ExpQuerySystemInformation
VOID __stdcall ExpQuerySystemInformation(UINT64 a1, VOID *a2, UINT64 a3, INT64 r9_0, UINT64 Length, UINT64 *a6){
int v7;
size_t v8;
unsigned __int8 v9;
unsigned int v10;
INT64 v11;
__int64 v12;
INT64 v13;
UINT16 v14;
INT64 v15;
_SYSTEM_INFORMATION_CLASS v16;
UINT16 v17;
unsigned int ActiveProcessorCount;
UINT16 ActiveGroupCount;
UINT64 v20;
_KPROCESS *v21;
unsigned __int16 v22;
__int64 v23;
__int64 v24;
_BYTE *v25;
__int64 v26;
UINT64 v27;
__int64 v28;
UINT64 v29;
__int64 v30;
UINT64 v31;
__int64 v32;
__int64 v33;
unsigned __int64 v34;
unsigned __int64 C3Time;
unsigned __int64 v36;
_KPROCESS *v37;
UINT16 v38;
__int64 v39;
__int64 v40;
UINT64 v41;
__int64 v42;
_KPROCESS *CurrentProcess;
unsigned __int16 ProcessPartitionId;
unsigned __int64 v45;
UINT64 v46;
unsigned __int64 v47;
UINT64 v48;
unsigned __int64 v49;
UINT64 v50;
unsigned __int64 v51;
unsigned __int64 C1Time;
unsigned int v53;
unsigned int v54;
_DWORD *v55;
int v56;
unsigned __int64 v57;
unsigned __int64 v58;
unsigned int v59;
VOID **PoolWithTag;
VOID **v61;
__int64 v62;
_KSPIN_LOCK *v63;
_EX_TIMEZONE_STATE *ExTimeZoneState;
unsigned __int64 v65;
char v66;
char *v67;
_ETHREAD *CurrentThread;
NTSTATUS v69;
_CONFIGURATION_INFORMATION *ConfigurationInformation;
INT64 v71;
_RTL_PROCESS_MODULES *v72;
INT64 v73;
__int64 v74;
unsigned int v75;
int v76;
int v77;
UINT64 v78;
unsigned int v79;
int v80;
int v81;
_KPRCB **v82;
__int64 v83;
_KPRCB **v84;
__int64 v85;
unsigned int i;
_DWORD *v87;
_EX_TIMEZONE_STATE *v88;
_EX_TIMEZONE_STATE *v89;
_SYSTEM_PROCESSOR_IDLE_INFORMATION *v90;
__int64 v91;
__int64 v92;
_SYSTEM_PROCESSOR_IDLE_INFORMATION *v93;
int v94;
_KPRCB **v95;
__int64 v96;
__int64 v97;
unsigned int v98;
int v99;
unsigned int v100;
__int16 j;
volatile unsigned __int64 CycleTime;
_QWORD *v103;
size_t v104;
__int64 v105;
unsigned int v106;
__int64 v107;
_DWORD *PoolWithQuotaTag;
int v109;
int v110;
unsigned __int64 IdleTime;
void *v112;
unsigned int v113;
NTSTATUS v114;
UINT64 *v115;
VOID *v116;
unsigned int v117;
__int64 v118;
char v119;
__int16 NestedPageProtectionFlags;
char v121;
INT64 v122;
INT64 v123;
BOOL IsUserCetAllowed;
_KTRANSACTION *v125;
UINT8 IsKTMCommitCoordinator;
int v127;
NTSTATUS v128;
_EPROCESS *v129;
VOID *v130;
VOID *v131;
NTSTATUS v132;
int v133;
__int64 v134;
UINT64 *ReturnSize;
POBJECT_HANDLE_INFORMATION HandleInformation;
INT64 Information;
INT64 v138;
int v139;
int v140;
char v141;
UINT64 InputBufferLength;
VOID *InputBuffer;
UINT64 *v144;
UINT64 SessionId;
unsigned __int16 v146;
unsigned int v147;
unsigned int v148;
_SYSTEM_INFORMATION_CLASS InformationClass;
_LOGICAL_PROCESSOR_RELATIONSHIP RelationshipType;
unsigned int v151;
UINT64 Count;
_LOGICAL_PROCESSOR_RELATIONSHIP v153;
int v154;
UINT64 DataLength;
_QWORD *v156;
_EPROCESS *Process;
PVOID v158;
VOID *Src;
UINT64 *PageList;
__int64 v161;
_HANDLE Handle[2];
VOID *ProcessId[2];
WCHAR *ProcessString;
UINT64 a4;
VOID *v166;
PVOID Object;
__int64 v168;
_GROUP_AFFINITY GroupAffinity;
int v170;
_SYSTEM_PROCESSOR_IDLE_INFORMATION TickInfo[9];
InputBufferLength = (unsigned int)a3;
InputBuffer = a2;
v7 = a1;
InformationClass = (int)a1;
v144 = a6;
v8 = 0;
a4 = 0i64;
Count = 0i64;
v140 = 0;
LODWORD(SessionId) = 0;
v146 = 0;
WORD2(v138) = 0;
GroupAffinity = 0i64;
Process = 0i64;
LODWORD(v138) = 0;
RelationshipType = RelationProcessorCore;
PageList = 0i64;
Src = 0i64;
v153 = RelationProcessorCore;
memset(TickInfo, 0i64, sizeof(TickInfo));
HIDWORD(Information) = 0;
v9 = KeGetCurrentThread()->$87BC921A506A176A34DE473FC146A343::gap0[10];
if( v9 )
{
switch( v7 )
{
case 12:
v11 = 8i64;
goto LABEL_6;
case 35:
case 145:
case 147:
case 149:
case 158:
case 163:
case 169:
case 202:
case 227:
v10 = 1;
v11 = 1i64;
break;
default:
v11 = 4i64;
LABEL_6:
v10 = 1;
break;
}
ProbeForWrite(r9_0, (unsigned int)Length, v11);
if( a6 )
{
v12 = (__int64)a6;
if( (unsigned __int64)a6 >= 0x7FFFFFFF0000i64 )
v12 = 0x7FFFFFFF0000i64;
*(_DWORD *)v12 = *(_DWORD *)v12;
}
}
else
{
v10 = 1;
}
LODWORD(Information) = 0;
RelationshipType = RelationAll;
v13 = 0i64;
v147 = 0;
v14 = 0;
v139 = 0;
WORD2(v138) = 0;
v146 = 0;
v161 = 0i64;
*(_QWORD *)Handle = 0i64;
v168 = 0i64;
v15 = 9i64;
v148 = 9;
v153 = 9;
v16 = InformationClass;
switch( InformationClass )
{
case SystemPerformanceInformation:
case SystemExceptionInformation:
case SystemContextSwitchInformation:
case SystemLostDelayedWriteInformation:
v139 = 0xFFFF;
WORD2(v138) = -1;
v17 = -1;
goto LABEL_15;
case SystemProcessorPerformanceInformation:
case SystemInterruptInformation:
case SystemProcessorIdleInformation:
case SystemProcessorPowerInformation:
case SystemLogicalProcessorInformation:
case SystemProcessorIdleCycleTimeInformation:
case SystemProcessorPerformanceDistribution:
case SystemProcessorCycleTimeInformation:
case SystemProcessorPerformanceInformationEx:
case SystemProcessorCycleStatsInformation:
if( (unsigned int)InputBufferLength < 2 )
return;
v139 = *(unsigned __int16 *)InputBuffer;
WORD2(v138) = v139;
ActiveGroupCount = KeQueryActiveGroupCount();
v17 = v139;
if( (unsigned __int16)v139 >= ActiveGroupCount )
return;
LABEL_15:
ActiveProcessorCount = KeQueryActiveProcessorCountEx(v17);
v13 = ActiveProcessorCount;
v147 = ActiveProcessorCount;
v14 = v139;
v15 = v148;
v16 = InformationClass;
LABEL_34:
v20 = (unsigned int)InputBufferLength;
goto LABEL_35;
case SystemWatchdogTimerInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 4 )
return;
v15 = *(unsigned int *)InputBuffer;
v153 = *(_DWORD *)InputBuffer;
goto LABEL_35;
case SystemLogicalProcessorAndGroupInformation:
v20 = (unsigned int)InputBufferLength;
if( (unsigned int)InputBufferLength < 4 )
return;
RelationshipType = *(_DWORD *)InputBuffer;
goto LABEL_35;
case SystemNodeDistanceInformation:
v20 = (unsigned int)InputBufferLength;
if( (unsigned int)InputBufferLength >= 2 )
{
v146 = *(_WORD *)InputBuffer;
if( v146 < (unsigned __int16)KeNumberNodes )
goto LABEL_35;
}
return;
case SystemIsolatedUserModeInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength )
{
if( (_DWORD)InputBufferLength != 8 )
return;
v161 = *(_QWORD *)InputBuffer;
}
else
{
v161 = 0i64;
}
LABEL_35:
switch( v16 )
{
case SystemBasicInformation:
case SystemNativeBasicInformation:
if( (_DWORD)Length == 64 )
{
ExpGetSystemBasicInformation(r9_0, v20, v15, v13);
goto LABEL_597;
}
if( a6 )
*(_DWORD *)a6 = 64;
return;
case SystemProcessorInformation:
if( (unsigned int)Length >= 0xC )
{
ExpGetSystemProcessorInformation(r9_0, v20, v15, v13);
LODWORD(Information) = 12;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 12;
return;
case SystemPerformanceInformation:
if( (unsigned int)Length >= 0x138 )
{
v10 = 344;
if( (unsigned int)Length <= 0x158 )
v10 = Length;
ExpQuerySystemPerformanceInformation(
(unsigned int)v13,
(VOID *)r9_0,
v10,
v13,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
goto LABEL_256;
