Microsoft (R) Windows Debugger Version 6.2.8229.0 X86
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: "C:\Program Files\Internet Explorer\iexplore.exe" http://A2-W7-IE8-3:32768/Ping-WithSomethingToMakeItASemiUniqueStringThatCanBeDifferentiatedFromOtherRequests
Symbol search path is: srv*\\server\Symbols*http://msdl.microsoft.com/download/symbols;srv*\\server\Symbols*http://symbols.mozilla.org/firefox;srv*\\server\Symbols*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 000a0000 00146000 iexplore.exe
ModLoad: 77190000 772cc000 ntdll.dll
ModLoad: 72e00000 72e60000 C:\Windows\system32\verifier.dll
Page heap: pid 0x758: page heap enabled with flags 0x3.
ModLoad: 75870000 75944000 C:\Windows\system32\kernel32.dll
ModLoad: 753f0000 7543b000 C:\Windows\system32\KERNELBASE.dll
ModLoad: 77050000 770f0000 C:\Windows\system32\ADVAPI32.dll
ModLoad: 755d0000 7567c000 C:\Windows\system32\msvcrt.dll
ModLoad: 76e20000 76e39000 C:\Windows\SYSTEM32\sechost.dll
ModLoad: 75980000 75a22000 C:\Windows\system32\RPCRT4.dll
ModLoad: 76e40000 76f09000 C:\Windows\system32\USER32.dll
ModLoad: 75820000 7586e000 C:\Windows\system32\GDI32.dll
ModLoad: 772d0000 772da000 C:\Windows\system32\LPK.dll
ModLoad: 770f0000 7718d000 C:\Windows\system32\USP10.dll
ModLoad: 772e0000 77337000 C:\Windows\system32\SHLWAPI.dll
ModLoad: 75c40000 7688a000 C:\Windows\system32\SHELL32.dll
ModLoad: 76b90000 76cec000 C:\Windows\system32\ole32.dll
ModLoad: 75a30000 75c31000 C:\Windows\system32\iertutil.dll
ModLoad: 756d0000 75810000 C:\Windows\system32\urlmon.dll
ModLoad: 75310000 7533f000 C:\Windows\system32\XmlLite.dll
ModLoad: 76f50000 77045000 C:\Windows\system32\WININET.dll
ModLoad: 76cf0000 76d7f000 C:\Windows\system32\OLEAUT32.dll
ModLoad: 75440000 75561000 C:\Windows\system32\CRYPT32.dll
ModLoad: 75300000 7530c000 C:\Windows\system32\MSASN1.dll
(758.530): Break instruction exception - code 80000003 (first chance)
eax=00000000 ebx=00000000 ecx=0029f9e4 edx=771d70f4 esi=fffffffe edi=00000000
eip=772305a6 esp=0029fa00 ebp=0029fa2c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!LdrpDoDebuggerBreak+0x2c:
772305a6 cc int 3
ModLoad: 77340000 7735f000 C:\Windows\system32\IMM32.DLL
<---- EVENT: break ld ---->
eax=01a66000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029ef60
eip=771d70f4 esp=0029ee78 ebp=0029eecc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76890000 7695c000 C:\Windows\system32\MSCTF.dll
<---- EVENT: break ld ---->
eax=01a74000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029ebc0
eip=771d70f4 esp=0029ead8 ebp=0029eb2c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 751e0000 751ec000 C:\Windows\system32\CRYPTBASE.DLL
<---- EVENT: break ld ---->
eax=02c2d000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029fa44
eip=771d70f4 esp=0029f95c ebp=0029f9b0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e890000 6f316000 C:\Windows\system32\IEFRAME.dll
<---- EVENT: break ld ---->
eax=02c69000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f9d8
eip=771d70f4 esp=0029f8f0 ebp=0029f944 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76d80000 76d85000 C:\Windows\system32\PSAPI.DLL
<---- EVENT: break ld ---->
eax=03850000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f638
eip=771d70f4 esp=0029f550 ebp=0029f5a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71370000 713ac000 C:\Windows\system32\OLEACC.dll
<---- EVENT: break ld ---->
eax=0386a000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f638
eip=771d70f4 esp=0029f550 ebp=0029f5a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 741b0000 7434e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
eax=03900000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f2c0
eip=771d70f4 esp=0029f1d8 ebp=0029f22c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75170000 7518b000 C:\Windows\system32\SspiCli.dll
<---- EVENT: break ld ---->
eax=0399e000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e634
eip=771d70f4 esp=0029e54c ebp=0029e5a0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75290000 7529b000 C:\Windows\system32\profapi.dll
<---- EVENT: break ld ---->
eax=03ac0000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029b7f8
eip=771d70f4 esp=0029b710 ebp=0029b764 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74750000 74771000 C:\Windows\system32\ntmarta.dll
<---- EVENT: break ld ---->
eax=03aa0000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e64c
eip=771d70f4 esp=0029e564 ebp=0029e5b8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75680000 756c5000 C:\Windows\system32\WLDAP32.dll
