A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.
 #1857  by Alex
 Sun Aug 08, 2010 7:24 pm
I'd like to ask you guys for uploading (rs, megaupload, hotfile, ...) few Windows modules from x86 Windows builds. If someone of you have also dumps of basic kernel structures like: KPROCESS/EPROCESS, KTHREAD/ETHREAD, TEB, PEB, OBJECT_TABLE, OBJECT_HEADER, OBJECT_TYPE, OBJECT_TYPE_INITIALIZER, ... and can upload them - it would be great!

I'm interested in such file as:
advapi32.dll
kernel32.dll
user32.dll
ntdll.dll

basesrv.dll
csrsrv.dll
winsrv.dll
csrss.exe
services.exe

ntoskrnl.exe
hal.dll
win32k.sys
Currently I have modules from Windows 2000 SP4 (5.0.2195.1), Windows XP SP1 (5.1.2600.0), Windows XP SP2 (5.1.2600.2180), Windows XP SP3 (5.1.2600.5938) and Windows 2003 SP1 (5.2.3790.1830). If you have access to other modules not mentioned here please upload them.

- Windows 2000 SP4
- Windows XP SP1
- Windows XP SP2
- Windows XP SP3
- Windows 2003 SP1

Thanks,
Alex
 #1862  by EP_X0FF
 Mon Aug 09, 2010 4:23 am
Windows 2003 SP2 == Windows 2003 SP1 (in most cases).
Windows Vista SP1 == Windows Vista SP2 (in most cases).

Some binaries from Windows 7
7600

kernel32.dll
user32.dll
win32k.sys
ntkrnlpa.exe
ntdll.dll
hal.dll

http://www.megaupload.com/?d=BEY64PZA

Windows 2003 no SP
5.2.3790.0 (srv03_rtm.030324-2048)
http://www.megaupload.com/?d=Y5TOKY8G

Windows Vista no SP
6.0.6000.16386 (vista_rtm.061101-2205)
http://www.megaupload.com/?d=UXTJN6HV
 #2201  by EP_X0FF
 Mon Aug 23, 2010 6:01 am
EPROCESS/ETHREAD/OBJECT_TYPE/OBJECT_TYPE_INITIALIZER looks same :)

However it is beta.
Attachments
(778 KiB) Downloaded 67 times
(434.31 KiB) Downloaded 32 times
(74.39 KiB) Downloaded 30 times
(908.3 KiB) Downloaded 32 times
 #2204  by EP_X0FF
 Mon Aug 23, 2010 7:18 am
It was reported that rku working OK on Windows 7 SP1 (well SR2 was designed with 7601 in mind), so I assume there no changes in shadow table :)

you can try SP1 from here
http://www.microsoft.com/downloads/deta ... 9b77cdfdda

7601.16562.100603-1800_Update_Sp_Wave0-B1SP1.0_DVD.iso
or windows6.1-KB976932-X86-INTL.exe