Microsoft (R) Windows Debugger Version 6.2.8229.0 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Symbol search path is: srv*\\FileServer\Shares\Symbols*http://msdl.microsoft.com/download/symbols;srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`003b0000 00000000`00468000 iexplore.exe
ModLoad: 00000000`76ee0000 00000000`77089000 ntdll.dll
ModLoad: 00000000`770c0000 00000000`77240000 ntdll32.dll
ModLoad: 00000000`00080000 00000000`000ee000 C:\Windows\system32\verifier.dll
Page heap: pid 0x1134: page heap enabled with flags 0x3.
ModLoad: 00000000`74740000 00000000`7477f000 C:\Windows\SYSTEM32\wow64.dll
ModLoad: 00000000`746e0000 00000000`7473c000 C:\Windows\SYSTEM32\wow64win.dll
ModLoad: 00000000`746d0000 00000000`746d8000 C:\Windows\SYSTEM32\wow64cpu.dll
(1134.55c): Break instruction exception - code 80000003 (first chance)
ntdll!LdrpDoDebuggerBreak+0x30:
00000000`76f8cb60 cc int 3
ModLoad: 00000000`76a10000 00000000`76b2f000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74d50000 00000000`74e60000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76a10000 00000000`76b2f000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76b30000 00000000`76c2a000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cab0000 00000000`6cb10000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Page heap: pid 0x1134: page heap enabled with flags 0x3.
ModLoad: 00000000`74d50000 00000000`74e60000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ea0000 00000000`74ee7000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ae0000 00000000`74b80000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74a30000 00000000`74adc000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74920000 00000000`74939000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74940000 00000000`74a30000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`747a0000 00000000`74800000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74790000 00000000`7479c000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75f70000 00000000`76070000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76070000 00000000`76100000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76730000 00000000`7673a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`762d0000 00000000`7636d000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76250000 00000000`762a7000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75320000 00000000`75f6a000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`750a0000 00000000`751fc000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74800000 00000000`74911000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76190000 00000000`7621f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76510000 00000000`766c8000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ef0000 00000000`7500b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74b80000 00000000`74b83000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
(1134.55c): WOW64 breakpoint - code 4000001f (first chance)
ModLoad: 72ec0000 72f0c000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73930000 00000000`73947000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`766d0000 00000000`76730000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75250000 00000000`7531c000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`70360000 00000000`70cad000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74e60000 00000000`74e65000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74280000 00000000`742bc000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71f80000 00000000`7211e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76780000 00000000`767fb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72c20000 00000000`72ca0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71d10000 00000000`71d18000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74650000 00000000`7465b000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74b90000 74bc5000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76740000 76746000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71020000 71064000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72180000 7219c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72ac0000 72ac7000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72b50000 72b63000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71d40000 71d64000 C:\Program Files (x86)\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71070000 71091000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 75200000 75245000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73e00000 00000000`73e0e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74540000 00000000`74556000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74420000 00000000`7445b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76100000 00000000`76183000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cc40000 00000000`6cc73000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`0a5d0000 00000000`0af1d000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6b530000 00000000`6c0f5000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746c0000 00000000`746c9000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6ca50000 00000000`6caa2000 C:\Windows\SysWOW64\RASAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6d3c0000 00000000`6d3d5000 C:\Windows\SysWOW64\rasman.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6e3f0000 00000000`6e3fd000 C:\Windows\SysWOW64\rtutils.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6ca40000 00000000`6ca46000 C:\Windows\SysWOW64\sensapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`08fa0000 00000000`09058000 iexplore.exe
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Symbol search path is: srv*\\FileServer\Shares\Symbols*http://msdl.microsoft.com/download/symbols;srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`003b0000 00000000`00468000 iexplore.exe
<---- EVENT: break cpr ---->
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`76ee0000 00000000`77089000 ntdll.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`770c0000 00000000`77240000 ntdll32.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`00080000 00000000`000ee000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Page heap: pid 0xFEC: page heap enabled with flags 0x3.