<---- EVENT: break ld ---->
eax=03aae000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e2ac
eip=771d70f4 esp=0029e1c4 ebp=0029e218 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76f10000 76f45000 C:\Windows\system32\ws2_32.DLL
<---- EVENT: break ld ---->
eax=03ab8000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e540
eip=771d70f4 esp=0029e458 ebp=0029e4ac iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76960000 76966000 C:\Windows\system32\NSI.dll
<---- EVENT: break ld ---->
eax=03c3e000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e1a0
eip=771d70f4 esp=0029e0b8 ebp=0029e10c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74b80000 74bc4000 C:\Windows\system32\dnsapi.DLL
<---- EVENT: break ld ---->
eax=03c78000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e6d8
eip=771d70f4 esp=0029e5f0 ebp=0029e644 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73340000 7335c000 C:\Windows\system32\iphlpapi.DLL
<---- EVENT: break ld ---->
eax=04206000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e6d8
eip=771d70f4 esp=0029e5f0 ebp=0029e644 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73330000 73337000 C:\Windows\system32\WINNSI.DLL
<---- EVENT: break ld ---->
eax=04210000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e338
eip=771d70f4 esp=0029e250 ebp=0029e2a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76d90000 76e13000 C:\Windows\system32\CLBCatQ.DLL
<---- EVENT: break ld ---->
eax=0428f000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043ff094
eip=771d70f4 esp=043fefac ebp=043ff000 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 70060000 700ba000 C:\Windows\System32\netprofm.dll
<---- EVENT: break ld ---->
eax=042ca000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe2c8
eip=771d70f4 esp=043fe1e0 ebp=043fe234 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73a20000 73a30000 C:\Windows\System32\nlaapi.dll
<---- EVENT: break ld ---->
eax=042de000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fdf28
eip=771d70f4 esp=043fde40 ebp=043fde94 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74d00000 74d17000 C:\Windows\system32\CRYPTSP.dll
<---- EVENT: break ld ---->
eax=0462d000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe4ac
eip=771d70f4 esp=043fe3c4 ebp=043fe418 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74aa0000 74adb000 C:\Windows\system32\rsaenh.dll
<---- EVENT: break ld ---->
eax=03bb0000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe3e4
eip=771d70f4 esp=043fe2fc ebp=043fe350 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75280000 7528e000 C:\Windows\system32\RpcRtRemote.dll
<---- EVENT: break ld ---->
eax=04669000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe1dc
eip=771d70f4 esp=043fe0f4 ebp=043fe148 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6fa00000 6fa08000 C:\Windows\System32\npmproxy.dll
<---- EVENT: break ld ---->
eax=04a5c000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe3b8
eip=771d70f4 esp=043fe2d0 ebp=043fe324 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74780000 74789000 C:\Windows\system32\VERSION.dll
<---- EVENT: break ld ---->
eax=04ac6000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f40c
eip=771d70f4 esp=0029f324 ebp=0029f378 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74cc0000 74cfc000 C:\Windows\system32\mswsock.dll
<---- EVENT: break ld ---->
eax=04aee000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fed2c
eip=771d70f4 esp=043fec44 ebp=043fec98 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76b10000 76b8b000 C:\Windows\system32\comdlg32.dll
<---- EVENT: break ld ---->
eax=04a18000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029fa0c
eip=771d70f4 esp=0029f924 ebp=0029f978 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74810000 74815000 C:\Windows\System32\wshtcpip.dll
<---- EVENT: break ld ---->
eax=0461d000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fef68
eip=771d70f4 esp=043fee80 ebp=043feed4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74cb0000 74cb6000 C:\Windows\System32\wship6.dll
<---- EVENT: break ld ---->
eax=04a2d000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fef8c
eip=771d70f4 esp=043feea4 ebp=043feef8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71c80000 71c86000 C:\Windows\system32\rasadhlp.dll
<---- EVENT: break ld ---->
eax=042fc000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe904
eip=771d70f4 esp=043fe81c ebp=043fe870 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6f5e0000 6f613000 C:\Program Files\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
