PfTStart
INT64 __fastcall PfTStart(INT64 a1, INT64 a2, UINT64 a3){
int v3;
INT64 v5;
int v6;
HANDLE v7;
INT64 v8;
INT64 v9;
int v11[8];
struct _UNICODE_STRING DestinationString;
HANDLE Handle;
PVOID Object;
Handle = 0i64;
v3 = a3;
DestinationString = 0i64;
if( (a3 & 1) != 0 && (xmmword_140C4FE44 & 1) == 0 )
v3 = a3 & 0xFFFFFFFE;
if( (v3 & 2) != 0 && (xmmword_140C4FE44 & 1) == 0 && (_DWORD)qword_140C4FE60 != 1 && HIDWORD(qword_140C4FE60) != 1 )
v3 &= ~2u;
if( (v3 & 1) != 0 )
{
v6 = PfTAllocateBuffers(a1 + 24, 0x8000ui64, 8ui64, 0x424C6650ui64);
if( v6 < 0 )
goto LABEL_30;
v6 = PfTAllocateBuffers(a1 + 64, 0x14028ui64, 2ui64, 0x54456650ui64);
if( v6 < 0 )
goto LABEL_30;
v6 = PsCreateSystemThreadEx(
&Handle,
0x1FFFFFui64,
0i64,
0i64,
0i64,
(PKSTART_ROUTINE)PfTLoggingWorker,
(PVOID)(a1 + 104),
0i64,
0i64);
if( v6 < 0 )
goto LABEL_30;
Object = 0i64;
ObReferenceObjectByHandle(Handle, 0x1FFFFFu, (POBJECT_TYPE)PsThreadType, 0, &Object, 0i64);
v7 = Handle;
*(_QWORD *)(a1 + 104) = Object;
ObCloseHandle(v7, 0);
}
if( (v3 & 3) != 0 && !*(_QWORD *)(a1 + 616) )
{
RtlInitUnicodeString(&DestinationString, L"\\KernelObjects\\SuperfetchTracesReady", a3);
v6 = PfpCreateEvent(&DestinationString, SynchronizationEvent, (KEVENT **)(a1 + 616));
if( v6 < 0 )
{
LABEL_30:
PfTCleanup(a1, v5);
PfTInitialize();
return(unsigned int)v6;
}
}
if( (v3 & 1) != 0 )
{
PfFbBufferListUpdateMax(a1 + 352, 0x100000);
PfFbBufferListAllocate(
v8,
(unsigned int)(((_DWORD)KeNumberProcessors_0 + 2) << 12),
(unsigned int)(2 * KeNumberProcessors_0 + 4));
}
if( (v3 & 2) != 0 )
{
PfFbBufferListUpdateMax(a1 + 224, 0x1000000);
PfFbBufferListAllocate(
v9,
(unsigned int)(((_DWORD)KeNumberProcessors_0 + 7) << 15),
(unsigned int)(2 * KeNumberProcessors_0 + 14));
}
ExAcquireFastMutex((FAST_MUTEX *)(a1 + 560));
if( (v3 & 1) != 0 )
{
*(_DWORD *)(a1 + 540) = HIDWORD(xmmword_140C4FE44);
if( dword_140C4FB18 < (unsigned int)dword_140C4FB1C )
PfTAccessTracingStart(a1, (__int64)&PfKernelGlobals, 2);
}
if( (v3 & 2) != 0 )
*(_DWORD *)(a1 + 548) = DWORD2(xmmword_140C4FE44);
KeReleaseGuardedMutex((_FAST_MUTEX *)(a1 + 560));
*(_DWORD *)(a1 + 8) |= v3;
if( (v3 & 1) != 0 )
{
_InterlockedOr(v11, 0);
PsEnumProcesses((__int64(__fastcall *)(unsigned __int64, __int64))PfCalculateProcessHash, 0i64);
PfTAccessTracingStart(a1, (__int64)&PfKernelGlobals, 1);
}
return 0;
}Referenced by:
PfSetSuperfetchInformation
PfpParametersPropagate