CmEtwRunDown
INT64 __stdcall CmEtwRunDown(UINT64 LoggerId, UINT8 KeyRundown, UINT8 HiveRundown, UINT8 Start){
UINT8 v4;
UINT8 v5;
unsigned int v6;
_CMHIVE *v8;
unsigned int v9;
__int64 *v10;
__int64 v11;
__int64 i;
_UNICODE_STRING *v13;
__int64 v14;
WCHAR v15;
WCHAR v16;
NTSTATUS v17;
PULONG ResultLength;
__int16 v22;
int v23;
ULONG v24;
void *KeyHandle;
_UNICODE_STRING *KeyPath;
_CMHIVE *NextActiveHive;
struct _UNICODE_STRING DestinationString;
struct _UNICODE_STRING ValueName;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int128 v31;
__int128 v32;
__int128 KeyValueInformation;
KAPC_STATE ApcState;
EVENT_DATA_DESCRIPTOR a1;
wchar_t *Buffer;
int Length;
int v38;
__int16 *v39;
__int64 v40;
char v41;
v4 = Start;
v5 = HiveRundown;
v6 = KeyRundown;
v23 = 0;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
v24 = 0;
KeyHandle = 0i64;
v22 = 0;
ValueName = 0i64;
KeyValueInformation = 0i64;
DestinationString = 0i64;
v31 = 0i64;
v32 = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
if( !v41 )
{
CmpAttachToRegistryProcess(&ApcState);
*(_QWORD *)&a1.Size = 24i64;
a1.Ptr = (unsigned __int64)&v31;
v8 = 0i64;
v40 = 2i64;
v39 = &v22;
while( 1 )
{
NextActiveHive = CmpGetNextActiveHive(v8);
v14 = (__int64)NextActiveHive;
if( !NextActiveHive )
break;
CmpLockRegistryExclusive();
if( v4 )
CmpLogHiveRundownEvent(v14, LoggerId, v6);
if( v5 )
{
v9 = *(_DWORD *)(v14 + 1648);
if( v9 )
{
v10 = (__int64 *)(*(_QWORD *)(v14 + 1640) + 16i64);
v11 = v9;
do
{
for( i = *v10; i; i = *(_QWORD *)(i + 8) )
{
KeyPath = 0i64;
CmpConstructNameWithStatus((_CM_KEY_CONTROL_BLOCK *)(i - 16), &KeyPath);
v13 = KeyPath;
if( KeyPath )
{
Buffer = KeyPath->Buffer;
Length = KeyPath->Length;
LODWORD(ResultLength) = 4200450;
*(_QWORD *)&v32 = i - 16;
v38 = 0;
EtwTraceSiloDcEvent(&a1, 3u, LoggerId, v6, 2329, (INT64)ResultLength);
CmpFreeTransientPoolWithTag(v13, 0x624E4D43ui64);
}
}
v10 += 3;
--v11;
}
while( v11 );
v14 = (__int64)NextActiveHive;
v4 = Start;
}
v5 = HiveRundown;
}
CmpUnlockRegistry();
v8 = (_CMHIVE *)v14;
}
KiUnstackDetachProcess(&ApcState, 0i64);
RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\System\\Select", v15);
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) >= 0 )
{
RtlInitUnicodeString(&ValueName, L"Current", v16);
v17 = ZwQueryValueKey(KeyHandle, &ValueName, KeyValuePartialInformation, &KeyValueInformation, 0x10u, &v24);
ZwClose(KeyHandle);
if( v17 >= 0 )
{
v23 = HIDWORD(KeyValueInformation);
LODWORD(ResultLength) = 4200450;
a1.Ptr = (unsigned __int64)&v23;
a1.Size = 4;
EtwTraceSiloDcEvent(&a1, 1u, LoggerId, v6, 2339, (INT64)ResultLength);
}
}
}
LODWORD(ResultLength) = 4200450;
a1.Ptr = (unsigned __int64)CmPerfCounters;
*(_QWORD *)&a1.Size = 88i64;
EtwTraceSiloDcEvent(&a1, 1u, LoggerId, v6, 2338, (INT64)ResultLength);
return 0i64;
}Referenced by:
EtwpKernelTraceRundown