EtwpDisableKernelTrace

VOID __stdcall EtwpDisableKernelTrace(
        _PERFINFO_GROUPMASK *DesiredFlags,
        _PERFINFO_GROUPMASK *FlagsToDisable,
        UINT64 LoggerId){
  unsigned int v6; 
  unsigned int v7; 
  unsigned int v8; 
  unsigned int v9; 
  unsigned int v10; 
  unsigned int i; 
  _ETHREAD *CurrentThread; 
  if( FlagsToDisable )
  {
    v6 = FlagsToDisable->Masks[0];
    if( (FlagsToDisable->Masks[0] & 0x20000) != 0 )
    {
      *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) = 0i64;
      CmpTraceTxrRoutine = 0i64;
    }
    if( (v6 & 0x100000) != 0 )
    {
      AlpcUnregisterLogRoutine();
      v6 = FlagsToDisable->Masks[0];
    }
    if( (v6 & 0x2000000) != 0 )
    {
      qword_140C00EF8 = 0i64;
      v6 = FlagsToDisable->Masks[0];
    }
    if( (v6 & 0x4000000) != 0 )
    {
      qword_140C00EF0 = 0i64;
      v6 = FlagsToDisable->Masks[0];
    }
    if( (v6 & 0x200) != 0 )
    {
      qword_140C00EE8 = 0i64;
      v6 = FlagsToDisable->Masks[0];
    }
    if( (v6 & 0x100) != 0 )
    {
      EtwpDiskIoNotifyRoutines = 0i64;
      qword_140C00ED8 = 0i64;
      v6 = FlagsToDisable->Masks[0];
    }
    if( (v6 & 0x400) != 0 )
      qword_140C544A8 = 0i64;
    v7 = FlagsToDisable->Masks[4];
    if( (v7 & 1) != 0 )
    {
      qword_140C544B0 = 0i64;
      v7 = FlagsToDisable->Masks[4];
    }
    if( (v7 & 2) != 0 )
      qword_140C544B8 = 0i64;
    v8 = FlagsToDisable->Masks[0];
    if( (FlagsToDisable->Masks[0] & 0x200000) != 0 )
    {
      EtwpSplitIoNotifyRoutines = 0i64;
      v8 = FlagsToDisable->Masks[0];
    }
    if( (v8 & 0x10000) != 0 )
      WmiSetNetworkNotify(0i64);
    if( (FlagsToDisable->Masks[1] & 0x10) != 0 )
      IoPerfReset(1ui64);
    v9 = FlagsToDisable->Masks[4];
    if( (v9 & 0x400000) != 0 )
    {
      qword_140C00EB8 = 0i64;
      v9 = FlagsToDisable->Masks[4];
    }
    if( (v9 & 0x80000) != 0 )
    {
      qword_140C00EC0 = 0i64;
      v9 = FlagsToDisable->Masks[4];
    }
    if( (v9 & 0x100000) != 0 )
    {
      qword_140C00EC8 = 0i64;
      v9 = FlagsToDisable->Masks[4];
    }
    if( (v9 & 0x200000) != 0 )
    {
      qword_140C00ED0 = 0i64;
      v9 = FlagsToDisable->Masks[4];
    }
    if( (v9 & 0x1000000) != 0 )
    {
      qword_140C11ED0 = 0i64;
      v9 = FlagsToDisable->Masks[4];
    }
    if( (v9 & 0x2000000) != 0 )
      qword_140C11ED8 = 0i64;
    if( (FlagsToDisable->Masks[2] & 0x8000000) != 0 )
      qword_140C11EE0 = 0i64;
    if( (FlagsToDisable->Masks[0] & 0x40000) != 0 )
      DbgSetDebugPrintCallback((PDEBUG_PRINT_CALLBACK)EtwpTraceDebugPrint, 0);
    v10 = FlagsToDisable->Masks[1];
    if( (v10 & 2) != 0 )
    {
      KeStopProfile((ULONG_PTR)&EtwpProfileObject);
      v10 = FlagsToDisable->Masks[1];
    }
    if( (v10 & 0x400) != 0 )
    {
      for( i = 0; i < EtwpPmcProfile; ++i )
        KeStopProfile((ULONG_PTR)qword_140C19C28 + 248 * i);
    }
    if( (FlagsToDisable->Masks[4] & 0x80u) != 0 )
    {
      CurrentThread = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)CurrentThread + 243);
      ExAcquirePushLockExclusiveEx((UINT64)&ObpStackTraceLock, 0i64);
      ObpTraceFlags &= ~4u;
      if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&ObpStackTraceLock, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
        ExfTryToWakePushLock((volatile INT64 *)&ObpStackTraceLock);
      KeAbPostRelease(&ObpStackTraceLock);
      KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
    }
    if( (FlagsToDisable->Masks[1] & 0x880000) != 0 && (!DesiredFlags || (DesiredFlags->Masks[1] & 0x880000) == 0) )
      KeCancelTimer2(&EtwpMemInfoTimer, 0i64);
  }
  EtwpUpdateFileInfoDriverState(DesiredFlags, FlagsToDisable, 0i64, LoggerId);
}

Referenced by:

EtwpEnableKernelTrace
EtwpUpdateGlobalGroupMasks