PopGetIdleTimesCallback
__int64 __fastcall PopGetIdleTimesCallback(__int64 a1, __int64 a2, __int64 a3){
struct _KPRCB *CurrentPrcb;
BOOL v7;
unsigned __int64 v8;
_DWORD *v9;
_QWORD *v10;
signed __int64 v11;
signed __int64 v12;
unsigned __int64 QuadPart;
signed __int64 v14;
signed __int64 v15;
UINT64 v16;
unsigned int v17;
int v18;
unsigned __int64 v19;
__int64 v21;
unsigned int i;
unsigned int v23;
_DWORD *v24;
__int64 v25;
int v26;
int v27;
int v28;
_DWORD *v29;
__int64 v30;
UINT64 v31;
UINT64 v32;
unsigned int v33;
_QWORD *v34;
int *v35;
__int64 v36;
_QWORD *v37;
LARGE_INTEGER PerformanceCounter;
unsigned int v39;
int v40;
CurrentPrcb = KeGetCurrentPrcb();
v7 = CurrentPrcb != (struct _KPRCB *)a1;
v8 = 0i64;
v9 = 0i64;
v10 = 0i64;
if( CurrentPrcb != (struct _KPRCB *)a1 )
{
_m_prefetchw((const void *)(a1 + 32800));
v11 = *(_QWORD *)(a1 + 32800);
do
{
v12 = v11;
v11 = _InterlockedCompareExchange64((volatile signed __int64 *)(a1 + 32800), v11, v11);
}
while( v12 != v11 );
v8 = v11;
if( !v11 )
return 3221225473i64;
}
v35 = *(int **)(a1 + 32776);
v36 = *(_QWORD *)(a1 + 0x8000);
PerformanceCounter = KeQueryPerformanceCounter(0i64);
QuadPart = PerformanceCounter.QuadPart;
v39 = *(_DWORD *)(*(_QWORD *)(a1 + 24) + 652i64);
v40 = *(_DWORD *)(a1 + 32388);
if( a2 )
{
*(_OWORD *)a2 = 0i64;
*(_OWORD *)(a2 + 16) = 0i64;
*(_OWORD *)(a2 + 32) = 0i64;
if( v35 )
{
v21 = v36;
if( v36 )
{
for( i = 0; ; ++i )
{
v23 = *v35;
v24 = v9;
v33 = i;
if( (unsigned int)*v35 >= *(_DWORD *)(v21 + 32) )
v23 = *(_DWORD *)(v21 + 32);
v37 = v10;
if( i >= v23 )
{
QuadPart = PerformanceCounter.QuadPart;
*(_QWORD *)a2 = PpmConvertTime(*((_QWORD *)v35 + 3), PopQpcFrequency, 0x989680ui64);
break;
}
v25 = 248i64 * i;
if( *(_BYTE *)(v25 + v21 + 1056) )
{
if( *(_BYTE *)(v25 + v21 + 1056) == 1 )
{
v26 = 1;
goto LABEL_33;
}
if( *(_BYTE *)(v25 + v21 + 1056) == 2 )
{
v26 = 2;
goto LABEL_33;
}
}
else if( *(_BYTE *)(v25 + v21 + 1059) )
{
v26 = 2 - (*(_BYTE *)(v25 + v21 + 1060) != 0);
goto LABEL_33;
}
v26 = 3;
LABEL_33:
v27 = v26 - 1;
if( v27 )
{
v28 = v27 - 1;
if( v28 )
{
if( v28 == 1 )
{
v29 = (_DWORD *)(a2 + 40);
v30 = a2 + 24;
}
else
{
v29 = 0i64;
v30 = 0i64;
}
}
else
{
v29 = (_DWORD *)(a2 + 36);
v30 = a2 + 16;
}
}
else
{
v29 = (_DWORD *)(a2 + 32);
v30 = a2 + 8;
}
v9 = v29;
v10 = (_QWORD *)v30;
v34 = (_QWORD *)v30;
if( i != *(_DWORD *)(v21 + 20) )
{
v10 = v37;
if( i != *(_DWORD *)(v21 + 20) )
v9 = v24;
}
if( v29 && v30 )
{
*v29 += v35[250 * i + 13] + v35[250 * i + 14];
v31 = *(_QWORD *)&v35[250 * i + 10];
if( *(_DWORD *)(v21 + 20) == i )
v31 += *(_QWORD *)(a1 + 32784);
v32 = PpmConvertTime(v31, PopQpcFrequency, 0x989680ui64);
i = v33;
v21 = v36;
*v34 += v32;
}
}
}
}
}
if( a3 )
{
if( !v7 )
PpmContinueActiveTimeAccumulation(a1, QuadPart);
*(_QWORD *)(a3 + 8) = PpmConvertTime(*(_QWORD *)(a1 + 32968), PopQpcFrequency, 0x989680ui64);
}
if( !v7 )
goto LABEL_18;
_m_prefetchw((const void *)(a1 + 32800));
v14 = *(_QWORD *)(a1 + 32800);
do
{
v15 = v14;
v14 = _InterlockedCompareExchange64((volatile signed __int64 *)(a1 + 32800), v14, v14);
}
while( v15 != v14 );
if( v8 != v14 )
return 3221225473i64;
if( QuadPart > v8 )
{
v16 = PpmConvertTime(QuadPart - v8, PopQpcFrequency, 0x989680ui64);
if( v10 && v9 )
{
++*v9;
*v10 += v16;
}
v17 = v39;
v18 = v40;
if( v16 > KeMaximumIncrement )
{
v19 = v16 / KeMaximumIncrement;
v17 = v19 + v39 - 1;
v18 = v19 + v40 - 1;
}
}
else
{
LABEL_18:
v18 = v40;
v17 = v39;
}
if( a2 )
{
if( v35 && v36 )
*(_QWORD *)a2 += *(_QWORD *)(a2 + 8) + *(_QWORD *)(a2 + 16) + *(_QWORD *)(a2 + 24);
else
*(_QWORD *)a2 = v17 * (unsigned __int64)KeMaximumIncrement;
}
if( a3 )
{
*(_DWORD *)a3 = v17;
*(_DWORD *)(a3 + 4) = v18;
}
return 0i64;
}Referenced by:
PoGetIdleTimes