EtwpCovSampImageNotify

VOID __stdcall EtwpCovSampImageNotify(PUNICODE_STRING FullImageName, _HANDLE ProcessId, PIMAGE_INFO ImageInfo){
  _DEVPROPKEY *v3; 
  __int64 v5; 
  ULONG *p_ImageSectionNumber; 
  INT64 v8; 
  UINT8 **v9; 
  _ETHREAD *CurrentThread; 
  INT64 Process; 
  _UNICODE_STRING *v12; 
  void *v13; 
  UINT64 *RequiredSize; 
  UINT64 *v15; 
  INT64 v16; 
  _LIST_ENTRY *v17; 

  v3 = 0i64;
  v16 = 0i64;
  v5 = *(_QWORD *)&ProcessId;
  v17 = 0i64;
  if( (ImageInfo->anonymous_0.Properties & 0x400) == 0 )
    return;
  p_ImageSectionNumber = &ImageInfo[-1].ImageSectionNumber;
  if( (int)EtwpCovSampAcquireSamplerRundown(&v17) >= 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    v3 = (_DEVPROPKEY *)(*(&ExBootDevicesRemovedEvent + 151) + 16i64);
    Process = (INT64)CurrentThread->Tcb.ApcState.Process;
    if( v5 )
    {
      if( v5 == *(_QWORD *)(Process + 1088)
        && EtwpCovSampProcessEnsureContext((INT128 *)CurrentThread->Tcb.ApcState.Process, v8, v9) >= 0 )
      {
        v12 = *(_UNICODE_STRING **)(Process + 2544);
        goto LABEL_9;
      }
    }
    else if( (ImageInfo->anonymous_0.Properties & 0x100) != 0 )
    {
      v12 = (_UNICODE_STRING *)(*(&ExBootDevicesRemovedEvent + 151) + 752i64);
LABEL_9:
      if( EtwpCovSampContextGetModule((INT64)v3, Process, (INT64)v12, FullImageName, (INT64)p_ImageSectionNumber, &v16) >= 0 )
        EtwpCovSampProcessAddModule(v12, v3, v16, (UINT64)ImageInfo->ImageBase, v13, RequiredSize, v15);
    }
  }
  if( v16 )
    EtwpCovSampModuleDereference((INT64)v3, v16);
  if( v17 )
  {
    ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&ExBootDevicesRemovedEvent + 152);
    KeLeaveCriticalRegion();
  }
}

Referenced by:

EtwpCovSampEnumerateDriver
EtwpCovSampEnumerateProcess