KeProcessorProfileControlArea
NTSTATUS __stdcall KeProcessorProfileControlArea(
PVOID SystemInformation,
UINT64 SystemInformationLength,
INT8 PreviousMode){
char v5;
VOID **v6;
VOID **PoolWithTag;
unsigned __int8 CurrentIrql;
__int64 v9;
NTSTATUS v10;
__int64 v11;
if( PreviousMode )
return -1073741790;
if( (_DWORD)SystemInformationLength != 16 )
return -1073741820;
v5 = *((_BYTE *)SystemInformation + 8);
v6 = 0i64;
if( v5 )
{
PoolWithTag = ExAllocatePoolWithTag(0x204ui64, 0xA0ui64, 1094930512i64);
v6 = PoolWithTag;
if( !PoolWithTag )
{
*(_QWORD *)SystemInformation = 0i64;
return -1073741670;
}
memset(PoolWithTag, 0i64, 0xA0u);
}
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
if( KiIsIntelPebsSupported(KeGetCurrentPrcb()) )
{
if( v5 )
{
v11 = *(_QWORD *)(v9 + 33944);
if( v11 )
{
*(_QWORD *)SystemInformation = v11;
v10 = -1073741302;
goto LABEL_16;
}
*(_QWORD *)(v9 + 33944) = v6;
*(_QWORD *)(v9 + 33952) = v6 + 5;
*(_QWORD *)SystemInformation = v6;
v6 = 0i64;
}
else
{
*(_QWORD *)SystemInformation = 0i64;
if( !*(_QWORD *)(v9 + 33944) )
{
v10 = -1073741664;
goto LABEL_16;
}
}
v10 = 0;
goto LABEL_16;
}
*(_QWORD *)SystemInformation = 0i64;
v10 = -1073741637;
LABEL_16:
__writecr8(CurrentIrql);
if( v6 )
ExFreePoolWithTag(v6, 0);
return v10;
}Referenced by:
NtSetSystemInformation