eax=03c72000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029f7a4
eip=771d70f4 esp=0029f6bc ebp=0029f710 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73590000 735c8000 C:\Windows\System32\fwpuclnt.dll
<---- EVENT: break ld ---->
eax=03c02000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043fe97c
eip=771d70f4 esp=043fe894 ebp=043fe8e8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75190000 751dc000 C:\Windows\system32\apphelp.dll
<---- EVENT: break ld ---->
eax=04466000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029a0e0
eip=771d70f4 esp=00299ff8 ebp=0029a04c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 734a0000 734af000 C:\Windows\system32\wkscli.dll
<---- EVENT: break ld ---->
eax=055dd000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029bc54
eip=771d70f4 esp=0029bb6c ebp=0029bbc0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 734b0000 734b9000 C:\Windows\system32\netutils.dll
<---- EVENT: break ld ---->
eax=05624000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029bc5c
eip=771d70f4 esp=0029bb74 ebp=0029bbc8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73a20000 73a30000 C:\Windows\system32\NLAapi.dll
<---- EVENT: break ld ---->
eax=0553a000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029b894
eip=771d70f4 esp=0029b7ac ebp=0029b800 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72090000 720e2000 C:\Windows\system32\RASAPI32.dll
<---- EVENT: break ld ---->
eax=05528000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029c17c
eip=771d70f4 esp=0029c094 ebp=0029c0e8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72070000 72085000 C:\Windows\system32\rasman.dll
<---- EVENT: break ld ---->
eax=056b1000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029bddc
eip=771d70f4 esp=0029bcf4 ebp=0029bd48 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73370000 7337d000 C:\Windows\system32\rtutils.dll
<---- EVENT: break ld ---->
eax=05534000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffdc000 edi=043ff334
eip=771d70f4 esp=043ff24c ebp=043ff2a0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72890000 72896000 C:\Windows\system32\sensapi.dll
<---- EVENT: break ld ---->
eax=056f7000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029c248
eip=771d70f4 esp=0029c160 ebp=0029c1b4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71cf0000 71d00000 C:\Windows\system32\napinsp.dll
<---- EVENT: break ld ---->
eax=04a29000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffd3000 edi=0631edb0
eip=771d70f4 esp=0631ecc8 ebp=0631ed1c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 70be0000 70bf2000 C:\Windows\system32\pnrpnsp.dll
<---- EVENT: break ld ---->
eax=04d42000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffd3000 edi=0631edb0
eip=771d70f4 esp=0631ecc8 ebp=0631ed1c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
Symbol search path is: srv*\\server\Symbols*http://msdl.microsoft.com/download/symbols;srv*\\server\Symbols*http://symbols.mozilla.org/firefox;srv*\\server\Symbols*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 000a0000 00146000 iexplore.exe
<---- EVENT: break cpr ---->
eax=000a1b0a ebx=7ffd8000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=771d70d8 esp=003bf7fc ebp=00000000 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000200
771d70d8 89442404 mov dword ptr [esp+4],eax ss:0023:003bf800=00000000
ModLoad: 77190000 772cc000 ntdll.dll
<---- EVENT: break ld ---->
eax=000a1b0a ebx=7ffd8000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=771d70d8 esp=003bf7fc ebp=00000000 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000200
ntdll!RtlUserThreadStart:
771d70d8 89442404 mov dword ptr [esp+4],eax ss:0023:003bf800=00000000
ModLoad: 70a60000 70a68000 C:\Windows\System32\winrnr.dll
<---- EVENT: break ld ---->
eax=06094000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffd3000 edi=0631edb0
eip=771d70f4 esp=0631ecc8 ebp=0631ed1c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72e00000 72e60000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
eax=003bf044 ebx=7726ec40 ecx=7722df1c edx=00000003 esi=7ffdf000 edi=00000000
eip=771d70f4 esp=003beea8 ebp=003bf260 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72790000 727bd000 C:\Windows\system32\IEUI.dll
<---- EVENT: break ld ---->
eax=0669e000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e068
eip=771d70f4 esp=0029df80 ebp=0029dfd4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
Page heap: pid 0xE30: page heap enabled with flags 0x3.
