EtwpUpdateProcessTracingCallback
INT64 __fastcall EtwpUpdateProcessTracingCallback(_EPROCESS *Process, VOID *Context){
__int64 v4;
struct _EX_RUNDOWN_REF *v5;
char v6;
unsigned int v7;
__int64 v8;
__int64 *v9;
_KAPC_STATE ApcState;
memset(&ApcState, 0, sizeof(ApcState));
v4 = *((_QWORD *)Process + 170);
if( v4 )
{
v5 = (struct _EX_RUNDOWN_REF *)((char *)Process + 1112);
if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)Process + 139) )
{
KiStackAttachProcess((_KPROCESS *)Process, 0i64, &ApcState);
v6 = *((_BYTE *)Context + 4);
v7 = *(_DWORD *)Context;
if( v6 )
_interlockedbittestandset((volatile signed __int32 *)(v4 + 888), v7);
else
_interlockedbittestandreset((volatile signed __int32 *)(v4 + 888), v7);
v8 = 0i64;
v9 = (__int64 *)*((_QWORD *)Process + 176);
if( v9 )
v8 = *v9;
if( v8 )
{
if( v6 )
_interlockedbittestandset((volatile signed __int32 *)(v8 + 576), v7);
else
_interlockedbittestandreset((volatile signed __int32 *)(v8 + 576), v7);
}
KiUnstackDetachProcess(&ApcState, 0i64);
ExReleaseRundownProtection(v5);
}
}
return 0i64;
}Referenced by:
EtwpUpdatePerProcessTracing