PopGetIdleTimesCallback

__int64 __fastcall PopGetIdleTimesCallback(__int64 a1, __int64 a2, __int64 a3){
  struct _KPRCB *CurrentPrcb; 
  BOOL v7; 
  unsigned __int64 v8; 
  _DWORD *v9; 
  _QWORD *v10; 
  signed __int64 v11; 
  signed __int64 v12; 
  unsigned __int64 QuadPart; 
  signed __int64 v14; 
  signed __int64 v15; 
  UINT64 v16; 
  unsigned int v17; 
  int v18; 
  unsigned __int64 v19; 
  __int64 v21; 
  unsigned int i; 
  unsigned int v23; 
  _DWORD *v24; 
  __int64 v25; 
  int v26; 
  int v27; 
  int v28; 
  _DWORD *v29; 
  __int64 v30; 
  UINT64 v31; 
  UINT64 v32; 
  unsigned int v33; 
  _QWORD *v34; 
  int *v35; 
  __int64 v36; 
  _QWORD *v37; 
  LARGE_INTEGER PerformanceCounter; 
  unsigned int v39; 
  int v40; 
  CurrentPrcb = KeGetCurrentPrcb();
  v7 = CurrentPrcb != (struct _KPRCB *)a1;
  v8 = 0i64;
  v9 = 0i64;
  v10 = 0i64;
  if( CurrentPrcb != (struct _KPRCB *)a1 )
  {
    _m_prefetchw((const void *)(a1 + 32800));
    v11 = *(_QWORD *)(a1 + 32800);
    do
    {
      v12 = v11;
      v11 = _InterlockedCompareExchange64((volatile signed __int64 *)(a1 + 32800), v11, v11);
    }
    while( v12 != v11 );
    v8 = v11;
    if( !v11 )
      return 3221225473i64;
  }
  v35 = *(int **)(a1 + 32776);
  v36 = *(_QWORD *)(a1 + 0x8000);
  PerformanceCounter = KeQueryPerformanceCounter(0i64);
  QuadPart = PerformanceCounter.QuadPart;
  v39 = *(_DWORD *)(*(_QWORD *)(a1 + 24) + 652i64);
  v40 = *(_DWORD *)(a1 + 32388);
  if( a2 )
  {
    *(_OWORD *)a2 = 0i64;
    *(_OWORD *)(a2 + 16) = 0i64;
    *(_OWORD *)(a2 + 32) = 0i64;
    if( v35 )
    {
      v21 = v36;
      if( v36 )
      {
        for( i = 0; ; ++i )
        {
          v23 = *v35;
          v24 = v9;
          v33 = i;
          if( (unsigned int)*v35 >= *(_DWORD *)(v21 + 32) )
            v23 = *(_DWORD *)(v21 + 32);
          v37 = v10;
          if( i >= v23 )
          {
            QuadPart = PerformanceCounter.QuadPart;
            *(_QWORD *)a2 = PpmConvertTime(*((_QWORD *)v35 + 3), PopQpcFrequency, 0x989680ui64);
            break;
          }
          v25 = 248i64 * i;
          if( *(_BYTE *)(v25 + v21 + 1056) )
          {
            if( *(_BYTE *)(v25 + v21 + 1056) == 1 )
            {
              v26 = 1;
              goto LABEL_33;
            }
            if( *(_BYTE *)(v25 + v21 + 1056) == 2 )
            {
              v26 = 2;
              goto LABEL_33;
            }
          }
          else if( *(_BYTE *)(v25 + v21 + 1059) )
          {
            v26 = 2 - (*(_BYTE *)(v25 + v21 + 1060) != 0);
            goto LABEL_33;
          }
          v26 = 3;
LABEL_33:
          v27 = v26 - 1;
          if( v27 )
          {
            v28 = v27 - 1;
            if( v28 )
            {
              if( v28 == 1 )
              {
                v29 = (_DWORD *)(a2 + 40);
                v30 = a2 + 24;
              }
              else
              {
                v29 = 0i64;
                v30 = 0i64;
              }
            }
            else
            {
              v29 = (_DWORD *)(a2 + 36);
              v30 = a2 + 16;
            }
          }
          else
          {
            v29 = (_DWORD *)(a2 + 32);
            v30 = a2 + 8;
          }
          v9 = v29;
          v10 = (_QWORD *)v30;
          v34 = (_QWORD *)v30;
          if( i != *(_DWORD *)(v21 + 20) )
          {
            v10 = v37;
            if( i != *(_DWORD *)(v21 + 20) )
              v9 = v24;
          }
          if( v29 && v30 )
          {
            *v29 += v35[250 * i + 13] + v35[250 * i + 14];
            v31 = *(_QWORD *)&v35[250 * i + 10];
            if( *(_DWORD *)(v21 + 20) == i )
              v31 += *(_QWORD *)(a1 + 32784);
            v32 = PpmConvertTime(v31, PopQpcFrequency, 0x989680ui64);
            i = v33;
            v21 = v36;
            *v34 += v32;
          }
        }
      }
    }
  }
  if( a3 )
  {
    if( !v7 )
      PpmContinueActiveTimeAccumulation(a1, QuadPart);
    *(_QWORD *)(a3 + 8) = PpmConvertTime(*(_QWORD *)(a1 + 32968), PopQpcFrequency, 0x989680ui64);
  }
  if( !v7 )
    goto LABEL_18;
  _m_prefetchw((const void *)(a1 + 32800));
  v14 = *(_QWORD *)(a1 + 32800);
  do
  {
    v15 = v14;
    v14 = _InterlockedCompareExchange64((volatile signed __int64 *)(a1 + 32800), v14, v14);
  }
  while( v15 != v14 );
  if( v8 != v14 )
    return 3221225473i64;
  if( QuadPart > v8 )
  {
    v16 = PpmConvertTime(QuadPart - v8, PopQpcFrequency, 0x989680ui64);
    if( v10 && v9 )
    {
      ++*v9;
      *v10 += v16;
    }
    v17 = v39;
    v18 = v40;
    if( v16 > KeMaximumIncrement )
    {
      v19 = v16 / KeMaximumIncrement;
      v17 = v19 + v39 - 1;
      v18 = v19 + v40 - 1;
    }
  }
  else
  {
LABEL_18:
    v18 = v40;
    v17 = v39;
  }
  if( a2 )
  {
    if( v35 && v36 )
      *(_QWORD *)a2 += *(_QWORD *)(a2 + 8) + *(_QWORD *)(a2 + 16) + *(_QWORD *)(a2 + 24);
    else
      *(_QWORD *)a2 = v17 * (unsigned __int64)KeMaximumIncrement;
  }
  if( a3 )
  {
    *(_DWORD *)a3 = v17;
    *(_DWORD *)(a3 + 4) = v18;
  }
  return 0i64;
}

Referenced by:

PoGetIdleTimes