ModLoad: 6fd70000 6fd75000 C:\Windows\system32\MSIMG32.dll
<---- EVENT: break ld ---->
eax=066ac000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029dcc8
eip=771d70f4 esp=0029dbe0 ebp=0029dc34 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75870000 75944000 C:\Windows\system32\kernel32.dll
<---- EVENT: break ld ---->
eax=00169000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf194
eip=771d70f4 esp=003bf0ac ebp=003bf100 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 753f0000 7543b000 C:\Windows\system32\KERNELBASE.dll
<---- EVENT: break ld ---->
eax=0016f000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bedf4
eip=771d70f4 esp=003bed0c ebp=003bed60 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 77050000 770f0000 C:\Windows\system32\ADVAPI32.dll
<---- EVENT: break ld ---->
eax=0019f000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 755d0000 7567c000 C:\Windows\system32\msvcrt.dll
<---- EVENT: break ld ---->
eax=001a3000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec74
eip=771d70f4 esp=003beb8c ebp=003bebe0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76e20000 76e39000 C:\Windows\SYSTEM32\sechost.dll
<---- EVENT: break ld ---->
eax=001b5000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec74
eip=771d70f4 esp=003beb8c ebp=003bebe0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75980000 75a22000 C:\Windows\system32\RPCRT4.dll
<---- EVENT: break ld ---->
eax=001c5000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be8d4
eip=771d70f4 esp=003be7ec ebp=003be840 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76e40000 76f09000 C:\Windows\system32\USER32.dll
<---- EVENT: break ld ---->
eax=001e5000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75820000 7586e000 C:\Windows\system32\GDI32.dll
<---- EVENT: break ld ---->
eax=001eb000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec00
eip=771d70f4 esp=003beb18 ebp=003beb6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 772d0000 772da000 C:\Windows\system32\LPK.dll
<---- EVENT: break ld ---->
eax=001f7000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be860
eip=771d70f4 esp=003be778 ebp=003be7cc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 770f0000 7718d000 C:\Windows\system32\USP10.dll
<---- EVENT: break ld ---->
eax=00205000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be534
eip=771d70f4 esp=003be44c ebp=003be4a0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 772e0000 77337000 C:\Windows\system32\SHLWAPI.dll
<---- EVENT: break ld ---->
eax=0021f000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75c40000 7688a000 C:\Windows\system32\SHELL32.dll
<---- EVENT: break ld ---->
eax=00231000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76b90000 76cec000 C:\Windows\system32\ole32.dll
<---- EVENT: break ld ---->
eax=01610000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75a30000 75c31000 C:\Windows\system32\iertutil.dll
<---- EVENT: break ld ---->
eax=0162a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 756d0000 75810000 C:\Windows\system32\urlmon.dll
<---- EVENT: break ld ---->
eax=0163a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003befa0
eip=771d70f4 esp=003beeb8 ebp=003bef0c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75310000 7533f000 C:\Windows\system32\XmlLite.dll
<---- EVENT: break ld ---->
eax=0163e000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec00
eip=771d70f4 esp=003beb18 ebp=003beb6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72c90000 72cbb000 C:\Program Files\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
eax=05ff7000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffad000 edi=06e3eee4
eip=771d70f4 esp=06e3edfc ebp=06e3ee50 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76f50000 77045000 C:\Windows\system32\WININET.dll
<---- EVENT: break ld ---->
eax=0164a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec00
eip=771d70f4 esp=003beb18 ebp=003beb6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76cf0000 76d7f000 C:\Windows\system32\OLEAUT32.dll
<---- EVENT: break ld ---->
eax=01662000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec00
eip=771d70f4 esp=003beb18 ebp=003beb6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75440000 75561000 C:\Windows\system32\CRYPT32.dll
<---- EVENT: break ld ---->
eax=01688000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bec00
eip=771d70f4 esp=003beb18 ebp=003beb6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75300000 7530c000 C:\Windows\system32\MSASN1.dll
<---- EVENT: break ld ---->
eax=0169a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be860
eip=771d70f4 esp=003be778 ebp=003be7cc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 77340000 7735f000 C:\Windows\system32\IMM32.DLL
<---- EVENT: break ld ---->
eax=01980000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be890
eip=771d70f4 esp=003be7a8 ebp=003be7fc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76890000 7695c000 C:\Windows\system32\MSCTF.dll
