ExpQuerySystemInformation
VOID __fastcall ExpQuerySystemInformation(UINT64 rcx0, VOID *a2, UINT64 a3, INT64 a4, UINT64 Length, UINT64 *a6){
int v7;
unsigned int v8;
unsigned __int8 v9;
unsigned int v10;
UINT64 v11;
__int64 v12;
__int64 v13;
USHORT v14;
__int64 v15;
_SYSTEM_INFORMATION_CLASS v16;
UINT16 v17;
unsigned int ActiveProcessorCount;
USHORT ActiveGroupCount;
UINT64 v20;
__int64 v21;
unsigned __int16 v22;
_BYTE *v23;
__int64 v24;
UINT64 v25;
UINT64 v26;
UINT64 v27;
UINT64 v28;
SIZE_T PeakSize;
SIZE_T CurrentSizeIncludingTransitionInPages;
SIZE_T PeakSizeIncludingTransitionInPages;
__int64 v32;
UINT16 v33;
UINT64 v34;
__int64 CurrentProcess;
unsigned __int16 ProcessPartitionId;
UINT64 v37;
UINT64 v38;
UINT64 v39;
SIZE_T MinimumWorkingSet;
unsigned int v41;
unsigned int v42;
_DWORD *v43;
int v44;
unsigned __int64 v45;
unsigned int v46;
UINT8 *PoolWithTag;
UINT8 *v48;
__int64 v49;
__int64 v50;
unsigned __int64 v51;
char v52;
char *v53;
_KTHREAD *CurrentThread;
int v55;
PCONFIGURATION_INFORMATION ConfigurationInformation;
INT64 v57;
INT64 v58;
unsigned int v59;
int v60;
_WORKING_SET_TYPE v61;
UINT64 v62;
unsigned int v63;
int v64;
int v65;
_KPRCB **v66;
__int64 v67;
_KPRCB **v68;
__int64 v69;
unsigned int i;
_DWORD *v71;
__int64 v72;
_OWORD *v73;
_SYSTEM_FILECACHE_INFORMATION *p_Src;
__int64 v75;
__int64 v76;
_SYSTEM_FILECACHE_INFORMATION *v77;
_KPRCB **v78;
__int64 v79;
__int64 v80;
int v81;
unsigned int v82;
int v83;
unsigned int v84;
__int16 j;
__int64 v86;
_QWORD *v87;
__int64 v88;
unsigned int v89;
__int64 v90;
_DWORD *PoolWithQuotaTag;
int v92;
int v93;
SIZE_T CurrentSize;
PVOID v95;
unsigned int v96;
NTSTATUS v97;
PVOID v98;
int v99;
UINT8 *v100;
unsigned int v101;
INT64 v102;
char v103;
__int16 NestedPageProtectionFlags;
INT64 v105;
WCHAR v106;
char v107;
INT64 v108;
bool IsIumEncryptionKeyAvailable;
INT64 v110;
INT64 v111;
bool IsUserCetAllowed;
KTRANSACTION *v113;
UINT8 IsKTMCommitCoordinator;
int v115;
INT64 v116;
NTSTATUS v117;
struct _DMA_ADAPTER *v118;
UINT8 *v119;
UINT8 *v120;
NTSTATUS v121;
int v122;
__int64 v123;
PVOID *Object;
POBJECT_HANDLE_INFORMATION HandleInformation;
size_t Size;
INT64 ProcNumber;
int v128;
int v129;
char v130[4];
UINT64 InputBufferLength;
VOID *InputBuffer;
UINT64 *v133;
UINT64 SessionId;
unsigned __int16 v135;
unsigned int v136;
unsigned int v137;
_SYSTEM_INFORMATION_CLASS InformationClass;
LOGICAL_PROCESSOR_RELATIONSHIP RelationshipType;
unsigned int v140;
UINT64 Count;
LOGICAL_PROCESSOR_RELATIONSHIP v142;
int v143;
unsigned int v144;
_QWORD *v145;
_EPROCESS *Process;
PVOID v147;
PVOID P;
PVOID v149;
INT64 a1;
HANDLE Handle;
HANDLE ProcessId[2];
char *v153;
UINT64 v154;
VOID *v155;
PVOID v156;
INT64 v157;
__int128 v158;
int v159;
_SYSTEM_FILECACHE_INFORMATION Src;
__int128 v161;
__int128 v162;
__int128 v163;
__int128 v164;
__int128 v165;
__int128 v166;
__int64 v167;
int v168;
InputBufferLength = (unsigned int)a3;
InputBuffer = a2;
v7 = rcx0;
InformationClass = (int)rcx0;
v133 = a6;
v8 = 0;
v154 = 0i64;
Count = 0i64;
v129 = 0;
LODWORD(SessionId) = 0;
v135 = 0;
WORD2(ProcNumber) = 0;
v158 = 0i64;
Process = 0i64;
LODWORD(ProcNumber) = 0;
RelationshipType = RelationProcessorCore;
v149 = 0i64;
P = 0i64;
v142 = RelationProcessorCore;
memset((INT64)&Src, 0i64);
HIDWORD(Size) = 0;
v9 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v9 )
{
switch( v7 )
{
case 12:
v11 = 8i64;
goto LABEL_6;
case 35:
case 145:
case 147:
case 149:
case 158:
case 163:
case 169:
case 202:
case 227:
v10 = 1;
v11 = 1i64;
break;
default:
v11 = 4i64;
LABEL_6:
v10 = 1;
break;
}
ProbeForWrite((VOID *)a4, (unsigned int)Length, v11);
if( a6 )
{
v12 = (__int64)a6;
if( (unsigned __int64)a6 >= 0x7FFFFFFF0000i64 )
v12 = 0x7FFFFFFF0000i64;
*(_DWORD *)v12 = *(_DWORD *)v12;
}
}
else
{
v10 = 1;
}
LODWORD(Size) = 0;
RelationshipType = RelationAll;
v13 = 0i64;
v136 = 0;
v14 = 0;
v128 = 0;
WORD2(ProcNumber) = 0;
v135 = 0;
a1 = 0i64;
Handle = 0i64;
v157 = 0i64;
v15 = 9i64;
v137 = 9;
v142 = 9;
v16 = InformationClass;
switch( InformationClass )
{
case SystemPerformanceInformation:
case SystemExceptionInformation:
case SystemContextSwitchInformation:
case SystemLostDelayedWriteInformation:
v128 = 0xFFFF;
WORD2(ProcNumber) = -1;
v17 = -1;
goto LABEL_15;
case SystemProcessorPerformanceInformation:
case SystemInterruptInformation:
case SystemProcessorIdleInformation:
case SystemProcessorPowerInformation:
case SystemLogicalProcessorInformation:
case SystemProcessorIdleCycleTimeInformation:
case SystemProcessorPerformanceDistribution:
case SystemProcessorCycleTimeInformation:
case SystemProcessorPerformanceInformationEx:
case SystemProcessorCycleStatsInformation:
if( (unsigned int)InputBufferLength < 2 )
return;
v128 = *(unsigned __int16 *)InputBuffer;
WORD2(ProcNumber) = v128;
ActiveGroupCount = KeQueryActiveGroupCount();
v17 = v128;
if( (unsigned __int16)v128 >= ActiveGroupCount )
return;
LABEL_15:
ActiveProcessorCount = KeQueryActiveProcessorCountEx(v17);
v13 = ActiveProcessorCount;
v136 = ActiveProcessorCount;
v14 = v128;
v15 = v137;
v16 = InformationClass;
LABEL_34:
v20 = (unsigned int)InputBufferLength;
goto LABEL_35;
case SystemWatchdogTimerInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 4 )
return;
v15 = *(unsigned int *)InputBuffer;
v142 = *(_DWORD *)InputBuffer;
goto LABEL_35;
case SystemLogicalProcessorAndGroupInformation:
v20 = (unsigned int)InputBufferLength;
if( (unsigned int)InputBufferLength < 4 )
return;
RelationshipType = *(_DWORD *)InputBuffer;
goto LABEL_35;
case SystemNodeDistanceInformation:
v20 = (unsigned int)InputBufferLength;
if( (unsigned int)InputBufferLength >= 2 )
{
v135 = *(_WORD *)InputBuffer;
if( v135 < (unsigned __int16)KeNumberNodes )
goto LABEL_35;
}
return;
case SystemIsolatedUserModeInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength )
{
if( (_DWORD)InputBufferLength != 8 )
return;
a1 = *(_QWORD *)InputBuffer;
}
else
{
a1 = 0i64;
}
LABEL_35:
switch( v16 )
{
case SystemBasicInformation:
case SystemNativeBasicInformation:
if( (_DWORD)Length == 64 )
{
ExpGetSystemBasicInformation(a4, v20, v15, v13);
goto LABEL_597;
}
if( a6 )
*(_DWORD *)a6 = 64;
return;
case SystemProcessorInformation:
if( (unsigned int)Length >= 0xC )
{
ExpGetSystemProcessorInformation(a4, v20, v15, v13);
LODWORD(Size) = 12;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 12;
return;
case SystemPerformanceInformation:
if( (unsigned int)Length >= 0x138 )
{
v10 = 344;
if( (unsigned int)Length <= 0x158 )
v10 = Length;
ExpQuerySystemPerformanceInformation((unsigned int)v13, (PVOID)a4, v10);