}
if( a6 )
*(_DWORD *)a6 = 344;
return;
case SystemTimeOfDayInformation:
if( (unsigned int)Length <= 0x30 )
{
KeQueryBootTimeValues(
(_LARGE_INTEGER *)&TickInfo[0].C1Time,
(_LARGE_INTEGER *)TickInfo,
(UINT64 *)&TickInfo[0].C1Transitions);
ExTimeZoneState = PsGetCurrentServerSiloGlobals(v63)->ExTimeZoneState;
TickInfo[0].C2Time = ExTimeZoneState->TimeZoneBias.QuadPart;
LODWORD(TickInfo[0].C3Time) = ExTimeZoneState->CurrentTimeZoneId;
*(_QWORD *)&TickInfo[0].C3Transitions = KUSER_SHARED_DATA.InterruptTimeBias;
memmove((VOID *)r9_0, TickInfo, Length);
goto LABEL_119;
}
if( a6 )
*(_DWORD *)a6 = 48;
return;
case SystemProcessInformation:
case SystemExtendedProcessInformation:
case SystemFullProcessInformation:
ExpGetProcessInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information, 0i64, v16);
goto LABEL_598;
case SystemDeviceInformation:
if( (_DWORD)Length == 24 )
{
ConfigurationInformation = IoGetConfigurationInformation();
*(_DWORD *)r9_0 = ConfigurationInformation->DiskCount;
*(_DWORD *)(r9_0 + 4) = ConfigurationInformation->FloppyCount;
*(_DWORD *)(r9_0 + 8) = ConfigurationInformation->CdRomCount;
*(_DWORD *)(r9_0 + 12) = ConfigurationInformation->TapeCount;
*(_DWORD *)(r9_0 + 16) = ConfigurationInformation->SerialCount;
*(_DWORD *)(r9_0 + 20) = ConfigurationInformation->ParallelCount;
goto LABEL_67;
}
if( a6 )
*(_DWORD *)a6 = 24;
return;
case SystemProcessorPerformanceInformation:
case SystemProcessorPerformanceInformationEx:
v53 = 48;
if( v16 != SystemProcessorPerformanceInformation )
v53 = 72;
if( (_DWORD)Length && !((unsigned int)Length % v53) )
{
v140 = 0;
v54 = 0;
while( 1 )
{
v148 = v54;
if( v54 >= (unsigned int)v13 )
break;
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)v54;
v55 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138));
v56 = v140;
if( (unsigned int)Length < v53 + v140 )
goto LABEL_91;
v140 += v53;
PoGetIdleTimes((PROCESSOR_NUMBER *)&v138, 0i64, (_SYSTEM_PROCESSOR_TICK_INFORMATION *)TickInfo);
*(_QWORD *)(r9_0 + 16) = (unsigned int)KeMaximumIncrement * (unsigned __int64)(unsigned int)v55[8098];
*(_QWORD *)(r9_0 + 8) = (unsigned int)KeMaximumIncrement * (unsigned __int64)HIDWORD(TickInfo[0].IdleTime);
*(_QWORD *)(r9_0 + 24) = (unsigned int)KeMaximumIncrement * (unsigned __int64)(unsigned int)v55[8099];
*(_QWORD *)(r9_0 + 32) = (unsigned int)KeMaximumIncrement * (unsigned __int64)(unsigned int)v55[8100];
*(_QWORD *)r9_0 = (unsigned int)KeMaximumIncrement * (unsigned __int64)LODWORD(TickInfo[0].IdleTime);
*(_DWORD *)(r9_0 + 40) = v55[8096];
if( InformationClass == SystemProcessorPerformanceInformationEx )
{
*(_QWORD *)(r9_0 + 48) = (unsigned int)KeMaximumIncrement * (unsigned __int64)(unsigned int)v55[8107];
*(_DWORD *)(r9_0 + 44) = 0;
*(_QWORD *)(r9_0 + 56) = 0i64;
*(_QWORD *)(r9_0 + 64) = 0i64;
}
r9_0 += v53;
v54 = v148 + 1;
LODWORD(v13) = v147;
v14 = v139;
}
v56 = v140;
LABEL_91:
LODWORD(Information) = v56;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = v13 * v53;
break;
case SystemFlagsInformation:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)r9_0 = NtGlobalFlag;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemModuleInformation:
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
KeEnterCriticalRegion();
ExAcquireResourceExclusiveLite((UINT64)&PsLoadedModuleResource, 1, v71);
ExpQueryModuleInformation(v72, r9_0, (UINT64 *)(unsigned int)Length);
goto LABEL_164;
case SystemLocksInformation:
if( (unsigned int)Length < 0x38 )
{
if( a6 )
*(_DWORD *)a6 = 56;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExpGetLockInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemStackTraceInformation:
if( (unsigned int)Length >= 0x128 )
goto LABEL_598;
if( a6 )
*(_DWORD *)a6 = 296;
return;
case SystemPagedPoolInformation:
case SystemNonPagedPoolInformation:
case SystemVdmInstemulInformation:
case SystemHotpatchInformation:
case SystemVirtualAddressInformation:
goto LABEL_598;
case SystemHandleInformation:
if( (unsigned int)Length >= 0x20 )
{
if( (r9_0 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExpGetHandleInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 32;
}
return;
case SystemObjectInformation:
if( (unsigned int)Length < 0x40 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExpGetObjectInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemPageFileInformation:
case SystemPageFileInformationEx:
v75 = 32;
if( v16 != SystemPageFileInformation )
v75 = 40;
LODWORD(Information) = v75;
if( (unsigned int)Length >= v75 )
{
LODWORD(Information) = 0;
LOBYTE(v8) = v16 == SystemPageFileInformationEx;
MmGetPageFileInformation((VOID *)0x28, r9_0, (unsigned int)Length, (UINT64 *)v8, (UINT64 *)&Information);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = v75;
return;
case SystemFileCacheInformation:
case SystemFileCacheInformationEx:
case SystemPagedPoolInformationEx:
case SystemSystemPtesInformationEx:
if( (unsigned int)Length < 0x40 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
v76 = 2;
if( v16 == SystemPagedPoolInformationEx )
{
v77 = 3;
}
else
{
if( v16 == SystemSystemPtesInformationEx )
v76 = 4;
v77 = v76;
}
MmQuerySystemWorkingSetInformation(v77, &TickInfo[0].IdleTime);
*(_QWORD *)r9_0 = TickInfo[0].IdleTime;
*(_QWORD *)(r9_0 + 8) = TickInfo[0].C1Time;
*(_DWORD *)(r9_0 + 16) = TickInfo[0].C2Time;
*(_QWORD *)(r9_0 + 24) = TickInfo[0].C3Time;
*(_QWORD *)(r9_0 + 32) = *(_QWORD *)&TickInfo[0].C1Transitions;
*(_QWORD *)(r9_0 + 40) = *(_QWORD *)&TickInfo[0].C3Transitions;
*(_QWORD *)(r9_0 + 48) = TickInfo[1].IdleTime;
*(_QWORD *)(r9_0 + 56) = TickInfo[1].C1Time;
LODWORD(Information) = 64;
goto LABEL_598;
case SystemPoolTagInformation:
if( (unsigned int)Length >= 0x30 )
{
ExGetPoolTagInfo((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 48;
return;
case SystemInterruptInformation:
LODWORD(Information) = 24 * v13;
if( (unsigned int)Length >= 24 * (int)v13 )
{
for( i = 0; i < (unsigned int)v13; ++i )
{
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)i;
v87 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138));
*(_DWORD *)r9_0 = v87[2895];
*(_DWORD *)(r9_0 + 4) = v87[3127];
*(_DWORD *)(r9_0 + 8) = v87[3143];
*(_DWORD *)(r9_0 + 12) = KeTimeIncrement;
*(_DWORD *)(r9_0 + 16) = 0;
*(_DWORD *)(r9_0 + 20) = 0;
r9_0 += 24i64;
LODWORD(v13) = v147;
v14 = v139;
}
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 24 * v13;
return;
case SystemDpcBehaviorInformation:
if( (_DWORD)Length == 20 )
{
*(_DWORD *)(r9_0 + 4) = KiMaximumDpcQueueDepth;
*(_DWORD *)(r9_0 + 8) = KiMinimumDpcRate;
*(_DWORD *)(r9_0 + 12) = KiAdjustDpcThreshold;
*(_DWORD *)(r9_0 + 16) = KiIdealDpcRate;
goto LABEL_276;
}
if( a6 )
*(_DWORD *)a6 = 20;
return;
case SystemTimeAdjustmentInformation:
if( (_DWORD)Length != 12 && (_DWORD)Length != 24 )
{
if( a6 )
*(_DWORD *)a6 = 12;
return;
}
ExAcquireTimeRefreshLock(1u);
v65 = KeTimeAdjustmentFrequency;
