通过KeUpdateSystemTime得到的80542159 8d0cc520425580 lea ecx,nt!KiTimerTableListHead (80554220)[eax*8]
,链表是空的,但xuetr能检测到很多,这是为什么呢?
kd> !list -t nt!_LIST_ENTRY.Flink -x "dt _KTIMER DueTime Period @@(#CONTAINING_RECORD(@$extret, nt!_KTIMER, TimerListEntry))" 80554220
nt_400000!_KTIMER
+0x010 DueTime : _ULARGE_INTEGER 0x0
+0x024 Period : 0n-1987496448
[注意]APP应用上架合规检测服务,协助应用顺利上架!