goto LABEL_256;
}
if( a6 )
*(_DWORD *)a6 = 344;
return;
case SystemTimeOfDayInformation:
if( (unsigned int)Length <= 0x30 )
{
KeQueryBootTimeValues((_LARGE_INTEGER *)&Src.PeakSize, (_LARGE_INTEGER *)&Src, &Src.MaximumWorkingSet);
v50 = PsGetCurrentServerSiloGlobals()[133];
*(_QWORD *)&Src.PageFaultCount = *(_QWORD *)(v50 + 440);
LODWORD(Src.MinimumWorkingSet) = *(_DWORD *)(v50 + 432);
Src.CurrentSizeIncludingTransitionInPages = KUSER_SHARED_DATA.InterruptTimeBias;
memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Length);
goto LABEL_119;
}
if( a6 )
*(_DWORD *)a6 = 48;
return;
case SystemProcessInformation:
case SystemExtendedProcessInformation:
case SystemFullProcessInformation:
ExpGetProcessInformation((VOID *)a4, (unsigned int)Length, &Size, 0i64, v16);
goto LABEL_598;
case SystemDeviceInformation:
if( (_DWORD)Length == 24 )
{
ConfigurationInformation = IoGetConfigurationInformation();
*(_DWORD *)a4 = ConfigurationInformation->DiskCount;
*(_DWORD *)(a4 + 4) = ConfigurationInformation->FloppyCount;
*(_DWORD *)(a4 + 8) = ConfigurationInformation->CdRomCount;
*(_DWORD *)(a4 + 12) = ConfigurationInformation->TapeCount;
*(_DWORD *)(a4 + 16) = ConfigurationInformation->SerialCount;
*(_DWORD *)(a4 + 20) = ConfigurationInformation->ParallelCount;
goto LABEL_67;
}
if( a6 )
*(_DWORD *)a6 = 24;
return;
case SystemProcessorPerformanceInformation:
case SystemProcessorPerformanceInformationEx:
v41 = 48;
if( v16 != SystemProcessorPerformanceInformation )
v41 = 72;
if( (_DWORD)Length && !((unsigned int)Length % v41) )
{
v129 = 0;
v42 = 0;
while( 1 )
{
v137 = v42;
if( v42 >= (unsigned int)v13 )
break;
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)v42;
v43 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
v44 = v129;
if( (unsigned int)Length < v41 + v129 )
goto LABEL_91;
v129 += v41;
PoGetIdleTimes((PROCESSOR_NUMBER *)&ProcNumber, 0i64, (INT64)&Src);
*(_QWORD *)(a4 + 16) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8098];
*(_QWORD *)(a4 + 8) = KeMaximumIncrement * (unsigned __int64)HIDWORD(Src.CurrentSize);
*(_QWORD *)(a4 + 24) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8099];
*(_QWORD *)(a4 + 32) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8100];
*(_QWORD *)a4 = KeMaximumIncrement * (unsigned __int64)LODWORD(Src.CurrentSize);
*(_DWORD *)(a4 + 40) = v43[8096];
if( InformationClass == SystemProcessorPerformanceInformationEx )
{
*(_QWORD *)(a4 + 48) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8107];
*(_DWORD *)(a4 + 44) = 0;
*(_QWORD *)(a4 + 56) = 0i64;
*(_QWORD *)(a4 + 64) = 0i64;
}
a4 += v41;
v42 = v137 + 1;
LODWORD(v13) = v136;
v14 = v128;
}
v44 = v129;
LABEL_91:
LODWORD(Size) = v44;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = v13 * v41;
break;
case SystemFlagsInformation:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)a4 = NtGlobalFlag;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemModuleInformation:
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
KeEnterCriticalRegion();
ExAcquireResourceExclusiveLite(&PsLoadedModuleResource, 1u);
ExpQueryModuleInformation(v57, (_DWORD *)a4, (unsigned int)Length, &Size);
goto LABEL_164;
case SystemLocksInformation:
if( (unsigned int)Length < 0x38 )
{
if( a6 )
*(_DWORD *)a6 = 56;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExpGetLockInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemStackTraceInformation:
if( (unsigned int)Length >= 0x128 )
goto LABEL_598;
if( a6 )
*(_DWORD *)a6 = 296;
return;
case SystemPagedPoolInformation:
case SystemNonPagedPoolInformation:
case SystemVdmInstemulInformation:
case SystemHotpatchInformation:
case SystemVirtualAddressInformation:
goto LABEL_598;
case SystemHandleInformation:
if( (unsigned int)Length >= 0x20 )
{
if( (a4 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExpGetHandleInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 32;
}
return;
case SystemObjectInformation:
if( (unsigned int)Length < 0x40 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExpGetObjectInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemPageFileInformation:
case SystemPageFileInformationEx:
v59 = 32;
if( v16 != SystemPageFileInformation )
v59 = 40;
LODWORD(Size) = v59;
if( (unsigned int)Length >= v59 )
{
LODWORD(Size) = 0;
LOBYTE(v8) = v16 == SystemPageFileInformationEx;
MmGetPageFileInformation((PVOID)0x28, a4, (unsigned int)Length, (UINT64 *)v8);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = v59;
return;
case SystemFileCacheInformation:
case SystemFileCacheInformationEx:
case SystemPagedPoolInformationEx:
case SystemSystemPtesInformationEx:
if( (unsigned int)Length < 0x40 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
v60 = 2;
if( v16 == SystemPagedPoolInformationEx )
{
v61 = WorkingSetTypePagedPool;
}
else
{
if( v16 == SystemSystemPtesInformationEx )
v60 = 4;
v61 = v60;
}
MmQuerySystemWorkingSetInformation(v61, &Src);
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
*(_DWORD *)(a4 + 16) = Src.PageFaultCount;
*(_QWORD *)(a4 + 24) = Src.MinimumWorkingSet;
*(_QWORD *)(a4 + 32) = Src.MaximumWorkingSet;
*(_QWORD *)(a4 + 40) = Src.CurrentSizeIncludingTransitionInPages;
*(_QWORD *)(a4 + 48) = Src.PeakSizeIncludingTransitionInPages;
*(_DWORD *)(a4 + 56) = Src.TransitionRePurposeCount;
*(_DWORD *)(a4 + 60) = Src.Flags;
LODWORD(Size) = 64;
goto LABEL_598;
case SystemPoolTagInformation:
if( (unsigned int)Length >= 0x30 )
{
ExGetPoolTagInfo((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 48;
return;
case SystemInterruptInformation:
LODWORD(Size) = 24 * v13;
if( (unsigned int)Length >= 24 * (int)v13 )
{
for( i = 0; i < (unsigned int)v13; ++i )
{
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)i;
v71 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
*(_DWORD *)a4 = v71[2895];
*(_DWORD *)(a4 + 4) = v71[3127];
*(_DWORD *)(a4 + 8) = v71[3143];
*(_DWORD *)(a4 + 12) = KeTimeIncrement;
*(_DWORD *)(a4 + 16) = 0;
*(_DWORD *)(a4 + 20) = 0;
a4 += 24i64;
LODWORD(v13) = v136;
v14 = v128;
}
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 24 * v13;
return;
case SystemDpcBehaviorInformation:
if( (_DWORD)Length == 20 )
{
*(_DWORD *)(a4 + 4) = KiMaximumDpcQueueDepth;
*(_DWORD *)(a4 + 8) = *(_DWORD *)KiMinimumDpcRate;
*(_DWORD *)(a4 + 12) = KiAdjustDpcThreshold;
*(_DWORD *)(a4 + 16) = KiIdealDpcRate;
goto LABEL_276;
}
if( a6 )
*(_DWORD *)a6 = 20;
return;
case SystemTimeAdjustmentInformation:
if( (_DWORD)Length != 12 && (_DWORD)Length != 24 )
{
if( a6 )
*(_DWORD *)a6 = 12;
return;
}
ExAcquireTimeRefreshLock(1u);