ModLoad: 00000000`74740000 00000000`7477f000 C:\Windows\SYSTEM32\wow64.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746e0000 00000000`7473c000 C:\Windows\SYSTEM32\wow64win.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746d0000 00000000`746d8000 C:\Windows\SYSTEM32\wow64cpu.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76a10000 00000000`76b2f000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74d50000 00000000`74e60000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76a10000 00000000`76b2f000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76b30000 00000000`76c2a000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cab0000 00000000`6cb10000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Page heap: pid 0xFEC: page heap enabled with flags 0x3.
ModLoad: 00000000`74d50000 00000000`74e60000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6ca10000 00000000`6ca3d000 C:\Windows\SysWOW64\IEUI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ea0000 00000000`74ee7000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71d30000 00000000`71d35000 C:\Windows\SysWOW64\MSIMG32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ae0000 00000000`74b80000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74a30000 00000000`74adc000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74920000 00000000`74939000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74940000 00000000`74a30000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`747a0000 00000000`74800000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74790000 00000000`7479c000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75f70000 00000000`76070000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76070000 00000000`76100000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76730000 00000000`7673a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`762d0000 00000000`7636d000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76250000 00000000`762a7000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75320000 00000000`75f6a000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`750a0000 00000000`751fc000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74800000 00000000`74911000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76190000 00000000`7621f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76510000 00000000`766c8000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ef0000 00000000`7500b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74b80000 00000000`74b83000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72ec0000 72f0c000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73930000 00000000`73947000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`766d0000 00000000`76730000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75250000 00000000`7531c000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`08990000 00000000`089cc000 C:\Windows\SysWOW64\oleacc.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`70360000 00000000`70cad000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74e60000 00000000`74e65000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74280000 00000000`742bc000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71f80000 00000000`7211e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76780000 00000000`767fb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c9e0000 00000000`6ca0f000 C:\Windows\SysWOW64\xmllite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c9a0000 00000000`6c9d1000 C:\Program Files (x86)\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72c20000 00000000`72ca0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71d10000 71d18000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71560000 716cf000 C:\Windows\SysWOW64\explorerframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`734e0000 00000000`7350f000 C:\Windows\SysWOW64\DUser.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73420000 00000000`734d2000 C:\Windows\SysWOW64\DUI70.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74650000 00000000`7465b000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 0e8f0000 0ea4c000 C:\Windows\SysWOW64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74b90000 00000000`74bc5000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76740000 00000000`76746000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71020000 00000000`71064000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72180000 00000000`7219c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72ac0000 00000000`72ac7000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73e00000 00000000`73e0e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72b50000 00000000`72b63000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6b530000 00000000`6c0f5000 C:\Windows\SysWOW64\MSHTML.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 746c0000 746c9000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76370000 7650d000 C:\Windows\syswow64\setupapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74e70000 74e97000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 762b0000 762c2000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c8e0000 6c99a000 C:\Windows\SysWOW64\d2d1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c4e0000 6c5eb000 C:\Windows\SysWOW64\DWrite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71d40000 71d64000 C:\Program Files (x86)\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c850000 00000000`6c8d3000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76750000 7677d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74c30000 74d4e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 77090000 7709c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c820000 6c84c000 C:\Windows\SysWOW64\d3d10_1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c650000 00000000`6c68a000 C:\Windows\SysWOW64\d3d10_1core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 73570000 7361a000 C:\Windows\SysWOW64\aticfx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c4d0000 6c4db000 C:\Windows\SysWOW64\atiuxpag.