EtwpGetPrivateSessionTraceHandle
INT64 __fastcall EtwpGetPrivateSessionTraceHandle(_DWORD *a1, UINT64 a2, UINT16 *a3){
unsigned int v3;
__int64 CurrentSiloState;
unsigned int v6;
char v7;
INT64 v8;
_ETHREAD *CurrentThread;
_DWORD *v10;
__int64 v11;
UINT16 v12;
unsigned int i;
INT64 v14;
INT64 PidDemuxList;
__int64 *j;
INT64 a2a;
ULONG_PTR BugCheckParameter2;
UINT64 Seed;
UINT16 *v21;
_EPROCESS *Process;
v21 = a3;
v3 = a2;
CurrentSiloState = EtwpGetCurrentSiloState();
v6 = 0;
Process = 0i64;
v7 = 0;
v8 = CurrentSiloState + 4080;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
a2a = v8;
--*((_WORD *)CurrentThread + 242);
BugCheckParameter2 = v8 + 16;
ExAcquirePushLockExclusiveEx(v8 + 16, 0i64);
if( v3 )
{
v10 = a1;
v11 = v3;
do
{
if( PsLookupProcessByProcessId((HANDLE)(unsigned int)*v10, (PEPROCESS *)&Process) )
{
*v10 = 0;
}
else
{
if( (unsigned int)EtwpCheckCurrentUserProcessAccess(Process) )
*v10 = 0;
ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
}
v10 += 2;
--v11;
}
while( v11 );
}
do
LABEL_9:
v12 = RtlRandomEx(&Seed) & 0x7FFF;
while( v12 < 0x40u );
for( i = 0; i < v3; ++i )
{
v14 = (unsigned int)a1[2 * i];
if( (_DWORD)v14 )
{
PidDemuxList = EtwpGetPidDemuxList(v14, a2a);
if( PidDemuxList )
{
for( j = *(__int64 **)(PidDemuxList + 32); j != (__int64 *)(PidDemuxList + 32); j = (__int64 *)*j )
{
if( *((_WORD *)j + 9) == v12 )
goto LABEL_9;
if( *((_WORD *)j + 8) == LOWORD(a1[2 * i + 1]) )
{
if( *((_WORD *)j + 10) != HIWORD(a1[2 * i + 1]) )
break;
*((_WORD *)j + 9) = v12;
v7 = 1;
}
}
}
}
}
ExReleasePushLockEx(BugCheckParameter2, 0i64);
KeLeaveCriticalRegion();
if( v7 )
*v21 = v12;
else
return(unsigned int)-1073741275;
return v6;
}Referenced by:
NtTraceControl