KsepDsEventDevicePowerCompleted
VOID __stdcall KsepDsEventDevicePowerCompleted(DRIVER_OBJECT *DriverObject, DEVICE_OBJECT *Fdo, IRP *Irp, INT64 Status){
UINT64 v4;
UINT64 UserDataCount;
struct _EVENT_DATA_DESCRIPTOR UserData;
DEVICE_OBJECT **v7;
int v8;
int v9;
IRP **v10;
int v11;
int v12;
int *v13;
int v14;
int v15;
DRIVER_OBJECT *v16;
DEVICE_OBJECT *v17;
IRP *v18;
int v19;
v19 = Status;
v18 = Irp;
v17 = Fdo;
v16 = DriverObject;
v4 = *(_QWORD *)KseEtwHandle;
if( *(_QWORD *)KseEtwHandle )
{
if( EtwEventEnabled(
*(UINT64 *)KseEtwHandle,
(EVENT_DESCRIPTOR *)&KseDsEventDevicePowerCompleted,
(EVENT_DESCRIPTOR *)Irp) )
{
UserData.Reserved = 0;
v9 = 0;
v12 = 0;
v15 = 0;
UserData.Ptr = (unsigned __int64)&v16;
UserData.Size = 8;
v7 = &v17;
v10 = &v18;
v8 = 8;
v11 = 8;
v13 = &v19;
LODWORD(UserDataCount) = 4;
v14 = 4;
EtwWriteEx(
v4,
(EVENT_DESCRIPTOR *)&KseDsEventDevicePowerCompleted,
0i64,
0i64,
0i64,
0i64,
UserDataCount,
&UserData);
}
}
}Referenced by:
KseDsCompletionHookForPowerDevice