v51 = KeTimeAdjustmentFrequency;
v52 = KeTimeSynchronization;
ExReleaseTimeRefreshLock();
if( (_DWORD)Length == 24 )
{
*(_QWORD *)a4 = v51;
*(_QWORD *)(a4 + 8) = KUSER_SHARED_DATA.QpcFrequency;
*(_BYTE *)(a4 + 16) = v52;
}
else
{
*(_DWORD *)a4 = KUSER_SHARED_DATA.QpcFrequency * (unsigned __int64)KeMaximumIncrement / v51;
*(_DWORD *)(a4 + 4) = KeMaximumIncrement;
*(_BYTE *)(a4 + 8) = v52;
}
LABEL_119:
LODWORD(Size) = Length;
goto LABEL_598;
case SystemPerformanceTraceInformation:
EtwQueryPerformanceTraceInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
goto LABEL_598;
case SystemExceptionInformation:
if( (unsigned int)Length < 0x10 )
{
if( a6 )
*(_DWORD *)a6 = 16;
return;
}
LODWORD(Size) = 16;
v64 = 0;
v65 = 0;
if( (_DWORD)v13 )
{
v66 = &KiProcessorBlock;
v67 = (unsigned int)v13;
do
{
v64 += *((_DWORD *)*v66 + 8398);
v65 += *((_DWORD *)*v66++ + 8108);
--v67;
}
while( v67 );
}
*(_DWORD *)a4 = v64;
*(_DWORD *)(a4 + 4) = v65;
*(_DWORD *)(a4 + 8) = 0;
*(_DWORD *)(a4 + 12) = 0;
goto LABEL_598;
case SystemKernelDebuggerInformation:
if( (unsigned int)Length >= 2 )
{
*(_BYTE *)a4 = (_BYTE)KdDebuggerEnabled;
*(_BYTE *)(a4 + 1) = (_BYTE)KdDebuggerNotPresent;
LODWORD(Size) = 2;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 2;
return;
case SystemContextSwitchInformation:
if( (unsigned int)Length < 0x30 )
{
if( a6 )
*(_DWORD *)a6 = 48;
return;
}
if( (_DWORD)v13 )
{
v68 = &KiProcessorBlock;
v69 = (unsigned int)v13;
do
{
v8 += *((_DWORD *)*v68++ + 2895);
--v69;
}
while( v69 );
}
*(_DWORD *)a4 = v8;
*(_DWORD *)(a4 + 4) = KeThreadSwitchCounters;
*(_DWORD *)(a4 + 8) = dword_140C319C8;
*(_DWORD *)(a4 + 12) = dword_140C319C4;
*(_DWORD *)(a4 + 16) = dword_140C319CC;
*(_DWORD *)(a4 + 20) = dword_140C319D0;
*(_DWORD *)(a4 + 24) = dword_140C319D8;
*(_DWORD *)(a4 + 28) = dword_140C319D4;
*(_DWORD *)(a4 + 32) = dword_140C319DC;
*(_DWORD *)(a4 + 36) = dword_140C319E0;
*(_DWORD *)(a4 + 40) = dword_140C319E4;
*(_DWORD *)(a4 + 44) = dword_140C319E8;
LODWORD(Size) = 48;
goto LABEL_598;
case SystemRegistryQuotaInformation:
if( (unsigned int)Length >= 0x10 )
{
CmQueryRegistryQuotaInformation((_SYSTEM_REGISTRY_QUOTA_INFORMATION *)a4);
LODWORD(Size) = 16;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 16;
return;
case SystemProcessorIdleInformation:
LODWORD(Size) = 48 * v13;
if( (unsigned int)Length >= 48 * (int)v13 )
{
while( v8 < (unsigned int)v13 )
{
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)v8;
PoGetIdleTimes((PROCESSOR_NUMBER *)&ProcNumber, (INT64)&Src, 0i64);
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
*(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
*(_OWORD *)(a4 + 32) = *(_OWORD *)&Src.MaximumWorkingSet;
a4 += 48i64;
++v8;
LODWORD(v13) = v136;
v14 = v128;
}
}
goto LABEL_598;
case SystemLegacyDriverInformation:
if( (unsigned int)Length >= 0x18 )
{
LODWORD(Size) = Length;
ExpQueryLegacyDriverInformation(a4, &Size);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 24;
return;
case SystemCurrentTimeZoneInformation:
if( (unsigned int)Length >= 0xAC )
{
v72 = PsGetCurrentServerSiloGlobals()[133];
ExAcquireTimeRefreshLock(1u);
Src = *(_SYSTEM_FILECACHE_INFORMATION *)v72;
v161 = *(_OWORD *)(v72 + 64);
v162 = *(_OWORD *)(v72 + 80);
v163 = *(_OWORD *)(v72 + 96);
v164 = *(_OWORD *)(v72 + 112);
v165 = *(_OWORD *)(v72 + 128);
v166 = *(_OWORD *)(v72 + 144);
v167 = *(_QWORD *)(v72 + 160);
v168 = *(_DWORD *)(v72 + 168);
ExReleaseTimeRefreshLock();
*(_SYSTEM_FILECACHE_INFORMATION *)a4 = Src;
*(_OWORD *)(a4 + 64) = v161;
*(_OWORD *)(a4 + 80) = v162;
*(_OWORD *)(a4 + 96) = v163;
*(_OWORD *)(a4 + 112) = v164;
*(_OWORD *)(a4 + 128) = v165;
*(_OWORD *)(a4 + 144) = v166;
*(_QWORD *)(a4 + 160) = v167;
*(_DWORD *)(a4 + 168) = v168;
LODWORD(Size) = 172;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 172;
return;
case SystemLookasideInformation:
ExpGetLookasideInformation((VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemRangeStartInformation:
if( (_DWORD)Length == 8 )
{
*(_QWORD *)a4 = 0xFFFF800000000000ui64;
goto LABEL_114;
}
if( a6 )
*(_DWORD *)a6 = 8;
return;
case SystemVerifierInformation:
if( (unsigned int)Length >= 0x90 )
{
VfGetVerifierInformation((PVOID)a4, (unsigned int)Length, &Size, 0i64);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 144;
return;
case SystemSessionProcessInformation:
if( (unsigned int)Length >= 0x10 )
{
LODWORD(SessionId) = *(_DWORD *)a4;
v155 = *(VOID **)(a4 + 8);
v140 = *(_DWORD *)(a4 + 4);
ProbeForWrite(v155, v140, 4ui64);
ExpGetProcessInformation(v155, v140, &Size, &SessionId, SystemProcessInformation);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 16;
return;
case SystemNumaProcessorMap:
ExpQueryNumaProcessorMap((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemPrefetcherInformation:
PfSnQueryPrefetcherInformation((PVOID)0x140000000i64, a4, Length, (UINT64 *)v9);
goto LABEL_598;
case SystemRecommendedSharedDataAlignment:
if( (unsigned int)Length >= 4 )
{
*(_DWORD *)a4 = KeGetRecommendedSharedDataAlignment();
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemComPlusPackage:
if( (_DWORD)Length == 4 )
{
if( KUSER_SHARED_DATA.ComPlusPackage != -1 || (int)ExpReadComPlusPackage() >= 0 )
{
*(_DWORD *)a4 = KUSER_SHARED_DATA.ComPlusPackage;
LODWORD(Size) = 4;
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 4;
}
return;
case SystemNumaAvailableMemory:
ExpQueryNumaAvailableMemory((VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemProcessorPowerInformation:
LODWORD(Size) = 80 * v13;
if( (unsigned int)Length >= 80 * (int)v13 )
{
while( v8 < (unsigned int)v13 )
{
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)v8;
v49 = (__int64)*(&KiProcessorBlock
+ (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
PoGetPerfStateAndParkingInfo((PROCESSOR_NUMBER *)&ProcNumber, (INT64)&Src, 0i64, &v154);
*(_OWORD *)a4 = 0i64;
*(_OWORD *)(a4 + 16) = 0i64;
*(_OWORD *)(a4 + 32) = 0i64;
*(_OWORD *)(a4 + 48) = 0i64;
*(_OWORD *)(a4 + 64) = 0i64;
*(_QWORD *)(a4 + 40) = KeMaximumIncrement
* (unsigned __int64)(unsigned int)(*(_DWORD *)(v49 + 32388) + *(_DWORD *)(v49 + 32392));
*(_QWORD *)(a4 + 48) = KeMaximumIncrement
* (unsigned __int64)*(unsigned int *)(*(_QWORD *)(v49 + 24) + 652i64);
if( BYTE4(Src.MinimumWorkingSet) )
{
*(_BYTE *)a4 = Src.PeakSize;
*(_BYTE *)(a4 + 7) = BYTE4(Src.PeakSize);
*(_BYTE *)(a4 + 8) = Src.PageFaultCount;
*(_DWORD *)(a4 + 12) = 1;
}
*(_QWORD *)(a4 + 72) = v154;
a4 += 80i64;
v145 = (_QWORD *)a4;
++v8;
LODWORD(v13) = v136;
v14 = v128;
}
}
goto LABEL_598;
case SystemEmulationBasicInformation:
