ExpQuerySystemInformation

VOID __fastcall ExpQuerySystemInformation(UINT64 rcx0, VOID *a2, UINT64 a3, INT64 a4, UINT64 Length, UINT64 *a6){
  int v7; 
  unsigned int v8; 
  unsigned __int8 v9; 
  unsigned int v10; 
  UINT64 v11; 
  __int64 v12; 
  __int64 v13; 
  USHORT v14; 
  __int64 v15; 
  _SYSTEM_INFORMATION_CLASS v16; 
  UINT16 v17; 
  unsigned int ActiveProcessorCount; 
  USHORT ActiveGroupCount; 
  UINT64 v20; 
  __int64 v21; 
  unsigned __int16 v22; 
  _BYTE *v23; 
  __int64 v24; 
  UINT64 v25; 
  UINT64 v26; 
  UINT64 v27; 
  UINT64 v28; 
  SIZE_T PeakSize; 
  SIZE_T CurrentSizeIncludingTransitionInPages; 
  SIZE_T PeakSizeIncludingTransitionInPages; 
  __int64 v32; 
  UINT16 v33; 
  UINT64 v34; 
  __int64 CurrentProcess; 
  unsigned __int16 ProcessPartitionId; 
  UINT64 v37; 
  UINT64 v38; 
  UINT64 v39; 
  SIZE_T MinimumWorkingSet; 
  unsigned int v41; 
  unsigned int v42; 
  _DWORD *v43; 
  int v44; 
  unsigned __int64 v45; 
  unsigned int v46; 
  UINT8 *PoolWithTag; 
  UINT8 *v48; 
  __int64 v49; 
  __int64 v50; 
  unsigned __int64 v51; 
  char v52; 
  char *v53; 
  _KTHREAD *CurrentThread; 
  int v55; 
  PCONFIGURATION_INFORMATION ConfigurationInformation; 
  INT64 v57; 
  INT64 v58; 
  unsigned int v59; 
  int v60; 
  _WORKING_SET_TYPE v61; 
  UINT64 v62; 
  unsigned int v63; 
  int v64; 
  int v65; 
  _KPRCB **v66; 
  __int64 v67; 
  _KPRCB **v68; 
  __int64 v69; 
  unsigned int i; 
  _DWORD *v71; 
  __int64 v72; 
  _OWORD *v73; 
  _SYSTEM_FILECACHE_INFORMATION *p_Src; 
  __int64 v75; 
  __int64 v76; 
  _SYSTEM_FILECACHE_INFORMATION *v77; 
  _KPRCB **v78; 
  __int64 v79; 
  __int64 v80; 
  int v81; 
  unsigned int v82; 
  int v83; 
  unsigned int v84; 
  __int16 j; 
  __int64 v86; 
  _QWORD *v87; 
  __int64 v88; 
  unsigned int v89; 
  __int64 v90; 
  _DWORD *PoolWithQuotaTag; 
  int v92; 
  int v93; 
  SIZE_T CurrentSize; 
  PVOID v95; 
  unsigned int v96; 
  NTSTATUS v97; 
  PVOID v98; 
  int v99; 
  UINT8 *v100; 
  unsigned int v101; 
  INT64 v102; 
  char v103; 
  __int16 NestedPageProtectionFlags; 
  INT64 v105; 
  WCHAR v106; 
  char v107; 
  INT64 v108; 
  bool IsIumEncryptionKeyAvailable; 
  INT64 v110; 
  INT64 v111; 
  bool IsUserCetAllowed; 
  KTRANSACTION *v113; 
  UINT8 IsKTMCommitCoordinator; 
  int v115; 
  INT64 v116; 
  NTSTATUS v117; 
  struct _DMA_ADAPTER *v118; 
  UINT8 *v119; 
  UINT8 *v120; 
  NTSTATUS v121; 
  int v122; 
  __int64 v123; 
  PVOID *Object; 
  POBJECT_HANDLE_INFORMATION HandleInformation; 
  size_t Size; 
  INT64 ProcNumber; 
  int v128; 
  int v129; 
  char v130[4]; 
  UINT64 InputBufferLength; 
  VOID *InputBuffer; 
  UINT64 *v133; 
  UINT64 SessionId; 
  unsigned __int16 v135; 
  unsigned int v136; 
  unsigned int v137; 
  _SYSTEM_INFORMATION_CLASS InformationClass; 
  LOGICAL_PROCESSOR_RELATIONSHIP RelationshipType; 
  unsigned int v140; 
  UINT64 Count; 
  LOGICAL_PROCESSOR_RELATIONSHIP v142; 
  int v143; 
  unsigned int v144; 
  _QWORD *v145; 
  _EPROCESS *Process; 
  PVOID v147; 
  PVOID P; 
  PVOID v149; 
  INT64 a1; 
  HANDLE Handle; 
  HANDLE ProcessId[2]; 
  char *v153; 
  UINT64 v154; 
  VOID *v155; 
  PVOID v156; 
  INT64 v157; 
  __int128 v158; 
  int v159; 
  _SYSTEM_FILECACHE_INFORMATION Src; 
  __int128 v161; 
  __int128 v162; 
  __int128 v163; 
  __int128 v164; 
  __int128 v165; 
  __int128 v166; 
  __int64 v167; 
  int v168; 
  InputBufferLength = (unsigned int)a3;
  InputBuffer = a2;
  v7 = rcx0;
  InformationClass = (int)rcx0;
  v133 = a6;
  v8 = 0;
  v154 = 0i64;
  Count = 0i64;
  v129 = 0;
  LODWORD(SessionId) = 0;
  v135 = 0;
  WORD2(ProcNumber) = 0;
  v158 = 0i64;
  Process = 0i64;
  LODWORD(ProcNumber) = 0;
  RelationshipType = RelationProcessorCore;
  v149 = 0i64;
  P = 0i64;
  v142 = RelationProcessorCore;
  memset((INT64)&Src, 0i64);
  HIDWORD(Size) = 0;
  v9 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v9 )
  {
    switch( v7 )
    {
      case 12:
        v11 = 8i64;
        goto LABEL_6;
      case 35:
      case 145:
      case 147:
      case 149:
      case 158:
      case 163:
      case 169:
      case 202:
      case 227:
        v10 = 1;
        v11 = 1i64;
        break;
      default:
        v11 = 4i64;
LABEL_6:
        v10 = 1;
        break;
    }
    ProbeForWrite((VOID *)a4, (unsigned int)Length, v11);
    if( a6 )
    {
      v12 = (__int64)a6;
      if( (unsigned __int64)a6 >= 0x7FFFFFFF0000i64 )
        v12 = 0x7FFFFFFF0000i64;
      *(_DWORD *)v12 = *(_DWORD *)v12;
    }
  }
  else
  {
    v10 = 1;
  }
  LODWORD(Size) = 0;
  RelationshipType = RelationAll;
  v13 = 0i64;
  v136 = 0;
  v14 = 0;
  v128 = 0;
  WORD2(ProcNumber) = 0;
  v135 = 0;
  a1 = 0i64;
  Handle = 0i64;
  v157 = 0i64;
  v15 = 9i64;
  v137 = 9;
  v142 = 9;
  v16 = InformationClass;
  switch( InformationClass )
  {
    case SystemPerformanceInformation:
    case SystemExceptionInformation:
    case SystemContextSwitchInformation:
    case SystemLostDelayedWriteInformation:
      v128 = 0xFFFF;
      WORD2(ProcNumber) = -1;
      v17 = -1;
      goto LABEL_15;
    case SystemProcessorPerformanceInformation:
    case SystemInterruptInformation:
    case SystemProcessorIdleInformation:
    case SystemProcessorPowerInformation:
    case SystemLogicalProcessorInformation:
    case SystemProcessorIdleCycleTimeInformation:
    case SystemProcessorPerformanceDistribution:
    case SystemProcessorCycleTimeInformation:
    case SystemProcessorPerformanceInformationEx:
    case SystemProcessorCycleStatsInformation:
      if( (unsigned int)InputBufferLength < 2 )
        return;
      v128 = *(unsigned __int16 *)InputBuffer;
      WORD2(ProcNumber) = v128;
      ActiveGroupCount = KeQueryActiveGroupCount();
      v17 = v128;
      if( (unsigned __int16)v128 >= ActiveGroupCount )
        return;
LABEL_15:
      ActiveProcessorCount = KeQueryActiveProcessorCountEx(v17);
      v13 = ActiveProcessorCount;
      v136 = ActiveProcessorCount;
      v14 = v128;
      v15 = v137;
      v16 = InformationClass;
LABEL_34:
      v20 = (unsigned int)InputBufferLength;
      goto LABEL_35;
    case SystemWatchdogTimerInformation:
      v20 = (unsigned int)InputBufferLength;
      if( (_DWORD)InputBufferLength != 4 )
        return;
      v15 = *(unsigned int *)InputBuffer;
      v142 = *(_DWORD *)InputBuffer;
      goto LABEL_35;
    case SystemLogicalProcessorAndGroupInformation:
      v20 = (unsigned int)InputBufferLength;
      if( (unsigned int)InputBufferLength < 4 )
        return;
      RelationshipType = *(_DWORD *)InputBuffer;
      goto LABEL_35;
    case SystemNodeDistanceInformation:
      v20 = (unsigned int)InputBufferLength;
      if( (unsigned int)InputBufferLength >= 2 )
      {
        v135 = *(_WORD *)InputBuffer;
        if( v135 < (unsigned __int16)KeNumberNodes )
          goto LABEL_35;
      }
      return;
    case SystemIsolatedUserModeInformation:
      v20 = (unsigned int)InputBufferLength;
      if( (_DWORD)InputBufferLength )
      {
        if( (_DWORD)InputBufferLength != 8 )
          return;
        a1 = *(_QWORD *)InputBuffer;
      }
      else
      {
        a1 = 0i64;
      }
LABEL_35:
      switch( v16 )
      {
        case SystemBasicInformation:
        case SystemNativeBasicInformation:
          if( (_DWORD)Length == 64 )
          {
            ExpGetSystemBasicInformation(a4, v20, v15, v13);
            goto LABEL_597;
          }
          if( a6 )
            *(_DWORD *)a6 = 64;
          return;
        case SystemProcessorInformation:
          if( (unsigned int)Length >= 0xC )
          {
            ExpGetSystemProcessorInformation(a4, v20, v15, v13);
            LODWORD(Size) = 12;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 12;
          return;
        case SystemPerformanceInformation:
          if( (unsigned int)Length >= 0x138 )
          {
            v10 = 344;
            if( (unsigned int)Length <= 0x158 )
              v10 = Length;
            ExpQuerySystemPerformanceInformation((unsigned int)v13, (PVOID)a4, v10);
            goto LABEL_256;
          }
          if( a6 )
            *(_DWORD *)a6 = 344;
          return;
        case SystemTimeOfDayInformation:
          if( (unsigned int)Length <= 0x30 )
          {
            KeQueryBootTimeValues((_LARGE_INTEGER *)&Src.PeakSize, (_LARGE_INTEGER *)&Src, &Src.MaximumWorkingSet);
            v50 = PsGetCurrentServerSiloGlobals()[133];
            *(_QWORD *)&Src.PageFaultCount = *(_QWORD *)(v50 + 440);
            LODWORD(Src.MinimumWorkingSet) = *(_DWORD *)(v50 + 432);
            Src.CurrentSizeIncludingTransitionInPages = KUSER_SHARED_DATA.InterruptTimeBias;
            memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Length);
            goto LABEL_119;
          }
          if( a6 )
            *(_DWORD *)a6 = 48;
          return;
        case SystemProcessInformation:
        case SystemExtendedProcessInformation:
        case SystemFullProcessInformation:
          ExpGetProcessInformation((VOID *)a4, (unsigned int)Length, &Size, 0i64, v16);
          goto LABEL_598;
        case SystemDeviceInformation:
