EtwStartAutoLogger
INT64 __stdcall EtwStartAutoLogger(WCHAR *LoggerName, WCHAR *LoggerKeyName, UINT64 *LoggerId){
UINT64 *v3;
void *v6;
char *v7;
WCHAR v8;
NTSTATUS v9;
char *PoolWithTag;
WCHAR v11;
UINT8 *v12;
int v13;
_WORD *v14;
int v15;
WCHAR v16;
int v17;
const WCHAR *v18;
unsigned int *v20;
int v21;
int v22;
unsigned int v23;
__int16 v24;
_DWORD *v25;
int v26;
WCHAR v27;
GUID v28;
__int64 v29;
__int64 v30;
int started;
unsigned int v32;
__int64 *v33;
unsigned int v34;
const WCHAR *v35;
__int64 v36;
_WORD *v37;
NTSTATUS KeyTreeForPath;
int v39;
UINT8 *v40;
unsigned __int16 v41;
UINT16 v42;
__int64 v43;
UINT8 *v44;
unsigned int v45;
__int64 v46;
unsigned int v47;
__int64 *CurrentServerSiloGlobals;
ULONG v49;
PVOID ValueData;
UINT64 ValueLength;
__int16 v52[2];
_DWORD KeyLength[3];
unsigned int v54;
int v55;
UINT64 Disposition;
HANDLE Handle;
__int16 v58;
int v59;
int v60;
ULONG v61;
void *KeyHandle;
UNICODE_STRING GuidString;
int v64;
int v65;
int v66;
void *Src;
__int128 v68;
__int128 v69;
struct _UNICODE_STRING v70;
__int128 v71;
struct _UNICODE_STRING UnicodeString;
struct _UNICODE_STRING FilterString;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
wchar_t *Str1;
_KEY_BASIC_INFORMATION *KeyInformation;
WCHAR *LoggerRegistryKeyName;
GUID Guid;
int v80;
int *v81;
int v82;
_DWORD *v83;
int v84;
char *v85;
int v86;
char *v87;
int v88;
char *v89;
int v90;
char *v91;
int v92;
__int128 *v93;
int v94;
__int128 *v95;
int v96;
char *v97;
int v98;
char *v99;
int v100;
char *v101;
int v102;
int *v103;
int v104;
struct _UNICODE_STRING *p_UnicodeString;
int v106;
char *v107;
int v108;
unsigned int *v109;
int v110;
struct _UNICODE_STRING *p_FilterString;
int v112;
__int128 *v113;
int v114;
int *v115;
int v116;
struct _UNICODE_STRING *v117;
int v118;
char *v119;
INT64 result[2];
const wchar_t *v121;
int *v122;
int v123;
int *v124;
__int128 v125;
__int128 v126;
__int128 v127;
__int64 v128;
INT64(__stdcall *v129)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v130;
int *v131;
int v132;
char *v133;
INT64(__stdcall *v134)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v135;
int *v136;
int v137;
char *v138;
INT64(__stdcall *v139)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v140;
int *v141;
int v142;
char *v143;
INT64(__stdcall *v144)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v145;
int *v146;
int v147;
__int16 *v148;
int v149;
INT64(__stdcall *v150)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v151;
int *v152;
int v153;
__int64 v154;
int v155;
INT64(__stdcall *v156)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v157;
int *v158;
int v159;
__int64 v160;
int v161;
INT64(__stdcall *v162)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v163;
int *v164;
int v165;
int *v166;
int v167;
INT64(__stdcall *v168)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v169;
int *v170;
int v171;
int *v172;
int v173;
INT64(__stdcall *v174)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v175;
int *v176;
int v177;
int *v178;
int v179;