if( (_DWORD)Length != 64 )
{
if( a6 )
*(_DWORD *)a6 = 64;
return;
}
ExpGetSystemEmulationBasicInformation(a4, v20, v15, v13);
LABEL_597:
LODWORD(Size) = 64;
goto LABEL_598;
case SystemEmulationProcessorInformation:
if( (unsigned int)Length >= 0xC )
{
ExpGetSystemEmulationProcessorInformation(a4);
LODWORD(Size) = 12;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 12;
return;
case SystemExtendedHandleInformation:
if( (unsigned int)Length >= 0x38 )
{
if( (a4 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExpGetHandleInformationEx((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 56;
}
return;
case SystemLostDelayedWriteInformation:
if( (unsigned int)Length < 4 )
{
if( a6 )
*(_DWORD *)a6 = 4;
return;
}
if( (_DWORD)v13 )
{
v78 = &KiProcessorBlock;
v79 = (unsigned int)v13;
do
{
v8 += *((_DWORD *)*v78++ + 8175);
--v79;
}
while( v79 );
}
*(_DWORD *)a4 = v8;
goto LABEL_157;
case SystemBigPoolInformation:
if( (unsigned int)Length < 0x20 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
ExGetBigPoolInfo((PVOID)a4, (unsigned int)Length, 1ui64, &Size);
goto LABEL_598;
case SystemSessionPoolTagInformation:
if( (unsigned int)Length < 0x10 )
{
if( a6 )
*(_DWORD *)a6 = 16;
return;
}
LODWORD(SessionId) = *(_DWORD *)a4;
v155 = *(VOID **)(a4 + 8);
v62 = *(unsigned int *)(a4 + 4);
v140 = *(_DWORD *)(a4 + 4);
if( ((unsigned __int8)v155 & 7) != 0 )
return;
ExGetSessionPoolTagInformation(v155, v62, &Size, &SessionId);
goto LABEL_598;
case SystemSessionMappedViewInformation:
if( (unsigned int)Length < 0x20 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
LODWORD(SessionId) = *(_DWORD *)(a4 + 8);
if( (a4 & 7) != 0 )
return;
MmGetSessionMappedViewInformation((VOID *)a4, (unsigned int)Length, &Size, &SessionId);
goto LABEL_598;
case SystemObjectSecurityMode:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)a4 = ObpObjectSecurityMode;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemWatchdogTimerInformation:
if( (_DWORD)Length != 8 )
return;
v80 = (unsigned int)(v15 - 7);
if( (_DWORD)v80 )
{
if( (_DWORD)v80 != 1 )
return;
*(_DWORD *)a4 = 8;
*(_DWORD *)(a4 + 4) = ((unsigned __int8(__fastcall *)(unsigned __int64, UINT64, __int64, __int64))off_140C008D0[0])(
0x140000000ui64,
v20,
v80,
v13);
}
else
{
*(_DWORD *)a4 = 7;
LOBYTE(v8) = off_140C008D8[0] != (__int64(__fastcall *)())xKdEnumerateDebuggingDevices;
*(_DWORD *)(a4 + 4) = v8;
}
goto LABEL_114;
case SystemLogicalProcessorInformation:
KeBuildLogicalProcessorSystemInformation(v14, a4, (unsigned int)Length, (UINT64)&Size);
HIDWORD(Size) = v81;
goto LABEL_598;
case SystemFirmwareTableInformation:
ExpGetSystemFirmwareTableInformation((PVOID)a4, v9, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemModuleInformationEx:
if( (unsigned int)ExIsRestrictedCaller(v9) )
return;
if( SeSinglePrivilegeCheck(*(_QWORD *)&SeLoadDriverPrivilege, v9) )
v10 = 0;
KeEnterCriticalRegion();
ExAcquireResourceExclusiveLite(&PsLoadedModuleResource, 1u);
ExpQueryModuleInformationEx(v58, (_WORD *)a4, (unsigned int)Length, v10, &Size);
LABEL_164:
ExReleaseResourceLite(&PsLoadedModuleResource);
KeLeaveCriticalRegion();
goto LABEL_598;
case SystemSuperfetchInformation:
PfQuerySuperfetchInformation(
(_SYSTEM_INFORMATION_CLASS)0x140000000ui64,
(PVOID)a4,
(unsigned int)Length,
v9,
&Size);
goto LABEL_598;
case SystemMemoryListInformation:
MmQueryMemoryListInformation((PVOID)0xFFFFFFFFFFFFFFFFi64, a4, (UINT64 *)(unsigned int)Length);
goto LABEL_598;
case SystemProcessorIdleCycleTimeInformation:
LODWORD(Size) = 8 * v13;
if( (unsigned int)Length >= 8 )
{
v84 = (unsigned int)Length >> 3;
if( (unsigned int)Length >= 8 * (int)v13 )
v84 = v13;
v145 = (_QWORD *)a4;
KeFlushProcessWriteBuffers(1u);
for( j = v128; ; j = WORD2(ProcNumber) )
{
v129 = v8;
if( v8 >= v84 )
break;
LOWORD(ProcNumber) = j;
WORD1(ProcNumber) = (unsigned __int8)v8;
v86 = *(_QWORD *)(*((_QWORD *)*(&KiProcessorBlock
+ (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber))
+ 3)
+ 72i64);
v87 = v145;
*v145 = v86;
v145 = v87 + 1;
v8 = v129 + 1;
}
}
goto LABEL_598;
case SystemRefTraceInformation:
ObQueryRefTraceInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemSpecialPoolInformation:
LODWORD(Size) = 8;
if( (_DWORD)Length == 8 )
{
*(_DWORD *)a4 = MmSpecialPoolTag;
LOBYTE(v8) = MmSpecialPoolCatchOverruns != 0;
*(_DWORD *)(a4 + 4) = v8;
}
goto LABEL_598;
case SystemProcessIdInformation:
LODWORD(Size) = 24;
if( (_DWORD)Length != 24 )
goto LABEL_598;
*(_OWORD *)ProcessId = *(_OWORD *)a4;
v153 = *(char **)(a4 + 16);
if( LOWORD(ProcessId[1]) || (BYTE2(ProcessId[1]) & 1) != 0 )
return;
if( v9 && WORD1(ProcessId[1]) )
{
if( ((unsigned __int8)v153 & 1) != 0 )
ExRaiseDatatypeMisalignment();
v53 = &v153[WORD1(ProcessId[1])];
if( (unsigned __int64)v53 > 0x7FFFFFFF0000i64 || v53 < v153 )
MEMORY[0x7FFFFFFF0000] = 0;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v144 = WORD1(ProcessId[1]);
KeEnterCriticalRegionThread((_KTHREAD *)CurrentThread);
if( PsLookupProcessByProcessId(ProcessId[0], (PEPROCESS *)&Process) < 0 )
{
KeLeaveCriticalRegionThread((__int64)CurrentThread);
return;
}
v55 = PsQueryFullProcessImageName((__int64)Process, (_OWORD *)(a4 + 8), v153, &v144);
ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
KeLeaveCriticalRegionThread((__int64)CurrentThread);
if( v55 == -1073741820 )
*(_WORD *)(a4 + 10) = v144;
goto LABEL_598;
case SystemBootEnvironmentInformation:
LODWORD(Size) = 32;
if( (unsigned int)Length < 0x14 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
*(_OWORD *)a4 = ExpBootEnvironmentInformation;
*(_DWORD *)(a4 + 16) = dword_140C19650;
if( (unsigned int)Length < (unsigned int)Size )
LABEL_276:
LODWORD(Size) = 20;
else
*(_QWORD *)(a4 + 24) = qword_140C19658;
goto LABEL_598;
case SystemHypervisorInformation:
HvlQueryEnlightenmentInfo((PVOID)a4, (unsigned int)Length, v9, &Size);
goto LABEL_598;
case SystemVerifierInformationEx:
if( (_DWORD)Length != 40 )
{
if( a6 )
*(_DWORD *)a6 = 40;
return;
}
if( (int)VfGetVerifierInformationEx(a4) >= 0 )
v8 = 40;
LODWORD(Size) = v8;
goto LABEL_598;
case SystemCoverageInformation:
if( !v9 || !SeSinglePrivilegeCheck(*(_QWORD *)&SeDebugPrivilege, v9) )
return;
if( (unsigned int)Length >= 0x40 )
{
ExpCovQueryInformation(a4, Length, (unsigned int *)&Size);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 64;
return;
case SystemSystemPartitionInformation:
IoQuerySystemDeviceName(
SystemSystemPartitionInformation,
(VOID *)a4,
(unsigned int)Length,
(UINT *)&Size,
(INT64)Object,
(INT64)HandleInformation,
Size,
ProcNumber);
