PfTStart

INT64 __fastcall PfTStart(INT64 a1, INT64 a2, UINT64 a3){
  int v3; 
  INT64 v5; 
  int v6; 
  HANDLE v7; 
  INT64 v8; 
  INT64 v9; 
  int v11[8]; 
  struct _UNICODE_STRING DestinationString; 
  HANDLE Handle; 
  PVOID Object; 
  Handle = 0i64;
  v3 = a3;
  DestinationString = 0i64;
  if( (a3 & 1) != 0 && (xmmword_140C4FE44 & 1) == 0 )
    v3 = a3 & 0xFFFFFFFE;
  if( (v3 & 2) != 0 && (xmmword_140C4FE44 & 1) == 0 && (_DWORD)qword_140C4FE60 != 1 && HIDWORD(qword_140C4FE60) != 1 )
    v3 &= ~2u;
  if( (v3 & 1) != 0 )
  {
    v6 = PfTAllocateBuffers(a1 + 24, 0x8000ui64, 8ui64, 0x424C6650ui64);
    if( v6 < 0 )
      goto LABEL_30;
    v6 = PfTAllocateBuffers(a1 + 64, 0x14028ui64, 2ui64, 0x54456650ui64);
    if( v6 < 0 )
      goto LABEL_30;
    v6 = PsCreateSystemThreadEx(
           &Handle,
           0x1FFFFFui64,
           0i64,
           0i64,
           0i64,
           (PKSTART_ROUTINE)PfTLoggingWorker,
           (PVOID)(a1 + 104),
           0i64,
           0i64);
    if( v6 < 0 )
      goto LABEL_30;
    Object = 0i64;
    ObReferenceObjectByHandle(Handle, 0x1FFFFFu, (POBJECT_TYPE)PsThreadType, 0, &Object, 0i64);
    v7 = Handle;
    *(_QWORD *)(a1 + 104) = Object;
    ObCloseHandle(v7, 0);
  }
  if( (v3 & 3) != 0 && !*(_QWORD *)(a1 + 616) )
  {
    RtlInitUnicodeString(&DestinationString, L"\\KernelObjects\\SuperfetchTracesReady", a3);
    v6 = PfpCreateEvent(&DestinationString, SynchronizationEvent, (KEVENT **)(a1 + 616));
    if( v6 < 0 )
    {
LABEL_30:
      PfTCleanup(a1, v5);
      PfTInitialize();
      return(unsigned int)v6;
    }
  }
  if( (v3 & 1) != 0 )
  {
    PfFbBufferListUpdateMax(a1 + 352, 0x100000);
    PfFbBufferListAllocate(
      v8,
      (unsigned int)(((_DWORD)KeNumberProcessors_0 + 2) << 12),
      (unsigned int)(2 * KeNumberProcessors_0 + 4));
  }
  if( (v3 & 2) != 0 )
  {
    PfFbBufferListUpdateMax(a1 + 224, 0x1000000);
    PfFbBufferListAllocate(
      v9,
      (unsigned int)(((_DWORD)KeNumberProcessors_0 + 7) << 15),
      (unsigned int)(2 * KeNumberProcessors_0 + 14));
  }
  ExAcquireFastMutex((FAST_MUTEX *)(a1 + 560));
  if( (v3 & 1) != 0 )
  {
    *(_DWORD *)(a1 + 540) = HIDWORD(xmmword_140C4FE44);
    if( dword_140C4FB18 < (unsigned int)dword_140C4FB1C )
      PfTAccessTracingStart(a1, (__int64)&PfKernelGlobals, 2);
  }
  if( (v3 & 2) != 0 )
    *(_DWORD *)(a1 + 548) = DWORD2(xmmword_140C4FE44);
  KeReleaseGuardedMutex((_FAST_MUTEX *)(a1 + 560));
  *(_DWORD *)(a1 + 8) |= v3;
  if( (v3 & 1) != 0 )
  {
    _InterlockedOr(v11, 0);
    PsEnumProcesses((__int64(__fastcall *)(unsigned __int64, __int64))PfCalculateProcessHash, 0i64);
    PfTAccessTracingStart(a1, (__int64)&PfKernelGlobals, 1);
  }
  return 0;
}

Referenced by:

PfSetSuperfetchInformation
PfpParametersPropagate