<---- EVENT: break ld ---->
eax=0198e000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003be4f0
eip=771d70f4 esp=003be408 ebp=003be45c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73e50000 73e90000 C:\Windows\system32\UxTheme.dll
<---- EVENT: break ld ---->
eax=06c99000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029dc08
eip=771d70f4 esp=0029db20 ebp=0029db74 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 751e0000 751ec000 C:\Windows\system32\CRYPTBASE.DLL
<---- EVENT: break ld ---->
eax=02b47000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf374
eip=771d70f4 esp=003bf28c ebp=003bf2e0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e890000 6f316000 C:\Windows\system32\IEFRAME.dll
<---- EVENT: break ld ---->
eax=02b83000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf310
eip=771d70f4 esp=003bf228 ebp=003bf27c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76d80000 76d85000 C:\Windows\system32\PSAPI.DLL
<---- EVENT: break ld ---->
eax=02b89000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bef70
eip=771d70f4 esp=003bee88 ebp=003beedc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71370000 713ac000 C:\Windows\system32\OLEACC.dll
<---- EVENT: break ld ---->
eax=02e84000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bef70
eip=771d70f4 esp=003bee88 ebp=003beedc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 741b0000 7434e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
eax=02f1a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bebf8
eip=771d70f4 esp=003beb10 ebp=003beb64 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76b10000 76b8b000 C:\Windows\system32\comdlg32.dll
<---- EVENT: break ld ---->
eax=02f5e000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf324
eip=771d70f4 esp=003bf23c ebp=003bf290 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e070000 6e0a5000 C:\Program Files\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
eax=02fd8000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf2b0
eip=771d70f4 esp=003bf1c8 ebp=003bf21c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75280000 7528e000 C:\Windows\system32\RpcRtRemote.dll
<---- EVENT: break ld ---->
eax=03287000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bee48
eip=771d70f4 esp=003bed60 ebp=003bedb4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e030000 6e063000 C:\Program Files\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
eax=0302a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bf0b8
eip=771d70f4 esp=003befd0 ebp=003bf024 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73ff0000 740e5000 C:\Windows\system32\propsys.dll
<---- EVENT: break ld ---->
eax=07f6c000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffd4000 edi=05f2d3b8
eip=771d70f4 esp=05f2d2d0 ebp=05f2d324 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76d90000 76e13000 C:\Windows\system32\CLBCatQ.DLL
<---- EVENT: break ld ---->
eax=0357d000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bdcc4
eip=771d70f4 esp=003bdbdc ebp=003bdc30 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73ff0000 740e5000 C:\Windows\system32\propsys.dll
<---- EVENT: break ld ---->
eax=035b7000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bcef8
eip=771d70f4 esp=003bce10 ebp=003bce64 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75290000 7529b000 C:\Windows\system32\profapi.dll
<---- EVENT: break ld ---->
eax=03621000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdf000 edi=003bcc10
eip=771d70f4 esp=003bcb28 ebp=003bcb7c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76970000 76b0d000 C:\Windows\system32\SETUPAPI.dll
<---- EVENT: break ld ---->
eax=0366d000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffd9000 edi=03f2f6f4
eip=771d70f4 esp=03f2f60c ebp=03f2f660 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75570000 75597000 C:\Windows\system32\CFGMGR32.dll
<---- EVENT: break ld ---->
eax=034ec000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffd9000 edi=03f2f354
eip=771d70f4 esp=03f2f26c ebp=03f2f2c0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 753d0000 753e2000 C:\Windows\system32\DEVOBJ.dll
<---- EVENT: break ld ---->
eax=03af4000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffd9000 edi=03f2f354
eip=771d70f4 esp=03f2f26c ebp=03f2f2c0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76970000 76b0d000 C:\Windows\system32\SETUPAPI.dll
<---- EVENT: break ld ---->
eax=07fb0000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffaf000 edi=070cf4b8
eip=771d70f4 esp=070cf3d0 ebp=070cf424 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75570000 75597000 C:\Windows\system32\CFGMGR32.dll
<---- EVENT: break ld ---->
eax=04c9c000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffaf000 edi=070cf118
eip=771d70f4 esp=070cf030 ebp=070cf084 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 753d0000 753e2000 C:\Windows\system32\DEVOBJ.dll
<---- EVENT: break ld ---->
eax=08b34000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffaf000 edi=070cf118
