KiTpBuildExcludedKernelTracepointRangeList
CHAR *__stdcall KiTpBuildExcludedKernelTracepointRangeList(){
volatile INT64 *PoolWithTag;
volatile INT64 *v1;
void *v2;
__int64 v3;
int v4;
unsigned __int64 ImageBase;
PoolWithTag = (volatile INT64 *)ExAllocatePoolWithTag(PagedPool, 0x20ui64, 0x70727446ui64);
v1 = PoolWithTag;
if( PoolWithTag )
{
*((_DWORD *)PoolWithTag + 4) = 0;
*((_DWORD *)PoolWithTag + 5) = 0;
*((_DWORD *)PoolWithTag + 6) = 0;
v2 = (void *)KiTpExcludedRoutines;
LODWORD(v3) = 0;
*((_QWORD *)PoolWithTag + 1) = PoolWithTag;
*PoolWithTag = (volatile INT64)PoolWithTag;
while( 1 )
{
ImageBase = 0i64;
RtlLookupFunctionEntry(v2, &ImageBase, 0i64);
RtlAddRange(v1);
if( v4 < 0 )
break;
v3 = (unsigned int)(v3 + 1);
v2 = (void *)*(&KiTpExcludedRoutines + v3);
if( !v2 )
return(CHAR *)v1;
}
RtlFreeRangeList((INT64)v1);
ExFreePoolWithTag((PVOID)v1, 0x70727446u);
}
return 0i64;
}Referenced by:
KiTpIsExcludedKernelTracepointLocation