EtwpCovSampImageNotify
VOID __stdcall EtwpCovSampImageNotify(PUNICODE_STRING FullImageName, _HANDLE ProcessId, PIMAGE_INFO ImageInfo){
_DEVPROPKEY *v3;
__int64 v5;
ULONG *p_ImageSectionNumber;
INT64 v8;
UINT8 **v9;
_ETHREAD *CurrentThread;
INT64 Process;
_UNICODE_STRING *v12;
void *v13;
UINT64 *RequiredSize;
UINT64 *v15;
INT64 v16;
_LIST_ENTRY *v17;
v3 = 0i64;
v16 = 0i64;
v5 = *(_QWORD *)&ProcessId;
v17 = 0i64;
if( (ImageInfo->anonymous_0.Properties & 0x400) == 0 )
return;
p_ImageSectionNumber = &ImageInfo[-1].ImageSectionNumber;
if( (int)EtwpCovSampAcquireSamplerRundown(&v17) >= 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v3 = (_DEVPROPKEY *)(*(&ExBootDevicesRemovedEvent + 151) + 16i64);
Process = (INT64)CurrentThread->Tcb.ApcState.Process;
if( v5 )
{
if( v5 == *(_QWORD *)(Process + 1088)
&& EtwpCovSampProcessEnsureContext((INT128 *)CurrentThread->Tcb.ApcState.Process, v8, v9) >= 0 )
{
v12 = *(_UNICODE_STRING **)(Process + 2544);
goto LABEL_9;
}
}
else if( (ImageInfo->anonymous_0.Properties & 0x100) != 0 )
{
v12 = (_UNICODE_STRING *)(*(&ExBootDevicesRemovedEvent + 151) + 752i64);
LABEL_9:
if( EtwpCovSampContextGetModule((INT64)v3, Process, (INT64)v12, FullImageName, (INT64)p_ImageSectionNumber, &v16) >= 0 )
EtwpCovSampProcessAddModule(v12, v3, v16, (UINT64)ImageInfo->ImageBase, v13, RequiredSize, v15);
}
}
if( v16 )
EtwpCovSampModuleDereference((INT64)v3, v16);
if( v17 )
{
ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&ExBootDevicesRemovedEvent + 152);
KeLeaveCriticalRegion();
}
}Referenced by:
EtwpCovSampEnumerateDriver
EtwpCovSampEnumerateProcess