EtwpDisableKernelTrace
VOID __stdcall EtwpDisableKernelTrace(
_PERFINFO_GROUPMASK *DesiredFlags,
_PERFINFO_GROUPMASK *FlagsToDisable,
UINT64 LoggerId){
unsigned int v6;
unsigned int v7;
unsigned int v8;
unsigned int v9;
unsigned int v10;
unsigned int i;
_ETHREAD *CurrentThread;
if( FlagsToDisable )
{
v6 = FlagsToDisable->Masks[0];
if( (FlagsToDisable->Masks[0] & 0x20000) != 0 )
{
*(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) = 0i64;
CmpTraceTxrRoutine = 0i64;
}
if( (v6 & 0x100000) != 0 )
{
AlpcUnregisterLogRoutine();
v6 = FlagsToDisable->Masks[0];
}
if( (v6 & 0x2000000) != 0 )
{
qword_140C00EF8 = 0i64;
v6 = FlagsToDisable->Masks[0];
}
if( (v6 & 0x4000000) != 0 )
{
qword_140C00EF0 = 0i64;
v6 = FlagsToDisable->Masks[0];
}
if( (v6 & 0x200) != 0 )
{
qword_140C00EE8 = 0i64;
v6 = FlagsToDisable->Masks[0];
}
if( (v6 & 0x100) != 0 )
{
EtwpDiskIoNotifyRoutines = 0i64;
qword_140C00ED8 = 0i64;
v6 = FlagsToDisable->Masks[0];
}
if( (v6 & 0x400) != 0 )
qword_140C544A8 = 0i64;
v7 = FlagsToDisable->Masks[4];
if( (v7 & 1) != 0 )
{
qword_140C544B0 = 0i64;
v7 = FlagsToDisable->Masks[4];
}
if( (v7 & 2) != 0 )
qword_140C544B8 = 0i64;
v8 = FlagsToDisable->Masks[0];
if( (FlagsToDisable->Masks[0] & 0x200000) != 0 )
{
EtwpSplitIoNotifyRoutines = 0i64;
v8 = FlagsToDisable->Masks[0];
}
if( (v8 & 0x10000) != 0 )
WmiSetNetworkNotify(0i64);
if( (FlagsToDisable->Masks[1] & 0x10) != 0 )
IoPerfReset(1ui64);
v9 = FlagsToDisable->Masks[4];
if( (v9 & 0x400000) != 0 )
{
qword_140C00EB8 = 0i64;
v9 = FlagsToDisable->Masks[4];
}
if( (v9 & 0x80000) != 0 )
{
qword_140C00EC0 = 0i64;
v9 = FlagsToDisable->Masks[4];
}
if( (v9 & 0x100000) != 0 )
{
qword_140C00EC8 = 0i64;
v9 = FlagsToDisable->Masks[4];
}
if( (v9 & 0x200000) != 0 )
{
qword_140C00ED0 = 0i64;
v9 = FlagsToDisable->Masks[4];
}
if( (v9 & 0x1000000) != 0 )
{
qword_140C11ED0 = 0i64;
v9 = FlagsToDisable->Masks[4];
}
if( (v9 & 0x2000000) != 0 )
qword_140C11ED8 = 0i64;
if( (FlagsToDisable->Masks[2] & 0x8000000) != 0 )
qword_140C11EE0 = 0i64;
if( (FlagsToDisable->Masks[0] & 0x40000) != 0 )
DbgSetDebugPrintCallback((PDEBUG_PRINT_CALLBACK)EtwpTraceDebugPrint, 0);
v10 = FlagsToDisable->Masks[1];
if( (v10 & 2) != 0 )
{
KeStopProfile((ULONG_PTR)&EtwpProfileObject);
v10 = FlagsToDisable->Masks[1];
}
if( (v10 & 0x400) != 0 )
{
for( i = 0; i < EtwpPmcProfile; ++i )
KeStopProfile((ULONG_PTR)qword_140C19C28 + 248 * i);
}
if( (FlagsToDisable->Masks[4] & 0x80u) != 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 243);
ExAcquirePushLockExclusiveEx((UINT64)&ObpStackTraceLock, 0i64);
ObpTraceFlags &= ~4u;
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&ObpStackTraceLock, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((volatile INT64 *)&ObpStackTraceLock);
KeAbPostRelease(&ObpStackTraceLock);
KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
}
if( (FlagsToDisable->Masks[1] & 0x880000) != 0 && (!DesiredFlags || (DesiredFlags->Masks[1] & 0x880000) == 0) )
KeCancelTimer2(&EtwpMemInfoTimer, 0i64);
}
EtwpUpdateFileInfoDriverState(DesiredFlags, FlagsToDisable, 0i64, LoggerId);
}Referenced by:
EtwpEnableKernelTrace
EtwpUpdateGlobalGroupMasks