v66 = KeTimeSynchronization;
ExReleaseTimeRefreshLock();
if( (_DWORD)Length == 24 )
{
*(_QWORD *)r9_0 = v65;
*(_QWORD *)(r9_0 + 8) = KUSER_SHARED_DATA.QpcFrequency;
*(_BYTE *)(r9_0 + 16) = v66;
}
else
{
*(_DWORD *)r9_0 = KUSER_SHARED_DATA.QpcFrequency * (unsigned __int64)(unsigned int)KeMaximumIncrement / v65;
*(_DWORD *)(r9_0 + 4) = KeMaximumIncrement;
*(_BYTE *)(r9_0 + 8) = v66;
}
LABEL_119:
LODWORD(Information) = Length;
goto LABEL_598;
case SystemPerformanceTraceInformation:
EtwQueryPerformanceTraceInformation((VOID *)r9_0, (unsigned int)Length, v9, (UINT64 *)&Information);
goto LABEL_598;
case SystemExceptionInformation:
if( (unsigned int)Length < 0x10 )
{
if( a6 )
*(_DWORD *)a6 = 16;
return;
}
LODWORD(Information) = 16;
v80 = 0;
v81 = 0;
if( (_DWORD)v13 )
{
v82 = &KiProcessorBlock;
v83 = (unsigned int)v13;
do
{
v80 += (*v82)->KeAlignmentFixupCount;
v81 += (*v82++)->KeExceptionDispatchCount;
--v83;
}
while( v83 );
}
*(_DWORD *)r9_0 = v80;
*(_DWORD *)(r9_0 + 4) = v81;
*(_DWORD *)(r9_0 + 8) = 0;
*(_DWORD *)(r9_0 + 12) = 0;
goto LABEL_598;
case SystemKernelDebuggerInformation:
if( (unsigned int)Length >= 2 )
{
*(_BYTE *)r9_0 = (_BYTE)KdDebuggerEnabled;
*(_BYTE *)(r9_0 + 1) = (_BYTE)KdDebuggerNotPresent;
LODWORD(Information) = 2;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 2;
return;
case SystemContextSwitchInformation:
if( (unsigned int)Length < 0x30 )
{
if( a6 )
*(_DWORD *)a6 = 48;
return;
}
if( (_DWORD)v13 )
{
v84 = &KiProcessorBlock;
v85 = (unsigned int)v13;
do
{
v8 += (*v84++)->KeContextSwitches;
--v85;
}
while( v85 );
}
*(_DWORD *)r9_0 = v8;
*(_DWORD *)(r9_0 + 4) = KeThreadSwitchCounters;
*(_DWORD *)(r9_0 + 8) = dword_140C319C8;
*(_DWORD *)(r9_0 + 12) = dword_140C319C4;
*(_DWORD *)(r9_0 + 16) = dword_140C319CC;
*(_DWORD *)(r9_0 + 20) = dword_140C319D0;
*(_DWORD *)(r9_0 + 24) = dword_140C319D8;
*(_DWORD *)(r9_0 + 28) = dword_140C319D4;
*(_DWORD *)(r9_0 + 32) = dword_140C319DC;
*(_DWORD *)(r9_0 + 36) = dword_140C319E0;
*(_DWORD *)(r9_0 + 40) = dword_140C319E4;
*(_DWORD *)(r9_0 + 44) = dword_140C319E8;
LODWORD(Information) = 48;
goto LABEL_598;
case SystemRegistryQuotaInformation:
if( (unsigned int)Length >= 0x10 )
{
CmQueryRegistryQuotaInformation();
LODWORD(Information) = 16;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 16;
return;
case SystemProcessorIdleInformation:
LODWORD(Information) = 48 * v13;
if( (unsigned int)Length >= 48 * (int)v13 )
{
while( v8 < (unsigned int)v13 )
{
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)v8;
PoGetIdleTimes((PROCESSOR_NUMBER *)&v138, TickInfo, 0i64);
*(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)r9_0 = TickInfo[0];
r9_0 += 48i64;
++v8;
LODWORD(v13) = v147;
v14 = v139;
}
}
goto LABEL_598;
case SystemLegacyDriverInformation:
if( (unsigned int)Length >= 0x18 )
{
LODWORD(Information) = Length;
ExpQueryLegacyDriverInformation(r9_0, (unsigned int *)&Information, v15, v13);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 24;
return;
case SystemCurrentTimeZoneInformation:
if( (unsigned int)Length >= 0xAC )
{
v88 = PsGetCurrentServerSiloGlobals((_KSPIN_LOCK *)0x140000000i64)->ExTimeZoneState;
ExAcquireTimeRefreshLock(1u);
*(_OWORD *)&TickInfo[0].IdleTime = *(_OWORD *)&v88->TimeZoneInformation.tzi.Bias;
*(_OWORD *)&TickInfo[0].C2Time = *(_OWORD *)&v88->TimeZoneInformation.tzi.StandardName[6];
*(_OWORD *)&TickInfo[0].C1Transitions = *(_OWORD *)&v88->TimeZoneInformation.tzi.StandardName[14];
TickInfo[1] = *(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)&v88->TimeZoneInformation.tzi.StandardName[22];
TickInfo[2] = *(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)&v88->TimeZoneInformation.tzi.DaylightName[4];
*(_OWORD *)&TickInfo[3].IdleTime = *(_OWORD *)&v88->TimeZoneInformation.tzi.DaylightName[28];
TickInfo[3].C2Time = *(_QWORD *)&v88->TimeZoneInformation.tzi.DaylightStart.Minute;
LODWORD(TickInfo[3].C3Time) = v88->TimeZoneInformation.tzi.DaylightBias;
ExReleaseTimeRefreshLock();
*(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)r9_0 = TickInfo[0];
*(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)(r9_0 + 48) = TickInfo[1];
*(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)(r9_0 + 96) = TickInfo[2];
*(_OWORD *)(r9_0 + 144) = *(_OWORD *)&TickInfo[3].IdleTime;
*(_QWORD *)(r9_0 + 160) = TickInfo[3].C2Time;
*(_DWORD *)(r9_0 + 168) = TickInfo[3].C3Time;
LODWORD(Information) = 172;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 172;
return;
case SystemLookasideInformation:
ExpGetLookasideInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemRangeStartInformation:
if( (_DWORD)Length == 8 )
{
*(_QWORD *)r9_0 = 0xFFFF800000000000ui64;
goto LABEL_114;
}
if( a6 )
*(_DWORD *)a6 = 8;
return;
case SystemVerifierInformation:
if( (unsigned int)Length >= 0x90 )
{
VfGetVerifierInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information, 0i64);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 144;
return;
case SystemSessionProcessInformation:
if( (unsigned int)Length >= 0x10 )
{
LODWORD(SessionId) = *(_DWORD *)r9_0;
v166 = *(VOID **)(r9_0 + 8);
v151 = *(_DWORD *)(r9_0 + 4);
ProbeForWrite((UINT64)v166, v151, 4i64);
ExpGetProcessInformation(v166, v151, (UINT64 *)&Information, &SessionId, SystemProcessInformation);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 16;
return;
case SystemNumaProcessorMap:
ExpQueryNumaProcessorMap((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemPrefetcherInformation:
PfSnQueryPrefetcherInformation(
(VOID *)0x140000000i64,
(VOID *)r9_0,
(unsigned int)Length,
v9,
(UINT64 *)&Information);
goto LABEL_598;
case SystemRecommendedSharedDataAlignment:
if( (unsigned int)Length >= 4 )
{
KeGetRecommendedSharedDataAlignment();
*(_DWORD *)r9_0 = v94;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemComPlusPackage:
if( (_DWORD)Length == 4 )
{
if( KUSER_SHARED_DATA.ComPlusPackage != -1 || ExpReadComPlusPackage() >= 0 )
{
*(_DWORD *)r9_0 = KUSER_SHARED_DATA.ComPlusPackage;
LODWORD(Information) = 4;
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 4;
}
return;
case SystemNumaAvailableMemory:
ExpQueryNumaAvailableMemory((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemProcessorPowerInformation:
LODWORD(Information) = 80 * v13;
if( (unsigned int)Length >= 80 * (int)v13 )
{
while( v8 < (unsigned int)v13 )
{
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)v8;
v62 = (__int64)*(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138));
PoGetPerfStateAndParkingInfo((PPROCESSOR_NUMBER)&v138, (UINT64)TickInfo, 0i64, &a4);
*(_OWORD *)r9_0 = 0i64;
*(_OWORD *)(r9_0 + 16) = 0i64;
*(_OWORD *)(r9_0 + 32) = 0i64;
*(_OWORD *)(r9_0 + 48) = 0i64;
*(_OWORD *)(r9_0 + 64) = 0i64;
*(_QWORD *)(r9_0 + 40) = (unsigned int)KeMaximumIncrement
* (unsigned __int64)(unsigned int)(*(_DWORD *)(v62 + 32388)
+ *(_DWORD *)(v62 + 32392));
*(_QWORD *)(r9_0 + 48) = (unsigned int)KeMaximumIncrement