INT64(__stdcall *v180)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v181;
int *v182;
int v183;
int *v184;
INT64(__stdcall *v185)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v186;
int *v187;
int v188;
wchar_t *Buffer;
int Length;
INT64(__stdcall *v191)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const WCHAR *v192;
int *v193;
int v194;
char *v195;
INT64(__stdcall *v196)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v197;
int *v198;
int v199;
unsigned int *v200;
INT64(__stdcall *v201)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v202;
int *v203;
int v204;
wchar_t *v205;
int v206;
INT64(__stdcall *v207)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v208;
int *v209;
int v210;
__int64 v211;
int v212;
INT64(__stdcall *v213)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v214;
int *v215;
int v216;
int *v217;
INT64(__stdcall *v218)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v219;
int *v220;
int v221;
wchar_t *v222;
int v223;
INT64(__stdcall *v224)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v225;
int *v226;
int v227;
int v228;
KeyInformation = (_KEY_BASIC_INFORMATION *)LoggerId;
LoggerRegistryKeyName = LoggerKeyName;
Str1 = LoggerName;
v3 = LoggerId;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
v64 = 1;
KeyHandle = 0i64;
DestinationString = 0i64;
Handle = 0i64;
v6 = 0i64;
v61 = 0;
v7 = 0i64;
v59 = 0;
UnicodeString = 0i64;
v54 = 0;
FilterString = 0i64;
v60 = 0;
v70 = 0i64;
v55 = 0;
v71 = 0i64;
KeyLength[0] = 0;
v69 = 0i64;
v52[0] = 0;
v68 = 0i64;
v66 = 0;
v65 = 100;
v58 = 0;
Guid = 0i64;
*(_QWORD *)&GuidString.Length = PsGetCurrentServerSiloGlobals()[108];
RtlInitUnicodeString(&DestinationString, LoggerKeyName, v8);
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v9 = ZwOpenKey(&KeyHandle, 0x2001Fu, &ObjectAttributes);
if( v9 >= 0 )
{
*(_QWORD *)&KeyLength[1] = ExAllocatePoolWithTag(PagedPool, 0x2000ui64, 0x50777445ui64);
v6 = *(void **)&KeyLength[1];
if( *(_QWORD *)&KeyLength[1] )
{
PoolWithTag = (char *)ExAllocatePoolWithTag(PagedPool, 0x504ui64, 0x50777445ui64);
v7 = PoolWithTag;
if( PoolWithTag )
{
memset((INT64)PoolWithTag, 0i64);
*((_DWORD *)v7 + 11) = 0x20000;
*((_DWORD *)v7 + 12) = 4;
RtlInitUnicodeString((PUNICODE_STRING)v7 + 9, LoggerName, v11);
*((_DWORD *)v7 + 18) = 0x80000000;
*((_WORD *)v7 + 36) = 176;
v12 = (UINT8 *)(v7 + 180);
v7[74] = -1;
*((_DWORD *)v7 + 44) = 1;
Src = v7 + 224;
v13 = 180;
v14 = v7 + 1252;
memset((INT64)result, 0i64);
result[0] = (INT64)EtwpQueryRegistryCallback;
v122 = &v80;
*(_QWORD *)&v125 = EtwpQueryRegistryCallback;
v121 = L"Start";
v123 = 4;
v81 = &v59;
v80 = 4;
*((_QWORD *)&v126 + 1) = &v82;
*(_QWORD *)&v126 = L"Immutable";
v83 = KeyLength;
LODWORD(v127) = 4;
v82 = 4;
LOBYTE(v15) = RtlpQueryRegistryValues((_KTRAP_FRAME *)0x40000000, (_KEXCEPTION_FRAME *)KeyHandle);
v9 = v15;
if( v15 < 0 )
goto LABEL_10;
if( !v3 )
{
v17 = KeyLength[0];
goto LABEL_7;
}
LODWORD(Disposition) = 0;
RtlInitUnicodeString(&DestinationString, (PCWSTR)v3, v16);
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.RootDirectory = 0i64;
