StartFirstUserProcess

VOID __stdcall StartFirstUserProcess(){
  VOID *v0; 
  __int64 v1; 
  size_t v2; 
  VOID **PoolWithTag; 
  VOID **v4; 
  __int128 v5; 
  void *UserProcess; 
  UINT16 v7; 
  INT64 v8; 
  CHAR v9; 
  NTSTATUS v10; 
  NTSTATUS v11; 
  _UNICODE_STRING DestinationString; 
  INT64 v13[13]; 
  int ProcessInformation; 
  _LARGE_INTEGER Interval; 

  *(_DWORD *)(&DestinationString.MaximumLength + 1) = 0;
  memset(v13, 0i64, sizeof(v13));
  if( QueryRegistryHideMachine() )
    RegistryOverwriteCentralProcessor();
  v0 = (VOID *)*((unsigned __int16 *)&stru_140D23928 + 9);
  v1 = stru_140D23928.MaximumLength + 1148i64;
  v2 = v1 + *((unsigned __int16 *)&stru_140D23928 + 9);
  PoolWithTag = ExAllocatePoolWithTag(0x200ui64, v1 + *((unsigned __int16 *)&stru_140D23928 + 9), 1649636176i64);
  v4 = PoolWithTag;
  if( !PoolWithTag )
    KeBugCheckEx(0x6Du, (PVOID)0xFFFFFFFFC000009Ai64, 0i64, 0i64, 0i64);
  memset(PoolWithTag, 0i64, v2);
  *((_DWORD *)v4 + 1) = v1;
  *(_DWORD *)v4 = v1;
  v4[16] = (char *)v4 + v1;
  *((_DWORD *)v4 + 2) = 4194305;
  v4[126] = v0;
  *((_OWORD *)v4 + 5) = 0i64;
  v4[11] = 0i64;
  v4[8] = v4 + 136;
  *((_WORD *)v4 + 29) = stru_140D23928.MaximumLength;
  RtlCopyUnicodeString((PUNICODE_STRING)(v4 + 7), &stru_140D23928);
  v4[13] = (char *)v4 + *((unsigned __int16 *)v4 + 29) + 1088;
  *((_WORD *)v4 + 49) = 60;
  RtlCopyUnicodeString((PUNICODE_STRING)v4 + 6, &NtInitialUserProcess);
  v5 = *((_OWORD *)v4 + 6);
  DestinationString.Buffer = (wchar_t *)v4[16];
  *((_OWORD *)v4 + 7) = v5;
  DestinationString.Length = 0;
  DestinationString.MaximumLength = (unsigned __int16)v0;
  RtlCopyUnicodeString(&DestinationString, &stru_140D23928 + 1);
  UserProcess = (void *)RtlCreateUserProcessEx((_UNICODE_STRING *)v4 + 6, (_RTL_USER_PROCESS_PARAMETERS *)v4);
  if( InbvIsBootDriverInstalled() )
    FinalizeBootLogo(v8, v7, v9);
  if( (int)UserProcess < 0 )
    KeBugCheckEx(0x6Du, UserProcess, 0i64, (PVOID)1, 0i64);
  ProcessInformation = 1;
  v10 = ZwSetInformationProcess(v13[1], 0x1Dui64, (UINT64)&ProcessInformation, 4ui64);
  if( v10 < 0 )
    KeBugCheckEx(0x6Du, (PVOID)v10, 0i64, (PVOID)2, 0i64);
  v11 = ZwResumeThread((VOID *)v13[2], 0i64);
  if( v11 < 0 )
    KeBugCheckEx(0x6Du, (PVOID)v11, 0i64, (PVOID)3, 0i64);
  byte_140C508A4 = 1;
  Interval.QuadPart = -50000000i64;
  KeDelayExecutionThread(0, 0, &Interval);
  ZwClose(v13[2]);
  ZwClose(v13[1]);
  ExFreePoolWithTag(v4, 0);
}

Referenced by:

Phase1InitializationIoReady