说明: 驅動級隱藏進程。 Macro for easy hook/unhook. On X86 implementations of Zw* func- tions, the DWORD following the first byte is the system call number, so we reach into the Zw function passed as a parameter, and pull the number out. This makes system call hoo <samllgo> 在 上传 | 大小:134144