EtwGetKernelTraceTimestamp

LARGE_INTEGER __fastcall EtwGetKernelTraceTimestamp(LARGE_INTEGER *a1, UINT64 a2){
  int v3; 
  unsigned int v4; 
  bool i; 
  unsigned int v6; 
  __int64 v7; 
  __int64 v8; 
  LARGE_INTEGER PerformanceCounter; 
  LARGE_INTEGER result; 
  LARGE_INTEGER v11; 
  v3 = 0;
  if( qword_140D238A0 )
  {
    v4 = *(_DWORD *)(qword_140D238A0 + 4224);
    for( i = !_BitScanForward(&v6, v4); !i; i = !_BitScanForward(&v6, v4) )
    {
      v7 = v6;
      v4 &= v4 - 1;
      v8 = 32i64 * v6 + qword_140D238A0 + 4260;
      if( v8 && ((unsigned int)a2 & *(_DWORD *)(v8 + 4 * ((unsigned __int64)(unsigned int)a2 >> 29)) & 0x1FFFFFFF) != 0 )
        v3 |= 1 << *(_BYTE *)(qword_140D238A0 + 2 * v7 + 4209);
    }
  }
  else
  {
    LOBYTE(v3) = 30;
  }
  if( (v3 & 2) != 0 )
    PerformanceCounter = KeQueryPerformanceCounter(0i64);
  else
    PerformanceCounter.QuadPart = 0i64;
  *a1 = PerformanceCounter;
  if( (v3 & 4) != 0 )
    result.QuadPart = RtlGetSystemTimePrecise();
  else
    result.QuadPart = 0i64;
  a1[1] = result;
  if( (v3 & 8) != 0 )
  {
    result.QuadPart = __rdtsc();
    a1[2] = result;
  }
  else
  {
    a1[2].QuadPart = 0i64;
  }
  if( (v3 & 0x10) != 0 )
  {
    v11.QuadPart = 0i64;
    ((void(__fastcall *)(LARGE_INTEGER *))off_140C009E0[0])(&v11);
    result = v11;
    a1[3] = v11;
  }
  else
  {
    a1[3].QuadPart = 0i64;
  }
  return result;
}

Referenced by:

CmCreateKey
CmKtmNotification
CmOpenKey
CmpCloseKeyObject
CmpReplicateKeyToVirtual
CmpSecurityMethod
HvcallFastExtended
HvcallInitiateHypercall
IopTimerDispatch
KeFlushIoBuffers
KiHvInterruptSubDispatch
KiInterruptSubDispatch
KiInterruptSubDispatchNoLock
KiInvokeInterruptServiceRoutine
KiProcessExpiredTimerList
KiScanInterruptObjectList
KiVmbusInterruptSubDispatch
NtDeleteKey
NtDeleteValueKey
NtEnumerateKey
NtEnumerateValueKey
NtFlushKey
NtQueryKey
NtQueryMultipleValueKey
NtQueryValueKey
NtSetInformationKey
NtSetValueKey