eip=771d70f4 esp=070cf030 ebp=070cf084 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71670000 717df000 C:\Windows\system32\explorerframe.dll
<---- EVENT: break ld ---->
eax=08f0a000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029d6c8
eip=771d70f4 esp=0029d5e0 ebp=0029d634 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73bd0000 73bff000 C:\Windows\system32\DUser.dll
<---- EVENT: break ld ---->
eax=09050000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029d328
eip=771d70f4 esp=0029d240 ebp=0029d294 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73c00000 73cb2000 C:\Windows\system32\DUI70.dll
<---- EVENT: break ld ---->
eax=08f32000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029d328
eip=771d70f4 esp=0029d240 ebp=0029d294 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75170000 7518b000 C:\Windows\system32\SspiCli.dll
<---- EVENT: break ld ---->
eax=03fff000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6f18c
eip=771d70f4 esp=03a6f0a4 ebp=03a6f0f8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6d5c0000 6d65c000 C:\Windows\system32\msfeeds.dll
<---- EVENT: break ld ---->
eax=090ac000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029e174
eip=771d70f4 esp=0029e08c ebp=0029e0e0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74d00000 74d17000 C:\Windows\system32\CRYPTSP.dll
<---- EVENT: break ld ---->
eax=0367b000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03def870
eip=771d70f4 esp=03def788 ebp=03def7dc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74aa0000 74adb000 C:\Windows\system32\rsaenh.dll
<---- EVENT: break ld ---->
eax=03f94000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03def7a8
eip=771d70f4 esp=03def6c0 ebp=03def714 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76f10000 76f45000 C:\Windows\system32\ws2_32.DLL
<---- EVENT: break ld ---->
eax=043e0000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6f098
eip=771d70f4 esp=03a6efb0 ebp=03a6f004 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 76960000 76966000 C:\Windows\system32\NSI.dll
<---- EVENT: break ld ---->
eax=043ee000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6ecf8
eip=771d70f4 esp=03a6ec10 ebp=03a6ec64 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72c90000 72cbb000 C:\Program Files\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
eax=03f48000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03def54c
eip=771d70f4 esp=03def464 ebp=03def4b8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74b80000 74bc4000 C:\Windows\system32\dnsapi.DLL
<---- EVENT: break ld ---->
eax=0449c000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6f230
eip=771d70f4 esp=03a6f148 ebp=03a6f19c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73340000 7335c000 C:\Windows\system32\iphlpapi.DLL
<---- EVENT: break ld ---->
eax=045d6000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6f230
eip=771d70f4 esp=03a6f148 ebp=03a6f19c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73330000 73337000 C:\Windows\system32\WINNSI.DLL
<---- EVENT: break ld ---->
eax=04383000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffdb000 edi=03a6ee90
eip=771d70f4 esp=03a6eda8 ebp=03a6edfc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75190000 751dc000 C:\Windows\system32\apphelp.dll
<---- EVENT: break ld ---->
eax=0469e000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03deb298
eip=771d70f4 esp=03deb1b0 ebp=03deb204 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72090000 720e2000 C:\Windows\system32\RASAPI32.dll
<---- EVENT: break ld ---->
eax=04dd8000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03ded2f0
eip=771d70f4 esp=03ded208 ebp=03ded25c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72070000 72085000 C:\Windows\system32\rasman.dll
<---- EVENT: break ld ---->
eax=04de8000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03decf50
eip=771d70f4 esp=03dece68 ebp=03decebc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73370000 7337d000 C:\Windows\system32\rtutils.dll
<---- EVENT: break ld ---->
eax=03fea000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03ded28c
eip=771d70f4 esp=03ded1a4 ebp=03ded1f8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72890000 72896000 C:\Windows\system32\sensapi.dll
<---- EVENT: break ld ---->
eax=04381000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03ded3bc
eip=771d70f4 esp=03ded2d4 ebp=03ded328 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74cc0000 74cfc000 C:\Windows\system32\mswsock.dll
<---- EVENT: break ld ---->
eax=04eec000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffd3000 edi=0533ed7c
eip=771d70f4 esp=0533ec94 ebp=0533ece8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74810000 74815000 C:\Windows\System32\wshtcpip.dll
<---- EVENT: break ld ---->
eax=04f24000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffd3000 edi=0533efb8
eip=771d70f4 esp=0533eed0 ebp=0533ef24 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75810000 75813000 C:\Windows\system32\Normaliz.dll
