EtwpPsProvTraceProcess

unsigned int __fastcall EtwpPsProvTraceProcess(_EPROCESS *Process, char a2, unsigned int *a3, __int64 a4, __int16 a5){
  unsigned int v9; 
  EVENT_DESCRIPTOR *v10; 
  unsigned int v11; 
  void *v12; 
  int v13; 
  struct DMA_ADAPTER *v14; 
  int v15; 
  struct _UNICODE_STRING *p_DestinationString; 
  __int64 *v17; 
  unsigned int v18; 
  unsigned int v19; 
  struct DMA_ADAPTER *v20; 
  int ReadOperationCount; 
  int WriteOperationCount; 
  __int64 v23; 
  int WriteTransferCount; 
  unsigned int *v25; 
  unsigned int *v26; 
  __int64 v27; 
  WCHAR v28; 
  int v29; 
  int v30; 
  int ProcessHandleCount; 
  int v32; 
  int v33; 
  int v34; 
  int v35; 
  int v36; 
  int SessionId; 
  int v38; 
  __int64 v39; 
  __int64 v40; 
  __int64 v41; 
  __int64 v42; 
  PVOID v43; 
  PVOID v44; 
  _EPROCESS *Processa; 
  __int64 v46; 
  PVOID TokenInformation; 
  PVOID P; 
  struct _SID_AND_ATTRIBUTES IntegritySA; 
  struct _UNICODE_STRING DestinationString; 
  _EPROCESS_VALUES result; 
  EVENT_DATA_DESCRIPTOR UserData; 
  __int64 v53; 
  __int64 v54; 
  __int64 v55; 
  __int64 v56; 
  int *v57; 
  __int64 v58; 
  __int64 *v59; 
  __int64 v60; 
  int *p_SessionId; 
  __int64 v62; 
  int *p_ProcessHandleCount; 
  __int64 v64; 
  __int64 *v65; 
  __int64 v66; 
  __int64 *v67; 
  __int64 v68; 
  void *p_CycleTime; 
  __int64 v70; 
  int *v71; 
  __int64 v72; 
  __int64 *v73; 
  __int64 v74; 
  int *v75; 
  __int64 v76; 
  int *v77; 
  __int64 v78; 
  unsigned int *v79; 
  __int64 v80; 
  unsigned int *v81; 
  unsigned int v82; 
  int v83; 
  wchar_t pszDest[16]; 
  v30 = 0;
  v36 = 0;
  SessionId = 0;
  v29 = 0;
  ProcessHandleCount = 0;
  v40 = 0i64;
  v41 = 0i64;
  v9 = memset((INT64)&result, 0i64);
  v32 = 0;
  v33 = 0;
  v34 = 0;
  v35 = 0;
  DestinationString = 0i64;
  switch( a5 )
  {
    case 769:
      v10 = (EVENT_DESCRIPTOR *)&ProcessStart;
      goto LABEL_3;
    case 770:
      v10 = (EVENT_DESCRIPTOR *)ProcessStop;
      goto LABEL_3;
    case 771:
      v10 = (EVENT_DESCRIPTOR *)ProcessRundown;
LABEL_3:
      LODWORD(v42) = *((_DWORD *)Process + 272);
      v11 = 3;
      *(_QWORD *)&UserData.Size = 4i64;
      UserData.Ptr = (unsigned __int64)&v42;
      v53 = (__int64)Process + 2296;
      v55 = (__int64)Process + 1128;
      v54 = 8i64;
      v56 = 8i64;
      if( ((a5 - 769) & 0xFFFD) != 0 )
      {
        if( a5 != 770 )
          return EtwWrite(*(UINT64 *)EtwpPsProvRegHandle, v10, 0i64, v11, &UserData);
        v43 = 0i64;
        PsQueryStatisticsProcess(Process, &result);
        v58 = 8i64;
        v57 = (int *)((char *)Process + 2112);
        v60 = 4i64;
        v59 = (__int64 *)((char *)Process + 2004);
        v20 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)Process);
        if( (int)SeQueryInformationToken(v20, TokenElevationType, &v43) >= 0 )
        {
          if( *(_DWORD *)v43 == 1 )
          {
            v44 = 0i64;
            if( (int)SeQueryInformationToken(v20, TokenElevation, &v44) >= 0 )
              v29 = *(_DWORD *)v44 != 0 ? 1 : 4;
            if( v44 )
              ExFreePoolWithTag(v44, 0);
          }
          else
          {
            v29 = *(_DWORD *)v43;
          }
        }
        ObFastDereferenceObject((INT64 *)Process + 151, v20);
        if( v43 )
          ExFreePoolWithTag(v43, 0);
        v62 = 4i64;
        p_SessionId = &v29;
        ProcessHandleCount = ObGetProcessHandleCount((struct _EX_RUNDOWN_REF *)Process, 0i64);
        v64 = 4i64;
        p_ProcessHandleCount = &ProcessHandleCount;
        v40 = *((_QWORD *)Process + 201);
        v40 <<= 12;
        v65 = &v40;
        v41 = *((_QWORD *)Process + 202);
        v41 <<= 12;
        v67 = &v41;
        p_CycleTime = &result.CycleTime;
        ReadOperationCount = result.ReadOperationCount;
        if( HIDWORD(result.ReadOperationCount) )