          if( (_DWORD)Length == 24 )
          {
            ConfigurationInformation = IoGetConfigurationInformation();
            *(_DWORD *)a4 = ConfigurationInformation->DiskCount;
            *(_DWORD *)(a4 + 4) = ConfigurationInformation->FloppyCount;
            *(_DWORD *)(a4 + 8) = ConfigurationInformation->CdRomCount;
            *(_DWORD *)(a4 + 12) = ConfigurationInformation->TapeCount;
            *(_DWORD *)(a4 + 16) = ConfigurationInformation->SerialCount;
            *(_DWORD *)(a4 + 20) = ConfigurationInformation->ParallelCount;
            goto LABEL_67;
          }
          if( a6 )
            *(_DWORD *)a6 = 24;
          return;
        case SystemProcessorPerformanceInformation:
        case SystemProcessorPerformanceInformationEx:
          v41 = 48;
          if( v16 != SystemProcessorPerformanceInformation )
            v41 = 72;
          if( (_DWORD)Length && !((unsigned int)Length % v41) )
          {
            v129 = 0;
            v42 = 0;
            while( 1 )
            {
              v137 = v42;
              if( v42 >= (unsigned int)v13 )
                break;
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)v42;
              v43 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
              v44 = v129;
              if( (unsigned int)Length < v41 + v129 )
                goto LABEL_91;
              v129 += v41;
              PoGetIdleTimes((PROCESSOR_NUMBER *)&ProcNumber, 0i64, (INT64)&Src);
              *(_QWORD *)(a4 + 16) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8098];
              *(_QWORD *)(a4 + 8) = KeMaximumIncrement * (unsigned __int64)HIDWORD(Src.CurrentSize);
              *(_QWORD *)(a4 + 24) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8099];
              *(_QWORD *)(a4 + 32) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8100];
              *(_QWORD *)a4 = KeMaximumIncrement * (unsigned __int64)LODWORD(Src.CurrentSize);
              *(_DWORD *)(a4 + 40) = v43[8096];
              if( InformationClass == SystemProcessorPerformanceInformationEx )
              {
                *(_QWORD *)(a4 + 48) = KeMaximumIncrement * (unsigned __int64)(unsigned int)v43[8107];
                *(_DWORD *)(a4 + 44) = 0;
                *(_QWORD *)(a4 + 56) = 0i64;
                *(_QWORD *)(a4 + 64) = 0i64;
              }
              a4 += v41;
              v42 = v137 + 1;
              LODWORD(v13) = v136;
              v14 = v128;
            }
            v44 = v129;
LABEL_91:
            LODWORD(Size) = v44;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = v13 * v41;
          break;
        case SystemFlagsInformation:
          if( (_DWORD)Length == 4 )
          {
            *(_DWORD *)a4 = NtGlobalFlag;
            goto LABEL_157;
          }
          if( a6 )
            *(_DWORD *)a6 = 4;
          return;
        case SystemModuleInformation:
          if( (unsigned int)ExIsRestrictedCaller(v9) )
            return;
          KeEnterCriticalRegion();
          ExAcquireResourceExclusiveLite(&PsLoadedModuleResource, 1u);
          ExpQueryModuleInformation(v57, (_DWORD *)a4, (unsigned int)Length, &Size);
          goto LABEL_164;
        case SystemLocksInformation:
          if( (unsigned int)Length < 0x38 )
          {
            if( a6 )
              *(_DWORD *)a6 = 56;
            return;
          }
          if( (unsigned int)ExIsRestrictedCaller(v9) )
            return;
          ExpGetLockInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemStackTraceInformation:
          if( (unsigned int)Length >= 0x128 )
            goto LABEL_598;
          if( a6 )
            *(_DWORD *)a6 = 296;
          return;
        case SystemPagedPoolInformation:
        case SystemNonPagedPoolInformation:
        case SystemVdmInstemulInformation:
        case SystemHotpatchInformation:
        case SystemVirtualAddressInformation:
          goto LABEL_598;
        case SystemHandleInformation:
          if( (unsigned int)Length >= 0x20 )
          {
            if( (a4 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
            {
              ExpGetHandleInformation((PVOID)a4, (unsigned int)Length, &Size);
              goto LABEL_598;
            }
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 32;
          }
          return;
        case SystemObjectInformation:
          if( (unsigned int)Length < 0x40 )
          {
            if( a6 )
              *(_DWORD *)a6 = 64;
            return;
          }
          if( (unsigned int)ExIsRestrictedCaller(v9) )
            return;
          ExpGetObjectInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemPageFileInformation:
        case SystemPageFileInformationEx:
          v59 = 32;
          if( v16 != SystemPageFileInformation )
            v59 = 40;
          LODWORD(Size) = v59;
          if( (unsigned int)Length >= v59 )
          {
            LODWORD(Size) = 0;
            LOBYTE(v8) = v16 == SystemPageFileInformationEx;
            MmGetPageFileInformation((PVOID)0x28, a4, (unsigned int)Length, (UINT64 *)v8);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = v59;
          return;
        case SystemFileCacheInformation:
        case SystemFileCacheInformationEx:
        case SystemPagedPoolInformationEx:
        case SystemSystemPtesInformationEx:
          if( (unsigned int)Length < 0x40 )
          {
            if( a6 )
              *(_DWORD *)a6 = 64;
            return;
          }
          v60 = 2;
          if( v16 == SystemPagedPoolInformationEx )
          {
            v61 = WorkingSetTypePagedPool;
          }
          else
          {
            if( v16 == SystemSystemPtesInformationEx )
              v60 = 4;
            v61 = v60;
          }
          MmQuerySystemWorkingSetInformation(v61, &Src);
          *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
          *(_DWORD *)(a4 + 16) = Src.PageFaultCount;
          *(_QWORD *)(a4 + 24) = Src.MinimumWorkingSet;
          *(_QWORD *)(a4 + 32) = Src.MaximumWorkingSet;
          *(_QWORD *)(a4 + 40) = Src.CurrentSizeIncludingTransitionInPages;
          *(_QWORD *)(a4 + 48) = Src.PeakSizeIncludingTransitionInPages;
          *(_DWORD *)(a4 + 56) = Src.TransitionRePurposeCount;
          *(_DWORD *)(a4 + 60) = Src.Flags;
          LODWORD(Size) = 64;
          goto LABEL_598;
        case SystemPoolTagInformation:
          if( (unsigned int)Length >= 0x30 )
          {
            ExGetPoolTagInfo((PVOID)a4, (unsigned int)Length, &Size);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 48;
          return;
        case SystemInterruptInformation:
          LODWORD(Size) = 24 * v13;
          if( (unsigned int)Length >= 24 * (int)v13 )
          {
            for( i = 0; i < (unsigned int)v13; ++i )
            {
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)i;
              v71 = *(&KiProcessorBlock + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
              *(_DWORD *)a4 = v71[2895];
              *(_DWORD *)(a4 + 4) = v71[3127];
              *(_DWORD *)(a4 + 8) = v71[3143];
              *(_DWORD *)(a4 + 12) = KeTimeIncrement;
              *(_DWORD *)(a4 + 16) = 0;
              *(_DWORD *)(a4 + 20) = 0;
              a4 += 24i64;
              LODWORD(v13) = v136;
              v14 = v128;
            }
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 24 * v13;
          return;
        case SystemDpcBehaviorInformation:
          if( (_DWORD)Length == 20 )
          {
            *(_DWORD *)(a4 + 4) = KiMaximumDpcQueueDepth;
            *(_DWORD *)(a4 + 8) = *(_DWORD *)KiMinimumDpcRate;
            *(_DWORD *)(a4 + 12) = KiAdjustDpcThreshold;
            *(_DWORD *)(a4 + 16) = KiIdealDpcRate;
            goto LABEL_276;
          }
          if( a6 )
            *(_DWORD *)a6 = 20;
          return;
        case SystemTimeAdjustmentInformation:
          if( (_DWORD)Length != 12 && (_DWORD)Length != 24 )
          {
            if( a6 )
              *(_DWORD *)a6 = 12;
            return;
          }
          ExAcquireTimeRefreshLock(1u);
          v51 = KeTimeAdjustmentFrequency;
          v52 = KeTimeSynchronization;
          ExReleaseTimeRefreshLock();
          if( (_DWORD)Length == 24 )
          {
            *(_QWORD *)a4 = v51;
            *(_QWORD *)(a4 + 8) = KUSER_SHARED_DATA.QpcFrequency;
            *(_BYTE *)(a4 + 16) = v52;
          }
          else
          {
            *(_DWORD *)a4 = KUSER_SHARED_DATA.QpcFrequency * (unsigned __int64)KeMaximumIncrement / v51;
            *(_DWORD *)(a4 + 4) = KeMaximumIncrement;
            *(_BYTE *)(a4 + 8) = v52;
          }
LABEL_119:
          LODWORD(Size) = Length;
          goto LABEL_598;
        case SystemPerformanceTraceInformation:
          EtwQueryPerformanceTraceInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
          goto LABEL_598;
        case SystemExceptionInformation:
          if( (unsigned int)Length < 0x10 )
          {
            if( a6 )
              *(_DWORD *)a6 = 16;
            return;
          }
          LODWORD(Size) = 16;