goto LABEL_598;
case SystemSystemDiskInformation:
IoQuerySystemDeviceName(
SystemSystemDiskInformation,
(VOID *)a4,
(unsigned int)Length,
(UINT *)&Size,
(INT64)Object,
(INT64)HandleInformation,
Size,
ProcNumber);
goto LABEL_598;
case SystemProcessorPerformanceDistribution:
WORD4(v158) = v14;
*(_QWORD *)&v158 = KeQueryGroupAffinity(v14);
v45 = (0x101010101010101i64
* (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ ((((unsigned __int64)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
+ (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ ((((unsigned __int64)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 56;
if( (unsigned int)PpmCapturePerformanceDistribution(
0i64,
0,
(unsigned int)((0x101010101010101i64
* (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ ((((unsigned __int64)v158
- (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
+ (((((_QWORD)v158
- (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
+ ((((unsigned __int64)v158
- (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 32) >> 24,
(__int64)&v158,
(unsigned int *)&InputBufferLength + 1) != -1073741820 )
goto LABEL_598;
v46 = HIDWORD(InputBufferLength);
if( HIDWORD(InputBufferLength) > (unsigned int)Length )
goto LABEL_96;
PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(NonPagedPoolNx, HIDWORD(InputBufferLength), 0x744D5050ui64);
v48 = PoolWithTag;
InputBuffer = PoolWithTag;
if( PoolWithTag )
{
memset((INT64)PoolWithTag, 0i64);
if( (int)PpmCapturePerformanceDistribution(
v48,
HIDWORD(InputBufferLength),
v45,
(__int64)&v158,
(unsigned int *)&Size) >= 0 )
memmove((UINT8 *)a4, v48, (unsigned int)Size);
ExFreePoolWithTag(v48, 0x744D5050u);
}
goto LABEL_598;
case SystemNumaProximityNodeInformation:
ExpQueryNumaProximityNode((VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemDynamicTimeZoneInformation:
if( (unsigned int)Length >= 0x1B0 )
{
v73 = (_OWORD *)PsGetCurrentServerSiloGlobals()[133];
ExAcquireTimeRefreshLock(1u);
p_Src = &Src;
v75 = 3i64;
v76 = 3i64;
do
{
*(_OWORD *)&p_Src->CurrentSize = *v73;
*(_OWORD *)&p_Src->PageFaultCount = v73[1];
*(_OWORD *)&p_Src->MaximumWorkingSet = v73[2];
*(_OWORD *)&p_Src->PeakSizeIncludingTransitionInPages = v73[3];
*(_OWORD *)&p_Src[1].CurrentSize = v73[4];
*(_OWORD *)&p_Src[1].PageFaultCount = v73[5];
*(_OWORD *)&p_Src[1].MaximumWorkingSet = v73[6];
p_Src += 2;
*(_OWORD *)&p_Src[-1].PeakSizeIncludingTransitionInPages = v73[7];
v73 += 8;
--v76;
}
while( v76 );
*(_OWORD *)&p_Src->CurrentSize = *v73;
*(_OWORD *)&p_Src->PageFaultCount = v73[1];
*(_OWORD *)&p_Src->MaximumWorkingSet = v73[2];
ExReleaseTimeRefreshLock();
v77 = &Src;
do
{
*(_OWORD *)a4 = *(_OWORD *)&v77->CurrentSize;
*(_OWORD *)(a4 + 16) = *(_OWORD *)&v77->PageFaultCount;
*(_OWORD *)(a4 + 32) = *(_OWORD *)&v77->MaximumWorkingSet;
*(_OWORD *)(a4 + 48) = *(_OWORD *)&v77->PeakSizeIncludingTransitionInPages;
*(_OWORD *)(a4 + 64) = *(_OWORD *)&v77[1].CurrentSize;
*(_OWORD *)(a4 + 80) = *(_OWORD *)&v77[1].PageFaultCount;
*(_OWORD *)(a4 + 96) = *(_OWORD *)&v77[1].MaximumWorkingSet;
a4 += 128i64;
*(_OWORD *)(a4 - 16) = *(_OWORD *)&v77[1].PeakSizeIncludingTransitionInPages;
v77 += 2;
--v75;
}
while( v75 );
*(_OWORD *)a4 = *(_OWORD *)&v77->CurrentSize;
*(_OWORD *)(a4 + 16) = *(_OWORD *)&v77->PageFaultCount;
*(_OWORD *)(a4 + 32) = *(_OWORD *)&v77->MaximumWorkingSet;
LODWORD(Size) = 432;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 432;
return;
case SystemCodeIntegrityInformation:
SeCodeIntegrityQueryInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemProcessorBrandString:
if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
23i64,
0i64,
0i64,
(char *)&InputBufferLength + 4) != -1073741820 )
goto LABEL_598;
v90 = HIDWORD(InputBufferLength);
if( (unsigned int)Length < HIDWORD(InputBufferLength) || !a4 )
{
LODWORD(Size) = HIDWORD(InputBufferLength);
goto LABEL_598;
}
if( v9 )
{
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
InputBuffer = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
v90 = HIDWORD(InputBufferLength);
}
else
{
PoolWithQuotaTag = (_DWORD *)a4;
InputBuffer = (VOID *)a4;
}
v92 = ((__int64(__fastcall *)(__int64, __int64, _DWORD *, size_t *))off_140C00A68[0])(
23i64,
v90,
PoolWithQuotaTag,
&Size);
if( !v9 )
goto LABEL_598;
if( v92 < 0 )
goto LABEL_419;
goto LABEL_418;
case SystemLogicalProcessorAndGroupInformation:
LODWORD(Size) = Length;
HIDWORD(Size) = KeQueryLogicalProcessorRelationship(
0i64,
RelationshipType,
(_SYSTEM_LOGICAL_PROCESSOR_INFORMATION_EX *)a4,
&Size);
goto LABEL_598;
case SystemProcessorCycleTimeInformation:
LODWORD(Size) = 8 * v13;
if( (unsigned int)Length >= 8 )
{
v89 = (unsigned int)Length >> 3;
if( (unsigned int)Length >= 8 * (int)v13 )
v89 = v13;
while( v8 < v89 )
{
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)v8;
*(_QWORD *)a4 = *((_QWORD *)*(&KiProcessorBlock
+ (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber))
+ 4071);
a4 += 8i64;
v145 = (_QWORD *)a4;
++v8;
v14 = v128;
}
}
goto LABEL_598;
case SystemStoreInformation:
SmQueryStoreInformation((PVOID)0x140000000i64, a4, Length, (UINT64 *)v9);
goto LABEL_598;
case SystemVhdBootInformation:
IoQueryVhdBootInformation((VOID *)0x140000000i64, a4, (UINT64 *)(unsigned int)Length);
goto LABEL_598;
case SystemCpuQuotaInformation:
PsQueryCpuQuotaInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
goto LABEL_598;
case SystemErrorPortTimeouts:
if( !(_DWORD)v20 )
{
LODWORD(Size) = 8;
if( (unsigned int)Length >= 8 )
{
*(_DWORD *)a4 = DbgkErrorPortStartTimeout;
*(_DWORD *)(a4 + 4) = DbgkErrorPortCommTimeout;
}
}
goto LABEL_598;
case SystemLowPriorityIoInformation:
IoQueryLowPriorityIoInformation(
(_SYSTEM_INFORMATION_CLASS)0x140000000ui64,
(VOID *)a4,
(unsigned int)Length,
&Size);
goto LABEL_598;
case SystemBootEntropyInformation:
LODWORD(Size) = 1096;
if( (_DWORD)Length != 1096 )
goto LABEL_598;
if( v9 )
return;
ExQueryBootEntropyInformation(a4);
goto LABEL_598;
case SystemVerifierCountersInformation:
if( (unsigned int)Length >= 0x110 )
{
VfGetVerifierInformation((PVOID)a4, (unsigned int)Length, &Size, 1ui64);
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 272;
return;
case SystemNodeDistanceInformation:
LODWORD(Size) = 4 * (unsigned __int16)KeNumberNodes;
if( (unsigned int)Length >= (unsigned int)Size )
{
v129 = 0;
v82 = 0;
v83 = v135;
while( v82 < (unsigned __int16)KeNumberNodes )
{
*(_DWORD *)(a4 + 4i64 * v82++) = *(_DWORD *)(*(_QWORD *)KeNodeDistance
+ 4i64 * (v8 + v83 * (unsigned __int16)KeNumberNodes));
v8 = v82;
v129 = v82;
}
}
goto LABEL_598;
case SystemAcpiAuditInformation:
LODWORD(Size) = 8;
if( (_DWORD)Length != 8 )
goto LABEL_598;
if( !a4 )
goto LABEL_598;
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, 8ui64, 0x6F666E49ui64);
v147 = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
if( ((int(__fastcall *)(__int64, __int64, _DWORD *, size_t *))off_140C00A68[0])(
26i64,
8i64,
PoolWithQuotaTag,
&Size) >= 0 )
{
*(_DWORD *)a4 = *PoolWithQuotaTag;
*(_DWORD *)(a4 + 4) ^= (PoolWithQuotaTag[1] ^ *(_DWORD *)(a4 + 4)) & 1;
v93 = *(_DWORD *)(a4 + 4) ^ ((unsigned __int8)*(_DWORD *)(a4 + 4) ^ (unsigned __int8)PoolWithQuotaTag[1]) & 2;
*(_DWORD *)(a4 + 4) = v93;
*(_DWORD *)(a4 + 4) = v93 ^ (PoolWithQuotaTag[1] ^ v93) & 4;
}
goto LABEL_419;
case SystemBasicPerformanceInformation:
if( (_DWORD)Length != 32 )
{
if( a6 )
*(_DWORD *)a6 = 32;
return;
}
CurrentProcess = PsGetCurrentProcess();
ProcessPartitionId = MmGetProcessPartitionId(CurrentProcess);
Src.CurrentSize = MmGetAvailablePages(ProcessPartitionId);
Src.PeakSize = MmGetTotalCommittedPages(v37);
*(_QWORD *)&Src.PageFaultCount = MmGetTotalCommitLimit(v38);
Src.MinimumWorkingSet = MmGetPeakCommitment(v39);
MinimumWorkingSet = Src.MinimumWorkingSet;
if( Src.MinimumWorkingSet < Src.PeakSize )
MinimumWorkingSet = Src.PeakSize;
Src.MinimumWorkingSet = MinimumWorkingSet;
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
*(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
LODWORD(Size) = 32;
goto LABEL_598;
case SystemQueryPerformanceCounterInformation:
LODWORD(Size) = 12;
if( (unsigned int)Length >= 4 )
{
v159 = *(_DWORD *)a4;
if( v159 == 1 && (unsigned int)Length >= 0xC )
{
*(_DWORD *)(a4 + 8) = 0;
*(_DWORD *)(a4 + 4) = 0;
*(_DWORD *)(a4 + 8) |= 1u;
*(_DWORD *)(a4 + 4) |= 1u;
if( KUSER_SHARED_DATA.QpcBypassEnabled )
*(_DWORD *)(a4 + 4) &= ~1u;
}
}
goto LABEL_598;
case SystemSessionBigPoolInformation:
if( (unsigned int)Length >= 0x10 )
{
LODWORD(SessionId) = *(_DWORD *)a4;
v155 = *(VOID **)(a4 + 8);
v63 = *(_DWORD *)(a4 + 4);
v140 = v63;
if( ((unsigned __int8)v155 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
{
ExGetSessionBigPoolInformation(v155, v63, &Size, &SessionId);
goto LABEL_598;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 16;
}
return;
case SystemBootGraphicsInformation:
LODWORD(Size) = 32;
if( (_DWORD)Length == 32 && (int)BgkQueryBootGraphicsInformation(0i64, &Src) >= 0 )
{
CurrentSize = Src.CurrentSize;
if( v9 )
CurrentSize = 0i64;
Src.CurrentSize = CurrentSize;
memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Size);
}
goto LABEL_598;
case SystemBadPageInformation:
if( !(_DWORD)v20 )
{
v97 = MmEnumerateBadPages((UINT64 **)&v149);
v98 = v149;
if( v149 )
v8 = 8 * *(_DWORD *)v149;
LODWORD(Size) = v8;
if( (unsigned int)Length < v8 )
v97 = -1073741820;
if( v149 )
{
if( v97 >= 0 )
memmove((UINT8 *)a4, (UINT8 *)v149 + 8, v8);
ExFreePoolWithTag(v98, 0);
}
}
goto LABEL_598;
case SystemPlatformBinaryInformation:
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
return;
ExpGetSystemPlatformBinary((VOID *)a4, (unsigned int)Length, v9);
goto LABEL_598;
case SystemPolicyInformation:
LODWORD(Size) = 32;
if( (_DWORD)Length == 32 )
ExHandleSPCall2(0x140000000ui64, a4);
goto LABEL_598;
case SystemHypervisorProcessorCountInformation:
LODWORD(Size) = 8;
if( (unsigned int)Length >= 8 )
{
HvlQueryActiveProcessors(&Count, 0i64);
if( !v99 && !HvlQueryProcessorTopologyCount(0i64, (UINT64 *)((char *)&Count + 4)) )
*(_QWORD *)a4 = Count;
}
goto LABEL_598;
case SystemDeviceDataInformation:
case SystemDeviceDataEnumerationInformation:
if( (_DWORD)Length == 48 )
{
ExpGetDeviceDataInformation(v16, (VOID *)a4, 0x30ui64);
}
else if( a6 )
{
*(_DWORD *)a6 = 48;
}
return;
case SystemMemoryTopologyInformation:
ExpQueryMemoryTopologyInformation((VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemMemoryChannelInformation:
ExpQueryChannelInformation((VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemBootLogoInformation:
if( (a6 || (unsigned int)Length >= 8) && (int)BgkQueryBootGraphicsInformation(2i64, &Size) >= 0 )
{
if( (_DWORD)Size )
{
if( (unsigned int)Length >= (unsigned int)Size && (int)BgkQueryBootGraphicsInformation(1i64, &P) >= 0 )
{
v95 = P;
if( P )
{
memmove((UINT8 *)a4, (UINT8 *)P, (unsigned int)Size);
ExFreePoolWithTag(v95, 0x4B494742u);
}
}
}
}
goto LABEL_598;
case SystemSecureBootPolicyInformation:
case SystemSecureBootInformation:
case SystemSecureBootPolicyFullInformation:
case SystemCodeIntegrityPlatformManifestInformation:
SeSecureBootQueryInformation(v16, (VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemPortableWorkspaceEfiLauncherInformation:
ExpQueryPortableWorkspaceEfiLauncherInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemKernelDebuggerInformationEx:
if( (unsigned int)Length >= 3 )
{
*(_BYTE *)a4 = KdpBootedNodebug == 0;
*(_BYTE *)(a4 + 1) = (_BYTE)KdDebuggerEnabled;
*(_BYTE *)(a4 + 2) = (_BYTE)KdDebuggerNotPresent == 0;
v10 = 3;
goto LABEL_256;
}
if( a6 )
*(_DWORD *)a6 = 3;
return;
case SystemBootMetadataInformation:
if( !ExBootLoaderMetadata )
goto LABEL_598;
v96 = *(_DWORD *)ExBootLoaderMetadata;
LODWORD(Size) = *(_DWORD *)ExBootLoaderMetadata;
if( !a4 || (unsigned int)Length < v96 )
goto LABEL_598;
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
return;
memmove((UINT8 *)a4, (UINT8 *)(ExBootLoaderMetadata + 4), (unsigned int)Size);
goto LABEL_598;
case SystemSoftRebootInformation:
LODWORD(Size) = 4;
if( (unsigned int)Length >= 4 )
{
*(_DWORD *)a4 = ExSoftRebootFlags;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemOfflineDumpConfigInformation:
if( !(_DWORD)v20 )
{
LODWORD(Size) = 32;
if( (unsigned int)Length < 0x20 )
{
if( (unsigned int)Length < 0xC )
{
HIDWORD(Size) = -1073741820;
}
else
{
LODWORD(Size) = 12;
*(_QWORD *)a4 = PoOffCrashConfigTable;
*(_DWORD *)(a4 + 8) = DWORD2(PoOffCrashConfigTable);
}
}
else
{
*(_QWORD *)a4 = PoOffCrashConfigTable;
*(_DWORD *)(a4 + 8) = DWORD2(PoOffCrashConfigTable);
*(_QWORD *)(a4 + 16) = xmmword_140C24E30;
*(_DWORD *)(a4 + 24) = DWORD2(xmmword_140C24E30);
}
}
goto LABEL_598;
case SystemProcessorFeaturesInformation:
if( (unsigned int)Length >= 0x20 )
{
ExpGetSystemProcessorFeaturesInformation((_QWORD *)a4);
LODWORD(Size) = 32;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 32;
return;
case SystemEdidInformation:
LODWORD(Size) = 128;
if( (_DWORD)Length == 128 && (int)BgkQueryBootGraphicsInformation(3i64, &Src) >= 0 )
memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Size);
goto LABEL_598;
case SystemManufacturingInformation:
LODWORD(Size) = WORD5(ExpManufacturingInformation) + 24;
