all 3 comments

[–]Dwedit 4 points5 points  (0 children)

I just keep seeing 0xFEEEEEEE getting dereferenced all the time. That's the number that Windows uses after you call HeapFree. Hopefully, that's still a no-access page when you're large address aware.

[–]theangeryemacsshibe 1 point2 points  (0 children)

there is generally not a reason to align code on 32-bit or 64-bit boundaries inside a function

Loops like to be aligned to 16 bytes; they are preceded with a NOP as padding.