EtwpDemuxPrivateTraceHandle
INT64 __fastcall EtwpDemuxPrivateTraceHandle(INT64 a1, UINT16 a2, UINT16 *a3){
int v5;
__int64 v7;
_ETHREAD *CurrentThread;
UINT64 v9;
__int64 v10;
INT64 v11;
unsigned int v12;
int v13;
int v14;
INT64 v15;
__int64 **v16;
__int64 *i;
UINT64 v18;
v5 = a1;
if( a2 >= 0x40u )
{
v7 = PsGetCurrentServerSiloGlobals()[108];
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v9 = v7 + 4096;
ExAcquirePushLockExclusiveEx(v7 + 4096, 0i64);
v10 = v7 + 4080;
LODWORD(v18) = v5;
v11 = *(_QWORD *)(v7 + 4080);
v12 = 0;
if( (*(_BYTE *)(v10 + 8) & 1) != 0 )
{
if( v11 )
v11 ^= v10;
else
v11 = 0i64;
}
v13 = *(_BYTE *)(v10 + 8) & 1;
if( v11 )
{
do
{
v14 = PidNodeCompare(&v18, v11);
if( v14 >= 0 )
{
if( v14 <= 0 )
break;
v15 = *(_QWORD *)(v11 + 8);
}
else
{
v15 = *(_QWORD *)v11;
}
if( v13 && v15 )
v11 ^= v15;
else
v11 = v15;
}
while( v11 );
if( v11 )
{
v16 = (__int64 **)(v11 + 32);
for( i = *v16; i != (__int64 *)v16; i = (__int64 *)*i )
{
if( *((_WORD *)i + 9) == a2 )
{
*a3 = *((_WORD *)i + 8);
goto LABEL_23;
}
}
}
}
v12 = -1073741162;
LABEL_23:
ExReleasePushLockEx(v9, 0i64);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
return v12;
}
else
{
*a3 = a2;
return 0i64;
}
}Referenced by:
EtwpEnableGuid
EtwpNotifyGuid