ExpQuerySystemPerformanceInformation
VOID __stdcall ExpQuerySystemPerformanceInformation(
UINT64 CapturedNumProcs,
VOID *SystemInformation,
UINT64 SystemInformationLength,
INT64 a4,
INT64 a5,
INT64 a6,
INT64 a7,
INT64 a8){
__int64 v8;
int v9;
__int64 v10;
int v11;
__int64 v12;
int v13;
__int64 v14;
_KPRCB **v15;
__int64 v16;
__int64 v17;
int v18;
int v19;
int v20;
_KPRCB **v21;
__int64 v22;
__int64 v23;
unsigned __int64 v24;
UINT64 v25;
unsigned __int64 v26;
UINT64 v27;
unsigned __int64 v28;
unsigned __int64 v29;
UINT64 v30;
unsigned __int64 v31;
unsigned __int64 v32;
int v33;
unsigned int v34;
unsigned __int64 v35;
int v36;
int v37;
int v38;
int v39;
int v40;
int v41;
int v42;
int v43;
int v44;
int v45;
int v46;
int v47;
_KPRCB **v48;
int v49;
_DWORD *v50;
unsigned __int64 v51;
unsigned __int64 v52;
unsigned __int64 v53;
unsigned __int64 v54;
unsigned __int64 v55;
int v56;
unsigned int v57;
unsigned int v58;
unsigned int v59;
unsigned int v60;
unsigned int v61;
unsigned int v62;
unsigned int v63;
unsigned int v64;
unsigned int v65;
unsigned int v66;
int v67;
_KPRCB **v68;
_KPRCB *v69;
int v70;
bool v71;
__int64 v72;
__int64 v73;
int v74;
int v75;
int v76;
__int64 v77;
__int64 v78;
__int64 Src[4];
int v80;
int v81;
int v82;
int v83;
int v84;
int v85;
int v86;
int v87;
int v88;
int v89;
int v90;
int v91;
int v92;
int v93;
int v94;
int v95;
int v96;
int v97;
int v98;
int v99;
UINT64 PagedPoolPages[2];
UINT64 NonPagedPoolAllocs;
NTSTATUS NumberOfFreeSystemPtes;
unsigned int SystemCodePage;
int TotalSystemDriverPages;
int TotalSystemCodePages;
UINT64 PagedPoolLookasideHits;
int v107;
int v108;
int v109;
unsigned int SystemDriverPage;
__int64 v111[15];
int v112;
__int64 v113;
int v114;
__int128 v115;
__int128 v116;
_KPRCB **v117;
_MM_SYSTEM_PAGE_COUNTS PageCounts;
__int64 UserTime[9];
unsigned int v120;
size_t Size;
unsigned __int16 ProcessPartitionId;
Size = SystemInformationLength;
v120 = CapturedNumProcs;
v8 = (unsigned int)CapturedNumProcs;
v86 = 0;
NonPagedPoolAllocs = 0i64;
PagedPoolLookasideHits = 0i64;
*(_OWORD *)PagedPoolPages = 0i64;
memset(v111, 0i64, sizeof(v111));
v9 = *(&stru_140C452E0 + 207);
v10 = *(&stru_140C452E0 + 105);
v11 = *(&stru_140C452E0 + 208);
v12 = *(&stru_140C452E0 + 106);
v13 = *(&stru_140C452E0 + 206);
v14 = *(&stru_140C452E0 + 107);
v117 = &KiProcessorBlock;
v115 = 0i64;
v116 = 0i64;
PageCounts = 0i64;
if( (_DWORD)v8 )
{
v15 = &KiProcessorBlock;
v16 = (unsigned int)v8;