          v64 = 0;
          v65 = 0;
          if( (_DWORD)v13 )
          {
            v66 = &KiProcessorBlock;
            v67 = (unsigned int)v13;
            do
            {
              v64 += *((_DWORD *)*v66 + 8398);
              v65 += *((_DWORD *)*v66++ + 8108);
              --v67;
            }
            while( v67 );
          }
          *(_DWORD *)a4 = v64;
          *(_DWORD *)(a4 + 4) = v65;
          *(_DWORD *)(a4 + 8) = 0;
          *(_DWORD *)(a4 + 12) = 0;
          goto LABEL_598;
        case SystemKernelDebuggerInformation:
          if( (unsigned int)Length >= 2 )
          {
            *(_BYTE *)a4 = (_BYTE)KdDebuggerEnabled;
            *(_BYTE *)(a4 + 1) = (_BYTE)KdDebuggerNotPresent;
            LODWORD(Size) = 2;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 2;
          return;
        case SystemContextSwitchInformation:
          if( (unsigned int)Length < 0x30 )
          {
            if( a6 )
              *(_DWORD *)a6 = 48;
            return;
          }
          if( (_DWORD)v13 )
          {
            v68 = &KiProcessorBlock;
            v69 = (unsigned int)v13;
            do
            {
              v8 += *((_DWORD *)*v68++ + 2895);
              --v69;
            }
            while( v69 );
          }
          *(_DWORD *)a4 = v8;
          *(_DWORD *)(a4 + 4) = KeThreadSwitchCounters;
          *(_DWORD *)(a4 + 8) = dword_140C319C8;
          *(_DWORD *)(a4 + 12) = dword_140C319C4;
          *(_DWORD *)(a4 + 16) = dword_140C319CC;
          *(_DWORD *)(a4 + 20) = dword_140C319D0;
          *(_DWORD *)(a4 + 24) = dword_140C319D8;
          *(_DWORD *)(a4 + 28) = dword_140C319D4;
          *(_DWORD *)(a4 + 32) = dword_140C319DC;
          *(_DWORD *)(a4 + 36) = dword_140C319E0;
          *(_DWORD *)(a4 + 40) = dword_140C319E4;
          *(_DWORD *)(a4 + 44) = dword_140C319E8;
          LODWORD(Size) = 48;
          goto LABEL_598;
        case SystemRegistryQuotaInformation:
          if( (unsigned int)Length >= 0x10 )
          {
            CmQueryRegistryQuotaInformation((_SYSTEM_REGISTRY_QUOTA_INFORMATION *)a4);
            LODWORD(Size) = 16;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 16;
          return;
        case SystemProcessorIdleInformation:
          LODWORD(Size) = 48 * v13;
          if( (unsigned int)Length >= 48 * (int)v13 )
          {
            while( v8 < (unsigned int)v13 )
            {
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)v8;
              PoGetIdleTimes((PROCESSOR_NUMBER *)&ProcNumber, (INT64)&Src, 0i64);
              *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
              *(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
              *(_OWORD *)(a4 + 32) = *(_OWORD *)&Src.MaximumWorkingSet;
              a4 += 48i64;
              ++v8;
              LODWORD(v13) = v136;
              v14 = v128;
            }
          }
          goto LABEL_598;
        case SystemLegacyDriverInformation:
          if( (unsigned int)Length >= 0x18 )
          {
            LODWORD(Size) = Length;
            ExpQueryLegacyDriverInformation(a4, &Size);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 24;
          return;
        case SystemCurrentTimeZoneInformation:
          if( (unsigned int)Length >= 0xAC )
          {
            v72 = PsGetCurrentServerSiloGlobals()[133];
            ExAcquireTimeRefreshLock(1u);
            Src = *(_SYSTEM_FILECACHE_INFORMATION *)v72;
            v161 = *(_OWORD *)(v72 + 64);
            v162 = *(_OWORD *)(v72 + 80);
            v163 = *(_OWORD *)(v72 + 96);
            v164 = *(_OWORD *)(v72 + 112);
            v165 = *(_OWORD *)(v72 + 128);
            v166 = *(_OWORD *)(v72 + 144);
            v167 = *(_QWORD *)(v72 + 160);
            v168 = *(_DWORD *)(v72 + 168);
            ExReleaseTimeRefreshLock();
            *(_SYSTEM_FILECACHE_INFORMATION *)a4 = Src;
            *(_OWORD *)(a4 + 64) = v161;
            *(_OWORD *)(a4 + 80) = v162;
            *(_OWORD *)(a4 + 96) = v163;
            *(_OWORD *)(a4 + 112) = v164;
            *(_OWORD *)(a4 + 128) = v165;
            *(_OWORD *)(a4 + 144) = v166;
            *(_QWORD *)(a4 + 160) = v167;
            *(_DWORD *)(a4 + 168) = v168;
            LODWORD(Size) = 172;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 172;
          return;
        case SystemLookasideInformation:
          ExpGetLookasideInformation((VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemRangeStartInformation:
          if( (_DWORD)Length == 8 )
          {
            *(_QWORD *)a4 = 0xFFFF800000000000ui64;
            goto LABEL_114;
          }
          if( a6 )
            *(_DWORD *)a6 = 8;
          return;
        case SystemVerifierInformation:
          if( (unsigned int)Length >= 0x90 )
          {
            VfGetVerifierInformation((PVOID)a4, (unsigned int)Length, &Size, 0i64);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 144;
          return;
        case SystemSessionProcessInformation:
          if( (unsigned int)Length >= 0x10 )
          {
            LODWORD(SessionId) = *(_DWORD *)a4;
            v155 = *(VOID **)(a4 + 8);
            v140 = *(_DWORD *)(a4 + 4);
            ProbeForWrite(v155, v140, 4ui64);
            ExpGetProcessInformation(v155, v140, &Size, &SessionId, SystemProcessInformation);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 16;
          return;
        case SystemNumaProcessorMap:
          ExpQueryNumaProcessorMap((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemPrefetcherInformation:
          PfSnQueryPrefetcherInformation((PVOID)0x140000000i64, a4, Length, (UINT64 *)v9);
          goto LABEL_598;
        case SystemRecommendedSharedDataAlignment:
          if( (unsigned int)Length >= 4 )
          {
            *(_DWORD *)a4 = KeGetRecommendedSharedDataAlignment();
            goto LABEL_157;
          }
          if( a6 )
            *(_DWORD *)a6 = 4;
          return;
        case SystemComPlusPackage:
          if( (_DWORD)Length == 4 )
          {
            if( KUSER_SHARED_DATA.ComPlusPackage != -1 || (int)ExpReadComPlusPackage() >= 0 )
            {
              *(_DWORD *)a4 = KUSER_SHARED_DATA.ComPlusPackage;
              LODWORD(Size) = 4;
              goto LABEL_598;
            }
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 4;
          }
          return;
        case SystemNumaAvailableMemory:
          ExpQueryNumaAvailableMemory((VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemProcessorPowerInformation:
          LODWORD(Size) = 80 * v13;
          if( (unsigned int)Length >= 80 * (int)v13 )
          {
            while( v8 < (unsigned int)v13 )
            {
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)v8;
              v49 = (__int64)*(&KiProcessorBlock
                             + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
              PoGetPerfStateAndParkingInfo((PROCESSOR_NUMBER *)&ProcNumber, (INT64)&Src, 0i64, &v154);
              *(_OWORD *)a4 = 0i64;
              *(_OWORD *)(a4 + 16) = 0i64;
              *(_OWORD *)(a4 + 32) = 0i64;
              *(_OWORD *)(a4 + 48) = 0i64;
              *(_OWORD *)(a4 + 64) = 0i64;
              *(_QWORD *)(a4 + 40) = KeMaximumIncrement
                                   * (unsigned __int64)(unsigned int)(*(_DWORD *)(v49 + 32388) + *(_DWORD *)(v49 + 32392));
              *(_QWORD *)(a4 + 48) = KeMaximumIncrement
                                   * (unsigned __int64)*(unsigned int *)(*(_QWORD *)(v49 + 24) + 652i64);
              if( BYTE4(Src.MinimumWorkingSet) )
              {
                *(_BYTE *)a4 = Src.PeakSize;
                *(_BYTE *)(a4 + 7) = BYTE4(Src.PeakSize);
                *(_BYTE *)(a4 + 8) = Src.PageFaultCount;
                *(_DWORD *)(a4 + 12) = 1;
              }
              *(_QWORD *)(a4 + 72) = v154;
              a4 += 80i64;
              v145 = (_QWORD *)a4;
              ++v8;
              LODWORD(v13) = v136;
              v14 = v128;
            }
          }
          goto LABEL_598;
        case SystemEmulationBasicInformation:
          if( (_DWORD)Length != 64 )
          {
            if( a6 )
              *(_DWORD *)a6 = 64;
            return;
          }
          ExpGetSystemEmulationBasicInformation(a4, v20, v15, v13);
LABEL_597:
          LODWORD(Size) = 64;
          goto LABEL_598;
        case SystemEmulationProcessorInformation:
          if( (unsigned int)Length >= 0xC )
          {
            ExpGetSystemEmulationProcessorInformation(a4);
            LODWORD(Size) = 12;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 12;
          return;
        case SystemExtendedHandleInformation:
          if( (unsigned int)Length >= 0x38 )
          {
            if( (a4 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
            {
              ExpGetHandleInformationEx((PVOID)a4, (unsigned int)Length, &Size);
              goto LABEL_598;
            }
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 56;
          }
          return;
