SeMakeSystemToken

INT64 __stdcall SeMakeSystemToken(){
  char *v0; 
  unsigned int v1; 
  _LARGE_INTEGER v2; 
  unsigned int v3; 
  VOID *Owner; 
  VOID *PrimaryGroup; 
  unsigned int v6; 
  int v7; 
  unsigned int v8; 
  UINT32 v9; 
  struct _ACL *PoolWithTag; 
  ACL *v11; 
  UINT32 v12; 
  struct _ACL *v13; 
  _ACL *v14; 
  void *v15; 
  void *v16; 
  CHAR v17; 
  UINT64 v18; 
  __int64 *v20; 
  __int64 v21; 
  __int64 v22; 
  _ACL *v23; 
  int v24[8]; 
  UINT8 AceType[4]; 
  UINT64 AccessMask; 
  ULONG v27[2]; 
  UINT64 GroupsLength; 
  UINT64 PrivilegeCount; 
  _TOKEN_SOURCE *v30; 
  UINT8 v31; 
  _TOKEN_MANDATORY_POLICY MandatoryPolicy; 
  _LARGE_INTEGER a2; 
  _LARGE_INTEGER ExpirationTime; 
  VOID *TokenHandle; 
  _SID_AND_ATTRIBUTES User; 
  INT16 a1[8]; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  _LUID_AND_ATTRIBUTES Privileges; 
  LUID v40; 
  int v41; 
  __int64 v42; 
  int v43; 
  LUID v44; 
  int v45; 
  LUID v46; 
  int v47; 
  LUID v48; 
  int v49; 
  LUID v50; 
  int v51; 
  __int64 v52; 
  int v53; 
  LUID v54; 
  int v55; 
  LUID v56; 
  int v57; 
  __int64 v58; 
  int v59; 
  __int64 v60; 
  int v61; 
  LUID v62; 
  int v63; 
  __int64 v64; 
  int v65; 
  LUID v66; 
  int v67; 
  LUID v68; 
  int v69; 
  LUID v70; 
  int v71; 
  LUID v72; 
  int v73; 
  LUID v74; 
  int v75; 
  LUID v76; 
  int v77; 
  __int64 v78; 
  int v79; 
  __int64 v80; 
  int v81; 
  __int64 v82; 
  int v83; 
  LUID v84; 
  int v85; 
  __int64 v86; 
  int v87; 
  INT64 v88; 
  int v89; 
  __int64 v90; 
  int v91; 
  LUID v92; 
  int v93; 
  __int64 v94; 
  int v95; 
  LUID v96; 
  int v97; 
  __int64 v98; 
  int v99; 
  _SID_AND_ATTRIBUTES Groups; 
  PSID v101; 
  int v102; 
  __int64 v103; 
  int v104; 
  __int64 v105; 
  int v106; 
  v0 = (char *)ExLeapSecondData;
  TokenHandle = 0i64;
  *(&User.Attributes + 1) = 0;
  *(&ObjectAttributes.Length + 1) = 0;
  MandatoryPolicy.Policy = 1;
  *(&ObjectAttributes.Attributes + 1) = 0;
  ExpirationTime.QuadPart = 0i64;
  a2.QuadPart = 0i64;
  *(__m128i *)a1 = _mm_load_si128((const __m128i *)&_xmm);
  if( !ExLeapSecondData || !*(_BYTE *)ExLeapSecondData )
  {
    RtlpTimeFieldsToTimeNoLeapSeconds(a1, &ExpirationTime);
    goto LABEL_6;
  }
  v1 = *((_DWORD *)ExLeapSecondData + 1);
  _InterlockedOr(v24, 0);
  if( !RtlpTimeFieldsToTimeNoLeapSeconds(a1, &a2) )
    goto LABEL_6;
  v2 = a2;
  v3 = 0;
  if( !v1 )
    goto LABEL_5;
  v20 = (__int64 *)(v0 + 8);
  while( 1 )
  {
    v21 = *v20;
    if( *v20 >= 0 )
    {
      if( v2.QuadPart < v21 + 10000000 )
      {
        if( v2.QuadPart < v21 )
          goto LABEL_5;
        v2.QuadPart = 2 * v2.QuadPart - v21;
      }
      else
      {
        v2.QuadPart += 10000000i64;
      }
      goto LABEL_18;
    }
    v22 = v21 & 0x7FFFFFFFFFFFFFFFi64;
    if( v2.QuadPart < v22 + 10000000 )
      break;
    v2.QuadPart -= 10000000i64;
LABEL_18:
    ++v3;
    ++v20;
    if( v3 >= v1 )
      goto LABEL_5;
  }
  if( v2.QuadPart < v22 )
LABEL_5:
    ExpirationTime = v2;
LABEL_6:
  Owner = SeAliasAdminsSid;
  PrimaryGroup = SeLocalSystemSid;
  v102 = 7;
  v104 = 7;
  v101 = SeWorldSid;
  User.Sid = SeLocalSystemSid;
  User.Attributes = 0;
  Groups.Sid = SeAliasAdminsSid;
  v103 = SeAuthenticatedUsersSid;
  v105 = SeSystemMandatorySid;
  Groups.Attributes = 14;
  v106 = 96;
  v6 = ((4 * *(unsigned __int8 *)(SeAuthenticatedUsersSid + 1) + 11) & 0xFFFFFFFC)
     + ((4 * *((unsigned __int8 *)SeWorldSid + 1) + 11) & 0xFFFFFFFC)
     + ((4 * *((unsigned __int8 *)SeAliasAdminsSid + 1) + 11) & 0xFFFFFFFC);
  v7 = *(unsigned __int8 *)(SeSystemMandatorySid + 1);
  Privileges.Attributes = 3;
  v41 = 0;
  v43 = 0;
  v45 = 3;