          ReadOperationCount = -1;
        v66 = 8i64;
        v32 = ReadOperationCount;
        v71 = &v32;
        WriteOperationCount = result.WriteOperationCount;
        if( HIDWORD(result.WriteOperationCount) )
          WriteOperationCount = -1;
        v68 = 8i64;
        v33 = WriteOperationCount;
        v23 = result.ReadTransferCount >> 10;
        v73 = (__int64 *)&v33;
        result.ReadTransferCount = v23;
        v70 = 8i64;
        if( HIDWORD(v23) )
          LODWORD(v23) = -1;
        v75 = &v34;
        v34 = v23;
        result.WriteTransferCount >>= 10;
        WriteTransferCount = result.WriteTransferCount;
        v72 = 4i64;
        v74 = 4i64;
        if( HIDWORD(result.WriteTransferCount) )
          WriteTransferCount = -1;
        v77 = &v35;
        v25 = (unsigned int *)((char *)Process + 1832);
        v76 = 4i64;
        v26 = (unsigned int *)((char *)Process + 1448);
        v79 = v25;
        v81 = v26;
        v27 = -1i64;
        v35 = WriteTransferCount;
        v78 = 4i64;
        v80 = 4i64;
        do
          ++v27;
        while( *((_BYTE *)v26 + v27) );
        v19 = v27 + 1;
      }
      else
      {
        v12 = (void *)*((_QWORD *)Process + 168);
        v46 = -1i64;
        v38 = -1;
        v36 = *((_DWORD *)Process + 336);
        LODWORD(v39) = -1;
        v57 = &v36;
        Processa = 0i64;
        TokenInformation = 0i64;
        P = 0i64;
        IntegritySA = 0i64;
        v58 = 4i64;
        if( PsLookupProcessByProcessId(v12, (PEPROCESS *)&Processa) >= 0 )
        {
          v46 = *((_QWORD *)Processa + 287);
          HalPutDmaAdapter((PADAPTER_OBJECT)Processa);
        }
        v60 = 8i64;
        v59 = &v46;
        SessionId = MmGetSessionId((__int64)Process);
        v13 = 1;
        v62 = 4i64;
        p_SessionId = &SessionId;
        if( (a2 & 1) == 0 )
        {
          v11 = 2;
          v13 = v30;
        }
        v64 = 4i64;
        if( (a2 & 8) != 0 )
          v13 = v11;
        p_ProcessHandleCount = &v30;
        v30 = v13;
        v14 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)Process);
        if( (int)SeQueryInformationToken(v14, TokenElevationType, &TokenInformation) >= 0 )
          v38 = *(_DWORD *)TokenInformation;
        v66 = 4i64;
        v65 = (__int64 *)&v38;
        if( TokenInformation )
          ExFreePoolWithTag(TokenInformation, 0);
        if( (int)SeQueryInformationToken(v14, TokenElevation, &P) >= 0 )
          LODWORD(v39) = *(_DWORD *)P;
        v68 = 4i64;
        v67 = &v39;
        if( P )
          ExFreePoolWithTag(P, 0);
        SeQueryTokenIntegrity(v14, &IntegritySA);
        v15 = *((unsigned __int8 *)IntegritySA.Sid + 1);
        p_CycleTime = IntegritySA.Sid;
        v70 = (unsigned int)(4 * v15 + 8);
        ObFastDereferenceObject((INT64 *)Process + 151, v14);
        p_DestinationString = (struct _UNICODE_STRING *)*((_QWORD *)Process + 184);
        if( !p_DestinationString || !p_DestinationString->Length )
        {
          RtlStringCchPrintfW(pszDest, 0xFui64, (WCHAR *)L"%S");
          RtlInitUnicodeString(&DestinationString, pszDest, v28);
          p_DestinationString = &DestinationString;
        }
        v17 = &EmptyUnicodeString;
        if( p_DestinationString )
          v17 = (__int64 *)p_DestinationString;
        v18 = *(unsigned __int16 *)v17;
        v71 = (int *)v17[1];
        v73 = &EtwpNull;
        v77 = (int *)(a4 + 4);
        v79 = a3 + 4;
        v80 = *a3;
        v81 = a3 + 68;
        v19 = a3[2];
        v72 = v18;
        v74 = 2i64;
        v75 = (int *)a4;
        v76 = 4i64;
        v78 = 4i64;
      }
      v11 = 16;
      v83 = 0;
      v82 = v19;
      return EtwWrite(*(UINT64 *)EtwpPsProvRegHandle, v10, 0i64, v11, &UserData);
  }
  return v9;
}

Referenced by:

EtwpPsProvProcessEnumCallback
EtwpWriteProcessEvent