<---- EVENT: break ld ---->
eax=04f30000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03ded5a4
eip=771d70f4 esp=03ded4bc ebp=03ded510 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73a20000 73a30000 C:\Windows\system32\NLAapi.dll
<---- EVENT: break ld ---->
eax=04e6c000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec9cc
eip=771d70f4 esp=03dec8e4 ebp=03dec938 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71c80000 71c86000 C:\Windows\system32\rasadhlp.dll
<---- EVENT: break ld ---->
eax=04d64000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec71c
eip=771d70f4 esp=03dec634 ebp=03dec688 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 734a0000 734af000 C:\Windows\system32\wkscli.dll
<---- EVENT: break ld ---->
eax=055e0000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec6dc
eip=771d70f4 esp=03dec5f4 ebp=03dec648 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71cf0000 71d00000 C:\Windows\system32\napinsp.dll
<---- EVENT: break ld ---->
eax=05620000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaf000 edi=0599ee98
eip=771d70f4 esp=0599edb0 ebp=0599ee04 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 70be0000 70bf2000 C:\Windows\system32\pnrpnsp.dll
<---- EVENT: break ld ---->
eax=04fa8000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaf000 edi=0599ee98
eip=771d70f4 esp=0599edb0 ebp=0599ee04 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 734b0000 734b9000 C:\Windows\system32\netutils.dll
<---- EVENT: break ld ---->
eax=057b6000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec6e4
eip=771d70f4 esp=03dec5fc ebp=03dec650 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 70a60000 70a68000 C:\Windows\System32\winrnr.dll
<---- EVENT: break ld ---->
eax=057d4000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaf000 edi=0599ee98
eip=771d70f4 esp=0599edb0 ebp=0599ee04 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74cb0000 74cb6000 C:\Windows\System32\wship6.dll
<---- EVENT: break ld ---->
eax=04fac000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaf000 edi=0599eef4
eip=771d70f4 esp=0599ee0c ebp=0599ee60 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73590000 735c8000 C:\Windows\System32\fwpuclnt.dll
<---- EVENT: break ld ---->
eax=03a80000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaf000 edi=0599e8e4
eip=771d70f4 esp=0599e7fc ebp=0599e850 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 723e0000 7240e000 C:\Windows\system32\MLANG.dll
<---- EVENT: break ld ---->
eax=0564a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03decb54
eip=771d70f4 esp=03deca6c ebp=03decac0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74750000 74771000 C:\Windows\system32\ntmarta.dll
<---- EVENT: break ld ---->
eax=057f4000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03decb28
eip=771d70f4 esp=03deca40 ebp=03deca94 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75680000 756c5000 C:\Windows\system32\WLDAP32.dll
<---- EVENT: break ld ---->
eax=0580b000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec788
eip=771d70f4 esp=03dec6a0 ebp=03dec6f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74780000 74789000 C:\Windows\system32\VERSION.dll
<---- EVENT: break ld ---->
eax=0583b000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec8d0
eip=771d70f4 esp=03dec7e8 ebp=03dec83c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73e50000 73e90000 C:\Windows\system32\UxTheme.dll
<---- EVENT: break ld ---->
eax=0565d000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03deccc8
eip=771d70f4 esp=03decbe0 ebp=03decc34 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71400000 714ac000 C:\Program Files\Classic Shell\ClassicExplorer32.dll
<---- EVENT: break ld ---->
eax=06299000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec708
eip=771d70f4 esp=03dec620 ebp=03dec674 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73b60000 73b73000 C:\Windows\system32\dwmapi.dll
<---- EVENT: break ld ---->
eax=062a9000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec3dc
eip=771d70f4 esp=03dec2f4 ebp=03dec348 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71320000 71352000 C:\Windows\system32\WINMM.dll
<---- EVENT: break ld ---->
eax=062b9000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec3dc
eip=771d70f4 esp=03dec2f4 ebp=03dec348 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73660000 73671000 C:\Windows\system32\NETAPI32.dll
<---- EVENT: break ld ---->
eax=062c7000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec3dc
eip=771d70f4 esp=03dec2f4 ebp=03dec348 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74ef0000 74f09000 C:\Windows\system32\srvcli.dll
<---- EVENT: break ld ---->
eax=062cd000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec03c
eip=771d70f4 esp=03debf54 ebp=03debfa8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 755a0000 755cf000 C:\Windows\system32\WINTRUST.dll
<---- EVENT: break ld ---->