* (unsigned __int64)*(unsigned int *)(*(_QWORD *)(v62 + 24) + 652i64);
if( BYTE4(TickInfo[0].C3Time) )
{
*(_BYTE *)r9_0 = TickInfo[0].C1Time;
*(_BYTE *)(r9_0 + 7) = BYTE4(TickInfo[0].C1Time);
*(_BYTE *)(r9_0 + 8) = TickInfo[0].C2Time;
*(_DWORD *)(r9_0 + 12) = 1;
}
*(_QWORD *)(r9_0 + 72) = a4;
r9_0 += 80i64;
v156 = (_QWORD *)r9_0;
++v8;
LODWORD(v13) = v147;
v14 = v139;
}
}
goto LABEL_598;
case SystemEmulationBasicInformation:
if( (_DWORD)Length != 64 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
ExpGetSystemEmulationBasicInformation(r9_0, v20, v15, v13);
LABEL_597:
LODWORD(Information) = 64;
goto LABEL_598;
case SystemEmulationProcessorInformation:
if( (unsigned int)Length >= 0xC )
{
ExpGetSystemEmulationProcessorInformation(r9_0);
LODWORD(Information) = 12;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 12;
return;
case SystemExtendedHandleInformation:
if( (unsigned int)Length >= 0x38 )
{
if( (r9_0 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExpGetHandleInformationEx((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 56;
}
return;
case SystemLostDelayedWriteInformation:
if( (unsigned int)Length < 4 )
{
if( a6 )
*(_DWORD *)a6 = 4;
return;
}
if( (_DWORD)v13 )
{
v95 = &KiProcessorBlock;
v96 = (unsigned int)v13;
do
{
v8 += (*v95++)->CcLostDelayedWrites;
--v96;
}
while( v96 );
}
*(_DWORD *)r9_0 = v8;
goto LABEL_157;
case SystemBigPoolInformation:
if( (unsigned int)Length < 0x20 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExGetBigPoolInfo((PVOID)r9_0, (unsigned int)Length, 1ui64, (UINT64 *)&Information);
goto LABEL_598;
case SystemSessionPoolTagInformation:
if( (unsigned int)Length < 0x10 )
{
if( a6 )
*(_DWORD *)a6 = 16;
return;
}
LODWORD(SessionId) = *(_DWORD *)r9_0;
v166 = *(VOID **)(r9_0 + 8);
v78 = *(unsigned int *)(r9_0 + 4);
v151 = *(_DWORD *)(r9_0 + 4);
if( ((unsigned __int8)v166 & 7) != 0 )
return;
ExGetSessionPoolTagInformation(v166, v78, (UINT64 *)&Information, &SessionId);
goto LABEL_598;
case SystemSessionMappedViewInformation:
if( (unsigned int)Length < 0x20 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
LODWORD(SessionId) = *(_DWORD *)(r9_0 + 8);
if( (r9_0 & 7) != 0 )
return;
MmGetSessionMappedViewInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information, &SessionId);
goto LABEL_598;
case SystemObjectSecurityMode:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)r9_0 = ObpObjectSecurityMode;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemWatchdogTimerInformation:
if( (_DWORD)Length != 8 )
return;
v97 = (unsigned int)(v15 - 7);
if( (_DWORD)v97 )
{
if( (_DWORD)v97 != 1 )
return;
*(_DWORD *)r9_0 = 8;
*(_DWORD *)(r9_0 + 4) = ((unsigned __int8(__fastcall *)(unsigned __int64, UINT64, __int64, INT64))off_140C008D0[0])(
0x140000000ui64,
v20,
v97,
v13);
}
else
{
*(_DWORD *)r9_0 = 7;
LOBYTE(v8) = off_140C008D8[0] != (__int64(__fastcall *)())xKdEnumerateDebuggingDevices;
*(_DWORD *)(r9_0 + 4) = v8;
}
goto LABEL_114;
case SystemLogicalProcessorInformation:
HIDWORD(Information) = KeBuildLogicalProcessorSystemInformation(
v14,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information);
goto LABEL_598;
case SystemFirmwareTableInformation:
ExpGetSystemFirmwareTableInformation((PVOID)r9_0, v9, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemModuleInformationEx:
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
if( SeSinglePrivilegeCheck(*(_QWORD *)&SeLoadDriverPrivilege, v9) )
v10 = 0;
KeEnterCriticalRegion();
ExAcquireResourceExclusiveLite((UINT64)&PsLoadedModuleResource, 1, v73);
ExpQueryModuleInformationEx(v74, (_WORD *)r9_0, Length, v10, (unsigned int *)&Information);
LABEL_164:
ExReleaseResourceLite(&PsLoadedModuleResource);
KeLeaveCriticalRegion();
goto LABEL_598;
case SystemSuperfetchInformation:
PfQuerySuperfetchInformation((VOID *)0x140000000i64, r9_0, Length, (UINT64 *)v9);
goto LABEL_598;
case SystemMemoryListInformation:
MmQueryMemoryListInformation((VOID *)0xFFFFFFFFFFFFFFFFi64, r9_0, (UINT64 *)(unsigned int)Length);
goto LABEL_598;
case SystemProcessorIdleCycleTimeInformation:
LODWORD(Information) = 8 * v13;
if( (unsigned int)Length >= 8 )
{
v100 = (unsigned int)Length >> 3;
if( (unsigned int)Length >= 8 * (int)v13 )
v100 = v13;
v156 = (_QWORD *)r9_0;
KeFlushProcessWriteBuffers(1u);
for( j = v139; ; j = WORD2(v138) )
{
v140 = v8;
if( v8 >= v100 )
break;
LOWORD(v138) = j;
WORD1(v138) = (unsigned __int8)v8;
CycleTime = (*(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138)))->IdleThread->Tcb.CycleTime;
v103 = v156;
*v156 = CycleTime;
v156 = v103 + 1;
v8 = v140 + 1;
}
}
goto LABEL_598;
case SystemRefTraceInformation:
ObQueryRefTraceInformation(
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information,
v13,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
goto LABEL_598;
case SystemSpecialPoolInformation:
LODWORD(Information) = 8;
if( (_DWORD)Length == 8 )
{
*(_DWORD *)r9_0 = MmSpecialPoolTag;
LOBYTE(v8) = MmSpecialPoolCatchOverruns != 0;
*(_DWORD *)(r9_0 + 4) = v8;
}
goto LABEL_598;
case SystemProcessIdInformation:
LODWORD(Information) = 24;
if( (_DWORD)Length != 24 )
goto LABEL_598;
*(_OWORD *)ProcessId = *(_OWORD *)r9_0;
ProcessString = *(WCHAR **)(r9_0 + 16);
if( LOWORD(ProcessId[1]) || (BYTE2(ProcessId[1]) & 1) != 0 )
return;
if( v9 && WORD1(ProcessId[1]) )
{
if( ((unsigned __int8)ProcessString & 1) != 0 )
ExRaiseDatatypeMisalignment();
v67 = (char *)ProcessString + WORD1(ProcessId[1]);
if( (unsigned __int64)v67 > 0x7FFFFFFF0000i64 || v67 < (char *)ProcessString )
MEMORY[0x7FFFFFFF0000] = 0;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
LODWORD(DataLength) = WORD1(ProcessId[1]);
KeEnterCriticalRegionThread(&CurrentThread->Tcb);
if( PsLookupProcessByProcessId(ProcessId[0], &Process) < 0 )
{
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
return;
}
v69 = PsQueryFullProcessImageName(Process, (_UNICODE_STRING *)(r9_0 + 8), ProcessString, &DataLength);
ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
if( v69 == -1073741820 )
*(_WORD *)(r9_0 + 10) = DataLength;
goto LABEL_598;
case SystemBootEnvironmentInformation:
LODWORD(Information) = 32;
if( (unsigned int)Length < 0x14 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
*(_OWORD *)r9_0 = *(&ExBootDevicesRemovedEvent + 68);
*(_DWORD *)(r9_0 + 16) = *(&ExBootDevicesRemovedEvent + 276);
if( (unsigned int)Length < (unsigned int)Information )
LABEL_276:
LODWORD(Information) = 20;
else
*(_QWORD *)(r9_0 + 24) = *(&ExBootDevicesRemovedEvent + 139);
goto LABEL_598;
case SystemHypervisorInformation:
HvlQueryEnlightenmentInfo((VOID *)r9_0, (unsigned int)Length, v9, (UINT64 *)&Information);
goto LABEL_598;
case SystemVerifierInformationEx:
if( (_DWORD)Length != 40 )
{
if( a6 )
*(_DWORD *)a6 = 40;
return;
}
if( (int)VfGetVerifierInformationEx(r9_0) >= 0 )
v8 = 40;
LODWORD(Information) = v8;
goto LABEL_598;
case SystemCoverageInformation:
