I wanted to see how a syscall is made under x86 on a x64 Windows system, as I'm already familiar with how it's done on x64.
Anyways, I was going instruction by instruction when I came across this jmp instruction that I don't understand. Here's the callstack I observed:
ntdll.dll!_Wow64SystemServiceCall@0()
ntdll.dll!_NtReadVirtualMemory@20()
KernelBase.dll!ReadProcessMemory()
Then, there's a jmp dword ptr [_Wow64Transition]. Here's where I'm confused. Right after the jump, there's an instruction jmp 0033::77CE7009. Stepping into this instruction will take be back to the end of ntdll.dll!_NtReadVirtualMemory@20() for some reason.
What is this far jump, and what does it do?