        case SystemLostDelayedWriteInformation:
          if( (unsigned int)Length < 4 )
          {
            if( a6 )
              *(_DWORD *)a6 = 4;
            return;
          }
          if( (_DWORD)v13 )
          {
            v78 = &KiProcessorBlock;
            v79 = (unsigned int)v13;
            do
            {
              v8 += *((_DWORD *)*v78++ + 8175);
              --v79;
            }
            while( v79 );
          }
          *(_DWORD *)a4 = v8;
          goto LABEL_157;
        case SystemBigPoolInformation:
          if( (unsigned int)Length < 0x20 )
          {
            if( a6 )
              *(_DWORD *)a6 = 32;
            return;
          }
          if( (unsigned int)ExIsRestrictedCaller(v9) )
            return;
          ExGetBigPoolInfo((PVOID)a4, (unsigned int)Length, 1ui64, &Size);
          goto LABEL_598;
        case SystemSessionPoolTagInformation:
          if( (unsigned int)Length < 0x10 )
          {
            if( a6 )
              *(_DWORD *)a6 = 16;
            return;
          }
          LODWORD(SessionId) = *(_DWORD *)a4;
          v155 = *(VOID **)(a4 + 8);
          v62 = *(unsigned int *)(a4 + 4);
          v140 = *(_DWORD *)(a4 + 4);
          if( ((unsigned __int8)v155 & 7) != 0 )
            return;
          ExGetSessionPoolTagInformation(v155, v62, &Size, &SessionId);
          goto LABEL_598;
        case SystemSessionMappedViewInformation:
          if( (unsigned int)Length < 0x20 )
          {
            if( a6 )
              *(_DWORD *)a6 = 32;
            return;
          }
          LODWORD(SessionId) = *(_DWORD *)(a4 + 8);
          if( (a4 & 7) != 0 )
            return;
          MmGetSessionMappedViewInformation((VOID *)a4, (unsigned int)Length, &Size, &SessionId);
          goto LABEL_598;
        case SystemObjectSecurityMode:
          if( (_DWORD)Length == 4 )
          {
            *(_DWORD *)a4 = ObpObjectSecurityMode;
            goto LABEL_157;
          }
          if( a6 )
            *(_DWORD *)a6 = 4;
          return;
        case SystemWatchdogTimerInformation:
          if( (_DWORD)Length != 8 )
            return;
          v80 = (unsigned int)(v15 - 7);
          if( (_DWORD)v80 )
          {
            if( (_DWORD)v80 != 1 )
              return;
            *(_DWORD *)a4 = 8;
            *(_DWORD *)(a4 + 4) = ((unsigned __int8(__fastcall *)(unsigned __int64, UINT64, __int64, __int64))off_140C008D0[0])(
                                    0x140000000ui64,
                                    v20,
                                    v80,
                                    v13);
          }
          else
          {
            *(_DWORD *)a4 = 7;
            LOBYTE(v8) = off_140C008D8[0] != (__int64(__fastcall *)())xKdEnumerateDebuggingDevices;
            *(_DWORD *)(a4 + 4) = v8;
          }
          goto LABEL_114;
        case SystemLogicalProcessorInformation:
          KeBuildLogicalProcessorSystemInformation(v14, a4, (unsigned int)Length, (UINT64)&Size);
          HIDWORD(Size) = v81;
          goto LABEL_598;
        case SystemFirmwareTableInformation:
          ExpGetSystemFirmwareTableInformation((PVOID)a4, v9, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemModuleInformationEx:
          if( (unsigned int)ExIsRestrictedCaller(v9) )
            return;
          if( SeSinglePrivilegeCheck(*(_QWORD *)&SeLoadDriverPrivilege, v9) )
            v10 = 0;
          KeEnterCriticalRegion();
          ExAcquireResourceExclusiveLite(&PsLoadedModuleResource, 1u);
          ExpQueryModuleInformationEx(v58, (_WORD *)a4, (unsigned int)Length, v10, &Size);
LABEL_164:
          ExReleaseResourceLite(&PsLoadedModuleResource);
          KeLeaveCriticalRegion();
          goto LABEL_598;
        case SystemSuperfetchInformation:
          PfQuerySuperfetchInformation(
            (_SYSTEM_INFORMATION_CLASS)0x140000000ui64,
            (PVOID)a4,
            (unsigned int)Length,
            v9,
            &Size);
          goto LABEL_598;
        case SystemMemoryListInformation:
          MmQueryMemoryListInformation((PVOID)0xFFFFFFFFFFFFFFFFi64, a4, (UINT64 *)(unsigned int)Length);
          goto LABEL_598;
        case SystemProcessorIdleCycleTimeInformation:
          LODWORD(Size) = 8 * v13;
          if( (unsigned int)Length >= 8 )
          {
            v84 = (unsigned int)Length >> 3;
            if( (unsigned int)Length >= 8 * (int)v13 )
              v84 = v13;
            v145 = (_QWORD *)a4;
            KeFlushProcessWriteBuffers(1u);
            for( j = v128; ; j = WORD2(ProcNumber) )
            {
              v129 = v8;
              if( v8 >= v84 )
                break;
              LOWORD(ProcNumber) = j;
              WORD1(ProcNumber) = (unsigned __int8)v8;
              v86 = *(_QWORD *)(*((_QWORD *)*(&KiProcessorBlock
                                            + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber))
                                + 3)
                              + 72i64);
              v87 = v145;
              *v145 = v86;
              v145 = v87 + 1;
              v8 = v129 + 1;
            }
          }
          goto LABEL_598;
        case SystemRefTraceInformation:
          ObQueryRefTraceInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemSpecialPoolInformation:
          LODWORD(Size) = 8;
          if( (_DWORD)Length == 8 )
          {
            *(_DWORD *)a4 = MmSpecialPoolTag;
            LOBYTE(v8) = MmSpecialPoolCatchOverruns != 0;
            *(_DWORD *)(a4 + 4) = v8;
          }
          goto LABEL_598;
        case SystemProcessIdInformation:
          LODWORD(Size) = 24;
          if( (_DWORD)Length != 24 )
            goto LABEL_598;
          *(_OWORD *)ProcessId = *(_OWORD *)a4;
          v153 = *(char **)(a4 + 16);
          if( LOWORD(ProcessId[1]) || (BYTE2(ProcessId[1]) & 1) != 0 )
            return;
          if( v9 && WORD1(ProcessId[1]) )
          {
            if( ((unsigned __int8)v153 & 1) != 0 )
              ExRaiseDatatypeMisalignment();
            v53 = &v153[WORD1(ProcessId[1])];
            if( (unsigned __int64)v53 > 0x7FFFFFFF0000i64 || v53 < v153 )
              MEMORY[0x7FFFFFFF0000] = 0;
          }
          CurrentThread = (_ETHREAD *)KeGetCurrentThread();
          v144 = WORD1(ProcessId[1]);
          KeEnterCriticalRegionThread((_KTHREAD *)CurrentThread);
          if( PsLookupProcessByProcessId(ProcessId[0], (PEPROCESS *)&Process) < 0 )
          {
            KeLeaveCriticalRegionThread((__int64)CurrentThread);
            return;
          }
          v55 = PsQueryFullProcessImageName((__int64)Process, (_OWORD *)(a4 + 8), v153, &v144);
          ObfDereferenceObjectWithTag(Process, 0x746C6644ui64);
          KeLeaveCriticalRegionThread((__int64)CurrentThread);
          if( v55 == -1073741820 )
            *(_WORD *)(a4 + 10) = v144;
          goto LABEL_598;
        case SystemBootEnvironmentInformation:
          LODWORD(Size) = 32;
          if( (unsigned int)Length < 0x14 )
          {
            if( a6 )
              *(_DWORD *)a6 = 32;
            return;
          }
          *(_OWORD *)a4 = ExpBootEnvironmentInformation;
          *(_DWORD *)(a4 + 16) = dword_140C19650;
          if( (unsigned int)Length < (unsigned int)Size )
LABEL_276:
            LODWORD(Size) = 20;
          else
            *(_QWORD *)(a4 + 24) = qword_140C19658;
          goto LABEL_598;
        case SystemHypervisorInformation:
          HvlQueryEnlightenmentInfo((PVOID)a4, (unsigned int)Length, v9, &Size);
          goto LABEL_598;
        case SystemVerifierInformationEx:
          if( (_DWORD)Length != 40 )
          {
            if( a6 )
              *(_DWORD *)a6 = 40;
            return;
          }
          if( (int)VfGetVerifierInformationEx(a4) >= 0 )
            v8 = 40;
          LODWORD(Size) = v8;
          goto LABEL_598;
        case SystemCoverageInformation:
          if( !v9 || !SeSinglePrivilegeCheck(*(_QWORD *)&SeDebugPrivilege, v9) )
            return;
          if( (unsigned int)Length >= 0x40 )
          {
            ExpCovQueryInformation(a4, Length, (unsigned int *)&Size);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 64;
          return;
        case SystemSystemPartitionInformation:
          IoQuerySystemDeviceName(
            SystemSystemPartitionInformation,
            (VOID *)a4,
            (unsigned int)Length,
            (UINT *)&Size,
            (INT64)Object,
            (INT64)HandleInformation,
            Size,
            ProcNumber);
          goto LABEL_598;
        case SystemSystemDiskInformation:
          IoQuerySystemDeviceName(
            SystemSystemDiskInformation,
            (VOID *)a4,
            (unsigned int)Length,
            (UINT *)&Size,
            (INT64)Object,
            (INT64)HandleInformation,
            Size,
            ProcNumber);
          goto LABEL_598;
        case SystemProcessorPerformanceDistribution:
          WORD4(v158) = v14;
          *(_QWORD *)&v158 = KeQueryGroupAffinity(v14);
