Heres a question that begs asking, as I have never seen a definitive answer to this question :
What are the register values set to apon entry to a win32 PE file?
I mean at the moment that the IP is pointing at the EntryPoint,
after the PE-Loader has loaded the segments into memory.
Posted on 2002-02-06 00:29:42 by Homer
these values are not fixed and you can't rely on them...

and again... search google for "Win95 structures and secrets"
and you'll find an interesting document about this topic...
Posted on 2002-02-06 03:15:44 by mob
Download my free symbolic debugger and find out!
Posted on 2002-02-06 16:35:02 by jorgon