EtwpPsProvTraceProcess
unsigned int __fastcall EtwpPsProvTraceProcess(_EPROCESS *Process, char a2, unsigned int *a3, __int64 a4, __int16 a5){
unsigned int v9;
EVENT_DESCRIPTOR *v10;
unsigned int v11;
void *v12;
int v13;
struct DMA_ADAPTER *v14;
int v15;
struct _UNICODE_STRING *p_DestinationString;
__int64 *v17;
unsigned int v18;
unsigned int v19;
struct DMA_ADAPTER *v20;
int ReadOperationCount;
int WriteOperationCount;
__int64 v23;
int WriteTransferCount;
unsigned int *v25;
unsigned int *v26;
__int64 v27;
WCHAR v28;
int v29;
int v30;
int ProcessHandleCount;
int v32;
int v33;
int v34;
int v35;
int v36;
int SessionId;
int v38;
__int64 v39;
__int64 v40;
__int64 v41;
__int64 v42;
PVOID v43;
PVOID v44;
_EPROCESS *Processa;
__int64 v46;
PVOID TokenInformation;
PVOID P;
struct _SID_AND_ATTRIBUTES IntegritySA;
struct _UNICODE_STRING DestinationString;
_EPROCESS_VALUES result;
EVENT_DATA_DESCRIPTOR UserData;
__int64 v53;
__int64 v54;
__int64 v55;
__int64 v56;
int *v57;
__int64 v58;
__int64 *v59;
__int64 v60;
int *p_SessionId;
__int64 v62;
int *p_ProcessHandleCount;
__int64 v64;
__int64 *v65;
__int64 v66;
__int64 *v67;
__int64 v68;
void *p_CycleTime;
__int64 v70;
int *v71;
__int64 v72;
__int64 *v73;
__int64 v74;
int *v75;
__int64 v76;
int *v77;
__int64 v78;
unsigned int *v79;
__int64 v80;
unsigned int *v81;
unsigned int v82;
int v83;
wchar_t pszDest[16];
v30 = 0;
v36 = 0;
SessionId = 0;
v29 = 0;
ProcessHandleCount = 0;
v40 = 0i64;
v41 = 0i64;
v9 = memset((INT64)&result, 0i64);
v32 = 0;
v33 = 0;
v34 = 0;
v35 = 0;
DestinationString = 0i64;
switch( a5 )
{
case 769:
v10 = (EVENT_DESCRIPTOR *)&ProcessStart;
goto LABEL_3;
case 770:
v10 = (EVENT_DESCRIPTOR *)ProcessStop;
goto LABEL_3;
case 771:
v10 = (EVENT_DESCRIPTOR *)ProcessRundown;
LABEL_3:
LODWORD(v42) = *((_DWORD *)Process + 272);
v11 = 3;
*(_QWORD *)&UserData.Size = 4i64;
UserData.Ptr = (unsigned __int64)&v42;
v53 = (__int64)Process + 2296;
v55 = (__int64)Process + 1128;
v54 = 8i64;
v56 = 8i64;
if( ((a5 - 769) & 0xFFFD) != 0 )
{
if( a5 != 770 )
return EtwWrite(*(UINT64 *)EtwpPsProvRegHandle, v10, 0i64, v11, &UserData);
v43 = 0i64;
PsQueryStatisticsProcess(Process, &result);
v58 = 8i64;
v57 = (int *)((char *)Process + 2112);
v60 = 4i64;
v59 = (__int64 *)((char *)Process + 2004);
v20 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)Process);
if( (int)SeQueryInformationToken(v20, TokenElevationType, &v43) >= 0 )
{
if( *(_DWORD *)v43 == 1 )
{
v44 = 0i64;
if( (int)SeQueryInformationToken(v20, TokenElevation, &v44) >= 0 )
v29 = *(_DWORD *)v44 != 0 ? 1 : 4;
if( v44 )
ExFreePoolWithTag(v44, 0);
}
else
{
v29 = *(_DWORD *)v43;
}
}
ObFastDereferenceObject((INT64 *)Process + 151, v20);
if( v43 )
ExFreePoolWithTag(v43, 0);
v62 = 4i64;
p_SessionId = &v29;
ProcessHandleCount = ObGetProcessHandleCount((struct _EX_RUNDOWN_REF *)Process, 0i64);
v64 = 4i64;
p_ProcessHandleCount = &ProcessHandleCount;
v40 = *((_QWORD *)Process + 201);
v40 <<= 12;
v65 = &v40;
v41 = *((_QWORD *)Process + 202);
v41 <<= 12;
v67 = &v41;
