EtwpFreeLoggerContext
VOID __fastcall EtwpFreeLoggerContext(_WMI_LOGGER_CONTEXT *LoggerContext){
__int64 v1;
__int64 v3;
__int64 v4;
__int64 v5;
void *v6;
__int64 v7;
INT64 v8;
_UNICODE_STRING *v9;
__int64 v10;
__int64 v11;
struct _DMA_ADAPTER *v12;
void *v13;
__int64 v14;
int v15;
PVOID *v16;
_QWORD *v17;
__int64 v18;
_DWORD *v19;
_QWORD *v20;
void *v21;
_WMI_LOGGER_CONTEXT *v22;
_WMI_LOGGER_CONTEXT *v23;
_WMI_LOGGER_CONTEXT *v24;
_WMI_LOGGER_CONTEXT *v25;
_QWORD *v26;
void *v27;
UINT64 v28[2];
__int64 v29;
v1 = *((_QWORD *)LoggerContext + 135);
EtwpRealtimeDisconnectAllConsumers(LoggerContext);
ExAcquirePushLockExclusiveEx((UINT64)LoggerContext + 704, 0i64);
*((_DWORD *)LoggerContext + 208) |= 0x200u;
if( (*((_DWORD *)LoggerContext + 209) & 0x20) != 0 )
{
v3 = *((_QWORD *)LoggerContext + 46);
*((_QWORD *)LoggerContext + 46) = 0i64;
*((_DWORD *)LoggerContext + 14) = 0;
_InterlockedAnd((volatile signed __int32 *)LoggerContext + 209, 0xFFFFFFDF);
KeSetEvent((PRKEVENT)((char *)LoggerContext + 472), 0);
KeSetEvent(*(PRKEVENT *)(v3 + 48), 0);
HalPutDmaAdapter((PADAPTER_OBJECT)v3);
}
ExReleasePushLockEx((UINT64)LoggerContext + 704, 0i64);
v4 = *(_DWORD *)LoggerContext;
EtwpCancelPendingStackwalkApcs((UINT64 *)LoggerContext);
v5 = (unsigned int)v4;
ExReleaseRundownProtectionCacheAwareEx(*(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(v1 + 448) + 8 * v4), 1u);
ExWaitForRundownProtectionReleaseCacheAware(*(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(v1 + 448) + 8 * v4));
if( *((_WORD *)LoggerContext + 524) )
{
v6 = (void *)*((_QWORD *)LoggerContext + 132);
*((_WORD *)LoggerContext + 524) = 0;
ExFreePoolWithTag(v6, 0);
*((_QWORD *)LoggerContext + 132) = 0i64;
}
v7 = *((_QWORD *)LoggerContext + 133);
if( v7 )
{
v8 = *(_QWORD *)(v7 + 8);
if( v8 )
{
v29 = 0i64;
*(_OWORD *)v28 = 0i64;
ExDeleteTimer(v8, 1, 1, v28);
v7 = *((_QWORD *)LoggerContext + 133);
}
if( *(_QWORD *)(v7 + 24) )
{
ExFreePoolWithTag(*(PVOID *)(v7 + 24), 0);
v7 = *((_QWORD *)LoggerContext + 133);
}
ExFreePoolWithTag((PVOID)v7, 0);
*((_QWORD *)LoggerContext + 133) = 0i64;
}
if( *((_DWORD *)LoggerContext + 79) != 1 )
KeGenericCallDpc((PKDEFERRED_ROUTINE)KeAbCrossThreadDeleteNopDpcRoutine, 0i64);
EtwpFreeCompression((INT64)LoggerContext);
KeCancelTimer((PKTIMER)((char *)LoggerContext + 520));
KeRemoveQueueDpc((_KDPC *)((char *)LoggerContext + 584));
v9 = (_UNICODE_STRING *)*((_QWORD *)LoggerContext + 134);
if( v9 )
{
EtwpCancelMemoryPreservation(LoggerContext);
RtlFreeAnsiString(v9 + 1);
ExFreePoolWithTag(v9, 0);
*((_QWORD *)LoggerContext + 134) = 0i64;
}
EtwpFreeTraceBufferPool((UINT64 *)LoggerContext);
if( (_DWORD)KeNumberProcessors_0 )
{
v10 = 0i64;
v11 = (unsigned int)KeNumberProcessors_0;
do
{
v10 += 64i64;
*(_QWORD *)(*(_QWORD *)(*(_QWORD *)(*((_QWORD *)LoggerContext + 135) + 4136i64) + v10 - 56) + 8 * v5) = 0i64;
--v11;
}
while( v11 );
}
RtlFreeAnsiString((_UNICODE_STRING *)((char *)LoggerContext + 168));
RtlFreeAnsiString((_UNICODE_STRING *)((char *)LoggerContext + 184));
RtlFreeAnsiString((_UNICODE_STRING *)((char *)LoggerContext + 200));
RtlFreeAnsiString((_UNICODE_STRING *)LoggerContext + 24);
