ExpQuerySystemPerformanceInformation

VOID __stdcall ExpQuerySystemPerformanceInformation(
        UINT64 CapturedNumProcs,
        VOID *SystemInformation,
        UINT64 SystemInformationLength,
        INT64 a4,
        INT64 a5,
        INT64 a6,
        INT64 a7,
        INT64 a8){
  __int64 v8; 
  int v9; 
  __int64 v10; 
  int v11; 
  __int64 v12; 
  int v13; 
  __int64 v14; 
  _KPRCB **v15; 
  __int64 v16; 
  __int64 v17; 
  int v18; 
  int v19; 
  int v20; 
  _KPRCB **v21; 
  __int64 v22; 
  __int64 v23; 
  unsigned __int64 v24; 
  UINT64 v25; 
  unsigned __int64 v26; 
  UINT64 v27; 
  unsigned __int64 v28; 
  unsigned __int64 v29; 
  UINT64 v30; 
  unsigned __int64 v31; 
  unsigned __int64 v32; 
  int v33; 
  unsigned int v34; 
  unsigned __int64 v35; 
  int v36; 
  int v37; 
  int v38; 
  int v39; 
  int v40; 
  int v41; 
  int v42; 
  int v43; 
  int v44; 
  int v45; 
  int v46; 
  int v47; 
  _KPRCB **v48; 
  int v49; 
  _DWORD *v50; 
  unsigned __int64 v51; 
  unsigned __int64 v52; 
  unsigned __int64 v53; 
  unsigned __int64 v54; 
  unsigned __int64 v55; 
  int v56; 
  unsigned int v57; 
  unsigned int v58; 
  unsigned int v59; 
  unsigned int v60; 
  unsigned int v61; 
  unsigned int v62; 
  unsigned int v63; 
  unsigned int v64; 
  unsigned int v65; 
  unsigned int v66; 
  int v67; 
  _KPRCB **v68; 
  _KPRCB *v69; 
  int v70; 
  bool v71; 
  __int64 v72; 
  __int64 v73; 
  int v74; 
  int v75; 
  int v76; 
  __int64 v77; 
  __int64 v78; 
  __int64 Src[4]; 
  int v80; 
  int v81; 
  int v82; 
  int v83; 
  int v84; 
  int v85; 
  int v86; 
  int v87; 
  int v88; 
  int v89; 
  int v90; 
  int v91; 
  int v92; 
  int v93; 
  int v94; 
  int v95; 
  int v96; 
  int v97; 
  int v98; 
  int v99; 
  UINT64 PagedPoolPages[2]; 
  UINT64 NonPagedPoolAllocs; 
  NTSTATUS NumberOfFreeSystemPtes; 
  unsigned int SystemCodePage; 
  int TotalSystemDriverPages; 
  int TotalSystemCodePages; 
  UINT64 PagedPoolLookasideHits; 
  int v107; 
  int v108; 
  int v109; 
  unsigned int SystemDriverPage; 
  __int64 v111[15]; 
  int v112; 
  __int64 v113; 
  int v114; 
  __int128 v115; 
  __int128 v116; 
  _KPRCB **v117; 
  _MM_SYSTEM_PAGE_COUNTS PageCounts; 
  __int64 UserTime[9]; 
  unsigned int v120; 
  size_t Size; 
  unsigned __int16 ProcessPartitionId; 

  Size = SystemInformationLength;
  v120 = CapturedNumProcs;
  v8 = (unsigned int)CapturedNumProcs;
  v86 = 0;
  NonPagedPoolAllocs = 0i64;
  PagedPoolLookasideHits = 0i64;
  *(_OWORD *)PagedPoolPages = 0i64;
  memset(v111, 0i64, sizeof(v111));
  v9 = *(&stru_140C452E0 + 207);
  v10 = *(&stru_140C452E0 + 105);
  v11 = *(&stru_140C452E0 + 208);
  v12 = *(&stru_140C452E0 + 106);
  v13 = *(&stru_140C452E0 + 206);
  v14 = *(&stru_140C452E0 + 107);
  v117 = &KiProcessorBlock;
  v115 = 0i64;
  v116 = 0i64;
  PageCounts = 0i64;
  if( (_DWORD)v8 )
  {
