驅動級隱藏進程。 Macroforeasyhook/unhook.OnX86implementationsofZw*func- tions,theDWORDfollowingthefirstbyteisthesystemcallnumber, sowereachintotheZwfunctionpassedasaparameter,andpullthe numberout.ThismakessystemcallhookingdependentONLYonthe Zw*functionimplement