v12 = (struct _DMA_ADAPTER *)*((_QWORD *)LoggerContext + 92);
if( v12 )
HalPutDmaAdapter(v12);
v13 = (void *)*((_QWORD *)LoggerContext + 99);
if( v13 )
ExFreePoolWithTag(v13, 0);
v14 = _InterlockedExchange64((volatile __int64 *)LoggerContext + 100, 0i64);
ObDereferenceSecurityDescriptor((PVOID)(v14 & 0xFFFFFFFFFFFFFFF0ui64), (unsigned int)(v14 & 0xF) + 1);
v15 = *((_DWORD *)LoggerContext + 208);
if( (v15 & 0x80u) != 0 )
{
ExFreePoolWithTag(*((PVOID *)LoggerContext + 123), 0);
ExFreePoolWithTag(*((PVOID *)LoggerContext + 118), 0);
v15 = *((_DWORD *)LoggerContext + 208);
}
if( (v15 & 0x2000) != 0 )
{
_InterlockedDecrement(&dword_140C53AA0);
v15 = *((_DWORD *)LoggerContext + 208);
}
if( (v15 & 0x1000000) != 0 )
EtwpFreeStackCache(*((PVOID *)LoggerContext + 124));
if( (*((_DWORD *)LoggerContext + 3) & 0x2000000) != 0 )
_interlockedbittestandreset((volatile signed __int32 *)(v1 + 4224), *((unsigned __int8 *)LoggerContext + 834));
if( *((_QWORD *)LoggerContext + 125) )
{
v16 = (PVOID *)*((_QWORD *)LoggerContext + 125);
if( (_DWORD)KeNumberProcessors_0 )
{
v17 = v16 + 3;
v18 = (unsigned int)KeNumberProcessors_0;
do
{
if( *v17 )
off_140C007E0[0]();
++v17;
--v18;
}
while( v18 );
}
if( *v16 )
ExFreePoolWithTag(*v16, 0);
ExFreePoolWithTag(v16, 0);
}
v19 = (_DWORD *)*((_QWORD *)LoggerContext + 126);
if( v19 )
{
if( (*((_DWORD *)LoggerContext + 208) & 0x8000) != 0 )
{
_InterlockedDecrement(&dword_140C53AC0);
v19 = (_DWORD *)*((_QWORD *)LoggerContext + 126);
}
if( v19 )
{
if( *v19 )
{
((void(__fastcall *)(_QWORD))off_140C009B8[0])((unsigned int)*v19);
v19 = (_DWORD *)*((_QWORD *)LoggerContext + 126);
}
ExFreePoolWithTag(v19, 0);
*((_QWORD *)LoggerContext + 126) = 0i64;
}
}
v20 = (_QWORD *)*((_QWORD *)LoggerContext + 127);
if( v20 )
{
if( v20[2] )
{
if( *v20 )
{
_interlockedbittestandreset(&KiCpuTracingFlags, 2u);
(*(void(__fastcall **)(_QWORD))(v20[2] + 8i64))(*v20);
}
ExReleaseExtensionTable(EtwpHwTraceExtensionHost);
}
ExFreePoolWithTag(v20, 0);
*((_QWORD *)LoggerContext + 127) = 0i64;
}
v21 = (void *)*((_QWORD *)LoggerContext + 159);
if( v21 )
ExFreePoolWithTag(v21, 0);
v22 = (_WMI_LOGGER_CONTEXT *)*((_QWORD *)LoggerContext + 14);
while( v22 != (_WMI_LOGGER_CONTEXT *)((char *)LoggerContext + 112) )
{
v23 = v22;
v22 = *(_WMI_LOGGER_CONTEXT **)v22;
ExFreePoolWithTag(v23, 0);
}
v24 = (_WMI_LOGGER_CONTEXT *)*((_QWORD *)LoggerContext + 128);
while( v24 != (_WMI_LOGGER_CONTEXT *)((char *)LoggerContext + 1024) )
{
v25 = v24;
v24 = *(_WMI_LOGGER_CONTEXT **)v24;
ExFreePoolWithTag(v25, 0);
}
while( *((_QWORD *)LoggerContext + 16) )
{
v26 = (_QWORD *)*((_QWORD *)LoggerContext + 16);
*((_QWORD *)LoggerContext + 16) = *v26;
ExFreePoolWithTag(v26, 0);
}
EtwpClearPartitionContext((INT64 *)LoggerContext + 163);
v27 = (void *)*((_QWORD *)LoggerContext + 164);
if( v27 )
ExFreePoolWithTag(v27, 0);
ExReInitializeRundownProtectionCacheAware(*(PEX_RUNDOWN_REF_CACHE_AWARE *)(*(_QWORD *)(v1 + 448) + 8 * v5));
*(_QWORD *)(*(_QWORD *)(v1 + 456) + 8 * v5) = 1i64;
ExFreePoolWithTag(LoggerContext, 0);
_InterlockedDecrement((volatile signed __int32 *)(v1 + 4124));
}Referenced by:
EtwpLogger
EtwpStartLogger
EtwpStopTrace