    v15 = &KiProcessorBlock;
    v16 = (unsigned int)v8;
    do
    {
      v17 = (__int64)*v15++;
      v9 += *(_DWORD *)(v17 + 11620);
      v11 += *(_DWORD *)(v17 + 11612);
      v13 += *(_DWORD *)(v17 + 11616);
      v14 += *(_QWORD *)(v17 + 11632);
      v10 += *(_QWORD *)(v17 + 11640);
      v12 += *(_QWORD *)(v17 + 11624);
      --v16;
    }
    while( v16 );
  }
  v80 = v11;
  v18 = 0;
  Src[2] = v14;
  v19 = 0;
  Src[1] = v12;
  v20 = 0;
  Src[3] = v10;
  v81 = v13;
  v82 = v9;
  if( (_DWORD)v8 )
  {
    v21 = &KiProcessorBlock;
    v22 = v8;
    do
    {
      v23 = (__int64)*v21++;
      v20 += *(_DWORD *)(v23 + 11580);
      v19 += *(_DWORD *)(v23 + 11576);
      --v22;
    }
    while( v22 );
  }
  v112 = v20;
  v113 = 0i64;
  v114 = v19;
  ProcessPartitionId = MmGetProcessPartitionId((INT64)KeGetCurrentThread()->ApcState.Process);
  LODWORD(v24) = MmGetAvailablePages(ProcessPartitionId);
  if( v24 > 0xFFFFFFFF )
    v83 = -1;
  else
    v83 = v24;
  LODWORD(v26) = MmGetTotalCommittedPages(v25);
  if( v26 > v28 )
    v84 = v28;
  else
    v84 = v26;
  MmGetTotalCommitLimit(v27);
  if( v29 > v31 )
    v85 = v31;
  else
    v85 = v29;
  LODWORD(v32) = MmGetPeakCommitment(v30);
  if( v32 > v35 )
    LODWORD(v32) = v35;
  v86 = v32;
  if( (unsigned int)v32 < v34 )
    v86 = v33;
  v36 = 0;
  v37 = 0;
  v38 = 0;
  v39 = 0;
  v40 = 0;
  v41 = 0;
  v42 = 0;
  v43 = 0;
  v44 = 0;
  v45 = 0;
  v46 = 0;
  v74 = 0;
  v47 = 0;
  v75 = 0;
  v76 = 0;
  if( v120 )
  {
    v48 = &KiProcessorBlock;
    v77 = v120;
    v49 = 0;
    do
    {
      v50 = *v48++;
      v36 += v50[2884];
      v37 += v50[2885];
      v38 += v50[2886];
      v39 += v50[8186];
      v40 += v50[2887];
      v41 += v50[2888];
      v42 += v50[2889];
      v43 += v50[8187];
      v44 += v50[8188];
      v49 += v50[2890];
      v74 += v50[2891];
      v75 += v50[2892];
      v76 += v50[2893];
      --v77;
    }
    while( v77 );
    v45 = v74;
    v46 = v75;
    v47 = v76;
  }
  else
  {
    v49 = 0;
  }
  v87 = v36;
  v88 = v37;
  v89 = v38;
  v90 = v39;
  v91 = v40;
  v92 = v41;
  v93 = v42;
  v94 = v43;
  v95 = v44;
  v96 = v49;
  v97 = v45;
  v98 = v46;
  v99 = v47;
  NumberOfFreeSystemPtes = MmGetNumberOfFreeSystemPtes();
  MmGetSystemPageCounts(&PageCounts);
  SystemCodePage = PageCounts.SystemCodePage;
  LODWORD(v51) = MmGetWorkingSetLeafSize(WorkingSetTypeSystemTypes);
  if( v51 > 0xFFFFFFFF )
    LODWORD(v51) = -1;
  v108 = v51;
  LODWORD(v52) = MmGetWorkingSetLeafSize(WorkingSetTypePagedPool);
  if( v52 > v53 )
    LODWORD(v52) = v53;
  v109 = v52;
  SystemDriverPage = PageCounts.SystemDriverPage;
  TotalSystemCodePages = PageCounts.TotalSystemCodePages;
  TotalSystemDriverPages = PageCounts.TotalSystemDriverPages;
  MiFreePoolPagesLeft(MiVaPagedPool);
  LODWORD(v54) = MiMaximumCommitmentAvailable();
  if( v55 > v54 )
    LODWORD(v55) = v54;