LODWORD(ValueLength) = 0;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v9 = ZwCreateKey(&Handle, 0x2001Fui64, &ObjectAttributes, 0i64, 0i64, ValueLength, &Disposition);
if( v9 == -1073741772 )
{
KeyTreeForPath = EtwpCreateKeyTreeForPath(v3);
LODWORD(v3) = 0;
if( KeyTreeForPath )
goto LABEL_78;
LODWORD(ValueLength) = 0;
v9 = ZwCreateKey(&Handle, 0x2001Fui64, &ObjectAttributes, 0i64, 0i64, ValueLength, &Disposition);
}
else
{
LODWORD(v3) = 0;
}
if( !v9 )
{
LABEL_79:
v17 = KeyLength[0];
if( (_DWORD)Disposition == 1 )
v17 = 1;
KeyLength[0] = v17;
LABEL_7:
if( !v17 )
{
if( Handle )
{
v128 = 0i64;
v124 = &v59;
v125 = 0i64;
v126 = 0i64;
v127 = 0i64;
LOBYTE(v39) = RtlpQueryRegistryValues((_KTRAP_FRAME *)0x40000000, (_KEXCEPTION_FRAME *)Handle);
v9 = v39;
if( v39 < 0 )
v9 = (int)v3;
}
}
if( v59 != (_DWORD)v3 )
{
LODWORD(v71) = 40;
v123 = 4;
result[0] = (INT64)EtwpQueryRegistryCallback;
v122 = &v80;
v80 = 4;
v121 = L"FlushThreshold";
*(_QWORD *)&v125 = EtwpQueryRegistryCallback;
v81 = (int *)(v7 + 76);
LODWORD(v127) = 4;
*((_QWORD *)&v126 + 1) = &v82;
*(_QWORD *)&v126 = L"BufferSize";
v131 = &v84;
v130 = L"MinimumBuffers";
v85 = v7 + 52;
v136 = &v86;
v135 = L"FlushTimer";
v87 = v7 + 68;
v141 = &v88;
v140 = L"MaximumBuffers";
v89 = v7 + 56;
v146 = &v90;
v145 = L"FileName";
v148 = v52;
v91 = v7 + 128;
*((_QWORD *)&v71 + 1) = v7 + 184;
v152 = &v92;
v151 = L"EnableKernelFlags";
v93 = &v71;
*((_QWORD *)&v68 + 1) = v7 + 228;
v158 = &v94;
v157 = L"StackWalkingFilter";
v82 = 4;
v83 = v7 + 48;
v129 = EtwpQueryRegistryCallback;
v132 = 4;
v84 = 4;
v134 = EtwpQueryRegistryCallback;
v137 = 4;
v86 = 4;
v139 = EtwpQueryRegistryCallback;
v142 = 4;
v88 = 4;
v144 = EtwpQueryRegistryCallback;
v147 = 1;
v90 = 1;
v150 = EtwpQueryRegistryCallback;
v153 = 3;
v92 = 3;
LODWORD(v68) = 1024;
v156 = EtwpQueryRegistryCallback;
v159 = 3;
v94 = 3;
v95 = &v68;
v20 = (unsigned int *)(v7 + 96);
v162 = EtwpQueryRegistryCallback;
v164 = &v96;
v163 = L"ClockType";
v166 = &v64;
v97 = v7 + 40;
v170 = &v98;
v169 = L"MaxFileSize";
v172 = &v65;
v99 = v7 + 60;
v176 = &v100;
v175 = L"LogFileMode";
v178 = &v66;
v101 = v7 + 64;
v182 = &v102;
v181 = L"DisableRealtimePersistence";
v103 = &v60;
v187 = &v104;
v186 = L"Guid";
Buffer = (wchar_t *)v52;
p_UnicodeString = &UnicodeString;
v193 = &v106;
v192 = L"FileCounter";
v198 = &v108;
v197 = L"FileMax";
v109 = &v54;
v203 = &v110;
v165 = 4;
v167 = 4;
v96 = 4;
v168 = EtwpQueryRegistryCallback;
v171 = 4;
v173 = 4;
v98 = 4;
v174 = EtwpQueryRegistryCallback;
v177 = 4;
v179 = 4;
v100 = 4;
v180 = EtwpQueryRegistryCallback;
v183 = 4;
v102 = 4;
v185 = EtwpQueryRegistryCallback;
v188 = 1;
v104 = 1;
v191 = EtwpQueryRegistryCallback;
v194 = 4;
v106 = 4;
v107 = v7 + 96;
v196 = EtwpQueryRegistryCallback;
v199 = 4;
v108 = 4;
v201 = EtwpQueryRegistryCallback;
v202 = L"PoolTagFilter";
v204 = 1;
v205 = (wchar_t *)v52;
p_FilterString = &FilterString;
*((_QWORD *)&v69 + 1) = v7 + 1276;
v209 = &v112;
v208 = L"StackCaching";
v113 = &v69;
v215 = &v114;
v214 = L"EnableSecurityProvider";
