PspQueryWorkingSetWatch
INT64 __stdcall PspQueryWorkingSetWatch(
PVOID ProcessHandle,
PROCESSINFOCLASS ProcessInformationClass,
PVOID ProcessInformation,
UINT64 ProcessInformationLength,
UINT64 *ReturnLength,
INT8 PreviousMode){
INT64 result;
int v8;
PVOID v9;
__int64 v10;
int v11;
_ETHREAD *CurrentThread;
__int64 v13;
signed __int32 v14;
unsigned int v15;
unsigned int v16;
__int64 i;
char *v18;
__int64 j;
PVOID Object;
char *v21;
_ETHREAD *v22;
__int64 v23;
unsigned int v26;
v26 = ProcessInformationLength;
Object = 0i64;
if( ProcessInformationClass == ProcessWorkingSetWatchEx )
{
if( (ProcessInformationLength & 0x1F) != 0 )
return 3221225476i64;
v8 = 32;
}
else
{
v8 = 16;
}
if( (unsigned int)ExIsRestrictedCaller(PreviousMode) )
return 3221225506i64;
LODWORD(result) = ObReferenceObjectByHandleWithTag(
ProcessHandle,
0x400u,
(POBJECT_TYPE)PsProcessType,
PreviousMode,
0x79517350u,
&Object,
0i64);
if( (int)result >= 0 )
{
v9 = Object;
v10 = *((_QWORD *)Object + 166);
v23 = v10;
if( !v10 )
{
v11 = -1073741823;
LABEL_17:
ObfDereferenceObjectWithTag(v9, 0x79517350ui64);
return(unsigned int)v11;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v22 = CurrentThread;
v11 = 0;
v13 = 0i64;
--*((_WORD *)CurrentThread + 242);
_m_prefetchw((const void *)v10);
v14 = _InterlockedOr((volatile signed __int32 *)v10, 1u);
if( (v14 & 1) != 0 )
{
v11 = -2147483622;
}
else
{
v15 = (unsigned __int16)v14 >> 1;
if( (unsigned __int16)v14 >> 1 )
{
if( (v14 & 0x7FFF0000) != 0 )
KeWaitForGate((PVOID)(v10 + 16), 0);
v16 = v8 * (v15 + 1);
if( v26 >= v16 )
{
_m_prefetchw((const void *)(v10 + 8));
v13 = *(_QWORD *)(v10 + 8);
if( ProcessInformationClass == ProcessWorkingSetWatchEx )
{
for( i = 0i64; ; i = (unsigned int)(i + 1) )
{
v18 = (char *)ProcessInformation + 32 * (unsigned int)i;
if( (unsigned int)i >= v15 )
break;
*(_OWORD *)v18 = *(_OWORD *)(v10 + 24 * i + 40);
*((_OWORD *)v18 + 1) = *(unsigned __int64 *)(v10 + 24 * i + 56);
}
v21 = (char *)ProcessInformation + 32 * (unsigned int)i;
*((_QWORD *)v18 + 2) = 0i64;
*((_QWORD *)v18 + 3) = 0i64;
}
else
{
v18 = (char *)ProcessInformation;
v21 = (char *)ProcessInformation;
for( j = 0i64; (unsigned int)j < v15; j = (unsigned int)(j + 1) )
{
*(_OWORD *)v18 = *(_OWORD *)(v10 + 24 * j + 40);
v18 += 16;
v21 = v18;
}
}
*(_QWORD *)v18 = 0i64;
*((_QWORD *)v18 + 1) = v13;
if( ReturnLength )
*(_DWORD *)ReturnLength = v16;
}
else
{
v11 = -1073741789;
if( ReturnLength )
*(_DWORD *)ReturnLength = v16;
}
if( v11 >= 0 )
{
_InterlockedExchangeAdd64((volatile signed __int64 *)(v10 + 8), -v13);
*(_DWORD *)v10 = 0;
goto LABEL_16;
}
}
else
{
v11 = -2147483622;
}
_interlockedbittestandreset((volatile signed __int32 *)v10, 0);
}
LABEL_16:
KeLeaveCriticalRegionThread((__int64)CurrentThread);
v9 = Object;
goto LABEL_17;
}
return result;
}Referenced by:
NtQueryInformationProcess