EtwpTiVadQueryEventWriteCallback

NTSTATUS __stdcall EtwpTiVadQueryEventWriteCallback(PVOID P){
  NTSTATUS Vad; 
  VOID **PoolWithTag; 
  CHAR v4; 
  unsigned int i; 
  void *v6; 
  VOID *v7; 
  INT64 a5; 
  INT64 a6; 

  Vad = 0;
  PoolWithTag = ExAllocatePoolWithTag(1ui64, (unsigned __int64)*((unsigned int *)P + 13) << 6, 1853049172i64);
  if( PoolWithTag )
  {
    v4 = EtwProviderEnabled(*(&ExBootDevicesRemovedEvent + 179), 0, 0x10000000ui64);
    Vad = EtwpTiQueryVad((INT64)PoolWithTag, *((_EPROCESS **)P + 8), *((PVOID **)P + 9), *((unsigned int *)P + 13), v4);
  }
  LODWORD(a6) = *((_DWORD *)P + 13);
  LODWORD(a5) = Vad;
  EtwpTiFillVadEventWrite(
    *((PEVENT_DATA_DESCRIPTOR *)P + 4),
    *((_DWORD *)P + 12),
    1,
    (INT64)PoolWithTag,
    a5,
    a6,
    *((PCEVENT_DESCRIPTOR *)P + 7));
  for( i = 0; i < *((_DWORD *)P + 13); ++i )
  {
    if( _bittest(&Vad, i) )
    {
      v6 = PoolWithTag[8 * (unsigned __int64)i + 7];
      if( v6 )
        ExFreePoolWithTag(v6, 0);
    }
  }
  if( PoolWithTag )
    ExFreePoolWithTag(PoolWithTag, 0);
  v7 = (VOID *)*((_QWORD *)P + 8);
  if( v7 )
    ObfDereferenceObjectWithTag(v7, 0x69547445ui64);
  return(unsigned int)ExFreePoolWithTag(P, 0);
}

Referenced by:

No references.