PerfLogExecutiveResourceWait
VOID __stdcall PerfLogExecutiveResourceWait(UINT64 Action, PVOID LockAddress, UINT64 RecursionCount){
unsigned int v3;
int v5;
struct _KPRCB *CurrentPrcb;
unsigned __int64 v7;
__int16 v8;
unsigned __int8 v9;
INT64 TrackingLockSlotForThread;
__int64 v11;
UINT64 Flag;
int v13;
__int64 v14[3];
unsigned int v15;
int v16;
PVOID v17;
int v18;
int v19;
EVENT_DATA_DESCRIPTOR EventData;
v3 = RecursionCount;
v5 = Action;
CurrentPrcb = KeGetCurrentPrcb();
v7 = __rdtsc();
v8 = *((unsigned __int8 *)CurrentPrcb + 208);
v9 = *((_BYTE *)CurrentPrcb + 209);
++*((_DWORD *)CurrentPrcb + 8540);
LOWORD(v13) = v8;
HIWORD(v13) = v9;
TrackingLockSlotForThread = EtwpGetTrackingLockSlotForThread((INT64)LockAddress, (unsigned int)Action & 0xFFFF0000);
if( TrackingLockSlotForThread )
{
++*((_DWORD *)CurrentPrcb + 8541);
if( ((v5 - 65572) & 0xFFFFFFDF) != 0 )
{
if( ((v5 - 66084) & 0xFFFFFFDF) == 0 )
{
if( *(_DWORD *)(TrackingLockSlotForThread + 32) == 4
&& *(_WORD *)(TrackingLockSlotForThread + 24) == v8
&& *(_BYTE *)(TrackingLockSlotForThread + 26) == v9 )
{
v11 = v7 - *(_QWORD *)TrackingLockSlotForThread;
}
else
{
v11 = 0i64;
}
if( !(v3 % EtwpExecutiveResourceTimeout) )
{
v14[0] = 0i64;
v18 = v5;
v17 = LockAddress;
v15 = v3;
v14[1] = v11;
v14[2] = *(_QWORD *)TrackingLockSlotForThread;
v19 = 0;
*(_QWORD *)&EventData.Size = 48i64;
LODWORD(Flag) = 22026242;
v16 = *((_DWORD *)KeGetCurrentThread() + 288);
EventData.Ptr = (unsigned __int64)v14;
EtwTraceKernelEvent(&EventData, 1ui64, 0x20020000ui64, 0x52Bu, Flag);
}
}
}
else
{
*(_DWORD *)(TrackingLockSlotForThread + 24) = v13;
*(_DWORD *)(TrackingLockSlotForThread + 32) = 4;
*(_QWORD *)TrackingLockSlotForThread = v7;
}
}
}Referenced by:
ExAcquireSharedWaitForExclusive