WmiTraceRundownNotify
INT64 __stdcall WmiTraceRundownNotify(UINT64 LoggerId, UINT64 TraceClass){
int v2;
int v4[2];
UINT64 v5;
__int64 v6;
PVOID P;
UINT64 v8;
v5 = LoggerId;
v4[1] = TraceClass;
P = 0i64;
LODWORD(v8) = 0;
v6 = 0x400000i64;
v4[0] = 2;
v2 = WmipBuildTraceDeviceList(0x400000i64, (INT64 **)&P, &v8);
if( v2 >= 0 )
{
v2 = WmipSendWmiIrpToTraceDeviceList((__int64)P, v8, 0xCu, 24, (__int64)v4);
if( v2 >= 0 )
v2 = 0;
}
if( P )
WmipFreeTraceDeviceList(P, v8);
return(unsigned int)v2;
}Referenced by:
EtwpKernelTraceRundown
EtwpLogFileNameRundown
EtwpUpdateFileInfoDriverState