I have two different versions of PEB structure definition (Microsoft's version is useless), one from French Reverse Engineering Team and the second is from ntinternals; however something is fishy - regardless of the OS - after the NTGlobalFlag (offset 0x68, I drow this conclusion by examining some should-be-obvious values - like ProcessHeaps and PostProcessInitRoutine where I'm getting 100% non-pointer values). Is there some good soul to share the info?





