WmiTraceRundownNotify

INT64 __stdcall WmiTraceRundownNotify(UINT64 LoggerId, UINT64 TraceClass){
  int v2; 
  int v4[2]; 
  UINT64 v5; 
  __int64 v6; 
  PVOID P; 
  UINT64 v8; 
  v5 = LoggerId;
  v4[1] = TraceClass;
  P = 0i64;
  LODWORD(v8) = 0;
  v6 = 0x400000i64;
  v4[0] = 2;
  v2 = WmipBuildTraceDeviceList(0x400000i64, (INT64 **)&P, &v8);
  if( v2 >= 0 )
  {
    v2 = WmipSendWmiIrpToTraceDeviceList((__int64)P, v8, 0xCu, 24, (__int64)v4);
    if( v2 >= 0 )
      v2 = 0;
  }
  if( P )
    WmipFreeTraceDeviceList(P, v8);
  return(unsigned int)v2;
}

Referenced by:

EtwpKernelTraceRundown
EtwpLogFileNameRundown
EtwpUpdateFileInfoDriverState