{
DWORD dwWritten;
DWORD dwRead;
+ SYSTEMTIME st;
EVENTLOGEOF EofRec;
PEVENTLOGRECORD RecBuf;
LARGE_INTEGER logFileSize;
- LARGE_INTEGER SystemTime;
ULONG RecOffSet;
ULONG WriteOffSet;
if (!Buffer)
return FALSE;
- NtQuerySystemTime(&SystemTime);
- RtlTimeToSecondsSince1970(&SystemTime, &((PEVENTLOGRECORD) Buffer)->TimeWritten);
+ GetSystemTime(&st);
+ SystemTimeToEventTime(&st, &((PEVENTLOGRECORD) Buffer)->TimeWritten);
EnterCriticalSection(&LogFile->cs);
PBYTE LogfAllocAndBuildNewRecord(LPDWORD lpRecSize,
DWORD dwRecordNumber,
- DWORD dwTime,
WORD wType,
WORD wCategory,
DWORD dwEventId,
{
DWORD dwRecSize;
PEVENTLOGRECORD pRec;
+ SYSTEMTIME SysTime;
WCHAR *str;
UINT i, pos;
PBYTE Buffer;
sizeof(EVENTLOGRECORD) + (lstrlenW(ComputerName) +
lstrlenW(SourceName) + 2) * sizeof(WCHAR);
- if (dwRecSize % sizeof(DWORD) != 0)
- dwRecSize += sizeof(DWORD) - (dwRecSize % sizeof(DWORD));
+ if (dwRecSize % 4 != 0)
+ dwRecSize += 4 - (dwRecSize % 4);
dwRecSize += dwSidLength;
}
dwRecSize += dwDataSize;
- if (dwRecSize % sizeof(DWORD) != 0)
- dwRecSize += sizeof(DWORD) - (dwRecSize % sizeof(DWORD));
+ if (dwRecSize % 4 != 0)
+ dwRecSize += 4 - (dwRecSize % 4);
- dwRecSize += sizeof(DWORD);
+ dwRecSize += 4;
Buffer = HeapAlloc(MyHeap, HEAP_ZERO_MEMORY, dwRecSize);
pRec->Reserved = LOGFILE_SIGNATURE;
pRec->RecordNumber = dwRecordNumber;
- pRec->TimeGenerated = dwTime;
- pRec->TimeWritten = dwTime;
+ GetSystemTime(&SysTime);
+ SystemTimeToEventTime(&SysTime, &pRec->TimeGenerated);
+ SystemTimeToEventTime(&SysTime, &pRec->TimeWritten);
pRec->EventID = dwEventId;
pRec->EventType = wType;
pRec->UserSidOffset = pos;
- if (pos % sizeof(DWORD) != 0)
- pos += sizeof(DWORD) - (pos % sizeof(DWORD));
+ if (pos % 4 != 0)
+ pos += 4 - (pos % 4);
if (dwSidLength)
{
pos += dwDataSize;
}
- if (pos % sizeof(DWORD) != 0)
- pos += sizeof(DWORD) - (pos % sizeof(DWORD));
+ if (pos % 4 != 0)
+ pos += 4 - (pos % 4);
*((PDWORD) (Buffer + pos)) = dwRecSize;
DWORD lastRec;
DWORD recSize;
DWORD dwError;
- DWORD dwTime;
- LARGE_INTEGER SystemTime;
if (!GetComputerNameW(szComputerName, &dwComputerNameLength))
{
return;
}
- NtQuerySystemTime(&SystemTime);
- RtlTimeToSecondsSince1970(&SystemTime, &dwTime);
-
lastRec = LogfGetCurrentRecord(pEventSource->LogFile);
logBuffer = LogfAllocAndBuildNewRecord(&recSize,
- dwTime,
lastRec,
wType,
wCategory,