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6b130000 6b52d000 C:\Windows\SysWOW64\atidxx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 716f0000 717eb000 C:\Windows\SysWOW64\WindowsCodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74540000 00000000`74556000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74420000 7445b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76100000 00000000`76183000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cc40000 00000000`6cc73000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`122d0000 00000000`12c1d000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`14150000 00000000`14d15000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71070000 00000000`71091000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75200000 00000000`75245000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73950000 00000000`739af000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73950000 00000000`739af000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c460000 00000000`6c4cc000 C:\Windows\SysWOW64\ieapfltr.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c450000 00000000`6c45b000 C:\Windows\SysWOW64\msimtf.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c420000 00000000`6c44b000 C:\Windows\SysWOW64\msls31.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c3f0000 00000000`6c41e000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74040000 00000000`74135000 C:\Windows\SysWOW64\PROPSYS.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c3f0000 00000000`6c41e000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76370000 00000000`7650d000 C:\Windows\syswow64\SETUPAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74e70000 00000000`74e97000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`762b0000 00000000`762c2000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74040000 00000000`74135000 C:\Windows\SysWOW64\propsys.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`721a0000 00000000`721c5000 C:\Windows\SysWOW64\POWRPROF.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c850000 00000000`6c8d3000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76750000 7677d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74c30000 74d4e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 77090000 7709c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 67a30000 67b32000 C:\Windows\SysWOW64\d3d10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c3b0000 6c3e3000 C:\Windows\SysWOW64\d3d10core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 716f0000 717eb000 C:\Windows\SysWOW64\windowscodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73400000 00000000`73412000 C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73e10000 00000000`73e1d000 C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73390000 00000000`733fb000 C:\Program Files\TortoiseSVN\bin\TortoiseSVN32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`70070000 00000000`70360000 C:\Program Files\TortoiseSVN\bin\libsvn_tsvn32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73360000 00000000`73384000 C:\Program Files\TortoiseSVN\bin\libapr_tsvn32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74600000 00000000`7463c000 C:\Windows\SysWOW64\MSWSOCK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`732a0000 00000000`7335f000 C:\Windows\SysWOW64\MSVCR100.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73130000 00000000`73166000 C:\Program Files\TortoiseSVN\bin\libaprutil_tsvn32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`738e0000 00000000`738ed000 C:\Program Files\TortoiseSVN\bin\intl3_tsvn32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73110000 00000000`73123000 C:\Program Files\TortoiseSVN\bin\libsasl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72fa0000 00000000`73009000 C:\Windows\SysWOW64\MSVCP100.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72e80000 00000000`72eb1000 EhStorAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72e80000 00000000`72eb1000 C:\Windows\SysWOW64\EhStorShell.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6b0a0000 00000000`6b124000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72da0000 00000000`72e10000 ntshrui.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72da0000 00000000`72e10000 C:\Windows\SysWOW64\ntshrui.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72130000 00000000`72149000 C:\Windows\SysWOW64\srvcli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74320000 00000000`7432b000 C:\Windows\SysWOW64\cscapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73290000 00000000`7329a000 C:\Windows\SysWOW64\slc.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73100000 00000000`73106000 C:\Windows\SysWOW64\IconCodecService.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`133c0000 00000000`13478000 iexplore.exe
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Symbol search path is: srv*\\FileServer\Shares\Symbols*http://msdl.microsoft.com/download/symbols;srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`003b0000 00000000`00468000 iexplore.exe
<---- EVENT: break cpr ---->
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`76ee0000 00000000`77089000 ntdll.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`770c0000 00000000`77240000 ntdll32.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`76f0c500 4883ec48 sub rsp,48h
ModLoad: 00000000`00100000 00000000`0016e000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Page heap: pid 0xC80: page heap enabled with flags 0x3.
ModLoad: 00000000`74740000 00000000`7477f000 C:\Windows\SYSTEM32\wow64.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746e0000 00000000`7473c000 C:\Windows\SYSTEM32\wow64win.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746d0000 00000000`746d8000 C:\Windows\SYSTEM32\wow64cpu.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76a10000 00000000`76b2f000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74d50000 00000000`74e60000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76a10000 00000000`76b2f000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76b30000 00000000`76c2a000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cab0000 00000000`6cb10000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
Page heap: pid 0xC80: page heap enabled with flags 0x3.