if( !v9 || !SeSinglePrivilegeCheck(*(_QWORD *)&SeDebugPrivilege, v9) )
return;
if( (unsigned int)Length >= 0x40 )
{
ExpCovQueryInformation(r9_0, Length, (unsigned int *)&Information);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 64;
return;
case SystemSystemPartitionInformation:
IoQuerySystemDeviceName(
SystemSystemPartitionInformation,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
goto LABEL_598;
case SystemSystemDiskInformation:
IoQuerySystemDeviceName(
SystemSystemDiskInformation,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
goto LABEL_598;
case SystemProcessorPerformanceDistribution:
GroupAffinity.Group = v14;
LODWORD(v57) = KeQueryGroupAffinity(v14);
GroupAffinity.Mask = v57;
v58 = (0x101010101010101i64
* ((((v57 - ((v57 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ (((v57 - ((v57 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
+ ((((v57 - ((v57 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ (((v57 - ((v57 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 56;
if( PpmCapturePerformanceDistribution(
0i64,
0i64,
(unsigned int)v58,
&GroupAffinity,
(UINT64 *)((char *)&InputBufferLength + 4)) != -1073741820 )
goto LABEL_598;
v59 = HIDWORD(InputBufferLength);
if( HIDWORD(InputBufferLength) > (unsigned int)Length )
goto LABEL_96;
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, HIDWORD(InputBufferLength), 1951223888i64);
v61 = PoolWithTag;
InputBuffer = PoolWithTag;
if( PoolWithTag )
{
memset(PoolWithTag, 0i64, HIDWORD(InputBufferLength));
if( PpmCapturePerformanceDistribution(
v61,
HIDWORD(InputBufferLength),
(unsigned int)v58,
&GroupAffinity,
(UINT64 *)&Information) >= 0 )
memmove((VOID *)r9_0, v61, Information);
ExFreePoolWithTag(v61, 0x744D5050u);
}
goto LABEL_598;
case SystemNumaProximityNodeInformation:
ExpQueryNumaProximityNode((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemDynamicTimeZoneInformation:
if( (unsigned int)Length >= 0x1B0 )
{
v89 = PsGetCurrentServerSiloGlobals((_KSPIN_LOCK *)0x140000000i64)->ExTimeZoneState;
ExAcquireTimeRefreshLock(1u);
v90 = TickInfo;
v91 = 3i64;
v92 = 3i64;
do
{
*(_OWORD *)&v90->IdleTime = *(_OWORD *)&v89->TimeZoneInformation.tzi.Bias;
*(_OWORD *)&v90->C2Time = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[6];
*(_OWORD *)&v90->C1Transitions = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[14];
*(_OWORD *)&v90[1].IdleTime = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[22];
*(_OWORD *)&v90[1].C2Time = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[30];
*(_OWORD *)&v90[1].C1Transitions = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardStart.Milliseconds;
*(_OWORD *)&v90[2].IdleTime = *(_OWORD *)&v89->TimeZoneInformation.tzi.DaylightName[4];
v90 = (_SYSTEM_PROCESSOR_IDLE_INFORMATION *)((char *)v90 + 128);
*(_OWORD *)&v90[-1].C1Transitions = *(_OWORD *)&v89->TimeZoneInformation.tzi.DaylightName[12];
v89 = (_EX_TIMEZONE_STATE *)((char *)v89 + 128);
--v92;
}
while( v92 );
*(_OWORD *)&v90->IdleTime = *(_OWORD *)&v89->TimeZoneInformation.tzi.Bias;
*(_OWORD *)&v90->C2Time = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[6];
*(_OWORD *)&v90->C1Transitions = *(_OWORD *)&v89->TimeZoneInformation.tzi.StandardName[14];
ExReleaseTimeRefreshLock();
v93 = TickInfo;
do
{
*(_OWORD *)r9_0 = *(_OWORD *)&v93->IdleTime;
*(_OWORD *)(r9_0 + 16) = *(_OWORD *)&v93->C2Time;
*(_OWORD *)(r9_0 + 32) = *(_OWORD *)&v93->C1Transitions;
*(_OWORD *)(r9_0 + 48) = *(_OWORD *)&v93[1].IdleTime;
*(_OWORD *)(r9_0 + 64) = *(_OWORD *)&v93[1].C2Time;
*(_OWORD *)(r9_0 + 80) = *(_OWORD *)&v93[1].C1Transitions;
*(_OWORD *)(r9_0 + 96) = *(_OWORD *)&v93[2].IdleTime;
r9_0 += 128i64;
*(_OWORD *)(r9_0 - 16) = *(_OWORD *)&v93[2].C2Time;
v93 = (_SYSTEM_PROCESSOR_IDLE_INFORMATION *)((char *)v93 + 128);
--v91;
}
while( v91 );
*(_OWORD *)r9_0 = *(_OWORD *)&v93->IdleTime;
*(_OWORD *)(r9_0 + 16) = *(_OWORD *)&v93->C2Time;
*(_OWORD *)(r9_0 + 32) = *(_OWORD *)&v93->C1Transitions;
LODWORD(Information) = 432;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 432;
return;
case SystemCodeIntegrityInformation:
SeCodeIntegrityQueryInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemProcessorBrandString:
if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
23i64,
0i64,
0i64,
(char *)&InputBufferLength + 4) != -1073741820 )
goto LABEL_598;
v107 = HIDWORD(InputBufferLength);
if( (unsigned int)Length < HIDWORD(InputBufferLength) || !r9_0 )
{
LODWORD(Information) = HIDWORD(InputBufferLength);
goto LABEL_598;
}
if( v9 )
{
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
InputBuffer = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
v107 = HIDWORD(InputBufferLength);
}
else
{
PoolWithQuotaTag = (_DWORD *)r9_0;
InputBuffer = (VOID *)r9_0;
}
v109 = ((__int64(__fastcall *)(__int64, __int64, _DWORD *, INT64 *))off_140C00A68[0])(
23i64,
v107,
PoolWithQuotaTag,
&Information);
if( !v9 )
goto LABEL_598;
if( v109 < 0 )
goto LABEL_419;
goto LABEL_418;
case SystemLogicalProcessorAndGroupInformation:
LODWORD(Information) = Length;
HIDWORD(Information) = KeQueryLogicalProcessorRelationship(
0i64,
RelationshipType,
(_SYSTEM_LOGICAL_PROCESSOR_INFORMATION_EX *)r9_0,
(UINT64 *)&Information);
goto LABEL_598;
case SystemProcessorCycleTimeInformation:
LODWORD(Information) = 8 * v13;
if( (unsigned int)Length >= 8 )
{
v106 = (unsigned int)Length >> 3;
if( (unsigned int)Length >= 8 * (int)v13 )
v106 = v13;
while( v8 < v106 )
{
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)v8;
*(_QWORD *)r9_0 = (*(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138)))->CycleTime;
r9_0 += 8i64;
v156 = (_QWORD *)r9_0;
++v8;
v14 = v139;
}
}
goto LABEL_598;
case SystemStoreInformation:
SmQueryStoreInformation((PVOID)0x140000000i64, r9_0, Length, (UINT64 *)v9);
goto LABEL_598;
case SystemVhdBootInformation:
IoQueryVhdBootInformation((VOID *)0x140000000i64, (VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemCpuQuotaInformation:
PsQueryCpuQuotaInformation((VOID *)r9_0, (unsigned int)Length, v9, (UINT64 *)&Information);
goto LABEL_598;
case SystemErrorPortTimeouts:
if( !(_DWORD)v20 )
{
LODWORD(Information) = 8;
if( (unsigned int)Length >= 8 )
{
*(_DWORD *)r9_0 = DbgkErrorPortStartTimeout;
*(_DWORD *)(r9_0 + 4) = DbgkErrorPortCommTimeout;
}
}
goto LABEL_598;
case SystemLowPriorityIoInformation:
IoQueryLowPriorityIoInformation(
(VOID *)0x140000000i64,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information);
goto LABEL_598;
case SystemBootEntropyInformation:
LODWORD(Information) = 1096;
if( (_DWORD)Length != 1096 )
goto LABEL_598;
if( v9 )
return;
ExQueryBootEntropyInformation(r9_0);
goto LABEL_598;
case SystemVerifierCountersInformation:
if( (unsigned int)Length >= 0x110 )
{
VfGetVerifierInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information, 1ui64);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 272;
return;
case SystemNodeDistanceInformation:
