PspWriteTebImpersonationInfo

NTSTATUS __stdcall PspWriteTebImpersonationInfo(_ETHREAD *Thread, _ETHREAD *CurrentThread){
  _DWORD *Teb; 
  _EPROCESS *Process; 
  unsigned int v6; 
  bool v7; 
  _BOOL8 v8; 
  _EWOW64PROCESS *WoW64Process; 
  unsigned __int16 Machine; 
  int v12[8]; 
  char v13; 
  bool v14; 
  _DWORD *v15; 
  _EPROCESS *v16; 
  _ETHREAD *v17; 
  _KAPC_STATE ApcState; 

  v17 = Thread;
  memset(&ApcState, 0, sizeof(ApcState));
  Teb = Thread->Tcb.Teb;
  v15 = Teb;
  if( Teb && (Thread->Tcb._bf_0 & 0x400) == 0 )
  {
    Process = Thread->Tcb.Process;
    v16 = Process;
    if( CurrentThread->Tcb.ApcState.Process == Process )
    {
      v13 = 0;
    }
    else
    {
      KiStackAttachProcess(Process, 0i64, &ApcState);
      v13 = 1;
    }
    if( Thread == CurrentThread || ExAcquireRundownProtection(&Thread->RundownProtect) )
    {
      do
      {
        v6 = Thread->CrossThreadFlags & 8;
        v7 = v6 != 0;
        v14 = v6 != 0;
        v8 = v6 != 0;
        Teb[1511] = v8;
        Teb[1530] = 0;
        WoW64Process = Process->WoW64Process;
        if( WoW64Process )
        {
          Machine = WoW64Process->Machine;
          if( Machine == 332 || Machine == 452 )
          {
            Teb[3047] = v8;
            Teb[3057] = 0;
          }
        }
        _InterlockedOr(v12, 0);
      }
      while( v7 != ((Thread->CrossThreadFlags & 8) != 0) );
      if( Thread != CurrentThread )
        ExReleaseRundownProtection(&Thread->RundownProtect);
    }
    if( v13 )
      KiUnstackDetachProcess(&ApcState, 0i64);
  }
  return 0;
}

Referenced by:

PsImpersonateClient
PsRestoreImpersonation