In this article we are going to discuss the inner depths of VB6 P-Code disassembly and the VB6 runtime.
As a malware analyst, VB6 in general, and P-Code in particular, has always been a problem area.
It is not well documented and the publicly available tooling did not give me the clarity I really desired.
This paper has been published on the Avast Decoded blog.
(local copy)