Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ;By Celtic88 (c) 2016
- ;Full PEB Structure
- Structure UNICODE_STRING Align #PB_Structure_AlignC
- Length.w;
- MaximumLength.w;
- *Buffer ;
- EndStructure
- Structure LIST_ENTRY Align #PB_Structure_AlignC
- *Flink.LIST_ENTRY;
- *Blink.LIST_ENTRY;
- EndStructure
- Structure LDR_DATA_TABLE_ENTRY Align #PB_Structure_AlignC
- InLoadOrderModuleList.LIST_ENTRY;
- InMemoryOrderModuleList.LIST_ENTRY;
- InInitializationOrderModuleList.LIST_ENTRY;
- *DllBase
- *EntryPoint
- SizeOfImage.l;
- FullDllName.UNICODE_STRING;
- BaseDllName.UNICODE_STRING;
- Flags.l ;
- LoadCount.w ;
- TlsIndex.w ;
- HashTableEntry.LIST_ENTRY ;
- TimeDateStamp.l ;
- EndStructure
- Structure PEB_LDR_DATA Align #PB_Structure_AlignC
- dwLength.l;
- dwInitialized.l;
- *lpSsHandle ;
- InLoadOrderModuleList.LIST_ENTRY;
- InMemoryOrderModuleList.LIST_ENTRY;
- InInitializationOrderModuleList.LIST_ENTRY
- *lpEntryInProgress
- EndStructure
- Structure RTL_CRITICAL_SECTION Align #PB_Structure_AlignC
- *DebugInfo;
- LockCount.l;
- RecursionCount.l;
- *OwningThread ;
- *LockSemaphore ;
- SpinCount.l ;
- EndStructure
- Structure _ULARGE_INTEGER Align #PB_Structure_AlignC
- StructureUnion
- LowPart.l;
- HighPart.l;
- QuadPart.q;
- EndStructureUnion
- EndStructure
- Structure RTL_USER_PROCESS_PARAMETERS Align #PB_Structure_AlignC
- Reserved1.b[16];
- Reserved2.b[10];
- ImagePathName.UNICODE_STRING;
- CommandLine.UNICODE_STRING;
- EndStructure
- Structure PEB Align #PB_Structure_AlignC;528
- bInheritedAddressSpace.b
- bReadImageFileExecOptions.b
- bBeingDebugged.b
- bSpareBool.b
- *lpMutant
- *lpImageBaseAddress
- *pLdr.PEB_LDR_DATA
- *lpProcessParameters.RTL_USER_PROCESS_PARAMETERS
- *lpSubSystemData
- *lpProcessHeap
- *pFastPebLock.RTL_CRITICAL_SECTION
- *lpFastPebLockRoutine
- *lpFastPebUnlockRoutine
- dwEnvironmentUpdateCount.l
- *lpKernelCallbackTable
- dwSystemReserved.l;
- dwAtlThunkSListPtr32.l;
- *pFreeList.PEB_FREE_BLOCK
- dwTlsExpansionCounter.l
- *lpTlsBitmap
- dwTlsBitmapBits.l[2]
- *lpReadOnlySharedMemoryBase
- *lpReadOnlySharedMemoryHeap
- *lpReadOnlyStaticServerData
- *lpAnsiCodePageData
- *lpOemCodePageData
- *lpUnicodeCaseTableData
- NumberOfProcessors.l
- dwNtGlobalFlag.l
- liCriticalSectionTimeout._ULARGE_INTEGER
- dwHeapSegmentReserve.l
- dwHeapSegmentCommit.l
- dwHeapDeCommitTotalFreeThreshold.l
- dwHeapDeCommitFreeBlockThreshold.l
- dwNumberOfHeaps.l
- dwMaximumNumberOfHeaps.l
- *lpProcessHeaps
- *lpGdiSharedHandleTable
- *lpProcessStarterHelper
- dwGdiDCAttributeList.l
- *lpLoaderLock
- dwOSMajorVersion.l
- dwOSMinorVersion.l
- wOSBuildNumber.w
- wOSMinorVersion.w
- dwOSPlatformId.l
- dwImageSubsystem.l
- dwImageSubSystemMajorVersion.l
- dwImageSubSystemMinorVersion.l
- dwImageProcessAffinityMask.l;
- GdiHandleBuffer.l[34]
- *lpPostProcessInitRoutine
- *lpTlsExpansionBitmap
- dwTlsExpansionBitmapBits.l[32]
- dwSessionId.l
- liAppCompatFlags._ULARGE_INTEGER;
- liAppCompatFlagsUser._ULARGE_INTEGER;
- *lppShimData ;
- *lpAppCompatInfo ;
- usCSDVersion.UNICODE_STRING ;
- *lpActivationContextData ;
- *lpProcessAssemblyStorageMap ;
- *lpSystemDefaultActivationContextData;
- *lpSystemAssemblyStorageMap ;
- dwMinimumStackCommit.l ;
- EndStructure
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement