Files
Elliot Killick 8f9257c1da A release
From June to now, most of my time on this project was spent writing
"The Rise of Microsoft". Researching and writing that thing took an
inordinate amount of time. Also, I took a break to work primarily on
another unreleased project I have before switching back to this one.

I am proud of what I got here though and I feel like it is all coming
together. My plans for the whitepapers are already well drafted and I
know they will make an impact.

I have learned a ton from working on this project and it has definitely
given me something to idly think about and work on in my spare time.

Finishing "The Problem with How Windows Uses Threads" was something I
thought I wanted done before this release, but oh well. The main README
is at about 50K words now, plus all the other smaller documents and you
are looking at about a small novel's worth of technical writing. And
technical writing takes multiple times longer than typical story
writing.

Anyway, this project is exciting for me - people who I show it to also
really like it - and I am even more excited about what is to come!
2025-11-30 23:00:08 -05:00
..
2025-11-30 23:00:08 -05:00
2025-11-30 23:00:08 -05:00
2025-11-30 23:00:08 -05:00

Timeline Verification

Understanding history requires knowing the timeline (i.e. the order in which things happened) to get an accurate depiction of events. Let's collect some details on the files included throughout Windows versions to help establish timeline information on its development.

Methods

DLL Imports/Exports

Contained are the imports and/or exports of the core DLLs from these Windows version:

  • Windows 3.1 KRNL286.EXE and KRNL386.EXE (16-bit and 32-bit base DLLs)
  • Windows NT 3.1 early pre-release BASE.DLL
  • Windows NT 3.1 NTDLL.dll and KERNEL32.dll

To obtain these file artifacts, see the Legacy Software Analysis document.

Windows 3.1 Files

> file KRNL286.EXE
KRNL286.EXE: MS-DOS executable, NE for MS Windows 3.x (3.0) (DLL or font)
> file KRNL386.EXE
KRNL386.EXE: MS-DOS executable, NE for MS Windows 3.x (3.0) (DLL or font)

16-Bit Windows executables are in the New Executable file format. Early 16-bit library executables did not support imports because Windows 3.1 did not have a dynamic linking mechanism. An EXE had to manually load another EXE, for instance by calling LoadLibrary, to use its functionality.

We use the exehdr tool to get infromation about a 16-bit executable, which can be obtained by downloading an early version of the VC++ development tools.

Windows NT 3.1 Early Pre-Release Files

> file BASE.DLL
BASE.DLL: PE Unknown PE signature 0xffff8300 (Microsoft compiled help format 2.0), for MS Windows, 2 sections

This Windows NT pre-release used a botched Portable Executable file format because the new format did not have a stable ABI yet (hence why the Microsoft compiled help format 2.0 detail is inaccurate). By the time of Windows NT's formal release, Microsoft split BASE.DLL into the KERNEL32.dll and NTDLL.dll files to separate the public and private Windows APIs.

There is no tool available that can parse this half-baked executable format, DLL information is obtained using the strings command.

Windows NT 3.1 Files

> file KERNEL32.DLL
KERNEL32.DLL: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows, 8 sections
> file NTDLL.DLL
NTDLL.DLL: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows, 10 sections

Execetubles in the final Windows NT release are in the Portable Executable file format.

We use the dumpbin tool to get DLL information, which can be obtained by installing Visual Studio with the C++ development pack.