LODWORD(Information) = 4 * (unsigned __int16)KeNumberNodes;
if( (unsigned int)Length >= (unsigned int)Information )
{
v140 = 0;
v98 = 0;
v99 = v146;
while( v98 < (unsigned __int16)KeNumberNodes )
{
*(_DWORD *)(r9_0 + 4i64 * v98++) = *((_DWORD *)KeNodeDistance + v8 + v99 * (unsigned __int16)KeNumberNodes);
v8 = v98;
v140 = v98;
}
}
goto LABEL_598;
case SystemAcpiAuditInformation:
LODWORD(Information) = 8;
if( (_DWORD)Length != 8 )
goto LABEL_598;
if( !r9_0 )
goto LABEL_598;
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, 8ui64, 0x6F666E49ui64);
v158 = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
if( ((int(__fastcall *)(__int64, __int64, _DWORD *, INT64 *))off_140C00A68[0])(
26i64,
8i64,
PoolWithQuotaTag,
&Information) >= 0 )
{
*(_DWORD *)r9_0 = *PoolWithQuotaTag;
*(_DWORD *)(r9_0 + 4) ^= (PoolWithQuotaTag[1] ^ *(_DWORD *)(r9_0 + 4)) & 1;
v110 = *(_DWORD *)(r9_0 + 4) ^ ((unsigned __int8)*(_DWORD *)(r9_0 + 4) ^ (unsigned __int8)PoolWithQuotaTag[1]) & 2;
*(_DWORD *)(r9_0 + 4) = v110;
*(_DWORD *)(r9_0 + 4) = v110 ^ (PoolWithQuotaTag[1] ^ v110) & 4;
}
goto LABEL_419;
case SystemBasicPerformanceInformation:
if( (_DWORD)Length != 32 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
CurrentProcess = (_EPROCESS *)PsGetCurrentProcess();
ProcessPartitionId = MmGetProcessPartitionId((INT64)CurrentProcess);
LODWORD(v45) = MmGetAvailablePages(ProcessPartitionId);
TickInfo[0].IdleTime = v45;
LODWORD(v47) = MmGetTotalCommittedPages(v46);
TickInfo[0].C1Time = v47;
MmGetTotalCommitLimit(v48);
TickInfo[0].C2Time = v49;
LODWORD(v51) = MmGetPeakCommitment(v50);
TickInfo[0].C3Time = v51;
C1Time = v51;
if( v51 < TickInfo[0].C1Time )
C1Time = TickInfo[0].C1Time;
TickInfo[0].C3Time = C1Time;
*(_OWORD *)r9_0 = *(_OWORD *)&TickInfo[0].IdleTime;
*(_OWORD *)(r9_0 + 16) = *(_OWORD *)&TickInfo[0].C2Time;
LODWORD(Information) = 32;
goto LABEL_598;
case SystemQueryPerformanceCounterInformation:
LODWORD(Information) = 12;
if( (unsigned int)Length >= 4 )
{
v170 = *(_DWORD *)r9_0;
if( v170 == 1 && (unsigned int)Length >= 0xC )
{
*(_DWORD *)(r9_0 + 8) = 0;
*(_DWORD *)(r9_0 + 4) = 0;
*(_DWORD *)(r9_0 + 8) |= 1u;
*(_DWORD *)(r9_0 + 4) |= 1u;
if( KUSER_SHARED_DATA.QpcBypassEnabled )
*(_DWORD *)(r9_0 + 4) &= ~1u;
}
}
goto LABEL_598;
case SystemSessionBigPoolInformation:
if( (unsigned int)Length >= 0x10 )
{
LODWORD(SessionId) = *(_DWORD *)r9_0;
v166 = *(VOID **)(r9_0 + 8);
v79 = *(_DWORD *)(r9_0 + 4);
v151 = v79;
if( ((unsigned __int8)v166 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExGetSessionBigPoolInformation(v166, v79, (UINT64 *)&Information, &SessionId);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 16;
}
return;
case SystemBootGraphicsInformation:
LODWORD(Information) = 32;
if( (_DWORD)Length == 32 && BgkQueryBootGraphicsInformation(BG_INFORMATION_TYPE_DISPLAY, TickInfo) >= 0 )
{
IdleTime = TickInfo[0].IdleTime;
if( v9 )
IdleTime = 0i64;
TickInfo[0].IdleTime = IdleTime;
memmove((VOID *)r9_0, TickInfo, Information);
}
goto LABEL_598;
case SystemBadPageInformation:
if( !(_DWORD)v20 )
{
v114 = MmEnumerateBadPages(&PageList);
v115 = PageList;
if( PageList )
v8 = 8 * *(_DWORD *)PageList;
LODWORD(Information) = v8;
if( (unsigned int)Length < v8 )
v114 = -1073741820;
if( PageList )
{
if( v114 >= 0 )
memmove((VOID *)r9_0, PageList + 1, v8);
ExFreePoolWithTag(v115, 0);
}
}
goto LABEL_598;
case SystemPlatformBinaryInformation:
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
return;
ExpGetSystemPlatformBinary((VOID *)r9_0, (unsigned int)Length, v9);
goto LABEL_598;
case SystemPolicyInformation:
LODWORD(Information) = 32;
if( (_DWORD)Length == 32 )
ExHandleSPCall2((_SYSTEM_POLICY_INFORMATION *)0x140000000i64);
goto LABEL_598;
case SystemHypervisorProcessorCountInformation:
LODWORD(Information) = 8;
if( (unsigned int)Length >= 8
&& !HvlQueryActiveProcessors(&Count, 0i64)
&& !HvlQueryProcessorTopologyCount(0i64, (UINT64 *)((char *)&Count + 4)) )
{
*(_QWORD *)r9_0 = Count;
}
goto LABEL_598;
case SystemDeviceDataInformation:
case SystemDeviceDataEnumerationInformation:
if( (_DWORD)Length == 48 )
{
ExpGetDeviceDataInformation(
v16,
(VOID *)r9_0,
0x30ui64,
v13,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
}
else if( a6 )
{
*(_DWORD *)a6 = 48;
}
return;
case SystemMemoryTopologyInformation:
ExpQueryMemoryTopologyInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemMemoryChannelInformation:
ExpQueryChannelInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemBootLogoInformation:
if( (a6 || (unsigned int)Length >= 8)
&& BgkQueryBootGraphicsInformation(BG_INFORMATION_TYPE_LOGO_SIZE, &Information) >= 0 )
{
if( (_DWORD)Information )
{
if( (unsigned int)Length >= (unsigned int)Information
&& BgkQueryBootGraphicsInformation(BG_INFORMATION_TYPE_LOGO, &Src) >= 0 )
{
v112 = Src;
if( Src )
{
memmove((VOID *)r9_0, Src, Information);
ExFreePoolWithTag(v112, 0x4B494742u);
}
}
}
}
goto LABEL_598;
case SystemSecureBootPolicyInformation:
case SystemSecureBootInformation:
case SystemSecureBootPolicyFullInformation:
case SystemCodeIntegrityPlatformManifestInformation:
SeSecureBootQueryInformation(v16, (VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemPortableWorkspaceEfiLauncherInformation:
ExpQueryPortableWorkspaceEfiLauncherInformation((PVOID)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemKernelDebuggerInformationEx:
if( (unsigned int)Length >= 3 )
{
*(_BYTE *)r9_0 = KdpBootedNodebug == 0;
*(_BYTE *)(r9_0 + 1) = (_BYTE)KdDebuggerEnabled;
*(_BYTE *)(r9_0 + 2) = (_BYTE)KdDebuggerNotPresent == 0;
v10 = 3;
goto LABEL_256;
}
if( a6 )
*(_DWORD *)a6 = 3;
return;
case SystemBootMetadataInformation:
if( !ExBootLoaderMetadata )
goto LABEL_598;
v113 = *(_DWORD *)ExBootLoaderMetadata;
LODWORD(Information) = *(_DWORD *)ExBootLoaderMetadata;
if( !r9_0 || (unsigned int)Length < v113 )
goto LABEL_598;
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
return;
memmove((VOID *)r9_0, (const VOID *)(ExBootLoaderMetadata + 4), Information);
goto LABEL_598;
case SystemSoftRebootInformation:
LODWORD(Information) = 4;
if( (unsigned int)Length >= 4 )
{
*(_DWORD *)r9_0 = ExSoftRebootFlags;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemOfflineDumpConfigInformation:
if( !(_DWORD)v20 )
{
LODWORD(Information) = 32;
if( (unsigned int)Length < 0x20 )
{
if( (unsigned int)Length < 0xC )
{
HIDWORD(Information) = -1073741820;
}
else
{
LODWORD(Information) = 12;
*(_DWORD *)r9_0 = *(&stru_140C23628 + 1534);
*(_QWORD *)(r9_0 + 4) = *(_QWORD *)((char *)&stru_140C23628 + 6140);
}
}
else
{
*(_DWORD *)r9_0 = *(&stru_140C23628 + 1534);
*(_QWORD *)(r9_0 + 4) = *(_QWORD *)((char *)&stru_140C23628 + 6140);
*(_QWORD *)(r9_0 + 16) = *(&stru_140C23628 + 769);
*(_DWORD *)(r9_0 + 24) = *(&stru_140C23628 + 1540);
}
}
goto LABEL_598;
case SystemProcessorFeaturesInformation:
if( (unsigned int)Length >= 0x20 )
{
ExpGetSystemProcessorFeaturesInformation((_QWORD *)r9_0);
