mov eax, 17h // system call # is 0x17 for NT (0x20 for 2k, 0x25 for XP)
lea edx, [esp+4] // make edx point to function params (user-mode stack)
// lea : loads edx with address of user args
int 2Eh // execute sys call trap for NT, 2k on x86
// (SYSENTER is used for XP,2003 on x86)
ret 2Ch
主要是这种函数的实现决定的,它的第一条指令是mov eax,id,看看原始数据就更清楚了!