又找了个在这
0054F295 5E POP ESI
0054F296 5F POP EDI
0054F297 ^ EB C5 JMP SHORT wb86.0054F25E ==>走到这里会跳到前面,把光标移动到下一行,F4跳过时程序会直接运行,所以还得单步运行,走到上面的0054F262处会跳到后面去了(地址712K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3q4F1M7h3&6Q4x3X3g2U0L8$3#2Q4x3V1k6S2M7Y4c8A6j5$3I4W2i4K6u0r3k6#2)9J5c8U0t1H3x3o6g2Q4x3X3b7H3z5q4)9J5k6o6l9#2i4K6u0r3j5e0l9&6y4e0p5#2y4U0S2Q4x3X3b7K6i4K6u0W2M7$3S2@1L8h3I4Q4c8f1k6Q4b7V1y4Q4z5o6V1`.
照着做了,居然脱出来了。
为什么同一种壳脱时遇到的情况不同呢?