StartFirstUserProcess

VOID __stdcall StartFirstUserProcess(){
  INT64 v0; 
  INT64 v1; 
  WCHAR v2; 
  __int64 MaximumLength; 
  __int64 v4; 
  char *PoolWithTag; 
  char *v6; 
  UNICODE_STRING *v7; 
  UNICODE_STRING *v8; 
  __int128 v9; 
  UNICODE_STRING *v10; 
  ULONG_PTR UserProcess; 
  char v12; 
  int v13; 
  NTSTATUS v14; 
  struct _UNICODE_STRING DestinationString; 
  INT64 result; 
  HANDLE ProcessHandle; 
  HANDLE ThreadHandle; 
  union _LARGE_INTEGER Interval; 
  *(_DWORD *)(&DestinationString.MaximumLength + 1) = 0;
  memset((INT64)&result, 0i64);
  if( QueryRegistryHideMachine(v1, v0, v2) )
    RegistryOverwriteCentralProcessor();
  MaximumLength = stru_140D23938.MaximumLength;
  v4 = stru_140D23928.MaximumLength + 1148i64;
  PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, v4 + stru_140D23938.MaximumLength, 0x62537350ui64);
  v6 = PoolWithTag;
  if( !PoolWithTag )
    KeBugCheckEx(0x6Du, 0xFFFFFFFFC000009Aui64, 0i64, 0i64, 0i64);
  memset((INT64)PoolWithTag, 0i64);
  *((_DWORD *)v6 + 1) = v4;
  *(_DWORD *)v6 = v4;
  *((_QWORD *)v6 + 16) = &v6[v4];
  *((_DWORD *)v6 + 2) = 4194305;
  *((_QWORD *)v6 + 126) = MaximumLength;
  *((_OWORD *)v6 + 5) = 0i64;
  *((_QWORD *)v6 + 11) = 0i64;
  *((_QWORD *)v6 + 8) = v6 + 1088;
  *((_WORD *)v6 + 29) = stru_140D23928.MaximumLength;
  RtlCopyUnicodeString((UNICODE_STRING *)(v6 + 56), &stru_140D23928, v7);
  *((_QWORD *)v6 + 13) = &v6[*((unsigned __int16 *)v6 + 29) + 1088];
  *((_WORD *)v6 + 49) = 60;
  RtlCopyUnicodeString((UNICODE_STRING *)v6 + 6, (UNICODE_STRING *)&NtInitialUserProcess, v8);
  v9 = *((_OWORD *)v6 + 6);
  DestinationString.Buffer = (wchar_t *)*((_QWORD *)v6 + 16);
  *((_OWORD *)v6 + 7) = v9;
  DestinationString.Length = 0;
  DestinationString.MaximumLength = MaximumLength;
  RtlCopyUnicodeString(&DestinationString, &stru_140D23938, v10);
  UserProcess = RtlCreateUserProcessEx((UNICODE_STRING *)v6 + 6, (_RTL_USER_PROCESS_PARAMETERS *)v6);
  InbvIsBootDriverInstalled();
  if( v12 )
    FinalizeBootLogo();
  if( (UserProcess & 0x80000000) != 0i64 )
    KeBugCheckEx(0x6Du, UserProcess, 0i64, 1ui64, 0i64);
  v13 = ZwSetInformationProcess((GROUP_AFFINITY *)ProcessHandle);
  if( v13 < 0 )
    KeBugCheckEx(0x6Du, v13, 0i64, 2ui64, 0i64);
  v14 = ZwResumeThread(ThreadHandle, 0i64);
  if( v14 < 0 )
    KeBugCheckEx(0x6Du, v14, 0i64, 3ui64, 0i64);
  byte_140C508A4 = 1;
  Interval.QuadPart = -50000000i64;
  KeDelayExecutionThread(0, 0, &Interval);
  ZwClose(ThreadHandle);
  ZwClose(ProcessHandle);
  ExFreePoolWithTag(v6, 0);
}

Referenced by:

Phase1InitializationIoReady