if( (unsigned int)Length >= (unsigned int)Size )
{
v100 = (UINT8 *)(a4 + 24);
*(_OWORD *)a4 = 0i64;
*(_QWORD *)(a4 + 16) = 0i64;
*(_DWORD *)a4 = ExpManufacturingInformation;
*(_DWORD *)(a4 + 8) = DWORD2(ExpManufacturingInformation);
if( WORD4(ExpManufacturingInformation) )
{
*(_QWORD *)(a4 + 16) = v100;
memmove(v100, (UINT8 *)Data, WORD5(ExpManufacturingInformation));
}
}
goto LABEL_598;
case SystemEnergyEstimationConfigInformation:
LODWORD(Size) = 1;
if( (_DWORD)Length )
{
*(_BYTE *)a4 = PoEnergyEstimationEnabled();
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
case SystemHypervisorDetailInformation:
HvlQueryDetailInfo((PVOID)a4, (unsigned int)Length, (UINT64 *)v15);
goto LABEL_598;
case SystemProcessorCycleStatsInformation:
LODWORD(Size) = (_DWORD)v13 << 6;
if( (unsigned int)Length >= 0x40 )
{
v101 = (unsigned int)Length >> 6;
if( (unsigned int)Length >= (_DWORD)v13 << 6 )
v101 = v13;
while( v8 < v101 )
{
LOWORD(ProcNumber) = v14;
WORD1(ProcNumber) = (unsigned __int8)v8;
v102 = (INT64)*(&KiProcessorBlock
+ (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
KeQueryCycleTimeStatsProcessor(v102, (_QWORD *)a4);
a4 += 64i64;
v145 = (_QWORD *)a4;
++v8;
v14 = v128;
}
}
goto LABEL_598;
case SystemTrustedPlatformModuleInformation:
SeQueryTrustedPlatformModuleInformation((PVOID)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemKernelDebuggerFlags:
if( !(_DWORD)Length )
{
if( a6 )
*(_DWORD *)a6 = 1;
return;
}
*(_BYTE *)a4 = KdIgnoreUmExceptions;
LABEL_256:
LODWORD(Size) = v10;
goto LABEL_598;
case SystemCodeIntegrityPolicyInformation:
case SystemCodeIntegrityPolicyFullInformation:
case SystemCodeIntegrityPoliciesFullInformation:
case SystemCodeIntegrityUnlockInformation:
case SystemCodeIntegrityVerificationInformation:
case SystemCodeIntegritySyntheticCacheInformation:
SeCodeIntegrityQueryPolicyInformation((unsigned int)v16);
goto LABEL_598;
case SystemIsolatedUserModeInformation:
LODWORD(Size) = 16;
if( (_DWORD)Length == 16 )
{
LOBYTE(Src.CurrentSize) ^= (LOBYTE(Src.CurrentSize) ^ (16 * ExpFirmwarePageProtectionSupported)) & 0x10;
if( VslIsSecureKernelRunning() )
{
v130[0] = 0;
LOBYTE(Src.CurrentSize) = v103 | 1;
NestedPageProtectionFlags = VslGetNestedPageProtectionFlags();
v107 = Src.CurrentSize;
if( (NestedPageProtectionFlags & 2) != 0 )
{
v107 = LOBYTE(Src.CurrentSize) | 2;
LOBYTE(Src.CurrentSize) |= 2u;
}
if( (NestedPageProtectionFlags & 0x20) != 0 )
{
v107 |= 4u;
LOBYTE(Src.CurrentSize) = v107;
}
if( (NestedPageProtectionFlags & 0x10) != 0 )
LOBYTE(Src.CurrentSize) = v107 | 8;
if( (NestedPageProtectionFlags & 0x200) != 0 )
BYTE1(Src.CurrentSize) |= 2u;
v108 = a1;
if( a1 )
{
VslIsTrustletRunning(a1, v130);
v108 = BYTE1(Src.CurrentSize);
LOBYTE(v108) = (v130[0] ^ BYTE1(Src.CurrentSize)) & 1 ^ BYTE1(Src.CurrentSize);
BYTE1(Src.CurrentSize) = v108;
}
IsIumEncryptionKeyAvailable = ExpIsIumEncryptionKeyAvailable(v108, v105, v106);
LOBYTE(Src.CurrentSize) ^= (LOBYTE(Src.CurrentSize) ^ (32 * IsIumEncryptionKeyAvailable)) & 0x20;
}
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
}
else if( a6 )
{
*(_DWORD *)a6 = 16;
}
goto LABEL_598;
case SystemHardwareSecurityTestInterfaceResultsInformation:
SeQueryHSTIResults();
goto LABEL_598;
case SystemSingleModuleInformation:
ExpQuerySingleModuleInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
goto LABEL_598;
case SystemVsmProtectionInformation:
HvlQueryVsmProtectionInfo((UINT8 *)a4, (unsigned int)Length, (UINT8 *)&Size);
goto LABEL_598;
case SystemAffinitizedInterruptProcessorInformation:
if( ExCpuSetResourceManagerAccessCheck(v9) < 0 )
return;
LODWORD(Size) = 168;
if( (_DWORD)Length == 168 )
KeGetAffinitizedInterruptsInfo((_KAFFINITY_EX *)a4, v116);
goto LABEL_598;
case SystemRootSiloInformation:
PsRootSiloInformation((_DWORD *)a4, Length, (unsigned int *)&Size);
goto LABEL_598;
case SystemCpuSetInformation:
if( Handle )
{
v156 = 0i64;
v117 = ObReferenceObjectByHandle(Handle, 0x1000u, (POBJECT_TYPE)PsProcessType, v9, &v156, 0i64);
v118 = (struct _DMA_ADAPTER *)v156;
if( v117 < 0 )
return;
}
else
{
v118 = (struct _DMA_ADAPTER *)Process;
}
KeQueryCpuSetInformation(a4, (unsigned int)Length, (INT64)&Size, (INT64)v118);
goto LABEL_545;
case SystemSecureKernelProfileInformation:
if( !(_DWORD)Length )
goto LABEL_598;
if( v9 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemProfilePrivilege, v9) )
return;
v119 = (UINT8 *)ExAllocatePoolWithQuotaTag((POOL_TYPE)520, (unsigned int)Length, 0x6F666E49ui64);
v120 = v119;
InputBuffer = v119;
if( v119 )
{
memset((INT64)v119, 0i64);
if( (int)VslQuerySecureKernelProfileInformation(v157, (INT64)v120, (unsigned int)Length, &Size) >= 0 )
memmove((UINT8 *)a4, v120, (unsigned int)Size);
ExFreePoolWithTag(v120, 0x6F666E49u);
}
goto LABEL_598;
case SystemInterruptSteeringInformation:
ExpQueryInterruptSteeringInformation(InputBuffer, v20, (VOID *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemSupportedProcessorArchitectures:
if( Handle )
{
v147 = 0i64;
v121 = ObReferenceObjectByHandle(Handle, 0x1000u, (POBJECT_TYPE)PsProcessType, v9, &v147, 0i64);
v118 = (struct _DMA_ADAPTER *)v147;
if( v121 < 0 )
return;
}
else
{
v118 = (struct _DMA_ADAPTER *)Process;
}
PsWow64GetSupportedArchitectures(a4, (unsigned int)Length, &Size, (INT64)v118);
LABEL_545:
if( v118 )
HalPutDmaAdapter(v118);
goto LABEL_598;
case SystemMemoryUsageInformation:
if( (_DWORD)Length != 56 )
{
if( a6 )
*(_DWORD *)a6 = 56;
return;
}
v21 = PsGetCurrentProcess();
v22 = MmGetProcessPartitionId(v21);
Src.CurrentSize = MmGetNumberOfPhysicalPages(v22) << 12;
Src.PeakSize = MmGetAvailablePages(v22) << 12;
MmGetResidentAvailablePages(v23);
*(_QWORD *)&Src.PageFaultCount = v24 << 12;
Src.MinimumWorkingSet = MmGetTotalCommittedPages(v25) << 12;
Src.CurrentSizeIncludingTransitionInPages = MmGetTotalCommitLimit(v26) << 12;
Src.PeakSizeIncludingTransitionInPages = MmGetPeakCommitment(v27) << 12;
Src.MaximumWorkingSet = MmGetSharedCommit(v28) << 12;
PeakSize = Src.CurrentSize;
if( Src.CurrentSize < Src.PeakSize )
PeakSize = Src.PeakSize;
Src.CurrentSize = PeakSize;
CurrentSizeIncludingTransitionInPages = Src.CurrentSizeIncludingTransitionInPages;
if( Src.CurrentSizeIncludingTransitionInPages < Src.MinimumWorkingSet )
CurrentSizeIncludingTransitionInPages = Src.MinimumWorkingSet;
Src.CurrentSizeIncludingTransitionInPages = CurrentSizeIncludingTransitionInPages;
PeakSizeIncludingTransitionInPages = Src.PeakSizeIncludingTransitionInPages;
if( Src.PeakSizeIncludingTransitionInPages < Src.MinimumWorkingSet )
