EtwGetKernelTraceTimestamp
LARGE_INTEGER __fastcall EtwGetKernelTraceTimestamp(LARGE_INTEGER *a1, UINT64 a2){
int v3;
unsigned int v4;
bool i;
unsigned int v6;
__int64 v7;
__int64 v8;
LARGE_INTEGER PerformanceCounter;
LARGE_INTEGER result;
LARGE_INTEGER v11;
v3 = 0;
if( qword_140D238A0 )
{
v4 = *(_DWORD *)(qword_140D238A0 + 4224);
for( i = !_BitScanForward(&v6, v4); !i; i = !_BitScanForward(&v6, v4) )
{
v7 = v6;
v4 &= v4 - 1;
v8 = 32i64 * v6 + qword_140D238A0 + 4260;
if( v8 && ((unsigned int)a2 & *(_DWORD *)(v8 + 4 * ((unsigned __int64)(unsigned int)a2 >> 29)) & 0x1FFFFFFF) != 0 )
v3 |= 1 << *(_BYTE *)(qword_140D238A0 + 2 * v7 + 4209);
}
}
else
{
LOBYTE(v3) = 30;
}
if( (v3 & 2) != 0 )
PerformanceCounter = KeQueryPerformanceCounter(0i64);
else
PerformanceCounter.QuadPart = 0i64;
*a1 = PerformanceCounter;
if( (v3 & 4) != 0 )
result.QuadPart = RtlGetSystemTimePrecise();
else
result.QuadPart = 0i64;
a1[1] = result;
if( (v3 & 8) != 0 )
{
result.QuadPart = __rdtsc();
a1[2] = result;
}
else
{
a1[2].QuadPart = 0i64;
}
if( (v3 & 0x10) != 0 )
{
v11.QuadPart = 0i64;
((void(__fastcall *)(LARGE_INTEGER *))off_140C009E0[0])(&v11);
result = v11;
a1[3] = v11;
}
else
{
a1[3].QuadPart = 0i64;
}
return result;
}Referenced by:
CmCreateKey
CmKtmNotification
CmOpenKey
CmpCloseKeyObject
CmpReplicateKeyToVirtual
CmpSecurityMethod
HvcallFastExtended
HvcallInitiateHypercall
IopTimerDispatch
KeFlushIoBuffers
KiHvInterruptSubDispatch
KiInterruptSubDispatch
KiInterruptSubDispatchNoLock
KiInvokeInterruptServiceRoutine
KiProcessExpiredTimerList
KiScanInterruptObjectList
KiVmbusInterruptSubDispatch
NtDeleteKey
NtDeleteValueKey
NtEnumerateKey
NtEnumerateValueKey
NtFlushKey
NtQueryKey
NtQueryMultipleValueKey
NtQueryValueKey
NtSetInformationKey
NtSetValueKey