v115 = &v55;
v220 = &v116;
v219 = L"DisallowList";
v222 = (wchar_t *)v52;
v117 = &v70;
v226 = &v118;
v225 = L"V2Options";
v227 = 11;
v118 = 11;
v110 = 1;
v207 = EtwpQueryRegistryCallback;
v210 = 3;
v112 = 3;
v213 = EtwpQueryRegistryCallback;
v216 = 4;
v114 = 4;
v218 = EtwpQueryRegistryCallback;
v221 = 1;
v116 = 1;
v224 = EtwpQueryRegistryCallback;
v119 = v7 + 80;
LODWORD(v69) = 8;
v228 = 8;
LOBYTE(v21) = RtlpQueryRegistryValues((_KTRAP_FRAME *)0x40000000, (_KEXCEPTION_FRAME *)KeyHandle);
v9 = v21;
if( v21 >= 0 )
{
if( Handle )
{
if( KeyLength[0] )
{
v124 = (int *)(v7 + 96);
v122 = &v106;
result[0] = (INT64)EtwpQueryRegistryCallback;
v121 = L"FileCounter";
v123 = 4;
v80 = 4;
v81 = (int *)(v7 + 96);
*(_QWORD *)&v125 = 0i64;
}
else
{
*((_QWORD *)&v127 + 1) = v7 + 48;
v124 = (int *)(v7 + 76);
v133 = v7 + 52;
v138 = v7 + 68;
v143 = v7 + 56;
v148 = (__int16 *)*((_QWORD *)v7 + 17);
v149 = *((unsigned __int16 *)v7 + 64);
v154 = *((_QWORD *)&v71 + 1);
v155 = v71;
v160 = *((_QWORD *)&v68 + 1);
v161 = v68;
v166 = (int *)(v7 + 40);
v172 = (int *)(v7 + 60);
v178 = (int *)(v7 + 64);
v184 = &v60;
Buffer = UnicodeString.Buffer;
Length = UnicodeString.Length;
v200 = &v54;
v205 = FilterString.Buffer;
v206 = FilterString.Length;
v211 = *((_QWORD *)&v69 + 1);
v212 = v69;
v217 = &v55;
v222 = v70.Buffer;
v223 = v70.Length;
v195 = v7 + 96;
}
RtlpQueryRegistryValues((_KTRAP_FRAME *)0x40000000, (_KEXCEPTION_FRAME *)Handle);
v9 = 0;
}
v22 = *((_DWORD *)v7 + 28) | 2;
*((_DWORD *)v7 + 28) = v22;
if( !v60 )
*((_DWORD *)v7 + 28) = v22 | 1;
v23 = (unsigned int)v71 >> 2;
if( (unsigned __int16)((unsigned int)v71 >> 2) )
{
*((_WORD *)v7 + 91) = 1;
*(_WORD *)v12 = v23 + 1;
++*((_WORD *)v7 + 89);
*((_WORD *)v7 + 88) += *(_WORD *)v12;
v13 = 4 * *(unsigned __int16 *)v12 + 180;
}
if( (_DWORD)v68 )
{
v40 = (UINT8 *)Src;
v41 = ((unsigned int)v68 >> 2) + 1;
if( (v68 & 3) == 0 )
v41 = (unsigned int)v68 >> 2;
*((_WORD *)Src + 1) = 3;
*(_WORD *)v40 = v41 + 1;
++*((_WORD *)v7 + 89);
*((_WORD *)v7 + 88) += *(_WORD *)v40;
v13 += 4 * *(unsigned __int16 *)v40;
if( (_WORD)v23 )
v12 += 4 * *(unsigned __int16 *)v12;
if( v12 != v40 )
memmove(v12, v40, 4i64 * v41 + 4);
}
if( FilterString.Buffer )
{
Src = &v7[4 * *((unsigned __int16 *)v7 + 88) + 176];
v42 = EtwpParsePoolTagFilter(&FilterString, (UINT64 *)v7 + 157);
v24 = v42;
if( v42 )
{
*v14 = v42 + 1;
*((_WORD *)v7 + 627) = 4;
++*((_WORD *)v7 + 89);
*((_WORD *)v7 + 88) += *v14;
v13 += 4 * (unsigned __int16)*v14;
if( Src != v14 )
memmove((UINT8 *)Src, (UINT8 *)v7 + 1252, 4i64 * v42 + 4);
}
}
else
{
v24 = v58;
}
if( (_DWORD)v69 == 8 )
{
v43 = *((unsigned __int16 *)v7 + 88);
*((_DWORD *)v7 + 318) = 327683;
++*((_WORD *)v7 + 89);
*((_WORD *)v7 + 88) += *((_WORD *)v7 + 636);
v44 = (UINT8 *)&v7[4 * v43 + 176];
v13 += 4 * *((unsigned __int16 *)v7 + 636);
if( v44 != (UINT8 *)(v7 + 1272) )
memmove(v44, (UINT8 *)v7 + 1272, 0xCui64);
}
if( !(_WORD)v23 && !(_DWORD)v68 && !(_DWORD)v69 && !v24 )
*((_DWORD *)v7 + 18) = 0;
v25 = v7 + 64;
v26 = *((_DWORD *)v7 + 16);