p_CycleTime = &result.CycleTime;
ReadOperationCount = result.ReadOperationCount;
if( HIDWORD(result.ReadOperationCount) )
ReadOperationCount = -1;
v66 = 8i64;
v32 = ReadOperationCount;
v71 = &v32;
WriteOperationCount = result.WriteOperationCount;
if( HIDWORD(result.WriteOperationCount) )
WriteOperationCount = -1;
v68 = 8i64;
v33 = WriteOperationCount;
v23 = result.ReadTransferCount >> 10;
v73 = (__int64 *)&v33;
result.ReadTransferCount = v23;
v70 = 8i64;
if( HIDWORD(v23) )
LODWORD(v23) = -1;
v75 = &v34;
v34 = v23;
result.WriteTransferCount >>= 10;
WriteTransferCount = result.WriteTransferCount;
v72 = 4i64;
v74 = 4i64;
if( HIDWORD(result.WriteTransferCount) )
WriteTransferCount = -1;
v77 = &v35;
v25 = (unsigned int *)((char *)Process + 1832);
v76 = 4i64;
v26 = (unsigned int *)((char *)Process + 1448);
v79 = v25;
v81 = v26;
v27 = -1i64;
v35 = WriteTransferCount;
v78 = 4i64;
v80 = 4i64;
do
++v27;
while( *((_BYTE *)v26 + v27) );
v19 = v27 + 1;
}
else
{
v12 = (void *)*((_QWORD *)Process + 168);
v46 = -1i64;
v38 = -1;
v36 = *((_DWORD *)Process + 336);
LODWORD(v39) = -1;
v57 = &v36;
Processa = 0i64;
TokenInformation = 0i64;
P = 0i64;
IntegritySA = 0i64;
v58 = 4i64;
if( PsLookupProcessByProcessId(v12, (PEPROCESS *)&Processa) >= 0 )
{
v46 = *((_QWORD *)Processa + 287);
HalPutDmaAdapter((PADAPTER_OBJECT)Processa);
}
v60 = 8i64;
v59 = &v46;
SessionId = MmGetSessionId((__int64)Process);
v13 = 1;
v62 = 4i64;
p_SessionId = &SessionId;
if( (a2 & 1) == 0 )
{
v11 = 2;
v13 = v30;
}
v64 = 4i64;
if( (a2 & 8) != 0 )
v13 = v11;
p_ProcessHandleCount = &v30;
v30 = v13;
v14 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)Process);
if( (int)SeQueryInformationToken(v14, TokenElevationType, &TokenInformation) >= 0 )
v38 = *(_DWORD *)TokenInformation;
v66 = 4i64;
v65 = (__int64 *)&v38;
if( TokenInformation )
ExFreePoolWithTag(TokenInformation, 0);
if( (int)SeQueryInformationToken(v14, TokenElevation, &P) >= 0 )
LODWORD(v39) = *(_DWORD *)P;
v68 = 4i64;
v67 = &v39;
if( P )
ExFreePoolWithTag(P, 0);
SeQueryTokenIntegrity(v14, &IntegritySA);
v15 = *((unsigned __int8 *)IntegritySA.Sid + 1);
p_CycleTime = IntegritySA.Sid;
v70 = (unsigned int)(4 * v15 + 8);
ObFastDereferenceObject((INT64 *)Process + 151, v14);
p_DestinationString = (struct _UNICODE_STRING *)*((_QWORD *)Process + 184);
if( !p_DestinationString || !p_DestinationString->Length )
{
RtlStringCchPrintfW(pszDest, 0xFui64, (WCHAR *)L"%S");
RtlInitUnicodeString(&DestinationString, pszDest, v28);
p_DestinationString = &DestinationString;
}
v17 = &EmptyUnicodeString;
if( p_DestinationString )
v17 = (__int64 *)p_DestinationString;
v18 = *(unsigned __int16 *)v17;
v71 = (int *)v17[1];
v73 = &EtwpNull;
v77 = (int *)(a4 + 4);
v79 = a3 + 4;
v80 = *a3;
v81 = a3 + 68;
v19 = a3[2];
v72 = v18;
v74 = 2i64;
v75 = (int *)a4;
v76 = 4i64;
v78 = 4i64;
}
v11 = 16;
v83 = 0;
v82 = v19;
return EtwWrite(*(UINT64 *)EtwpPsProvRegHandle, v10, 0i64, v11, &UserData);
}
return v9;
}Referenced by:
EtwpPsProvProcessEnumCallback
EtwpWriteProcessEvent