eax=062f9000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec3dc
eip=771d70f4 esp=03dec2f4 ebp=03dec348 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73b60000 73b73000 C:\Windows\system32\DWMAPI.DLL
<---- EVENT: break ld ---->
eax=062fd000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03ded288
eip=771d70f4 esp=03ded1a0 ebp=03ded1f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 751f0000 7524f000 C:\Windows\system32\SXS.DLL
<---- EVENT: break ld ---->
eax=06de4000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec660
eip=771d70f4 esp=03dec578 ebp=03dec5cc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 751f0000 7524f000 C:\Windows\system32\SXS.DLL
<---- EVENT: break ld ---->
eax=09507000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffda000 edi=049fddb8
eip=771d70f4 esp=049fdcd0 ebp=049fdd24 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 723e0000 7240e000 C:\Windows\system32\MLANG.dll
<---- EVENT: break ld ---->
eax=09787000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=00298908
eip=771d70f4 esp=00298820 ebp=00298874 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75810000 75813000 C:\Windows\system32\Normaliz.dll
<---- EVENT: break ld ---->
eax=09aa4000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=00298c6c
eip=771d70f4 esp=00298b84 ebp=00298bd8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6a390000 6a953000 C:\Windows\System32\mshtml.dll
<---- EVENT: break ld ---->
eax=0467c000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec120
eip=771d70f4 esp=03dec038 ebp=03dec08c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72760000 7278a000 C:\Windows\System32\msls31.dll
<---- EVENT: break ld ---->
eax=06ed6000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03debd80
eip=771d70f4 esp=03debc98 ebp=03debcec iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6de80000 6deef000 C:\Windows\System32\ieapfltr.dll
<---- EVENT: break ld ---->
eax=0725c000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03debf98
eip=771d70f4 esp=03debeb0 ebp=03debf04 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 75010000 75018000 C:\Windows\System32\Secur32.dll
<---- EVENT: break ld ---->
eax=07276000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03debbf8
eip=771d70f4 esp=03debb10 ebp=03debb64 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71320000 71352000 C:\Windows\system32\WINMM.dll
<---- EVENT: break ld ---->
eax=07511000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03debbc8
eip=771d70f4 esp=03debae0 ebp=03debb34 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 740f0000 74129000 C:\Windows\system32\MMDevAPI.DLL
<---- EVENT: break ld ---->
eax=04f46000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffac000 edi=07a9f5b4
eip=771d70f4 esp=07a9f4cc ebp=07a9f520 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 72880000 7288b000 C:\Windows\system32\msimtf.dll
<---- EVENT: break ld ---->
eax=075be000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03de9ad8
eip=771d70f4 esp=03de99f0 ebp=03de9a44 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6d500000 6d5b2000 C:\Windows\System32\jscript.dll
<---- EVENT: break ld ---->
eax=07b10000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03dec4f8
eip=771d70f4 esp=03dec410 ebp=03dec464 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e610000 6e743000 C:\Windows\System32\msxml3.dll
<---- EVENT: break ld ---->
eax=07d0f000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffda000 edi=03deb438
eip=771d70f4 esp=03deb350 ebp=03deb3a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 71400000 714ac000 C:\Program Files\Classic Shell\ClassicExplorer32.dll
<---- EVENT: break ld ---->
eax=0466a000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaa000 edi=0965c488
eip=771d70f4 esp=0965c3a0 ebp=0965c3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 73660000 73671000 C:\Windows\system32\NETAPI32.dll
<---- EVENT: break ld ---->
eax=0920f000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaa000 edi=0965c15c
eip=771d70f4 esp=0965c074 ebp=0965c0c8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 74ef0000 74f09000 C:\Windows\system32\srvcli.dll
<---- EVENT: break ld ---->
eax=09215000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaa000 edi=0965bdbc
eip=771d70f4 esp=0965bcd4 ebp=0965bd28 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 755a0000 755cf000 C:\Windows\system32\WINTRUST.dll
<---- EVENT: break ld ---->
eax=09241000 ebx=00000000 ecx=00151000 edx=00000000 esi=7ffaa000 edi=0965c15c
eip=771d70f4 esp=0965c074 ebp=0965c0c8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
ModLoad: 6e610000 6e743000 C:\Windows\System32\msxml3.dll
<---- EVENT: break ld ---->
eax=09338000 ebx=00000000 ecx=012a1000 edx=00000000 esi=7ffde000 edi=0029d2b8
eip=771d70f4 esp=0029d1d0 ebp=0029d224 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771d70f4 c3 ret
(e30.cd4): Access violation - code c0000005 (first chance)
(e30.cd4): Access violation - code c0000005 (!!! second chance !!!)