StartFirstUserProcess
VOID __stdcall StartFirstUserProcess(){
INT64 v0;
INT64 v1;
WCHAR v2;
__int64 MaximumLength;
__int64 v4;
char *PoolWithTag;
char *v6;
UNICODE_STRING *v7;
UNICODE_STRING *v8;
__int128 v9;
UNICODE_STRING *v10;
ULONG_PTR UserProcess;
char v12;
int v13;
NTSTATUS v14;
struct _UNICODE_STRING DestinationString;
INT64 result;
HANDLE ProcessHandle;
HANDLE ThreadHandle;
union _LARGE_INTEGER Interval;
*(_DWORD *)(&DestinationString.MaximumLength + 1) = 0;
memset((INT64)&result, 0i64);
if( QueryRegistryHideMachine(v1, v0, v2) )
RegistryOverwriteCentralProcessor();
MaximumLength = stru_140D23938.MaximumLength;
v4 = stru_140D23928.MaximumLength + 1148i64;
PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, v4 + stru_140D23938.MaximumLength, 0x62537350ui64);
v6 = PoolWithTag;
if( !PoolWithTag )
KeBugCheckEx(0x6Du, 0xFFFFFFFFC000009Aui64, 0i64, 0i64, 0i64);
memset((INT64)PoolWithTag, 0i64);
*((_DWORD *)v6 + 1) = v4;
*(_DWORD *)v6 = v4;
*((_QWORD *)v6 + 16) = &v6[v4];
*((_DWORD *)v6 + 2) = 4194305;
*((_QWORD *)v6 + 126) = MaximumLength;
*((_OWORD *)v6 + 5) = 0i64;
*((_QWORD *)v6 + 11) = 0i64;
*((_QWORD *)v6 + 8) = v6 + 1088;
*((_WORD *)v6 + 29) = stru_140D23928.MaximumLength;
RtlCopyUnicodeString((UNICODE_STRING *)(v6 + 56), &stru_140D23928, v7);
*((_QWORD *)v6 + 13) = &v6[*((unsigned __int16 *)v6 + 29) + 1088];
*((_WORD *)v6 + 49) = 60;
RtlCopyUnicodeString((UNICODE_STRING *)v6 + 6, (UNICODE_STRING *)&NtInitialUserProcess, v8);
v9 = *((_OWORD *)v6 + 6);
DestinationString.Buffer = (wchar_t *)*((_QWORD *)v6 + 16);
*((_OWORD *)v6 + 7) = v9;
DestinationString.Length = 0;
DestinationString.MaximumLength = MaximumLength;
RtlCopyUnicodeString(&DestinationString, &stru_140D23938, v10);
UserProcess = RtlCreateUserProcessEx((UNICODE_STRING *)v6 + 6, (_RTL_USER_PROCESS_PARAMETERS *)v6);
InbvIsBootDriverInstalled();
if( v12 )
FinalizeBootLogo();
if( (UserProcess & 0x80000000) != 0i64 )
KeBugCheckEx(0x6Du, UserProcess, 0i64, 1ui64, 0i64);
v13 = ZwSetInformationProcess((GROUP_AFFINITY *)ProcessHandle);
if( v13 < 0 )
KeBugCheckEx(0x6Du, v13, 0i64, 2ui64, 0i64);
v14 = ZwResumeThread(ThreadHandle, 0i64);
if( v14 < 0 )
KeBugCheckEx(0x6Du, v14, 0i64, 3ui64, 0i64);
byte_140C508A4 = 1;
Interval.QuadPart = -50000000i64;
KeDelayExecutionThread(0, 0, &Interval);
ZwClose(ThreadHandle);
ZwClose(ProcessHandle);
ExFreePoolWithTag(v6, 0);
}Referenced by:
Phase1InitializationIoReady