EtwQueryProcessTelemetryInfo
__int64 __fastcall EtwQueryProcessTelemetryInfo(
ULONG_PTR BugCheckParameter1,
volatile void *Address,
SIZE_T Length,
char a4,
__int64 a5){
UINT64 v5;
int v8;
__int64 *v9;
struct DMA_ADAPTER *v10;
int v11;
unsigned int v12;
__int64 v13;
__int64 v14;
UINT8 *v15;
unsigned __int16 *v16;
UINT8 *v17;
UINT8 *v18;
UINT8 *v19;
UINT64 Size;
int v23;
__int64 v24;
PVOID P[2];
_DWORD *v26;
UINT8 **v27;
struct DMA_ADAPTER *v28;
ULONG_PTR v29;
size_t v30;
size_t v31;
UINT8 v32[256];
UINT8 v33[144];
_KAPC_STATE ApcState;
UINT8 Src[80];
v5 = (unsigned int)Length;
v29 = BugCheckParameter1;
v26 = (_DWORD *)a5;
memset(&ApcState, 0, sizeof(ApcState));
memset((INT64)&v30, 0i64);
memset((INT64)Src, 0i64);
LODWORD(Size) = 0;
*(_OWORD *)P = 0i64;
v8 = 0;
v24 = 0i64;
v9 = &EmptyUnicodeString;
if( *(_QWORD *)(BugCheckParameter1 + 1472) )
v9 = *(__int64 **)(BugCheckParameter1 + 1472);
v27 = (UINT8 **)v9;
v10 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)BugCheckParameter1);
v28 = v10;
v23 = 0;
EtwpQueryTokenPackageInfo((__int64)v10, (__int64)&v30, &v23);
v11 = SeQueryUserSidToken(v10, Src, 0x44ui64, &Size);
if( v11 >= 0 )
{
if( (int)PsAcquireProcessExitSynchronization((struct _EX_RUNDOWN_REF *)BugCheckParameter1) >= 0 )
{
KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
EtwpQueryProcessOtherInfo(BugCheckParameter1, (__int64)&v24);
EtwpQueryProcessCommandLine((_EPROCESS *)BugCheckParameter1, (_UNICODE_STRING *)P);
KiUnstackDetachProcess(&ApcState, 0i64);
ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
v8 = v24;
}
v12 = Size + 100 + v30 + v31 + *(unsigned __int16 *)v9 + LOWORD(P[0]);
if( v26 )
*v26 = v12;
if( a4 )
ProbeForWrite((VOID *)Address, v5, 4ui64);
memset((INT64)Address, 0i64);
if( (unsigned int)v5 < 0x60 )
{
v11 = -1073741820;
HIDWORD(Size) = -1073741820;
}
else
{
*(_DWORD *)Address = 96;
*((_DWORD *)Address + 1) = *(_DWORD *)(BugCheckParameter1 + 1088);
*((_QWORD *)Address + 1) = PsGetProcessStartKey(BugCheckParameter1);
*((_QWORD *)Address + 2) = *(_QWORD *)(BugCheckParameter1 + 1128);
*((_QWORD *)Address + 3) = *(_QWORD *)(BugCheckParameter1 + 2304);
*((_QWORD *)Address + 4) = *(_QWORD *)(BugCheckParameter1 + 2312);
*((_QWORD *)Address + 5) = *(_QWORD *)(BugCheckParameter1 + 2296);
*((_QWORD *)Address + 6) = MmGetSessionCreateTime(v13);
*((_DWORD *)Address + 14) = PsGetProcessSessionId(BugCheckParameter1);
*((_DWORD *)Address + 15) = KUSER_SHARED_DATA.BootId;
*((_DWORD *)Address + 16) = v8;
*((_DWORD *)Address + 17) = HIDWORD(v24);
if( (unsigned int)v5 >= v12 )
{
*((_DWORD *)Address + 18) = 96;
v14 = (unsigned int)Size;
memmove((UINT8 *)Address + 96, Src, (unsigned int)Size);
v15 = (UINT8 *)Address + v14 + 96;
*((_DWORD *)Address + 19) = v14 + 96;
v16 = (unsigned __int16 *)v27;
memmove(v15, v27[1], *(unsigned __int16 *)v27);
v17 = &v15[*v16 + 2];
*((_DWORD *)Address + 20) = (_DWORD)v17 - (_DWORD)Address;
memmove(v17, v32, v30);
v18 = &v17[v30];
*((_DWORD *)Address + 21) = (_DWORD)v18 - (_DWORD)Address;
memmove(v18, v33, v31);
v19 = &v18[v31];
*((_DWORD *)Address + 22) = (_DWORD)v19 - (_DWORD)Address;
memmove(v19, (UINT8 *)P[1], LOWORD(P[0]));
v11 = 0;
}
else
{
v11 = -2147483643;
HIDWORD(Size) = -2147483643;
}
}
}
if( P[1] )
ExFreePoolWithTag(P[1], 0);
if( v10 )
ObFastDereferenceObject((INT64 *)(BugCheckParameter1 + 1208), v10);
return(unsigned int)v11;
}Referenced by:
NtQueryInformationProcess