EtwpTiQueryVad
NTSTATUS __stdcall EtwpTiQueryVad(INT64 a1, _EPROCESS *a2, PVOID *a3, UINT64 a4, CHAR a5){
unsigned int v5;
int v8;
NTSTATUS v9;
unsigned int v10;
PVOID *v11;
char *v12;
NTSTATUS VirtualMemory;
VOID **PoolWithTag;
_KAPC_STATE ApcState;
v5 = a4;
memset(&ApcState, 0, sizeof(ApcState));
if( a2 == KeGetCurrentThread()->ApcState.Process )
{
v8 = 0;
}
else
{
KiStackAttachProcess(a2, 0i64, &ApcState);
v8 = 1;
}
v9 = 0;
v10 = 0;
if( v5 )
{
v11 = (PVOID *)(a1 + 56);
v12 = (char *)(a1 + 8);
do
{
VirtualMemory = ZwQueryVirtualMemory(-1, *a3, MemoryRegionInformation, v12, 48, 0i64);
*((_DWORD *)v11 - 14) = VirtualMemory;
if( VirtualMemory >= 0 )
{
v9 |= 1 << v10;
if( a5 )
{
PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x200ui64, 1853049172i64);
*v11 = PoolWithTag;
if( !PoolWithTag
|| ZwQueryVirtualMemory(-1, *a3, MemoryMappedFilenameInformation, PoolWithTag, 512, 0i64) >= 0 )
{
goto LABEL_9;
}
ExFreePoolWithTag(*v11, 0);
}
*v11 = 0i64;
}
LABEL_9:
++v10;
v12 += 64;
++a3;
v11 += 8;
}
while( v10 < v5 );
}
if( v8 )
KiUnstackDetachProcess(&ApcState, 0i64);
return v9;
}Referenced by:
EtwpTiVadQueryEventWriteCallback