do
{
v17 = (__int64)*v15++;
v9 += *(_DWORD *)(v17 + 11620);
v11 += *(_DWORD *)(v17 + 11612);
v13 += *(_DWORD *)(v17 + 11616);
v14 += *(_QWORD *)(v17 + 11632);
v10 += *(_QWORD *)(v17 + 11640);
v12 += *(_QWORD *)(v17 + 11624);
--v16;
}
while( v16 );
}
v80 = v11;
v18 = 0;
Src[2] = v14;
v19 = 0;
Src[1] = v12;
v20 = 0;
Src[3] = v10;
v81 = v13;
v82 = v9;
if( (_DWORD)v8 )
{
v21 = &KiProcessorBlock;
v22 = v8;
do
{
v23 = (__int64)*v21++;
v20 += *(_DWORD *)(v23 + 11580);
v19 += *(_DWORD *)(v23 + 11576);
--v22;
}
while( v22 );
}
v112 = v20;
v113 = 0i64;
v114 = v19;
ProcessPartitionId = MmGetProcessPartitionId((INT64)KeGetCurrentThread()->ApcState.Process);
LODWORD(v24) = MmGetAvailablePages(ProcessPartitionId);
if( v24 > 0xFFFFFFFF )
v83 = -1;
else
v83 = v24;
LODWORD(v26) = MmGetTotalCommittedPages(v25);
if( v26 > v28 )
v84 = v28;
else
v84 = v26;
MmGetTotalCommitLimit(v27);
if( v29 > v31 )
v85 = v31;
else
v85 = v29;
LODWORD(v32) = MmGetPeakCommitment(v30);
if( v32 > v35 )
LODWORD(v32) = v35;
v86 = v32;
if( (unsigned int)v32 < v34 )
v86 = v33;
v36 = 0;
v37 = 0;
v38 = 0;
v39 = 0;
v40 = 0;
v41 = 0;
v42 = 0;
v43 = 0;
v44 = 0;
v45 = 0;
v46 = 0;
v74 = 0;
v47 = 0;
v75 = 0;
v76 = 0;
if( v120 )
{
v48 = &KiProcessorBlock;
v77 = v120;
v49 = 0;
do
{
v50 = *v48++;
v36 += v50[2884];
v37 += v50[2885];
v38 += v50[2886];
v39 += v50[8186];
v40 += v50[2887];
v41 += v50[2888];
v42 += v50[2889];
v43 += v50[8187];
v44 += v50[8188];
v49 += v50[2890];
v74 += v50[2891];
v75 += v50[2892];
v76 += v50[2893];
--v77;
}
while( v77 );
v45 = v74;
v46 = v75;
v47 = v76;
}
else
{
v49 = 0;
}
v87 = v36;
v88 = v37;
v89 = v38;
v90 = v39;
v91 = v40;
v92 = v41;
v93 = v42;
v94 = v43;
v95 = v44;
v96 = v49;
v97 = v45;
v98 = v46;
v99 = v47;
NumberOfFreeSystemPtes = MmGetNumberOfFreeSystemPtes();
MmGetSystemPageCounts(&PageCounts);
SystemCodePage = PageCounts.SystemCodePage;
LODWORD(v51) = MmGetWorkingSetLeafSize(WorkingSetTypeSystemTypes);
if( v51 > 0xFFFFFFFF )
LODWORD(v51) = -1;
v108 = v51;
LODWORD(v52) = MmGetWorkingSetLeafSize(WorkingSetTypePagedPool);
if( v52 > v53 )
LODWORD(v52) = v53;
v109 = v52;
SystemDriverPage = PageCounts.SystemDriverPage;
TotalSystemCodePages = PageCounts.TotalSystemCodePages;
TotalSystemDriverPages = PageCounts.TotalSystemDriverPages;
MiFreePoolPagesLeft(MiVaPagedPool);
LODWORD(v54) = MiMaximumCommitmentAvailable();
if( v55 > v54 )
LODWORD(v55) = v54;
v107 = v55;
Src[0] = (unsigned int)KeMaximumIncrement
