逆--Win7x64 UserTimer结构获取,NtUserSetTimer,_SetTimer,InternalSetTimer 枚举进程定时器
用户层调用SetTimer-->内核NtUserSetTimer处理NtUserSetTimer-->_SetTimer-->InternalSetTimer-->FindTimer/HMAllocObject去看看NtUserSetTimer函数原型UINT_PTR
APIENTRY
NtUserSetTimer
(
HWNDhWnd,
UINT_PTRnIDEvent,
UINTuElapse