          v45 = (0x101010101010101i64
               * (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
                 + ((((unsigned __int64)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
                 + (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
                   + ((((unsigned __int64)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 56;
          if( (unsigned int)PpmCapturePerformanceDistribution(
                               0i64,
                               0,
                               (unsigned int)((0x101010101010101i64
                                             * (((((_QWORD)v158 - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
                                               + ((((unsigned __int64)v158
                                                  - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)
                                               + (((((_QWORD)v158
                                                   - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) & 0x3333333333333333i64)
                                                 + ((((unsigned __int64)v158
                                                    - (((unsigned __int64)v158 >> 1) & 0x5555555555555555i64)) >> 2) & 0x3333333333333333i64)) >> 4)) & 0xF0F0F0F0F0F0F0Fi64)) >> 32) >> 24,
                               (__int64)&v158,
                               (unsigned int *)&InputBufferLength + 1) != -1073741820 )
            goto LABEL_598;
          v46 = HIDWORD(InputBufferLength);
          if( HIDWORD(InputBufferLength) > (unsigned int)Length )
            goto LABEL_96;
          PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(NonPagedPoolNx, HIDWORD(InputBufferLength), 0x744D5050ui64);
          v48 = PoolWithTag;
          InputBuffer = PoolWithTag;
          if( PoolWithTag )
          {
            memset((INT64)PoolWithTag, 0i64);
            if( (int)PpmCapturePerformanceDistribution(
                        v48,
                        HIDWORD(InputBufferLength),
                        v45,
                        (__int64)&v158,
                        (unsigned int *)&Size) >= 0 )
              memmove((UINT8 *)a4, v48, (unsigned int)Size);
            ExFreePoolWithTag(v48, 0x744D5050u);
          }
          goto LABEL_598;
        case SystemNumaProximityNodeInformation:
          ExpQueryNumaProximityNode((VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemDynamicTimeZoneInformation:
          if( (unsigned int)Length >= 0x1B0 )
          {
            v73 = (_OWORD *)PsGetCurrentServerSiloGlobals()[133];
            ExAcquireTimeRefreshLock(1u);
            p_Src = &Src;
            v75 = 3i64;
            v76 = 3i64;
            do
            {
              *(_OWORD *)&p_Src->CurrentSize = *v73;
              *(_OWORD *)&p_Src->PageFaultCount = v73[1];
              *(_OWORD *)&p_Src->MaximumWorkingSet = v73[2];
              *(_OWORD *)&p_Src->PeakSizeIncludingTransitionInPages = v73[3];
              *(_OWORD *)&p_Src[1].CurrentSize = v73[4];
              *(_OWORD *)&p_Src[1].PageFaultCount = v73[5];
              *(_OWORD *)&p_Src[1].MaximumWorkingSet = v73[6];
              p_Src += 2;
              *(_OWORD *)&p_Src[-1].PeakSizeIncludingTransitionInPages = v73[7];
              v73 += 8;
              --v76;
            }
            while( v76 );
            *(_OWORD *)&p_Src->CurrentSize = *v73;
            *(_OWORD *)&p_Src->PageFaultCount = v73[1];
            *(_OWORD *)&p_Src->MaximumWorkingSet = v73[2];
            ExReleaseTimeRefreshLock();
            v77 = &Src;
            do
            {
              *(_OWORD *)a4 = *(_OWORD *)&v77->CurrentSize;
              *(_OWORD *)(a4 + 16) = *(_OWORD *)&v77->PageFaultCount;
              *(_OWORD *)(a4 + 32) = *(_OWORD *)&v77->MaximumWorkingSet;
              *(_OWORD *)(a4 + 48) = *(_OWORD *)&v77->PeakSizeIncludingTransitionInPages;
              *(_OWORD *)(a4 + 64) = *(_OWORD *)&v77[1].CurrentSize;
              *(_OWORD *)(a4 + 80) = *(_OWORD *)&v77[1].PageFaultCount;
              *(_OWORD *)(a4 + 96) = *(_OWORD *)&v77[1].MaximumWorkingSet;
              a4 += 128i64;
              *(_OWORD *)(a4 - 16) = *(_OWORD *)&v77[1].PeakSizeIncludingTransitionInPages;
              v77 += 2;
              --v75;
            }
            while( v75 );
            *(_OWORD *)a4 = *(_OWORD *)&v77->CurrentSize;
            *(_OWORD *)(a4 + 16) = *(_OWORD *)&v77->PageFaultCount;
            *(_OWORD *)(a4 + 32) = *(_OWORD *)&v77->MaximumWorkingSet;
            LODWORD(Size) = 432;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 432;
          return;
        case SystemCodeIntegrityInformation:
          SeCodeIntegrityQueryInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemProcessorBrandString:
          if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
                 23i64,
                 0i64,
                 0i64,
                 (char *)&InputBufferLength + 4) != -1073741820 )
            goto LABEL_598;
          v90 = HIDWORD(InputBufferLength);
          if( (unsigned int)Length < HIDWORD(InputBufferLength) || !a4 )
          {
            LODWORD(Size) = HIDWORD(InputBufferLength);
            goto LABEL_598;
          }
          if( v9 )
          {
            PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
            InputBuffer = PoolWithQuotaTag;
            if( !PoolWithQuotaTag )
              goto LABEL_598;
            v90 = HIDWORD(InputBufferLength);
          }
          else
          {
            PoolWithQuotaTag = (_DWORD *)a4;
            InputBuffer = (VOID *)a4;
          }
          v92 = ((__int64(__fastcall *)(__int64, __int64, _DWORD *, size_t *))off_140C00A68[0])(
                  23i64,
                  v90,
                  PoolWithQuotaTag,
                  &Size);
          if( !v9 )
            goto LABEL_598;
          if( v92 < 0 )
            goto LABEL_419;
          goto LABEL_418;
        case SystemLogicalProcessorAndGroupInformation:
          LODWORD(Size) = Length;
          HIDWORD(Size) = KeQueryLogicalProcessorRelationship(
                            0i64,
                            RelationshipType,
                            (_SYSTEM_LOGICAL_PROCESSOR_INFORMATION_EX *)a4,
                            &Size);
          goto LABEL_598;
        case SystemProcessorCycleTimeInformation:
          LODWORD(Size) = 8 * v13;
          if( (unsigned int)Length >= 8 )
          {
            v89 = (unsigned int)Length >> 3;
            if( (unsigned int)Length >= 8 * (int)v13 )
              v89 = v13;
            while( v8 < v89 )
            {
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)v8;
              *(_QWORD *)a4 = *((_QWORD *)*(&KiProcessorBlock
                                          + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber))
                              + 4071);
              a4 += 8i64;
              v145 = (_QWORD *)a4;
              ++v8;
              v14 = v128;
            }
          }
          goto LABEL_598;
        case SystemStoreInformation:
          SmQueryStoreInformation((PVOID)0x140000000i64, a4, Length, (UINT64 *)v9);
          goto LABEL_598;
        case SystemVhdBootInformation:
          IoQueryVhdBootInformation((VOID *)0x140000000i64, a4, (UINT64 *)(unsigned int)Length);
          goto LABEL_598;
        case SystemCpuQuotaInformation:
          PsQueryCpuQuotaInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
          goto LABEL_598;
        case SystemErrorPortTimeouts:
          if( !(_DWORD)v20 )
          {
            LODWORD(Size) = 8;
            if( (unsigned int)Length >= 8 )
            {
              *(_DWORD *)a4 = DbgkErrorPortStartTimeout;
              *(_DWORD *)(a4 + 4) = DbgkErrorPortCommTimeout;
            }
          }
          goto LABEL_598;
        case SystemLowPriorityIoInformation:
          IoQueryLowPriorityIoInformation(
            (_SYSTEM_INFORMATION_CLASS)0x140000000ui64,
            (VOID *)a4,
            (unsigned int)Length,
            &Size);
          goto LABEL_598;
        case SystemBootEntropyInformation:
          LODWORD(Size) = 1096;
          if( (_DWORD)Length != 1096 )
            goto LABEL_598;
          if( v9 )
            return;
          ExQueryBootEntropyInformation(a4);
          goto LABEL_598;
        case SystemVerifierCountersInformation:
          if( (unsigned int)Length >= 0x110 )
          {
            VfGetVerifierInformation((PVOID)a4, (unsigned int)Length, &Size, 1ui64);
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 272;
          return;
        case SystemNodeDistanceInformation:
          LODWORD(Size) = 4 * (unsigned __int16)KeNumberNodes;
          if( (unsigned int)Length >= (unsigned int)Size )
          {
            v129 = 0;
            v82 = 0;
            v83 = v135;
            while( v82 < (unsigned __int16)KeNumberNodes )
            {
              *(_DWORD *)(a4 + 4i64 * v82++) = *(_DWORD *)(*(_QWORD *)KeNodeDistance