ModLoad: 00000000`74d50000 00000000`74e60000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ea0000 00000000`74ee7000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ae0000 00000000`74b80000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74a30000 00000000`74adc000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74920000 00000000`74939000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74940000 00000000`74a30000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`747a0000 00000000`74800000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74790000 00000000`7479c000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75f70000 00000000`76070000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76070000 00000000`76100000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76730000 00000000`7673a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`762d0000 00000000`7636d000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76250000 00000000`762a7000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75320000 00000000`75f6a000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`750a0000 00000000`751fc000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74800000 00000000`74911000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76190000 00000000`7621f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76510000 00000000`766c8000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74ef0000 00000000`7500b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74b80000 00000000`74b83000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72ec0000 72f0c000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73930000 00000000`73947000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`766d0000 00000000`76730000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75250000 00000000`7531c000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`70360000 00000000`70cad000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74e60000 00000000`74e65000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74280000 00000000`742bc000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71f80000 00000000`7211e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76780000 00000000`767fb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c9a0000 00000000`6c9d1000 C:\Program Files (x86)\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72c20000 00000000`72ca0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71d10000 00000000`71d18000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74650000 7465b000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74b90000 74bc5000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76740000 76746000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 71020000 71064000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72180000 7219c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 72ac0000 72ac7000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73e00000 00000000`73e0e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72b50000 00000000`72b63000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6b530000 00000000`6c0f5000 C:\Windows\SysWOW64\MSHTML.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`746c0000 00000000`746c9000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76370000 00000000`7650d000 C:\Windows\syswow64\setupapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74e70000 00000000`74e97000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 762b0000 762c2000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c8e0000 6c99a000 C:\Windows\SysWOW64\d2d1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 6c4e0000 6c5eb000 C:\Windows\SysWOW64\DWrite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74540000 74556000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71d40000 00000000`71d64000 C:\Program Files (x86)\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c850000 00000000`6c8d3000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 76750000 7677d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74c30000 74d4e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 77090000 7709c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 74420000 7445b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c820000 00000000`6c84c000 C:\Windows\SysWOW64\d3d10_1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c650000 00000000`6c68a000 C:\Windows\SysWOW64\d3d10_1core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 73570000 7361a000 C:\Windows\SysWOW64\aticfx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c4d0000 00000000`6c4db000 C:\Windows\SysWOW64\atiuxpag.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`76100000 00000000`76183000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6b130000 00000000`6b52d000 C:\Windows\SysWOW64\atidxx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6cc40000 00000000`6cc73000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`12910000 00000000`1325d000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71070000 00000000`71091000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`75200000 00000000`75245000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`14a80000 00000000`15645000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`73950000 00000000`739af000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`12c00000 00000000`12d5c000 C:\Windows\SysWOW64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c460000 00000000`6c4cc000 C:\Windows\SysWOW64\ieapfltr.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c450000 00000000`6c45b000 C:\Windows\SysWOW64\msimtf.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`74040000 00000000`74135000 C:\Windows\SysWOW64\PROPSYS.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`67870000 00000000`67a2b000 C:\Windows\SysWOW64\jscript9.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c420000 00000000`6c44b000 C:\Windows\SysWOW64\msls31.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c3f0000 00000000`6c41e000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`721a0000 00000000`721c5000 C:\Windows\SysWOW64\POWRPROF.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`72be0000 00000000`72c12000 C:\Windows\SysWOW64\WINMM.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`67a30000 00000000`67b32000 C:\Windows\SysWOW64\d3d10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`6c3b0000 00000000`6c3e3000 C:\Windows\SysWOW64\d3d10core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`716f0000 00000000`717eb000 C:\Windows\SysWOW64\windowscodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
ModLoad: 00000000`71d30000 00000000`71d35000 C:\Windows\SysWOW64\MSIMG32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`76f3159a c3 ret
(c80.e1c): Access violation - code c0000005 (first chance)