EtwpGetPrivateSessionTraceHandle
NTSTATUS __stdcall EtwpGetPrivateSessionTraceHandle(){
unsigned int v0;
INT64 v1;
unsigned __int16 *v2;
unsigned int v3;
_DWORD *v4;
_ETW_SILODRIVERSTATE *CurrentSiloState;
NTSTATUS v6;
char v7;
_EX_PUSH_LOCK *p_PrivHandleDemuxTable;
_ETHREAD *CurrentThread;
_DWORD *v10;
__int64 v11;
unsigned __int16 v12;
unsigned int i;
int v14;
INT64 PidDemuxList;
__int64 *j;
__int64 v18;
ULONG_PTR PushLock;
UINT64 Seed;
unsigned __int16 *v21;
_EPROCESS *Process;
v21 = v2;
v3 = v0;
v4 = (_DWORD *)v1;
CurrentSiloState = EtwpGetCurrentSiloState(v1);
v6 = 0;
Process = 0i64;
v7 = 0;
p_PrivHandleDemuxTable = (_EX_PUSH_LOCK *)&CurrentSiloState->PrivHandleDemuxTable;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v18 = (__int64)p_PrivHandleDemuxTable;
--CurrentThread->Tcb.KernelApcDisable;
PushLock = (_DWORD)p_PrivHandleDemuxTable + 16;
ExAcquirePushLockExclusiveEx(p_PrivHandleDemuxTable + 2, 0i64);
if( v3 )
{
v10 = v4;
v11 = v3;
do
{
if( PsLookupProcessByProcessId((VOID *)(unsigned int)*v10, &Process) )
{
*v10 = 0;
}
else
{
if( EtwpCheckCurrentUserProcessAccess(Process) )
*v10 = 0;
ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
}
v10 += 2;
--v11;
}
while( v11 );
}
do
LABEL_9:
v12 = RtlRandomEx(&Seed) & 0x7FFF;
while( v12 < 0x40u );
for( i = 0; i < v3; ++i )
{
v14 = v4[2 * i];
if( v14 )
{
PidDemuxList = EtwpGetPidDemuxList(v14, v18);
if( PidDemuxList )
{
for( j = *(__int64 **)(PidDemuxList + 32); j != (__int64 *)(PidDemuxList + 32); j = (__int64 *)*j )
{
if( *((_WORD *)j + 9) == v12 )
goto LABEL_9;
if( *((_WORD *)j + 8) == LOWORD(v4[2 * i + 1]) )
{
if( *((_WORD *)j + 10) != HIWORD(v4[2 * i + 1]) )
break;
*((_WORD *)j + 9) = v12;
v7 = 1;
}
}
}
}
}
ExReleasePushLockEx(PushLock, 0);
KeLeaveCriticalRegion();
if( !v7 )
return -1073741275;
*v21 = v12;
return v6;
}Referenced by:
NtTraceControl