandle,
         0x40000000ui64,
         &ObjectAttributes,
         &IoStatusBlock,
         0i64,
         FileAttributes,
         ShareAccess,
         CreateDisposition,
         CreateOptions,
         0i64,
         EaLength);
  if( v6 >= 0 )
  {
    if( IoStatusBlock.Information == 2 )
      v6 = ZwWriteFile(FileHandle, 0i64, 0i64, 0i64, &IoStatusBlock, &Buffer, 2u, 0i64, 0i64);
    if( v6 >= 0 )
    {
      Length = String->Length;
      ByteOffset.QuadPart = -1i64;
      v6 = ZwWriteFile(FileHandle, 0i64, 0i64, 0i64, &IoStatusBlock, String->Buffer, Length, &ByteOffset, 0i64);
    }
    ZwClose(FileHandle);
  }
  ExReleaseResourceLite((PERESOURCE)&qword_140D2C030[4]);
  KeLeaveCriticalRegionThread((__int64)CurrentThread);
  return(unsigned int)v6;
}

Referenced by:

IopBootLog
IopCopyBootLogRegistryToFile