-
-
[求助]DPC timer检测
-
发表于:
2015-6-5 10:56
3802
-
通过KeUpdateSystemTime得到的80542159 8d0cc520425580 lea ecx,nt!KiTimerTableListHead (80554220)[eax*8]
,链表是空的,但xuetr能检测到很多,这是为什么呢?
kd> !list -t nt!_LIST_ENTRY.Flink -x "dt _KTIMER DueTime Period @@(#CONTAINING_RECORD(@$extret, nt!_KTIMER, TimerListEntry))" 80554220
nt_400000!_KTIMER
+0x010 DueTime : _ULARGE_INTEGER 0x0
+0x024 Period : 0n-1987496448
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课