EtwpTiVadQueryEventWriteCallback
NTSTATUS __stdcall EtwpTiVadQueryEventWriteCallback(PVOID P){
NTSTATUS Vad;
VOID **PoolWithTag;
CHAR v4;
unsigned int i;
void *v6;
VOID *v7;
INT64 a5;
INT64 a6;
Vad = 0;
PoolWithTag = ExAllocatePoolWithTag(1ui64, (unsigned __int64)*((unsigned int *)P + 13) << 6, 1853049172i64);
if( PoolWithTag )
{
v4 = EtwProviderEnabled(*(&ExBootDevicesRemovedEvent + 179), 0, 0x10000000ui64);
Vad = EtwpTiQueryVad((INT64)PoolWithTag, *((_EPROCESS **)P + 8), *((PVOID **)P + 9), *((unsigned int *)P + 13), v4);
}
LODWORD(a6) = *((_DWORD *)P + 13);
LODWORD(a5) = Vad;
EtwpTiFillVadEventWrite(
*((PEVENT_DATA_DESCRIPTOR *)P + 4),
*((_DWORD *)P + 12),
1,
(INT64)PoolWithTag,
a5,
a6,
*((PCEVENT_DESCRIPTOR *)P + 7));
for( i = 0; i < *((_DWORD *)P + 13); ++i )
{
if( _bittest(&Vad, i) )
{
v6 = PoolWithTag[8 * (unsigned __int64)i + 7];
if( v6 )
ExFreePoolWithTag(v6, 0);
}
}
if( PoolWithTag )
ExFreePoolWithTag(PoolWithTag, 0);
v7 = (VOID *)*((_QWORD *)P + 8);
if( v7 )
ObfDereferenceObjectWithTag(v7, 0x69547445ui64);
return(unsigned int)ExFreePoolWithTag(P, 0);
}Referenced by:
No references.