PerfLogExecutiveResourceWait

VOID __stdcall PerfLogExecutiveResourceWait(UINT64 Action, PVOID LockAddress, UINT64 RecursionCount){
  unsigned int v3; 
  int v5; 
  struct _KPRCB *CurrentPrcb; 
  unsigned __int64 v7; 
  __int16 v8; 
  unsigned __int8 v9; 
  INT64 TrackingLockSlotForThread; 
  __int64 v11; 
  UINT64 Flag; 
  int v13; 
  __int64 v14[3]; 
  unsigned int v15; 
  int v16; 
  PVOID v17; 
  int v18; 
  int v19; 
  EVENT_DATA_DESCRIPTOR EventData; 
  v3 = RecursionCount;
  v5 = Action;
  CurrentPrcb = KeGetCurrentPrcb();
  v7 = __rdtsc();
  v8 = *((unsigned __int8 *)CurrentPrcb + 208);
  v9 = *((_BYTE *)CurrentPrcb + 209);
  ++*((_DWORD *)CurrentPrcb + 8540);
  LOWORD(v13) = v8;
  HIWORD(v13) = v9;
  TrackingLockSlotForThread = EtwpGetTrackingLockSlotForThread((INT64)LockAddress, (unsigned int)Action & 0xFFFF0000);
  if( TrackingLockSlotForThread )
  {
    ++*((_DWORD *)CurrentPrcb + 8541);
    if( ((v5 - 65572) & 0xFFFFFFDF) != 0 )
    {
      if( ((v5 - 66084) & 0xFFFFFFDF) == 0 )
      {
        if( *(_DWORD *)(TrackingLockSlotForThread + 32) == 4
          && *(_WORD *)(TrackingLockSlotForThread + 24) == v8
          && *(_BYTE *)(TrackingLockSlotForThread + 26) == v9 )
        {
          v11 = v7 - *(_QWORD *)TrackingLockSlotForThread;
        }
        else
        {
          v11 = 0i64;
        }
        if( !(v3 % EtwpExecutiveResourceTimeout) )
        {
          v14[0] = 0i64;
          v18 = v5;
          v17 = LockAddress;
          v15 = v3;
          v14[1] = v11;
          v14[2] = *(_QWORD *)TrackingLockSlotForThread;
          v19 = 0;
          *(_QWORD *)&EventData.Size = 48i64;
          LODWORD(Flag) = 22026242;
          v16 = *((_DWORD *)KeGetCurrentThread() + 288);
          EventData.Ptr = (unsigned __int64)v14;
          EtwTraceKernelEvent(&EventData, 1ui64, 0x20020000ui64, 0x52Bu, Flag);
        }
      }
    }
    else
    {
      *(_DWORD *)(TrackingLockSlotForThread + 24) = v13;
      *(_DWORD *)(TrackingLockSlotForThread + 32) = 4;
      *(_QWORD *)TrackingLockSlotForThread = v7;
    }
  }
}

Referenced by:

ExAcquireSharedWaitForExclusive