LODWORD(Information) = 32;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 32;
return;
case SystemEdidInformation:
LODWORD(Information) = 128;
if( (_DWORD)Length == 128 && BgkQueryBootGraphicsInformation(BG_INFORMATION_TYPE_EDID, TickInfo) >= 0 )
memmove((VOID *)r9_0, TickInfo, Information);
goto LABEL_598;
case SystemManufacturingInformation:
LODWORD(Information) = *(&ExBootDevicesRemovedEvent + 565) + 24;
if( (unsigned int)Length >= (unsigned int)Information )
{
v116 = (VOID *)(r9_0 + 24);
*(_OWORD *)r9_0 = 0i64;
*(_QWORD *)(r9_0 + 16) = 0i64;
*(_DWORD *)r9_0 = *(&ExBootDevicesRemovedEvent + 280);
*(_WORD *)(r9_0 + 8) = *(&ExBootDevicesRemovedEvent + 564);
*(_WORD *)(r9_0 + 10) = *(&ExBootDevicesRemovedEvent + 565);
if( *(&ExBootDevicesRemovedEvent + 564) )
{
*(_QWORD *)(r9_0 + 16) = v116;
memmove(v116, *(&ExBootDevicesRemovedEvent + 142), *(&ExBootDevicesRemovedEvent + 565));
}
}
goto LABEL_598;
case SystemEnergyEstimationConfigInformation:
LODWORD(Information) = 1;
if( (_DWORD)Length )
{
*(_BYTE *)r9_0 = PoEnergyEstimationEnabled();
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
case SystemHypervisorDetailInformation:
HvlQueryDetailInfo((VOID *)r9_0, (unsigned int)Length, (UINT64 *)v15);
goto LABEL_598;
case SystemProcessorCycleStatsInformation:
LODWORD(Information) = (_DWORD)v13 << 6;
if( (unsigned int)Length >= 0x40 )
{
v117 = (unsigned int)Length >> 6;
if( (unsigned int)Length >= (_DWORD)v13 << 6 )
v117 = v13;
while( v8 < v117 )
{
LOWORD(v138) = v14;
WORD1(v138) = (unsigned __int8)v8;
v118 = (__int64)*(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((UINT16 *)&v138));
KeQueryCycleTimeStatsProcessor(v118, (_QWORD *)r9_0);
r9_0 += 64i64;
v156 = (_QWORD *)r9_0;
++v8;
v14 = v139;
}
}
goto LABEL_598;
case SystemTrustedPlatformModuleInformation:
SeQueryTrustedPlatformModuleInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemKernelDebuggerFlags:
if( !(_DWORD)Length )
{
if( a6 )
*(_DWORD *)a6 = 1;
return;
}
*(_BYTE *)r9_0 = KdIgnoreUmExceptions;
LABEL_256:
LODWORD(Information) = v10;
goto LABEL_598;
case SystemCodeIntegrityPolicyInformation:
case SystemCodeIntegrityPolicyFullInformation:
case SystemCodeIntegrityPoliciesFullInformation:
case SystemCodeIntegrityUnlockInformation:
case SystemCodeIntegrityVerificationInformation:
case SystemCodeIntegritySyntheticCacheInformation:
SeCodeIntegrityQueryPolicyInformation((unsigned int)v16);
goto LABEL_598;
case SystemIsolatedUserModeInformation:
LODWORD(Information) = 16;
if( (_DWORD)Length == 16 )
{
LOBYTE(TickInfo[0].IdleTime) ^= (LOBYTE(TickInfo[0].IdleTime) ^ (16 * *(&ExBootDevicesRemovedEvent + 1056))) & 0x10;
if( VslIsSecureKernelRunning() )
{
v141 = 0;
LOBYTE(TickInfo[0].IdleTime) = v119 | 1;
NestedPageProtectionFlags = VslGetNestedPageProtectionFlags();
v121 = TickInfo[0].IdleTime;
if( (NestedPageProtectionFlags & 2) != 0 )
{
v121 = LOBYTE(TickInfo[0].IdleTime) | 2;
LOBYTE(TickInfo[0].IdleTime) |= 2u;
}
if( (NestedPageProtectionFlags & 0x20) != 0 )
{
v121 |= 4u;
LOBYTE(TickInfo[0].IdleTime) = v121;
}
if( (NestedPageProtectionFlags & 0x10) != 0 )
LOBYTE(TickInfo[0].IdleTime) = v121 | 8;
if( (NestedPageProtectionFlags & 0x200) != 0 )
BYTE1(TickInfo[0].IdleTime) |= 2u;
if( v161 )
{
VslIsTrustletRunning(v161, &v141);
BYTE1(TickInfo[0].IdleTime) ^= (v141 ^ BYTE1(TickInfo[0].IdleTime)) & 1;
}
LOBYTE(TickInfo[0].IdleTime) ^= (LOBYTE(TickInfo[0].IdleTime) ^ (32 * ExpIsIumEncryptionKeyAvailable())) & 0x20;
}
*(_OWORD *)r9_0 = *(_OWORD *)&TickInfo[0].IdleTime;
}
else if( a6 )
{
*(_DWORD *)a6 = 16;
}
goto LABEL_598;
case SystemHardwareSecurityTestInterfaceResultsInformation:
SeQueryHSTIResults((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information);
goto LABEL_598;
case SystemSingleModuleInformation:
ExpQuerySingleModuleInformation((PVOID)r9_0, (unsigned int)Length, v9, (UINT64 *)&Information);
goto LABEL_598;
case SystemVsmProtectionInformation:
HvlQueryVsmProtectionInfo((VOID *)r9_0, Length);
goto LABEL_598;
case SystemAffinitizedInterruptProcessorInformation:
if( ExCpuSetResourceManagerAccessCheck(v9) < 0 )
return;
LODWORD(Information) = 168;
if( (_DWORD)Length == 168 )
KeGetAffinitizedInterruptsInfo((_KAFFINITY_EX *)r9_0);
goto LABEL_598;
case SystemRootSiloInformation:
PsRootSiloInformation((_DWORD *)r9_0, Length, (unsigned int *)&Information);
goto LABEL_598;
case SystemCpuSetInformation:
if( *(_QWORD *)Handle )
{
Object = 0i64;
v128 = ObReferenceObjectByHandle(
*(VOID **)Handle,
0x1000ui64,
(_OBJECT_TYPE *)PsProcessType,
v9,
&Object,
0i64);
v129 = (_EPROCESS *)Object;
if( v128 < 0 )
return;
}
else
{
v129 = Process;
}
KeQueryCpuSetInformation((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information, &v129->Pcb);
goto LABEL_545;
case SystemSecureKernelProfileInformation:
if( !(_DWORD)Length )
goto LABEL_598;
if( v9 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemProfilePrivilege, v9) )
return;
v130 = ExAllocatePoolWithQuotaTag((POOL_TYPE)520, (unsigned int)Length, 0x6F666E49ui64);
v131 = v130;
InputBuffer = v130;
if( v130 )
{
memset(v130, 0i64, Length);
if( VslQuerySecureKernelProfileInformation(v168, (INT64)v131, Length, &Information) >= 0 )
memmove((VOID *)r9_0, v131, Information);
ExFreePoolWithTag(v131, 0x6F666E49u);
}
goto LABEL_598;
case SystemInterruptSteeringInformation:
ExpQueryInterruptSteeringInformation(
InputBuffer,
v20,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information);
goto LABEL_598;
case SystemSupportedProcessorArchitectures:
if( *(_QWORD *)Handle )
{
v158 = 0i64;
v132 = ObReferenceObjectByHandle(
*(VOID **)Handle,
0x1000ui64,
(_OBJECT_TYPE *)PsProcessType,
v9,
&v158,
0i64);
v129 = (_EPROCESS *)v158;
if( v132 < 0 )
return;
}
else
{
v129 = Process;
}
PsWow64GetSupportedArchitectures((VOID *)r9_0, (unsigned int)Length, (UINT64 *)&Information, v129);
LABEL_545:
if( v129 )
HalPutDmaAdapter((PADAPTER_OBJECT)v129);
goto LABEL_598;
case SystemMemoryUsageInformation:
if( (_DWORD)Length != 56 )
{
if( a6 )
*(_DWORD *)a6 = 56;
return;
}
v21 = (_EPROCESS *)PsGetCurrentProcess();
v22 = MmGetProcessPartitionId((INT64)v21);
LODWORD(v23) = MmGetNumberOfPhysicalPages(v22);
TickInfo[0].IdleTime = v23 << 12;
LODWORD(v24) = MmGetAvailablePages(v22);
TickInfo[0].C1Time = v24 << 12;
MmGetResidentAvailablePages(v25);
TickInfo[0].C2Time = v26 << 12;
LODWORD(v28) = MmGetTotalCommittedPages(v27);
TickInfo[0].C3Time = v28 << 12;
MmGetTotalCommitLimit(v29);
*(_QWORD *)&TickInfo[0].C3Transitions = v30 << 12;
LODWORD(v32) = MmGetPeakCommitment(v31);
TickInfo[1].IdleTime = v32 << 12;
MmGetSharedCommit();
*(_QWORD *)&TickInfo[0].C1Transitions = v33 << 12;
v34 = TickInfo[0].IdleTime;
if( TickInfo[0].IdleTime < TickInfo[0].C1Time )
v34 = TickInfo[0].C1Time;
TickInfo[0].IdleTime = v34;
C3Time = *(_QWORD *)&TickInfo[0].C3Transitions;
if( *(_QWORD *)&TickInfo[0].C3Transitions < TickInfo[0].C3Time )