PeakSizeIncludingTransitionInPages = Src.MinimumWorkingSet;
Src.PeakSizeIncludingTransitionInPages = PeakSizeIncludingTransitionInPages;
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
*(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
*(_OWORD *)(a4 + 32) = *(_OWORD *)&Src.MaximumWorkingSet;
*(_QWORD *)(a4 + 48) = Src.PeakSizeIncludingTransitionInPages;
LODWORD(Size) = 56;
goto LABEL_598;
case SystemCodeIntegrityCertificateInformation:
if( (_DWORD)Length != 16 )
return;
ExpQueryCodeIntegrityCertificateInfo(*(VOID **)a4, *(unsigned int *)(a4 + 8));
goto LABEL_598;
case SystemPhysicalMemoryInformation:
if( (_DWORD)Length != 24 )
{
if( a6 )
*(_DWORD *)a6 = 24;
return;
}
v32 = PsGetCurrentProcess();
v33 = MmGetProcessPartitionId(v32);
Src.CurrentSize = MmGetNumberOfPhysicalPages(v33) << 12;
Src.PeakSize = MmGetLowestPhysicalPage(v33) << 12;
*(_QWORD *)&Src.PageFaultCount = (MmGetHighestPhysicalPage(v34) << 12) + 4095;
*(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
*(_QWORD *)(a4 + 16) = *(_QWORD *)&Src.PageFaultCount;
LABEL_67:
LODWORD(Size) = 24;
goto LABEL_598;
case SystemControlFlowTransition:
WbDispatchOperation((PVOID)a4, (unsigned int)Length);
goto LABEL_598;
case SystemKernelDebuggingAllowed:
if( (_DWORD)Length )
{
if( a6 )
*(_DWORD *)a6 = 0;
}
else
{
BYTE4(SessionId) = 1;
ZwFilterBootOption();
}
return;
case SystemActivityModerationUserSettings:
if( (_DWORD)Length != 8 )
return;
if( (int)PsQueryActivityModerationUserSettings(&Src) >= 0 )
*(_QWORD *)a4 = Src.CurrentSize;
goto LABEL_598;
case SystemFlushInformation:
if( (unsigned int)Length >= 0x20 )
{
ExpGetSystemFlushInformation(a4);
LODWORD(Size) = 32;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 32;
return;
case SystemProcessorIdleMaskInformation:
LODWORD(Size) = 8 * KeQueryActiveGroupCount();
if( (unsigned int)Length >= (unsigned int)Size )
{
memset(a4, 0i64);
v129 = 0;
while( v8 < (unsigned __int16)KeNumberNodes )
{
v88 = *((_QWORD *)&KeNodeBlock + v8);
WORD2(ProcNumber) = *(_WORD *)(v88 + 144);
*(_QWORD *)(a4 + 8i64 * WORD2(ProcNumber)) |= *(_QWORD *)(v88 + 24);
v8 = ++v129;
}
}
goto LABEL_598;
case SystemWriteConstraintInformation:
if( (unsigned int)Length >= 8 )
{
ExpGetSystemWriteConstraintInformation((_QWORD *)a4);
LODWORD(Size) = 8;
goto LABEL_598;
}
if( a6 )
*(_DWORD *)a6 = 8;
return;
case SystemKernelVaShadowInformation:
KeQueryKvaShadowInformation((_DWORD *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemHypervisorSharedPageInformation:
LODWORD(Size) = 8;
if( (unsigned int)Length >= 8 )
{
v123 = qword_140C4DB88;
*(_QWORD *)a4 = 0i64;
*(_QWORD *)a4 = v123;
}
goto LABEL_598;
case SystemFirmwareBootPerformanceInformation:
if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
34i64,
0i64,
0i64,
(char *)&InputBufferLength + 4) != -1073741820 )
return;
v46 = HIDWORD(InputBufferLength);
if( (unsigned int)Length < HIDWORD(InputBufferLength) || !a4 )
{
LABEL_96:
LODWORD(Size) = v46;
goto LABEL_598;
}
if( v9 )
{
PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
InputBuffer = PoolWithQuotaTag;
if( !PoolWithQuotaTag )
goto LABEL_598;
v46 = HIDWORD(InputBufferLength);
}
else
{
PoolWithQuotaTag = (_DWORD *)a4;
InputBuffer = (VOID *)a4;
}
v122 = ((__int64(__fastcall *)(__int64, _QWORD, _DWORD *, size_t *))off_140C00A68[0])(
34i64,
v46,
PoolWithQuotaTag,
&Size);
if( v9 )
{
if( v122 >= 0 )
LABEL_418:
memmove((UINT8 *)a4, (UINT8 *)PoolWithQuotaTag, (unsigned int)Size);
LABEL_419:
ExFreePoolWithTag(PoolWithQuotaTag, 0x6F666E49u);
}
goto LABEL_598;
case SystemFirmwarePartitionInformation:
IoQuerySystemDeviceName(
SystemFirmwarePartitionInformation,
(VOID *)a4,
(unsigned int)Length,
(UINT *)&Size,
(INT64)Object,
(INT64)HandleInformation,
Size,
ProcNumber);
goto LABEL_598;
case SystemSpeculationControlInformation:
KeQuerySpeculationControlInformation((UINT8 *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemDmaGuardPolicyInformation:
LODWORD(Size) = 1;
if( (_DWORD)Length == 1 )
{
v143 = 0;
if( ((int(__fastcall *)(__int64, __int64, _SYSTEM_FILECACHE_INFORMATION *, int *))off_140C00A68[0])(
47i64,
1i64,
&Src,
&v143) >= 0
&& v143 == 1 )
{
*(_BYTE *)a4 = Src.CurrentSize;
}
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
case SystemLeapSecondInformation:
if( (_DWORD)Length != 8 )
{
if( a6 )
*(_DWORD *)a6 = 8;
return;
}
*(_BYTE *)a4 = *(_BYTE *)ExLeapSecondData != 0;
*(_DWORD *)(a4 + 4) = 0;
LABEL_114:
LODWORD(Size) = 8;
goto LABEL_598;
case SystemFlags2Information:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)a4 = *(_DWORD *)NtGlobalFlag2;
goto LABEL_157;
}
if( a6 )
*(_DWORD *)a6 = 4;
return;
case SystemSecurityModelInformation:
SeSecurityModelQueryInformation((_DWORD *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemFeatureConfigurationInformation:
CmQuerySingleFeatureConfiguration((INT64 *)InputBuffer, v20, a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemFeatureConfigurationSectionInformation:
CmQueryFeatureConfigurationSections(
(INT64)InputBuffer,
v20,
(_OWORD *)a4,
(unsigned int)Length,
(INT64)&Size,
*((_BYTE *)KeGetCurrentThread() + 562));
goto LABEL_598;
case SystemSecureSpeculationControlInformation:
KeQuerySecureSpeculationInformation((UINT8 *)a4, (unsigned int)Length, &Size);
goto LABEL_598;
case SystemShadowStackInformation:
if( (_DWORD)Length == 4 )
{
*(_DWORD *)a4 = 0;
if( !PsIsCurrentThreadInServerSilo() )
{
*(_DWORD *)a4 ^= (*(_DWORD *)a4 ^ (unsigned __int8)KeIsCetCapable(v111, v110)) & 1;
IsUserCetAllowed = KeIsUserCetAllowed();
*(_DWORD *)a4 = (unsigned int)v113 ^ ((unsigned __int8)v113 ^ (unsigned __int8)(2 * IsUserCetAllowed)) & 2;
IsKTMCommitCoordinator = ext_ms_win_ntos_tm_l1_1_0_TmIsKTMCommitCoordinator(v113);
*(_DWORD *)a4 = v115 ^ ((unsigned __int16)v115 ^ (unsigned __int16)(IsKTMCommitCoordinator << 8)) & 0x100;
}
LABEL_157:
LODWORD(Size) = 4;
LABEL_598:
if( a6 )
*(_DWORD *)a6 = Size;
}
else if( a6 )
{
*(_DWORD *)a6 = 4;
}
return;
case SystemPoolZeroingInformation:
LODWORD(Size) = 1;
if( (_DWORD)Length == 1 )
{
*(_BYTE *)a4 = 1;
}
else if( a6 )
{
*(_DWORD *)a6 = 1;
}
goto LABEL_598;
default:
return;
}
return;
case SystemCpuSetInformation:
case SystemSupportedProcessorArchitectures:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 8 )
return;
Handle = *(HANDLE *)InputBuffer;
goto LABEL_35;
case SystemSecureKernelProfileInformation:
v20 = (unsigned int)InputBufferLength;
if( (_DWORD)InputBufferLength != 8 )
return;
v157 = *(_QWORD *)InputBuffer;
goto LABEL_35;
default:
goto LABEL_34;
}
}Referenced by:
NtQuerySystemInformation
NtQuerySystemInformationEx