* (unsigned __int64)(unsigned int)PsQueryRuntimeProcess(*(_EPROCESS **)&PsIdleProcess, (UINT64 *)UserTime);
ExQueryPoolUsage(
PagedPoolPages,
(UINT64 *)((char *)PagedPoolPages + 4),
&PagedPoolPages[1],
(UINT64 *)((char *)&PagedPoolPages[1] + 4),
(UINT64 *)((char *)&PagedPoolLookasideHits + 4),
&NonPagedPoolAllocs,
(UINT64 *)((char *)&NonPagedPoolAllocs + 4),
&PagedPoolLookasideHits);
v56 = 0;
v57 = *(&CmpDummyThreadEvent + 715);
v58 = 0;
memset(v111, 0, 20);
v59 = 0;
v60 = 0;
v61 = 0;
HIDWORD(v111[2]) = *(&CmpDummyThreadEvent + 715);
v62 = 0;
memset(&v111[3], 0, 96);
v63 = 0;
v64 = 0;
v65 = 0;
v66 = 0;
v67 = 0;
if( v120 )
{
v78 = v120;
v68 = &KiProcessorBlock;
do
{
v69 = *v68;
LODWORD(v111[0]) = v69->CcFastReadNoWait + v18;
HIDWORD(v111[6]) += v69->CcPinReadNoWait;
v56 += v69->CcFastReadWait;
v58 += v69->CcFastReadResourceMiss;
v59 += v69->CcFastReadNotPossible;
v60 += v69->CcFastMdlReadNoWait;
v57 += v69->CcFastMdlReadWait;
v61 += v69->CcFastMdlReadResourceMiss;
v62 += v69->CcFastMdlReadNotPossible;
v63 += v69->CcMapDataNoWait;
v64 += v69->CcMapDataWait;
v65 += v69->CcMapDataNoWaitMiss;
v66 += v69->CcMapDataWaitMiss;
v67 += v69->CcPinMappedDataCount;
LODWORD(v111[7]) += v69->CcPinReadWait;
HIDWORD(v111[7]) += v69->CcPinReadNoWaitMiss;
LODWORD(v111[8]) += v69->CcPinReadWaitMiss;
HIDWORD(v111[8]) += v69->CcCopyReadNoWait;
LODWORD(v111[9]) += v69->CcCopyReadWait;
HIDWORD(v111[9]) += v69->CcCopyReadNoWaitMiss;
LODWORD(v111[10]) += v69->CcCopyReadWaitMiss;
HIDWORD(v111[10]) += v69->CcMdlReadNoWait;
LODWORD(v111[11]) += v69->CcMdlReadWait;
HIDWORD(v111[11]) += v69->CcMdlReadNoWaitMiss;
LODWORD(v111[12]) += v69->CcMdlReadWaitMiss;
HIDWORD(v111[12]) += v69->CcReadAheadIos;
LODWORD(v111[13]) += v69->CcLazyWriteIos;
HIDWORD(v111[13]) += v69->CcLazyWritePages;
LODWORD(v111[14]) += v69->CcDataFlushes;
v70 = v69->CcDataPages + HIDWORD(v111[14]);
v68 = v117 + 1;
HIDWORD(v111[14]) = v70;
v71 = v78-- == 1;
v18 = v111[0];
++v117;
}
while( !v71 );
HIDWORD(v111[0]) = v56;
v111[1] = __PAIR64__(v59, v58);
v111[2] = __PAIR64__(v57, v60);
v111[3] = __PAIR64__(v62, v61);
v111[4] = __PAIR64__(v64, v63);
v111[5] = __PAIR64__(v66, v65);
LODWORD(v111[6]) = v67;
}
v115 = *(_OWORD *)qword_140C50818;
MmGetResidentAvailablePages((_BYTE *)ProcessPartitionId);
*(_QWORD *)&v116 = v72;
MmGetSharedCommit();
*((_QWORD *)&v116 + 1) = v73;
memmove(SystemInformation, Src, Size);
}Referenced by:
ExpQuerySystemInformation