NtQuerySystemInformation
INT64 __fastcall NtQuerySystemInformation(
_SYSTEM_INFORMATION_CLASS SystemInformationClass,
VOID *SystemInformation,
UINT64 SystemInformationLength,
UINT64 *ReturnLength){
__int16 *v4;
int v5;
UINT64 v6;
INT64 result;
UINT64 Length;
__int16 v9;
v4 = 0i64;
v5 = SystemInformationLength;
v9 = 0;
if( SystemInformationClass < SystemWow64SharedInformationObsolete
|| SystemInformationClass >= SystemProcessorIdleCycleTimeInformation )
{
switch( SystemInformationClass )
{
case SystemProcessorPerformanceInformation:
case SystemInterruptInformation:
case SystemProcessorIdleInformation:
case SystemProcessorPowerInformation:
case SystemProcessorIdleCycleTimeInformation:
case SystemProcessorPerformanceDistribution:
case SystemProcessorCycleTimeInformation:
case SystemProcessorPerformanceInformationEx:
v9 = *((unsigned __int8 *)KeGetCurrentPrcb() + 208);
goto LABEL_8;
case SystemLogicalProcessorInformation:
LABEL_8:
v4 = &v9;
v6 = 2i64;
goto LABEL_4;
case SystemLogicalProcessorAndGroupInformation:
case SystemNodeDistanceInformation:
case SystemInterruptSteeringInformation:
case SystemFeatureConfigurationInformation:
case SystemFeatureConfigurationSectionInformation:
return 3221225475i64;
default:
break;
}
}
v6 = 0i64;
LABEL_4:
LODWORD(Length) = v5;
ExpQuerySystemInformation(*(UINT64 *)&SystemInformationClass, v4, v6, (INT64)SystemInformation, Length, ReturnLength);
return result;
}Referenced by:
AlpcpInitSystem
HalpTimerConfigureQpcBypass