ObCheckRefTraceProcess
NTSTATUS __stdcall ObCheckRefTraceProcess(_EPROCESS *ProcessObject){
NTSTATUS result;
UINT8 *ProcessImageFileName;
_ETHREAD *CurrentThread;
_STRING DestinationString;
_UNICODE_STRING String1;
DestinationString = 0i64;
String1 = 0i64;
if( (ObpTraceFlags & 0x20) == 0 )
return 0;
ProcessImageFileName = PsGetProcessImageFileName(ProcessObject);
RtlInitAnsiString(&DestinationString, (PCSZ)ProcessImageFileName);
if( !DestinationString.Length )
return 0;
result = RtlAnsiStringToUnicodeString(&String1, &DestinationString, 1u);
if( result >= 0 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.SpecialApcDisable;
ExAcquirePushLockExclusiveEx(&stru_140C25A40, 0i64);
if( (ObpTraceFlags & 0x20) != 0 && (unsigned __int8)RtlPrefixUnicodeString(&String1, qword_140C259C0, 1u) )
_InterlockedOr((volatile signed __int32 *)&ProcessObject->1120, 0x200u);
if( (_InterlockedExchangeAdd64(&stru_140C25A40._bf_0, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(&stru_140C25A40);
KeAbPostRelease(&stru_140C25A40);
KiLeaveGuardedRegionUnsafe((__int64)KeGetCurrentThread());
RtlFreeAnsiString(&String1);
return 0;
}
return result;
}Referenced by:
No references.