查看主题内容
程序载入时主线程的堆栈情况:0012FFC4 7C817027 返回到 kernel32.7C8170270012FFC8 7C930228 ntdll.7C9302280012FFCC FFFFFFFF...0012FFF8 0040B158 OFFSET CreateTh.<模块入口点>0012FFFC 00000000CreateThread并弹出提示后的主线程栈情况:0012FF8C 0012FFB4 指向下一个 SEH 记录的指针0012FF90 0040A0CD SE处理程序0012FF94 0012FFA80012FF98 7FFD60000012FF9C 000000010012FFA0 0040A000 CreateTh.0040A0000012FFA4 00E0DAA4 UNICODE "MsgBoxThread(1) Running..."0012FFA8 /0012FFC00012FFAC |0040B189 返回到 CreateTh.0040B189 来自 CreateTh.0040A0680012FFB0 |7C92DCBA 返回到 ntdll.7C92DCBA0012FFB4 |0012FFE0 指向下一个 SEH 记录的指针0012FFB8 |00403E18 SE处理程序0012FFBC |0012FFC00012FFC0 \0012FFF00012FFC4 7C817027 返回到 kernel32.7C8170270012FFC8 7C930228 ntdll.7C9302280012FFCC FFFFFFFF...0012FFF8 0040B158 OFFSET CreateTh.<模块入口点>0012FFFC 00000000而子线程的栈是这样的:00F3FF98 00F3FFDC 指向下一个 SEH 记录的指针00F3FF9C 0040A0CD SE处理程序00F3FFA0 00F3FFB400F3FFA4 0000000000F3FFA8 0000000000F3FFAC 806E5E0000F3FFB0 00E0DAEC UNICODE "MsgBoxThread(0) Running..."00F3FFB4 00F3FFEC00F3FFB8 7C80B6D9 返回到 kernel32.7C80B6D900F3FFBC 0000000000F3FFC0 0000002700F3FFC4 003F003F00F3FFC8 0000000000F3FFCC 7FFDE00000F3FFD0 89DA460000F3FFD4 00F3FFC000F3FFD8 88462F9000F3FFDC FFFFFFFF SEH 链尾部00F3FFE0 7C839A88 SE处理程序00F3FFE4 7C80B6E0 kernel32.7C80B6E000F3FFE8 0000000000F3FFEC 0000000000F3FFF0 0000000000F3FFF4 0040A068 CreateTh.0040A06800F3FFF8 0000000000F3FFFC 00000000