                                                         + 4i64 * (v8 + v83 * (unsigned __int16)KeNumberNodes));
              v8 = v82;
              v129 = v82;
            }
          }
          goto LABEL_598;
        case SystemAcpiAuditInformation:
          LODWORD(Size) = 8;
          if( (_DWORD)Length != 8 )
            goto LABEL_598;
          if( !a4 )
            goto LABEL_598;
          PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, 8ui64, 0x6F666E49ui64);
          v147 = PoolWithQuotaTag;
          if( !PoolWithQuotaTag )
            goto LABEL_598;
          if( ((int(__fastcall *)(__int64, __int64, _DWORD *, size_t *))off_140C00A68[0])(
                 26i64,
                 8i64,
                 PoolWithQuotaTag,
                 &Size) >= 0 )
          {
            *(_DWORD *)a4 = *PoolWithQuotaTag;
            *(_DWORD *)(a4 + 4) ^= (PoolWithQuotaTag[1] ^ *(_DWORD *)(a4 + 4)) & 1;
            v93 = *(_DWORD *)(a4 + 4) ^ ((unsigned __int8)*(_DWORD *)(a4 + 4) ^ (unsigned __int8)PoolWithQuotaTag[1]) & 2;
            *(_DWORD *)(a4 + 4) = v93;
            *(_DWORD *)(a4 + 4) = v93 ^ (PoolWithQuotaTag[1] ^ v93) & 4;
          }
          goto LABEL_419;
        case SystemBasicPerformanceInformation:
          if( (_DWORD)Length != 32 )
          {
            if( a6 )
              *(_DWORD *)a6 = 32;
            return;
          }
          CurrentProcess = PsGetCurrentProcess();
          ProcessPartitionId = MmGetProcessPartitionId(CurrentProcess);
          Src.CurrentSize = MmGetAvailablePages(ProcessPartitionId);
          Src.PeakSize = MmGetTotalCommittedPages(v37);
          *(_QWORD *)&Src.PageFaultCount = MmGetTotalCommitLimit(v38);
          Src.MinimumWorkingSet = MmGetPeakCommitment(v39);
          MinimumWorkingSet = Src.MinimumWorkingSet;
          if( Src.MinimumWorkingSet < Src.PeakSize )
            MinimumWorkingSet = Src.PeakSize;
          Src.MinimumWorkingSet = MinimumWorkingSet;
          *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
          *(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
          LODWORD(Size) = 32;
          goto LABEL_598;
        case SystemQueryPerformanceCounterInformation:
          LODWORD(Size) = 12;
          if( (unsigned int)Length >= 4 )
          {
            v159 = *(_DWORD *)a4;
            if( v159 == 1 && (unsigned int)Length >= 0xC )
            {
              *(_DWORD *)(a4 + 8) = 0;
              *(_DWORD *)(a4 + 4) = 0;
              *(_DWORD *)(a4 + 8) |= 1u;
              *(_DWORD *)(a4 + 4) |= 1u;
              if( KUSER_SHARED_DATA.QpcBypassEnabled )
                *(_DWORD *)(a4 + 4) &= ~1u;
            }
          }
          goto LABEL_598;
        case SystemSessionBigPoolInformation:
          if( (unsigned int)Length >= 0x10 )
          {
            LODWORD(SessionId) = *(_DWORD *)a4;
            v155 = *(VOID **)(a4 + 8);
            v63 = *(_DWORD *)(a4 + 4);
            v140 = v63;
            if( ((unsigned __int8)v155 & 7) == 0 && !(unsigned int)ExIsRestrictedCaller(v9) )
            {
              ExGetSessionBigPoolInformation(v155, v63, &Size, &SessionId);
              goto LABEL_598;
            }
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 16;
          }
          return;
        case SystemBootGraphicsInformation:
          LODWORD(Size) = 32;
          if( (_DWORD)Length == 32 && (int)BgkQueryBootGraphicsInformation(0i64, &Src) >= 0 )
          {
            CurrentSize = Src.CurrentSize;
            if( v9 )
              CurrentSize = 0i64;
            Src.CurrentSize = CurrentSize;
            memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Size);
          }
          goto LABEL_598;
        case SystemBadPageInformation:
          if( !(_DWORD)v20 )
          {
            v97 = MmEnumerateBadPages((UINT64 **)&v149);
            v98 = v149;
            if( v149 )
              v8 = 8 * *(_DWORD *)v149;
            LODWORD(Size) = v8;
            if( (unsigned int)Length < v8 )
              v97 = -1073741820;
            if( v149 )
            {
              if( v97 >= 0 )
                memmove((UINT8 *)a4, (UINT8 *)v149 + 8, v8);
              ExFreePoolWithTag(v98, 0);
            }
          }
          goto LABEL_598;
        case SystemPlatformBinaryInformation:
          if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
            return;
          ExpGetSystemPlatformBinary((VOID *)a4, (unsigned int)Length, v9);
          goto LABEL_598;
        case SystemPolicyInformation:
          LODWORD(Size) = 32;
          if( (_DWORD)Length == 32 )
            ExHandleSPCall2(0x140000000ui64, a4);
          goto LABEL_598;
        case SystemHypervisorProcessorCountInformation:
          LODWORD(Size) = 8;
          if( (unsigned int)Length >= 8 )
          {
            HvlQueryActiveProcessors(&Count, 0i64);
            if( !v99 && !HvlQueryProcessorTopologyCount(0i64, (UINT64 *)((char *)&Count + 4)) )
              *(_QWORD *)a4 = Count;
          }
          goto LABEL_598;
        case SystemDeviceDataInformation:
        case SystemDeviceDataEnumerationInformation:
          if( (_DWORD)Length == 48 )
          {
            ExpGetDeviceDataInformation(v16, (VOID *)a4, 0x30ui64);
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 48;
          }
          return;
        case SystemMemoryTopologyInformation:
          ExpQueryMemoryTopologyInformation((VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemMemoryChannelInformation:
          ExpQueryChannelInformation((VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemBootLogoInformation:
          if( (a6 || (unsigned int)Length >= 8) && (int)BgkQueryBootGraphicsInformation(2i64, &Size) >= 0 )
          {
            if( (_DWORD)Size )
            {
              if( (unsigned int)Length >= (unsigned int)Size && (int)BgkQueryBootGraphicsInformation(1i64, &P) >= 0 )
              {
                v95 = P;
                if( P )
                {
                  memmove((UINT8 *)a4, (UINT8 *)P, (unsigned int)Size);
                  ExFreePoolWithTag(v95, 0x4B494742u);
                }
              }
            }
          }
          goto LABEL_598;
        case SystemSecureBootPolicyInformation:
        case SystemSecureBootInformation:
        case SystemSecureBootPolicyFullInformation:
        case SystemCodeIntegrityPlatformManifestInformation:
          SeSecureBootQueryInformation(v16, (VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemPortableWorkspaceEfiLauncherInformation:
          ExpQueryPortableWorkspaceEfiLauncherInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemKernelDebuggerInformationEx:
          if( (unsigned int)Length >= 3 )
          {
            *(_BYTE *)a4 = KdpBootedNodebug == 0;
            *(_BYTE *)(a4 + 1) = (_BYTE)KdDebuggerEnabled;
            *(_BYTE *)(a4 + 2) = (_BYTE)KdDebuggerNotPresent == 0;
            v10 = 3;
            goto LABEL_256;
          }
          if( a6 )
            *(_DWORD *)a6 = 3;
          return;
        case SystemBootMetadataInformation:
          if( !ExBootLoaderMetadata )
            goto LABEL_598;
          v96 = *(_DWORD *)ExBootLoaderMetadata;
          LODWORD(Size) = *(_DWORD *)ExBootLoaderMetadata;
          if( !a4 || (unsigned int)Length < v96 )
            goto LABEL_598;
          if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeTcbPrivilege, v9) )
            return;
          memmove((UINT8 *)a4, (UINT8 *)(ExBootLoaderMetadata + 4), (unsigned int)Size);
          goto LABEL_598;
        case SystemSoftRebootInformation:
          LODWORD(Size) = 4;
          if( (unsigned int)Length >= 4 )
          {
            *(_DWORD *)a4 = ExSoftRebootFlags;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 4;
          return;
        case SystemOfflineDumpConfigInformation:
          if( !(_DWORD)v20 )
          {
            LODWORD(Size) = 32;
            if( (unsigned int)Length < 0x20 )
            {
              if( (unsigned int)Length < 0xC )
              {
                HIDWORD(Size) = -1073741820;
              }
              else
              {
                LODWORD(Size) = 12;
                *(_QWORD *)a4 = PoOffCrashConfigTable;
                *(_DWORD *)(a4 + 8) = DWORD2(PoOffCrashConfigTable);
              }
            }
            else
            {
              *(_QWORD *)a4 = PoOffCrashConfigTable;
              *(_DWORD *)(a4 + 8) = DWORD2(PoOffCrashConfigTable);
              *(_QWORD *)(a4 + 16) = xmmword_140C24E30;
              *(_DWORD *)(a4 + 24) = DWORD2(xmmword_140C24E30);
            }
          }
          goto LABEL_598;
        case SystemProcessorFeaturesInformation:
          if( (unsigned int)Length >= 0x20 )
          {
            ExpGetSystemProcessorFeaturesInformation((_QWORD *)a4);
            LODWORD(Size) = 32;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 32;
          return;
        case SystemEdidInformation:
          LODWORD(Size) = 128;
          if( (_DWORD)Length == 128 && (int)BgkQueryBootGraphicsInformation(3i64, &Src) >= 0 )