if( (v26 & 0x500) != 0 && (v26 & 0x200) == 0 || *((_QWORD *)v7 + 17) )
{
LABEL_41:
if( v9 >= 0 )
{
if( v55 )
{
if( (*v25 & 0x80u) == 0 || (*v25 & 0x100) == 0 || *((_QWORD *)v7 + 17) )
v9 = -1073741790;
else
*((_DWORD *)v7 + 28) |= 0x8004000u;
}
if( v9 >= 0 )
{
if( v54 )
{
v34 = *v20 + 1;
*v20 = v34;
if( v34 > v54 || v34 > 0x10 )
*v20 = 1;
v35 = (const WCHAR *)Handle;
if( !Handle )
v35 = (const WCHAR *)KeyHandle;
LODWORD(ValueLength) = 4;
RtlWriteRegistryValue(0x40000000ui64, v35, L"FileCounter", 4ui64, v7 + 96, ValueLength);
}
if( !wcscmp(Str1, (PWCHAR)L"GlobalLogger") )
Guid = GlobalLoggerGuid;
else
v9 = UnicodeString.Buffer ? RtlGUIDFromString(&UnicodeString, &Guid) : -1073741811;
if( v9 >= 0 )
{
v28 = Guid;
v29 = *(_QWORD *)&GuidString.Length;
v30 = *(_QWORD *)&GuidString.Length;
*(_DWORD *)v7 = v13;
*(GUID *)(v7 + 24) = v28;
started = EtwpStartLogger(v30, (__int64)v7, v27);
v32 = *((unsigned __int16 *)v7 + 4);
v9 = started;
if( started >= 0 )
{
if( *((_WORD *)v7 + 4) && v55 )
{
v36 = 0i64;
v37 = (_WORD *)(v29 + 4048);
while( *v37 )
{
v36 = (unsigned int)(v36 + 1);
++v37;
if( (unsigned int)v36 >= 8 )
goto LABEL_52;
}
*(_WORD *)(v29 + 2 * v36 + 4048) = v32;
}
LABEL_52:
if( v70.Length )
{
v45 = v70.Length / 0x4Cu;
if( v70.Length == 76 * v45 )
{
GuidString.Buffer = v70.Buffer;
*(&GuidString.MaximumLength + 2) = 0;
GuidString.Length = 76;
*(_DWORD *)&GuidString.MaximumLength = (unsigned __int16)(v70.MaximumLength - v70.Length + 76);
if( v45 <= 0x200 )
{
v46 = *(_QWORD *)&KeyLength[1];
v47 = 0;
if( v45 )
{
while( 1 )
{
v9 = RtlGUIDFromString(&GuidString, (GUID *)(v46 + 16i64 * v47));
if( v9 )
break;
GuidString.Buffer += 38;
if( ++v47 >= v45 )
goto LABEL_110;
}
}
else
{
LABEL_110:
if( !v9 )
{
CurrentServerSiloGlobals = PsGetCurrentServerSiloGlobals();
EtwpUpdateDisallowList((PVOID)CurrentServerSiloGlobals[108], v32);
}
}
}
}
}
v33 = PsGetCurrentServerSiloGlobals();
LODWORD(ValueData) = KeyLength[0];
EtwpEnableKeyProviders(
(_ETW_SILODRIVERSTATE *)v33[108],
v32,
LoggerRegistryKeyName,
KeyInformation,
(UINT64)ValueData);
}
}
}
}
goto LABEL_10;
}
if( RtlCreateUnicodeString((UNICODE_STRING *)v7 + 8, (PWCHAR)L"%SystemRoot%") )
{
v9 = 0;
v25 = v7 + 64;
goto LABEL_41;
}
v9 = -1073741801;
}
}
LABEL_10:
v6 = *(void **)&KeyLength[1];
goto LABEL_11;
}
LABEL_78:
v9 = 0;
Handle = 0i64;
goto LABEL_79;
}
}
v9 = -1073741801;
}
LABEL_11:
v18 = (const WCHAR *)KeyHandle;
if( KeyHandle )
{
if( v9 < 0 )
{
v49 = RtlNtStatusToDosError(v9);
v18 = (const WCHAR *)KeyHandle;
v61 = v49;
}
LODWORD(ValueLength) = 4;
if( Handle )
v18 = (const WCHAR *)Handle;
RtlWriteRegistryValue(0x40000000ui64, v18, L"Status", 4ui64, &v61, ValueLength);
ZwClose(KeyHandle);
}
if( Handle )
ZwClose(Handle);
if( v7 )
{
RtlFreeAnsiString((_UNICODE_STRING *)v7 + 8);
ExFreePoolWithTag(v7, 0);
}
if( v6 )
ExFreePoolWithTag(v6, 0);
RtlFreeAnsiString(&UnicodeString);
RtlFreeAnsiString(&FilterString);
RtlFreeAnsiString(&v70);
return(unsigned int)v9;
}Referenced by:
EtwpEnumerateAutologgerPath
EtwpInitializeAutoLoggers
PerfDiagpStartPerfDiagLogger