EtwpTiQueryVad

NTSTATUS __stdcall EtwpTiQueryVad(INT64 a1, _EPROCESS *a2, PVOID *a3, UINT64 a4, CHAR a5){
  unsigned int v5; 
  int v8; 
  NTSTATUS v9; 
  unsigned int v10; 
  PVOID *v11; 
  char *v12; 
  NTSTATUS VirtualMemory; 
  VOID **PoolWithTag; 
  _KAPC_STATE ApcState; 

  v5 = a4;
  memset(&ApcState, 0, sizeof(ApcState));
  if( a2 == KeGetCurrentThread()->ApcState.Process )
  {
    v8 = 0;
  }
  else
  {
    KiStackAttachProcess(a2, 0i64, &ApcState);
    v8 = 1;
  }
  v9 = 0;
  v10 = 0;
  if( v5 )
  {
    v11 = (PVOID *)(a1 + 56);
    v12 = (char *)(a1 + 8);
    do
    {
      VirtualMemory = ZwQueryVirtualMemory(-1, *a3, MemoryRegionInformation, v12, 48, 0i64);
      *((_DWORD *)v11 - 14) = VirtualMemory;
      if( VirtualMemory >= 0 )
      {
        v9 |= 1 << v10;
        if( a5 )
        {
          PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x200ui64, 1853049172i64);
          *v11 = PoolWithTag;
          if( !PoolWithTag
            || ZwQueryVirtualMemory(-1, *a3, MemoryMappedFilenameInformation, PoolWithTag, 512, 0i64) >= 0 )
          {
            goto LABEL_9;
          }
          ExFreePoolWithTag(*v11, 0);
        }
        *v11 = 0i64;
      }
LABEL_9:
      ++v10;
      v12 += 64;
      ++a3;
      v11 += 8;
    }
    while( v10 < v5 );
  }
  if( v8 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  return v9;
}

Referenced by:

EtwpTiVadQueryEventWriteCallback