C3Time = TickInfo[0].C3Time;
*(_QWORD *)&TickInfo[0].C3Transitions = C3Time;
v36 = TickInfo[1].IdleTime;
if( TickInfo[1].IdleTime < TickInfo[0].C3Time )
v36 = TickInfo[0].C3Time;
TickInfo[1].IdleTime = v36;
*(_SYSTEM_PROCESSOR_IDLE_INFORMATION *)r9_0 = TickInfo[0];
*(_QWORD *)(r9_0 + 48) = TickInfo[1].IdleTime;
LODWORD(Information) = 56;
goto LABEL_598;
case SystemCodeIntegrityCertificateInformation:
if( (_DWORD)Length != 16 )
return;
ExpQueryCodeIntegrityCertificateInfo(*(VOID **)r9_0, *(unsigned int *)(r9_0 + 8));
goto LABEL_598;
case SystemPhysicalMemoryInformation:
if( (_DWORD)Length != 24 )
{
if( a6 )
*(_DWORD *)a6 = 24;
return;
}
v37 = (_EPROCESS *)PsGetCurrentProcess();
v38 = MmGetProcessPartitionId((INT64)v37);
LODWORD(v39) = MmGetNumberOfPhysicalPages(v38);
TickInfo[0].IdleTime = v39 << 12;
LODWORD(v40) = MmGetLowestPhysicalPage(v38);
TickInfo[0].C1Time = v40 << 12;
LODWORD(v42) = MmGetHighestPhysicalPage(v41);
TickInfo[0].C2Time = (v42 << 12) + 4095;
*(_OWORD *)r9_0 = *(_OWORD *)&TickInfo[0].IdleTime;
*(_QWORD *)(r9_0 + 16) = TickInfo[0].C2Time;
LABEL_67:
LODWORD(Information) = 24;
goto LABEL_598;
case SystemControlFlowTransition:
WbDispatchOperation((VOID *)r9_0, Length);
goto LABEL_598;
case SystemKernelDebuggingAllowed:
if( (_DWORD)Length )
{
if( a6 )
*(_DWORD *)a6 = 0;
}
else
{
BYTE4(SessionId) = 1;
LODWORD(ReturnSize) = 1;
ZwFilterBootOption(
FilterBootOptionOperationSetElement,
0x10200003ui64,
0x260000A0ui64,
(char *)&SessionId + 4,
(UINT64)ReturnSize);
}
return;
case SystemActivityModerationUserSettings:
if( (_DWORD)Length != 8 )
return;
if( (int)PsQueryActivityModerationUserSettings((_QWORD *)TickInfo) >= 0 )
*(_QWORD *)r9_0 = TickInfo[0].IdleTime;
goto LABEL_598;
case SystemFlushInformation:
if( (unsigned int)Length >= 0x20 )
{
ExpGetSystemFlushInformation(r9_0);
LODWORD(Information) = 32;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 32;
return;
case SystemProcessorIdleMaskInformation:
v104 = 8 * KeQueryActiveGroupCount();
LODWORD(Information) = v104;
if( (unsigned int)Length >= v104 )
{
memset((VOID *)r9_0, 0i64, v104);
v140 = 0;
while( v8 < (unsigned __int16)KeNumberNodes )
{
v105 = KeNodeBlock[v8];
WORD2(v138) = *(_WORD *)(v105 + 144);
*(_QWORD *)(r9_0 + 8i64 * WORD2(v138)) |= *(_QWORD *)(v105 + 24);
v8 = ++v140;
}
}
goto LABEL_598;
case SystemWriteConstraintInformation:
if( (unsigned int)Length >= 8 )
{
ExpGetSystemWriteConstraintInformation((_QWORD *)r9_0);
LODWORD(Information) = 8;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 8;
return;
case SystemKernelVaShadowInformation:
KeQueryKvaShadowInformation((_DWORD *)r9_0, Length, &Information);
goto LABEL_598;
case SystemHypervisorSharedPageInformation:
LODWORD(Information) = 8;
if( (unsigned int)Length >= 8 )
{
v134 = *(&stru_140C4DB30 + 11);
*(_QWORD *)r9_0 = 0i64;
*(_QWORD *)r9_0 = v134;
}
goto LABEL_598;
case SystemFirmwareBootPerformanceInformation:
if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
34i64,
0i64,
0i64,
(char *)&InputBufferLength + 4) != -1073741820 )
return;
v59 = HIDWORD(InputBufferLength);
if( (unsigned int)Length < HIDWORD(InputBufferLength) || !r9_0 )
{
LABEL_96:
LODWORD(Information) = v59;
goto LABEL_598;
}
if( v9 )
{
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
InputBuffer = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
v59 = HIDWORD(InputBufferLength);
}
else
{
PoolWithQuotaTag = (_DWORD *)r9_0;
InputBuffer = (VOID *)r9_0;
}
v133 = ((__int64(__fastcall *)(__int64, _QWORD, _DWORD *, INT64 *))off_140C00A68[0])(
34i64,
v59,
PoolWithQuotaTag,
&Information);
if( v9 )
{
if( v133 >= 0 )
LABEL_418:
memmove((VOID *)r9_0, PoolWithQuotaTag, Information);
LABEL_419:
ExFreePoolWithTag(PoolWithQuotaTag, 0x6F666E49u);
}
goto LABEL_598;
case SystemFirmwarePartitionInformation:
IoQuerySystemDeviceName(
SystemFirmwarePartitionInformation,
(VOID *)r9_0,
(unsigned int)Length,
(UINT64 *)&Information,
(INT64)ReturnSize,
(INT64)HandleInformation,
Information,
v138);
goto LABEL_598;
case SystemSpeculationControlInformation:
KeQuerySpeculationControlInformation((VOID *)r9_0, Length);
goto LABEL_598;
case SystemDmaGuardPolicyInformation:
LODWORD(Information) = 1;
if( (_DWORD)Length == 1 )
{
v154 = 0;
if( ((int(__fastcall *)(__int64, __int64, _SYSTEM_PROCESSOR_IDLE_INFORMATION *, int *))off_140C00A68[0])(
47i64,
1i64,
TickInfo,
&v154) >= 0
&& v154 == 1 )
{
*(_BYTE *)r9_0 = TickInfo[0].IdleTime;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
case SystemLeapSecondInformation:
if( (_DWORD)Length != 8 )
{
if( a6 )
*(_DWORD *)a6 = 8;
return;
}
*(_BYTE *)r9_0 = **(&ExBootDevicesRemovedEvent + 103) != 0;
*(_DWORD *)(r9_0 + 4) = 0;
LABEL_114:
LODWORD(Information) = 8;
goto LABEL_598;
case SystemFlags2Information:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)r9_0 = NtGlobalFlag2;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemSecurityModelInformation:
SeSecurityModelQueryInformation((_DWORD *)r9_0, Length, &Information);
goto LABEL_598;
case SystemFeatureConfigurationInformation:
CmQuerySingleFeatureConfiguration((__int64 *)InputBuffer, v20, r9_0, Length, &Information);
goto LABEL_598;
case SystemFeatureConfigurationSectionInformation:
LOBYTE(HandleInformation) = KeGetCurrentThread()->PreviousMode;
CmQueryFeatureConfigurationSections(
(__int64)InputBuffer,
v20,
(_OWORD *)r9_0,
Length,
(__int64)&Information,
(_KPROCESSOR_MODE)HandleInformation);
goto LABEL_598;
case SystemSecureSpeculationControlInformation:
KeQuerySecureSpeculationInformation((VOID *)r9_0, Length);
goto LABEL_598;
case SystemShadowStackInformation:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)r9_0 = 0;
if( !PsIsCurrentThreadInServerSilo() )
{
*(_DWORD *)r9_0 ^= (*(_DWORD *)r9_0 ^ (unsigned __int8)KeIsCetCapable(v123, v122)) & 1;
IsUserCetAllowed = KeIsUserCetAllowed();
*(_DWORD *)r9_0 = (unsigned int)v125 ^ ((unsigned __int8)v125 ^ (unsigned __int8)(2 * IsUserCetAllowed)) & 2;
IsKTMCommitCoordinator = ext_ms_win_ntos_tm_l1_1_0_TmIsKTMCommitCoordinator(v125);
*(_DWORD *)r9_0 = v127 ^ ((unsigned __int16)v127 ^ (unsigned __int16)(IsKTMCommitCoordinator << 8)) & 0x100;
}
LABEL_157:
LODWORD(Information) = 4;
LABEL_598:
if( a6 )
*(_DWORD *)a6 = Information;
}
else if( a6 )
{
*(_DWORD *)a6 = 4;
}
return;
case SystemPoolZeroingInformation:
LODWORD(Information) = 1;
if( (_DWORD)Length == 1 )
{
*(_BYTE *)r9_0 = 1;
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
default:
return;
}
return;
case SystemCpuSetInformation:
case SystemSupportedProcessorArchitectures:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 8 )
return;
*(_QWORD *)Handle = *(_QWORD *)InputBuffer;
goto LABEL_35;
case SystemSecureKernelProfileInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 8 )
return;
v168 = *(_QWORD *)InputBuffer;
goto LABEL_35;
default:
goto LABEL_34;
}
}Referenced by:
NtQuerySystemInformation
NtQuerySystemInformationEx