CmEtwRunDown

INT64 __stdcall CmEtwRunDown(UINT64 LoggerId, UINT8 KeyRundown, UINT8 HiveRundown, UINT8 Start){
  UINT8 v4; 
  UINT8 v5; 
  unsigned int v6; 
  _CMHIVE *v8; 
  unsigned int v9; 
  __int64 *v10; 
  __int64 v11; 
  __int64 i; 
  _UNICODE_STRING *v13; 
  __int64 v14; 
  WCHAR v15; 
  WCHAR v16; 
  NTSTATUS v17; 
  PULONG ResultLength; 
  __int16 v22; 
  int v23; 
  ULONG v24; 
  void *KeyHandle; 
  _UNICODE_STRING *KeyPath; 
  _CMHIVE *NextActiveHive; 
  struct _UNICODE_STRING DestinationString; 
  struct _UNICODE_STRING ValueName; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  __int128 v31; 
  __int128 v32; 
  __int128 KeyValueInformation; 
  KAPC_STATE ApcState; 
  EVENT_DATA_DESCRIPTOR a1; 
  wchar_t *Buffer; 
  int Length; 
  int v38; 
  __int16 *v39; 
  __int64 v40; 
  char v41; 
  v4 = Start;
  v5 = HiveRundown;
  v6 = KeyRundown;
  v23 = 0;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  v24 = 0;
  KeyHandle = 0i64;
  v22 = 0;
  ValueName = 0i64;
  KeyValueInformation = 0i64;
  DestinationString = 0i64;
  v31 = 0i64;
  v32 = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  if( !v41 )
  {
    CmpAttachToRegistryProcess(&ApcState);
    *(_QWORD *)&a1.Size = 24i64;
    a1.Ptr = (unsigned __int64)&v31;
    v8 = 0i64;
    v40 = 2i64;
    v39 = &v22;
    while( 1 )
    {
      NextActiveHive = CmpGetNextActiveHive(v8);
      v14 = (__int64)NextActiveHive;
      if( !NextActiveHive )
        break;
      CmpLockRegistryExclusive();
      if( v4 )
        CmpLogHiveRundownEvent(v14, LoggerId, v6);
      if( v5 )
      {
        v9 = *(_DWORD *)(v14 + 1648);
        if( v9 )
        {
          v10 = (__int64 *)(*(_QWORD *)(v14 + 1640) + 16i64);
          v11 = v9;
          do
          {
            for( i = *v10; i; i = *(_QWORD *)(i + 8) )
            {
              KeyPath = 0i64;
              CmpConstructNameWithStatus((_CM_KEY_CONTROL_BLOCK *)(i - 16), &KeyPath);
              v13 = KeyPath;
              if( KeyPath )
              {
                Buffer = KeyPath->Buffer;
                Length = KeyPath->Length;
                LODWORD(ResultLength) = 4200450;
                *(_QWORD *)&v32 = i - 16;
                v38 = 0;
                EtwTraceSiloDcEvent(&a1, 3u, LoggerId, v6, 2329, (INT64)ResultLength);
                CmpFreeTransientPoolWithTag(v13, 0x624E4D43ui64);
              }
            }
            v10 += 3;
            --v11;
          }
          while( v11 );
          v14 = (__int64)NextActiveHive;
          v4 = Start;
        }
        v5 = HiveRundown;
      }
      CmpUnlockRegistry();
      v8 = (_CMHIVE *)v14;
    }
    KiUnstackDetachProcess(&ApcState, 0i64);
    RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\System\\Select", v15);
    ObjectAttributes.Length = 48;
    ObjectAttributes.ObjectName = &DestinationString;
    ObjectAttributes.RootDirectory = 0i64;
    ObjectAttributes.Attributes = 576;
    *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
    if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) >= 0 )
    {
      RtlInitUnicodeString(&ValueName, L"Current", v16);
      v17 = ZwQueryValueKey(KeyHandle, &ValueName, KeyValuePartialInformation, &KeyValueInformation, 0x10u, &v24);
      ZwClose(KeyHandle);
      if( v17 >= 0 )
      {
        v23 = HIDWORD(KeyValueInformation);
        LODWORD(ResultLength) = 4200450;
        a1.Ptr = (unsigned __int64)&v23;
        a1.Size = 4;
        EtwTraceSiloDcEvent(&a1, 1u, LoggerId, v6, 2339, (INT64)ResultLength);
      }
    }
  }
  LODWORD(ResultLength) = 4200450;
  a1.Ptr = (unsigned __int64)CmPerfCounters;
  *(_QWORD *)&a1.Size = 88i64;
  EtwTraceSiloDcEvent(&a1, 1u, LoggerId, v6, 2338, (INT64)ResultLength);
  return 0i64;
}

Referenced by:

EtwpKernelTraceRundown