            memmove((UINT8 *)a4, (UINT8 *)&Src, (unsigned int)Size);
          goto LABEL_598;
        case SystemManufacturingInformation:
          LODWORD(Size) = WORD5(ExpManufacturingInformation) + 24;
          if( (unsigned int)Length >= (unsigned int)Size )
          {
            v100 = (UINT8 *)(a4 + 24);
            *(_OWORD *)a4 = 0i64;
            *(_QWORD *)(a4 + 16) = 0i64;
            *(_DWORD *)a4 = ExpManufacturingInformation;
            *(_DWORD *)(a4 + 8) = DWORD2(ExpManufacturingInformation);
            if( WORD4(ExpManufacturingInformation) )
            {
              *(_QWORD *)(a4 + 16) = v100;
              memmove(v100, (UINT8 *)Data, WORD5(ExpManufacturingInformation));
            }
          }
          goto LABEL_598;
        case SystemEnergyEstimationConfigInformation:
          LODWORD(Size) = 1;
          if( (_DWORD)Length )
          {
            *(_BYTE *)a4 = PoEnergyEstimationEnabled();
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 1;
          }
          goto LABEL_598;
        case SystemHypervisorDetailInformation:
          HvlQueryDetailInfo((PVOID)a4, (unsigned int)Length, (UINT64 *)v15);
          goto LABEL_598;
        case SystemProcessorCycleStatsInformation:
          LODWORD(Size) = (_DWORD)v13 << 6;
          if( (unsigned int)Length >= 0x40 )
          {
            v101 = (unsigned int)Length >> 6;
            if( (unsigned int)Length >= (_DWORD)v13 << 6 )
              v101 = v13;
            while( v8 < v101 )
            {
              LOWORD(ProcNumber) = v14;
              WORD1(ProcNumber) = (unsigned __int8)v8;
              v102 = (INT64)*(&KiProcessorBlock
                            + (unsigned int)KeGetProcessorIndexFromNumber((_PROCESSOR_NUMBER *)&ProcNumber));
              KeQueryCycleTimeStatsProcessor(v102, (_QWORD *)a4);
              a4 += 64i64;
              v145 = (_QWORD *)a4;
              ++v8;
              v14 = v128;
            }
          }
          goto LABEL_598;
        case SystemTrustedPlatformModuleInformation:
          SeQueryTrustedPlatformModuleInformation((PVOID)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemKernelDebuggerFlags:
          if( !(_DWORD)Length )
          {
            if( a6 )
              *(_DWORD *)a6 = 1;
            return;
          }
          *(_BYTE *)a4 = KdIgnoreUmExceptions;
LABEL_256:
          LODWORD(Size) = v10;
          goto LABEL_598;
        case SystemCodeIntegrityPolicyInformation:
        case SystemCodeIntegrityPolicyFullInformation:
        case SystemCodeIntegrityPoliciesFullInformation:
        case SystemCodeIntegrityUnlockInformation:
        case SystemCodeIntegrityVerificationInformation:
        case SystemCodeIntegritySyntheticCacheInformation:
          SeCodeIntegrityQueryPolicyInformation((unsigned int)v16);
          goto LABEL_598;
        case SystemIsolatedUserModeInformation:
          LODWORD(Size) = 16;
          if( (_DWORD)Length == 16 )
          {
            LOBYTE(Src.CurrentSize) ^= (LOBYTE(Src.CurrentSize) ^ (16 * ExpFirmwarePageProtectionSupported)) & 0x10;
            if( VslIsSecureKernelRunning() )
            {
              v130[0] = 0;
              LOBYTE(Src.CurrentSize) = v103 | 1;
              NestedPageProtectionFlags = VslGetNestedPageProtectionFlags();
              v107 = Src.CurrentSize;
              if( (NestedPageProtectionFlags & 2) != 0 )
              {
                v107 = LOBYTE(Src.CurrentSize) | 2;
                LOBYTE(Src.CurrentSize) |= 2u;
              }
              if( (NestedPageProtectionFlags & 0x20) != 0 )
              {
                v107 |= 4u;
                LOBYTE(Src.CurrentSize) = v107;
              }
              if( (NestedPageProtectionFlags & 0x10) != 0 )
                LOBYTE(Src.CurrentSize) = v107 | 8;
              if( (NestedPageProtectionFlags & 0x200) != 0 )
                BYTE1(Src.CurrentSize) |= 2u;
              v108 = a1;
              if( a1 )
              {
                VslIsTrustletRunning(a1, v130);
                v108 = BYTE1(Src.CurrentSize);
                LOBYTE(v108) = (v130[0] ^ BYTE1(Src.CurrentSize)) & 1 ^ BYTE1(Src.CurrentSize);
                BYTE1(Src.CurrentSize) = v108;
              }
              IsIumEncryptionKeyAvailable = ExpIsIumEncryptionKeyAvailable(v108, v105, v106);
              LOBYTE(Src.CurrentSize) ^= (LOBYTE(Src.CurrentSize) ^ (32 * IsIumEncryptionKeyAvailable)) & 0x20;
            }
            *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 16;
          }
          goto LABEL_598;
        case SystemHardwareSecurityTestInterfaceResultsInformation:
          SeQueryHSTIResults();
          goto LABEL_598;
        case SystemSingleModuleInformation:
          ExpQuerySingleModuleInformation((PVOID)a4, (unsigned int)Length, v9, &Size);
          goto LABEL_598;
        case SystemVsmProtectionInformation:
          HvlQueryVsmProtectionInfo((UINT8 *)a4, (unsigned int)Length, (UINT8 *)&Size);
          goto LABEL_598;
        case SystemAffinitizedInterruptProcessorInformation:
          if( ExCpuSetResourceManagerAccessCheck(v9) < 0 )
            return;
          LODWORD(Size) = 168;
          if( (_DWORD)Length == 168 )
            KeGetAffinitizedInterruptsInfo((_KAFFINITY_EX *)a4, v116);
          goto LABEL_598;
        case SystemRootSiloInformation:
          PsRootSiloInformation((_DWORD *)a4, Length, (unsigned int *)&Size);
          goto LABEL_598;
        case SystemCpuSetInformation:
          if( Handle )
          {
            v156 = 0i64;
            v117 = ObReferenceObjectByHandle(Handle, 0x1000u, (POBJECT_TYPE)PsProcessType, v9, &v156, 0i64);
            v118 = (struct _DMA_ADAPTER *)v156;
            if( v117 < 0 )
              return;
          }
          else
          {
            v118 = (struct _DMA_ADAPTER *)Process;
          }
          KeQueryCpuSetInformation(a4, (unsigned int)Length, (INT64)&Size, (INT64)v118);
          goto LABEL_545;
        case SystemSecureKernelProfileInformation:
          if( !(_DWORD)Length )
            goto LABEL_598;
          if( v9 && !SeSinglePrivilegeCheck(*(_QWORD *)&SeSystemProfilePrivilege, v9) )
            return;
          v119 = (UINT8 *)ExAllocatePoolWithQuotaTag((POOL_TYPE)520, (unsigned int)Length, 0x6F666E49ui64);
          v120 = v119;
          InputBuffer = v119;
          if( v119 )
          {
            memset((INT64)v119, 0i64);
            if( (int)VslQuerySecureKernelProfileInformation(v157, (INT64)v120, (unsigned int)Length, &Size) >= 0 )
              memmove((UINT8 *)a4, v120, (unsigned int)Size);
            ExFreePoolWithTag(v120, 0x6F666E49u);
          }
          goto LABEL_598;
        case SystemInterruptSteeringInformation:
          ExpQueryInterruptSteeringInformation(InputBuffer, v20, (VOID *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemSupportedProcessorArchitectures:
          if( Handle )
          {
            v147 = 0i64;
            v121 = ObReferenceObjectByHandle(Handle, 0x1000u, (POBJECT_TYPE)PsProcessType, v9, &v147, 0i64);
            v118 = (struct _DMA_ADAPTER *)v147;
            if( v121 < 0 )
              return;
          }
          else
          {
            v118 = (struct _DMA_ADAPTER *)Process;
          }
          PsWow64GetSupportedArchitectures(a4, (unsigned int)Length, &Size, (INT64)v118);
LABEL_545:
          if( v118 )
            HalPutDmaAdapter(v118);
          goto LABEL_598;
        case SystemMemoryUsageInformation:
          if( (_DWORD)Length != 56 )
          {
            if( a6 )
              *(_DWORD *)a6 = 56;
            return;
          }
          v21 = PsGetCurrentProcess();
          v22 = MmGetProcessPartitionId(v21);
          Src.CurrentSize = MmGetNumberOfPhysicalPages(v22) << 12;
          Src.PeakSize = MmGetAvailablePages(v22) << 12;
          MmGetResidentAvailablePages(v23);
          *(_QWORD *)&Src.PageFaultCount = v24 << 12;
          Src.MinimumWorkingSet = MmGetTotalCommittedPages(v25) << 12;
          Src.CurrentSizeIncludingTransitionInPages = MmGetTotalCommitLimit(v26) << 12;
          Src.PeakSizeIncludingTransitionInPages = MmGetPeakCommitment(v27) << 12;
          Src.MaximumWorkingSet = MmGetSharedCommit(v28) << 12;
          PeakSize = Src.CurrentSize;
          if( Src.CurrentSize < Src.PeakSize )
            PeakSize = Src.PeakSize;
          Src.CurrentSize = PeakSize;
          CurrentSizeIncludingTransitionInPages = Src.CurrentSizeIncludingTransitionInPages;
          if( Src.CurrentSizeIncludingTransitionInPages < Src.MinimumWorkingSet )
            CurrentSizeIncludingTransitionInPages = Src.MinimumWorkingSet;
          Src.CurrentSizeIncludingTransitionInPages = CurrentSizeIncludingTransitionInPages;
          PeakSizeIncludingTransitionInPages = Src.PeakSizeIncludingTransitionInPages;
          if( Src.PeakSizeIncludingTransitionInPages < Src.MinimumWorkingSet )
            PeakSizeIncludingTransitionInPages = Src.MinimumWorkingSet;
          Src.PeakSizeIncludingTransitionInPages = PeakSizeIncludingTransitionInPages;