  Privileges.Luid = SeTcbPrivilege;
  v8 = v6 + ((4 * v7 + 11) & 0xFFFFFFFC) + 16;
  v40 = SeCreateTokenPrivilege;
  v42 = SeTakeOwnershipPrivilege;
  v44 = SeCreatePagefilePrivilege;
  v46 = SeLockMemoryPrivilege;
  v48 = SeAssignPrimaryTokenPrivilege;
  v50 = SeIncreaseQuotaPrivilege;
  v52 = *(_QWORD *)SeIncreaseBasePriorityPrivilege;
  v54 = SeCreatePermanentPrivilege;
  v56 = SeDebugPrivilege;
  v58 = SeAuditPrivilege;
  v60 = *(_QWORD *)SeSecurityPrivilege;
  v62 = SeSystemEnvironmentPrivilege;
  v64 = SeChangeNotifyPrivilege;
  v66 = SeBackupPrivilege;
  v68 = SeRestorePrivilege;
  v47 = 3;
  v49 = 0;
  v51 = 0;
  v53 = 3;
  v55 = 3;
  v57 = 3;
  v59 = 3;
  v61 = 0;
  v63 = 0;
  v65 = 3;
  v67 = 0;
  v70 = SeShutdownPrivilege;
  v72 = SeLoadDriverPrivilege;
  v74 = SeProfileSingleProcessPrivilege;
  v76 = SeSystemtimePrivilege;
  v78 = SeUndockPrivilege;
  v80 = SeManageVolumePrivilege;
  v82 = SeImpersonatePrivilege;
  v84 = SeCreateGlobalPrivilege;
  v86 = SeTrustedCredManAccessPrivilege;
  v88 = SeRelabelPrivilege;
  v90 = SeIncreaseWorkingSetPrivilege;
  v92 = SeTimeZonePrivilege;
  v94 = SeCreateSymbolicLinkPrivilege;
  v96 = SeSystemProfilePrivilege;
  v75 = 3;
  v83 = 3;
  v85 = 3;
  v91 = 3;
  v93 = 3;
  v95 = 3;
  v97 = 3;
  v99 = 3;
  v98 = SeDelegateSessionUserImpersonatePrivilege;
  v69 = 0;
  v71 = 0;
  v73 = 0;
  v77 = 0;
  v79 = 0;
  v81 = 0;
  v87 = 0;
  v89 = 0;
  v9 = 4 * *((unsigned __int8 *)SeLocalSystemSid + 1) + 24;
  PoolWithTag = (struct _ACL *)ExAllocatePoolWithTag(PagedPool, v9, 0x63416553ui64);
  v11 = PoolWithTag;
  if( PoolWithTag )
  {
    RtlCreateAcl(PoolWithTag, v9, 2u);
    v12 = 4 * *((unsigned __int8 *)SeProcTrustWinTcbSid + 1) + 24;
    v13 = (struct _ACL *)ExAllocatePoolWithTag(PagedPool, v12, 0x63416553ui64);
    v14 = v13;
    if( v13 )
    {
      RtlCreateAcl(v13, v12, 2u);
      RtlAddAccessAllowedAce(v11, 2u, 0xF01FFu, SeLocalSystemSid);
      LODWORD(AccessMask) = 131096;
      RtlAddProcessTrustLabelAce(v14, 2ui64, 0i64, SeProcTrustWinTcbSid, 0x14u, AccessMask);
      v15 = ExAllocatePoolWithTag(PagedPool, 0x28ui64, 0x64536553ui64);
      v16 = v15;
      if( v15 )
      {
        RtlCreateSecurityDescriptor(v15, 1ui64);
        RtlSetDaclSecurityDescriptor(v16, 1u, v11, 0);
        RtlSetSaclSecurityDescriptor(v16, 1u, v14, 0);
        RtlSetOwnerSecurityDescriptor(v16, SeAliasAdminsSid, 0);
        RtlSetGroupSecurityDescriptor(v16, SeAliasAdminsSid, 0);
        ObjectAttributes.Length = 48;
        memset(&ObjectAttributes.RootDirectory, 0, 20);
        ObjectAttributes.SecurityQualityOfService = 0i64;
        LODWORD(PrivilegeCount) = 31;
        LODWORD(GroupsLength) = v8;
        v27[0] = 4;
        ObjectAttributes.SecurityDescriptor = v16;
        SepCreateToken(
          &TokenHandle,
          v17,
          v18,
          &ObjectAttributes,
          *(_TOKEN_TYPE *)AceType,
          (_SECURITY_IMPERSONATION_LEVEL)AccessMask,
          (_LUID *)&SeSystemAuthenticationId,
          &ExpirationTime,
          &User,
          *(UINT64 *)v27,
          &Groups,
          GroupsLength,
          PrivilegeCount,
          &Privileges,
          Owner,
          PrimaryGroup,
          SeSystemDefaultDacl,
          v30,
          v31);
        SeSetMandatoryPolicyToken(TokenHandle, &MandatoryPolicy);
        ExFreePoolWithTag(v11, 0);
        ExFreePoolWithTag(v14, 0);
        ExFreePoolWithTag(v16, 0);
        return(INT64)TokenHandle;
      }
      ExFreePoolWithTag(v11, 0);
      v23 = v14;
    }
    else
    {
      v23 = v11;
    }
    ExFreePoolWithTag(v23, 0);
  }
  return 0i64;
}

Referenced by:

SepInitializationPhase0