StartFirstUserProcess
VOID __stdcall StartFirstUserProcess(){
VOID *v0;
__int64 v1;
size_t v2;
VOID **PoolWithTag;
VOID **v4;
__int128 v5;
void *UserProcess;
UINT16 v7;
INT64 v8;
CHAR v9;
NTSTATUS v10;
NTSTATUS v11;
_UNICODE_STRING DestinationString;
INT64 v13[13];
int ProcessInformation;
_LARGE_INTEGER Interval;
*(_DWORD *)(&DestinationString.MaximumLength + 1) = 0;
memset(v13, 0i64, sizeof(v13));
if( QueryRegistryHideMachine() )
RegistryOverwriteCentralProcessor();
v0 = (VOID *)*((unsigned __int16 *)&stru_140D23928 + 9);
v1 = stru_140D23928.MaximumLength + 1148i64;
v2 = v1 + *((unsigned __int16 *)&stru_140D23928 + 9);
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, v1 + *((unsigned __int16 *)&stru_140D23928 + 9), 1649636176i64);
v4 = PoolWithTag;
if( !PoolWithTag )
KeBugCheckEx(0x6Du, (PVOID)0xFFFFFFFFC000009Ai64, 0i64, 0i64, 0i64);
memset(PoolWithTag, 0i64, v2);
*((_DWORD *)v4 + 1) = v1;
*(_DWORD *)v4 = v1;
v4[16] = (char *)v4 + v1;
*((_DWORD *)v4 + 2) = 4194305;
v4[126] = v0;
*((_OWORD *)v4 + 5) = 0i64;
v4[11] = 0i64;
v4[8] = v4 + 136;
*((_WORD *)v4 + 29) = stru_140D23928.MaximumLength;
RtlCopyUnicodeString((PUNICODE_STRING)(v4 + 7), &stru_140D23928);
v4[13] = (char *)v4 + *((unsigned __int16 *)v4 + 29) + 1088;
*((_WORD *)v4 + 49) = 60;
RtlCopyUnicodeString((PUNICODE_STRING)v4 + 6, &NtInitialUserProcess);
v5 = *((_OWORD *)v4 + 6);
DestinationString.Buffer = (wchar_t *)v4[16];
*((_OWORD *)v4 + 7) = v5;
DestinationString.Length = 0;
DestinationString.MaximumLength = (unsigned __int16)v0;
RtlCopyUnicodeString(&DestinationString, &stru_140D23928 + 1);
UserProcess = (void *)RtlCreateUserProcessEx((_UNICODE_STRING *)v4 + 6, (_RTL_USER_PROCESS_PARAMETERS *)v4);
if( InbvIsBootDriverInstalled() )
FinalizeBootLogo(v8, v7, v9);
if( (int)UserProcess < 0 )
KeBugCheckEx(0x6Du, UserProcess, 0i64, (PVOID)1, 0i64);
ProcessInformation = 1;
v10 = ZwSetInformationProcess(v13[1], 0x1Dui64, (UINT64)&ProcessInformation, 4ui64);
if( v10 < 0 )
KeBugCheckEx(0x6Du, (PVOID)v10, 0i64, (PVOID)2, 0i64);
v11 = ZwResumeThread((VOID *)v13[2], 0i64);
if( v11 < 0 )
KeBugCheckEx(0x6Du, (PVOID)v11, 0i64, (PVOID)3, 0i64);
byte_140C508A4 = 1;
Interval.QuadPart = -50000000i64;
KeDelayExecutionThread(0, 0, &Interval);
ZwClose(v13[2]);
ZwClose(v13[1]);
ExFreePoolWithTag(v4, 0);
}Referenced by:
Phase1InitializationIoReady