EtwpCheckGuidAccessAndDoRundown
INT64 __fastcall EtwpCheckGuidAccessAndDoRundown(
_ETW_SILODRIVERSTATE *SiloState,
const _GUID *Guid,
UINT64 TargetLoggerId,
_EVENT_FILTER_DESCRIPTOR *FilterDescriptor,
UINT8 Start){
unsigned int v5;
char v7;
INT64 result;
unsigned int v9;
int v10;
UINT64 v11;
unsigned int v12;
_DWORD *v13;
unsigned int v14;
UINT64 **a5;
UINT64 a6;
UINT8 dst[16];
__int128 v18;
unsigned int v19;
v5 = TargetLoggerId;
*(_OWORD *)dst = 0i64;
v7 = (char)FilterDescriptor;
v18 = 0i64;
result = EtwpCheckGuidAccess(&SystemTraceControlGuid, 0x80ui64, 0i64);
v9 = result;
if( (int)result >= 0 )
{
v10 = *(_DWORD *)(Start + 12i64);
if( v10 == -2147483647 )
{
v11 = *(unsigned int *)(Start + 8i64);
if( (unsigned int)v11 <= 0x20 && (v11 & 3) == 0 )
{
v12 = 1;
if( v19 > 1 )
{
v13 = (_DWORD *)(Start + 24i64);
while( v13[1] != -2147483644 || (*v13 & 3) == 0 )
{
++v12;
v13 += 4;
if( v12 >= v19 )
goto LABEL_10;
}
return 3221225485i64;
}
LABEL_10:
memmove(dst, *(UINT8 **)Start, v11);
v14 = v19 - 1;
a5 = (UINT64 **)(Start + 16i64);
if( v19 <= 1 )
v14 = 0;
LODWORD(a6) = v14;
if( v19 <= 1 )
a5 = 0i64;
EtwpLogKernelTraceRundown((UINT64)SiloState, (PVOID)v5, (__int128 *)dst, v7, a5, a6);
return v9;
}
return 3221225485i64;
}
if( v10 == -2147483646 )
{
if( *(_DWORD *)(Start + 8i64) != 8 )
return 3221225485i64;
return(unsigned int)EtwpCheckLoggerAccessAndDoRundown(SiloState, **(unsigned __int16 **)Start, v5, v7);
}
else
{
return(unsigned int)-1073741811;
}
}
return result;
}Referenced by:
EtwpEnableDisableSpecialGuids