          *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
          *(_OWORD *)(a4 + 16) = *(_OWORD *)&Src.PageFaultCount;
          *(_OWORD *)(a4 + 32) = *(_OWORD *)&Src.MaximumWorkingSet;
          *(_QWORD *)(a4 + 48) = Src.PeakSizeIncludingTransitionInPages;
          LODWORD(Size) = 56;
          goto LABEL_598;
        case SystemCodeIntegrityCertificateInformation:
          if( (_DWORD)Length != 16 )
            return;
          ExpQueryCodeIntegrityCertificateInfo(*(VOID **)a4, *(unsigned int *)(a4 + 8));
          goto LABEL_598;
        case SystemPhysicalMemoryInformation:
          if( (_DWORD)Length != 24 )
          {
            if( a6 )
              *(_DWORD *)a6 = 24;
            return;
          }
          v32 = PsGetCurrentProcess();
          v33 = MmGetProcessPartitionId(v32);
          Src.CurrentSize = MmGetNumberOfPhysicalPages(v33) << 12;
          Src.PeakSize = MmGetLowestPhysicalPage(v33) << 12;
          *(_QWORD *)&Src.PageFaultCount = (MmGetHighestPhysicalPage(v34) << 12) + 4095;
          *(_OWORD *)a4 = *(_OWORD *)&Src.CurrentSize;
          *(_QWORD *)(a4 + 16) = *(_QWORD *)&Src.PageFaultCount;
LABEL_67:
          LODWORD(Size) = 24;
          goto LABEL_598;
        case SystemControlFlowTransition:
          WbDispatchOperation((PVOID)a4, (unsigned int)Length);
          goto LABEL_598;
        case SystemKernelDebuggingAllowed:
          if( (_DWORD)Length )
          {
            if( a6 )
              *(_DWORD *)a6 = 0;
          }
          else
          {
            BYTE4(SessionId) = 1;
            ZwFilterBootOption();
          }
          return;
        case SystemActivityModerationUserSettings:
          if( (_DWORD)Length != 8 )
            return;
          if( (int)PsQueryActivityModerationUserSettings(&Src) >= 0 )
            *(_QWORD *)a4 = Src.CurrentSize;
          goto LABEL_598;
        case SystemFlushInformation:
          if( (unsigned int)Length >= 0x20 )
          {
            ExpGetSystemFlushInformation(a4);
            LODWORD(Size) = 32;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 32;
          return;
        case SystemProcessorIdleMaskInformation:
          LODWORD(Size) = 8 * KeQueryActiveGroupCount();
          if( (unsigned int)Length >= (unsigned int)Size )
          {
            memset(a4, 0i64);
            v129 = 0;
            while( v8 < (unsigned __int16)KeNumberNodes )
            {
              v88 = *((_QWORD *)&KeNodeBlock + v8);
              WORD2(ProcNumber) = *(_WORD *)(v88 + 144);
              *(_QWORD *)(a4 + 8i64 * WORD2(ProcNumber)) |= *(_QWORD *)(v88 + 24);
              v8 = ++v129;
            }
          }
          goto LABEL_598;
        case SystemWriteConstraintInformation:
          if( (unsigned int)Length >= 8 )
          {
            ExpGetSystemWriteConstraintInformation((_QWORD *)a4);
            LODWORD(Size) = 8;
            goto LABEL_598;
          }
          if( a6 )
            *(_DWORD *)a6 = 8;
          return;
        case SystemKernelVaShadowInformation:
          KeQueryKvaShadowInformation((_DWORD *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemHypervisorSharedPageInformation:
          LODWORD(Size) = 8;
          if( (unsigned int)Length >= 8 )
          {
            v123 = qword_140C4DB88;
            *(_QWORD *)a4 = 0i64;
            *(_QWORD *)a4 = v123;
          }
          goto LABEL_598;
        case SystemFirmwareBootPerformanceInformation:
          if( ((unsigned int(__fastcall *)(__int64, _QWORD, _QWORD, char *))off_140C00A68[0])(
                 34i64,
                 0i64,
                 0i64,
                 (char *)&InputBufferLength + 4) != -1073741820 )
            return;
          v46 = HIDWORD(InputBufferLength);
          if( (unsigned int)Length < HIDWORD(InputBufferLength) || !a4 )
          {
LABEL_96:
            LODWORD(Size) = v46;
            goto LABEL_598;
          }
          if( v9 )
          {
            PoolWithQuotaTag = ExAllocatePoolWithQuotaTag((POOL_TYPE)9, HIDWORD(InputBufferLength), 0x6F666E49ui64);
            InputBuffer = PoolWithQuotaTag;
            if( !PoolWithQuotaTag )
              goto LABEL_598;
            v46 = HIDWORD(InputBufferLength);
          }
          else
          {
            PoolWithQuotaTag = (_DWORD *)a4;
            InputBuffer = (VOID *)a4;
          }
          v122 = ((__int64(__fastcall *)(__int64, _QWORD, _DWORD *, size_t *))off_140C00A68[0])(
                   34i64,
                   v46,
                   PoolWithQuotaTag,
                   &Size);
          if( v9 )
          {
            if( v122 >= 0 )
LABEL_418:
              memmove((UINT8 *)a4, (UINT8 *)PoolWithQuotaTag, (unsigned int)Size);
LABEL_419:
            ExFreePoolWithTag(PoolWithQuotaTag, 0x6F666E49u);
          }
          goto LABEL_598;
        case SystemFirmwarePartitionInformation:
          IoQuerySystemDeviceName(
            SystemFirmwarePartitionInformation,
            (VOID *)a4,
            (unsigned int)Length,
            (UINT *)&Size,
            (INT64)Object,
            (INT64)HandleInformation,
            Size,
            ProcNumber);
          goto LABEL_598;
        case SystemSpeculationControlInformation:
          KeQuerySpeculationControlInformation((UINT8 *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemDmaGuardPolicyInformation:
          LODWORD(Size) = 1;
          if( (_DWORD)Length == 1 )
          {
            v143 = 0;
            if( ((int(__fastcall *)(__int64, __int64, _SYSTEM_FILECACHE_INFORMATION *, int *))off_140C00A68[0])(
                   47i64,
                   1i64,
                   &Src,
                   &v143) >= 0
              && v143 == 1 )
            {
              *(_BYTE *)a4 = Src.CurrentSize;
            }
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 1;
          }
          goto LABEL_598;
        case SystemLeapSecondInformation:
          if( (_DWORD)Length != 8 )
          {
            if( a6 )
              *(_DWORD *)a6 = 8;
            return;
          }
          *(_BYTE *)a4 = *(_BYTE *)ExLeapSecondData != 0;
          *(_DWORD *)(a4 + 4) = 0;
LABEL_114:
          LODWORD(Size) = 8;
          goto LABEL_598;
        case SystemFlags2Information:
          if( (_DWORD)Length == 4 )
          {
            *(_DWORD *)a4 = *(_DWORD *)NtGlobalFlag2;
            goto LABEL_157;
          }
          if( a6 )
            *(_DWORD *)a6 = 4;
          return;
        case SystemSecurityModelInformation:
          SeSecurityModelQueryInformation((_DWORD *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemFeatureConfigurationInformation:
          CmQuerySingleFeatureConfiguration((INT64 *)InputBuffer, v20, a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemFeatureConfigurationSectionInformation:
          CmQueryFeatureConfigurationSections(
            (INT64)InputBuffer,
            v20,
            (_OWORD *)a4,
            (unsigned int)Length,
            (INT64)&Size,
            *((_BYTE *)KeGetCurrentThread() + 562));
          goto LABEL_598;
        case SystemSecureSpeculationControlInformation:
          KeQuerySecureSpeculationInformation((UINT8 *)a4, (unsigned int)Length, &Size);
          goto LABEL_598;
        case SystemShadowStackInformation:
          if( (_DWORD)Length == 4 )
          {
            *(_DWORD *)a4 = 0;
            if( !PsIsCurrentThreadInServerSilo() )
            {
              *(_DWORD *)a4 ^= (*(_DWORD *)a4 ^ (unsigned __int8)KeIsCetCapable(v111, v110)) & 1;
              IsUserCetAllowed = KeIsUserCetAllowed();
              *(_DWORD *)a4 = (unsigned int)v113 ^ ((unsigned __int8)v113 ^ (unsigned __int8)(2 * IsUserCetAllowed)) & 2;
              IsKTMCommitCoordinator = ext_ms_win_ntos_tm_l1_1_0_TmIsKTMCommitCoordinator(v113);
              *(_DWORD *)a4 = v115 ^ ((unsigned __int16)v115 ^ (unsigned __int16)(IsKTMCommitCoordinator << 8)) & 0x100;
            }
LABEL_157:
            LODWORD(Size) = 4;
LABEL_598:
            if( a6 )
              *(_DWORD *)a6 = Size;
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 4;
          }
          return;
        case SystemPoolZeroingInformation:
          LODWORD(Size) = 1;
          if( (_DWORD)Length == 1 )
          {
            *(_BYTE *)a4 = 1;
          }
          else if( a6 )
          {
            *(_DWORD *)a6 = 1;
          }
          goto LABEL_598;
        default:
          return;
      }
      return;
    case SystemCpuSetInformation:
    case SystemSupportedProcessorArchitectures:
      v20 = (unsigned int)InputBufferLength;
      if( (_DWORD)InputBufferLength != 8 )
        return;
      Handle = *(HANDLE *)InputBuffer;
      goto LABEL_35;
    case SystemSecureKernelProfileInformation:
      v20 = (unsigned int)InputBufferLength;
      if( (_DWORD)InputBufferLength != 8 )
        return;
      v157 = *(_QWORD *)InputBuffer;
      goto LABEL_35;
    default:
      goto LABEL_34;
  }
}

Referenced by:

NtQuerySystemInformation
NtQuerySystemInformationEx