EtwpUpdateLevelKwFilter

__int64 __fastcall EtwpUpdateLevelKwFilter(__int64 a1, __int64 a2, char a3, _QWORD *a4){
  unsigned int v4; 
  VOID **PoolWithTag; 
  _OWORD *v9; 

  v4 = 0;
  if( a3 )
  {
    *a4 = _InterlockedExchange64((volatile __int64 *)(a1 + 64), 0i64);
  }
  else
  {
    if( *(_DWORD *)(a2 + 8) != 24 )
      return 3221225485i64;
    PoolWithTag = *(VOID ***)(a1 + 64);
    if( PoolWithTag || (PoolWithTag = ExAllocatePoolWithTag(0i64, 0x18ui64, 1182233669i64)) != 0i64 )
    {
      v9 = *(_OWORD **)a2;
      *(_OWORD *)PoolWithTag = *(_OWORD *)*(_QWORD *)a2;
      PoolWithTag[2] = (VOID *)*((_QWORD *)v9 + 2);
      if( !*PoolWithTag )
        *PoolWithTag = (VOID *)-1i64;
      if( !*((_BYTE *)PoolWithTag + 16) )
        *((_BYTE *)PoolWithTag + 16) = -1;
      *(_QWORD *)(a1 + 64) = PoolWithTag;
    }
    else
    {
      return(unsigned int)-1073741801;
    }
  }
  return v4;
}

Referenced by:

EtwpUpdateFilterData