  v107 = v55;
  Src[0] = (unsigned int)KeMaximumIncrement
         * (unsigned __int64)(unsigned int)PsQueryRuntimeProcess(*(_EPROCESS **)&PsIdleProcess, (UINT64 *)UserTime);
  ExQueryPoolUsage(
    PagedPoolPages,
    (UINT64 *)((char *)PagedPoolPages + 4),
    &PagedPoolPages[1],
    (UINT64 *)((char *)&PagedPoolPages[1] + 4),
    (UINT64 *)((char *)&PagedPoolLookasideHits + 4),
    &NonPagedPoolAllocs,
    (UINT64 *)((char *)&NonPagedPoolAllocs + 4),
    &PagedPoolLookasideHits);
  v56 = 0;
  v57 = *(&CmpDummyThreadEvent + 715);
  v58 = 0;
  memset(v111, 0, 20);
  v59 = 0;
  v60 = 0;
  v61 = 0;
  HIDWORD(v111[2]) = *(&CmpDummyThreadEvent + 715);
  v62 = 0;
  memset(&v111[3], 0, 96);
  v63 = 0;
  v64 = 0;
  v65 = 0;
  v66 = 0;
  v67 = 0;
  if( v120 )
  {
    v78 = v120;
    v68 = &KiProcessorBlock;
    do
    {
      v69 = *v68;
      LODWORD(v111[0]) = v69->CcFastReadNoWait + v18;
      HIDWORD(v111[6]) += v69->CcPinReadNoWait;
      v56 += v69->CcFastReadWait;
      v58 += v69->CcFastReadResourceMiss;
      v59 += v69->CcFastReadNotPossible;
      v60 += v69->CcFastMdlReadNoWait;
      v57 += v69->CcFastMdlReadWait;
      v61 += v69->CcFastMdlReadResourceMiss;
      v62 += v69->CcFastMdlReadNotPossible;
      v63 += v69->CcMapDataNoWait;
      v64 += v69->CcMapDataWait;
      v65 += v69->CcMapDataNoWaitMiss;
      v66 += v69->CcMapDataWaitMiss;
      v67 += v69->CcPinMappedDataCount;
      LODWORD(v111[7]) += v69->CcPinReadWait;
      HIDWORD(v111[7]) += v69->CcPinReadNoWaitMiss;
      LODWORD(v111[8]) += v69->CcPinReadWaitMiss;
      HIDWORD(v111[8]) += v69->CcCopyReadNoWait;
      LODWORD(v111[9]) += v69->CcCopyReadWait;
      HIDWORD(v111[9]) += v69->CcCopyReadNoWaitMiss;
      LODWORD(v111[10]) += v69->CcCopyReadWaitMiss;
      HIDWORD(v111[10]) += v69->CcMdlReadNoWait;
      LODWORD(v111[11]) += v69->CcMdlReadWait;
      HIDWORD(v111[11]) += v69->CcMdlReadNoWaitMiss;
      LODWORD(v111[12]) += v69->CcMdlReadWaitMiss;
      HIDWORD(v111[12]) += v69->CcReadAheadIos;
      LODWORD(v111[13]) += v69->CcLazyWriteIos;
      HIDWORD(v111[13]) += v69->CcLazyWritePages;
      LODWORD(v111[14]) += v69->CcDataFlushes;
      v70 = v69->CcDataPages + HIDWORD(v111[14]);
      v68 = v117 + 1;
      HIDWORD(v111[14]) = v70;
      v71 = v78-- == 1;
      v18 = v111[0];
      ++v117;
    }
    while( !v71 );
    HIDWORD(v111[0]) = v56;
    v111[1] = __PAIR64__(v59, v58);
    v111[2] = __PAIR64__(v57, v60);
    v111[3] = __PAIR64__(v62, v61);
    v111[4] = __PAIR64__(v64, v63);
    v111[5] = __PAIR64__(v66, v65);
    LODWORD(v111[6]) = v67;
  }
  v115 = *(_OWORD *)qword_140C50818;
  MmGetResidentAvailablePages((_BYTE *)ProcessPartitionId);
  *(_QWORD *)&v116 = v72;
  MmGetSharedCommit();
  *((_QWORD *)&v116 + 1) = v73;
  memmove(SystemInformation, Src, Size);
}

Referenced by:

ExpQuerySystemInformation