EtwpSendReplyDataBlock

NTSTATUS __stdcall EtwpSendReplyDataBlock(_ETWP_NOTIFICATION_HEADER *DataBlock){
  _ETHREAD *CurrentThread; 
  void *ReplyObject; 
  unsigned int ReplyIndex; 
  NTSTATUS v5; 
  struct _DMA_ADAPTER *v6; 
  _QWORD *v7; 
  __int64 v8; 
  PADAPTER_OBJECT DmaAdapter; 
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  ReplyObject = DataBlock->ReplyObject;
  ReplyIndex = DataBlock->ReplyIndex;
  --*((_WORD *)CurrentThread + 242);
  DmaAdapter = 0i64;
  v5 = ObReferenceObjectByHandle(ReplyObject, 4u, EtwpRegistrationObjectType, 1, (PVOID *)&DmaAdapter, 0i64);
  if( v5 >= 0 )
  {
    v6 = DmaAdapter;
    if( (DmaAdapter[6].Size & 2) != 0 )
    {
      if( ReplyIndex >= 4 )
      {
        v5 = -1073741811;
      }
      else
      {
        v7 = (_QWORD *)_InterlockedExchange64((volatile __int64 *)&DmaAdapter[3] + ReplyIndex, 0i64);
        if( v7 )
        {
          v8 = v7[4];
          if( (*(_BYTE *)(v8 + 98) & 0x40) != 0 )
            v5 = -1073741055;
          else
            v5 = EtwpQueueReply(*(_ETW_REPLY_QUEUE **)(v8 + 48), DataBlock);
          EtwpReleaseQueueEntry(v7, 2);
        }
        else
        {
          v5 = -1073741811;
        }
        v6 = DmaAdapter;
      }
    }
    else
    {
      v5 = -1073741816;
    }
    HalPutDmaAdapter(v6);
  }
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  return v5;
}

Referenced by:

NtTraceControl