ObCheckRefTraceProcess

NTSTATUS __stdcall ObCheckRefTraceProcess(_EPROCESS *ProcessObject){
  NTSTATUS result; 
  UINT8 *ProcessImageFileName; 
  _ETHREAD *CurrentThread; 
  _STRING DestinationString; 
  _UNICODE_STRING String1; 

  DestinationString = 0i64;
  String1 = 0i64;
  if( (ObpTraceFlags & 0x20) == 0 )
    return 0;
  ProcessImageFileName = PsGetProcessImageFileName(ProcessObject);
  RtlInitAnsiString(&DestinationString, (PCSZ)ProcessImageFileName);
  if( !DestinationString.Length )
    return 0;
  result = RtlAnsiStringToUnicodeString(&String1, &DestinationString, 1u);
  if( result >= 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --CurrentThread->Tcb.SpecialApcDisable;
    ExAcquirePushLockExclusiveEx(&stru_140C25A40, 0i64);
    if( (ObpTraceFlags & 0x20) != 0 && (unsigned __int8)RtlPrefixUnicodeString(&String1, qword_140C259C0, 1u) )
      _InterlockedOr((volatile signed __int32 *)&ProcessObject->1120, 0x200u);
    if( (_InterlockedExchangeAdd64(&stru_140C25A40._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
      ExfTryToWakePushLock(&stru_140C25A40);
    KeAbPostRelease(&stru_140C25A40);
    KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
    RtlFreeAnsiString(&String1);
    return 0;
  }
  return result;
}

Referenced by:

No references.