PoExecutePerfCheck
VOID __stdcall PoExecutePerfCheck(){
UINT64 v0;
unsigned __int64 v1;
signed __int64 v2;
unsigned int v3;
UINT64 v4;
UINT64 v5;
v0 = PpmCheckLastExecutionTime;
if( PpmCheckLastExecutionTime )
{
v1 = (unsigned int)KeTimeIncrement;
if( PpmCheckPeriod > (unsigned __int64)(unsigned int)KeTimeIncrement )
v1 = PpmCheckPeriod;
v2 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart;
if( v1 + PpmCheckLastExecutionTime <= *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart )
{
v3 = 0;
if( PpmCheckLastExecutionTime != 1 )
{
if( PpmCheckLastExecutionTime + v1 + KeMaximumIncrement > *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart )
v2 = v1 + PpmCheckLastExecutionTime;
v4 = v2 - v1 - PpmCheckLastExecutionTime;
if( v4 >= v1 )
{
v3 = 64;
v5 = v4 / v1;
if( (unsigned int)v5 < 0x40 )
v3 = v5;
}
}
if( v0 == _InterlockedCompareExchange64(
(volatile signed __int64 *)&PpmCheckLastExecutionTime,
v2,
PpmCheckLastExecutionTime) )
KiInsertQueueDpc((_KDPC *)&PpmCheckStartDpc, (PVOID)v3, 0i64, 0i64, 0);
}
}
}Referenced by:
KiUpdateTime