Microsoft (R) Windows Debugger Version 6.2.8229.0 X86
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: "C:\Program Files\Internet Explorer\iexplore.exe" http://A2-W7-IE8-3:32768/Ping-WithSomethingToMakeItASemiUniqueStringThatCanBeDifferentiatedFromOtherRequests
Symbol search path is: srv*\\server\Symbols*http://msdl.microsoft.com/download/symbols;srv*\\server\Symbols*http://symbols.mozilla.org/firefox;srv*\\server\Symbols*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 003d0000 00476000 iexplore.exe
ModLoad: 77130000 7726c000 ntdll.dll
ModLoad: 6e080000 6e0e0000 C:\Windows\system32\verifier.dll
Page heap: pid 0xB2C: page heap enabled with flags 0x3.
ModLoad: 76d70000 76e44000 C:\Windows\system32\kernel32.dll
ModLoad: 75410000 7545b000 C:\Windows\system32\KERNELBASE.dll
ModLoad: 77090000 77130000 C:\Windows\system32\ADVAPI32.dll
ModLoad: 75bb0000 75c5c000 C:\Windows\system32\msvcrt.dll
ModLoad: 76080000 76099000 C:\Windows\SYSTEM32\sechost.dll
ModLoad: 75820000 758c2000 C:\Windows\system32\RPCRT4.dll
ModLoad: 75fb0000 76079000 C:\Windows\system32\USER32.dll
ModLoad: 76d20000 76d6e000 C:\Windows\system32\GDI32.dll
ModLoad: 77270000 7727a000 C:\Windows\system32\LPK.dll
ModLoad: 76e50000 76eed000 C:\Windows\system32\USP10.dll
ModLoad: 75dc0000 75e17000 C:\Windows\system32\SHLWAPI.dll
ModLoad: 760a0000 76cea000 C:\Windows\system32\SHELL32.dll
ModLoad: 75c60000 75dbc000 C:\Windows\system32\ole32.dll
ModLoad: 75950000 75b51000 C:\Windows\system32\iertutil.dll
ModLoad: 75680000 757c0000 C:\Windows\system32\urlmon.dll
ModLoad: 75460000 7548f000 C:\Windows\system32\XmlLite.dll
ModLoad: 75e20000 75f15000 C:\Windows\system32\WININET.dll
ModLoad: 75f20000 75faf000 C:\Windows\system32\OLEAUT32.dll
ModLoad: 752b0000 753d1000 C:\Windows\system32\CRYPT32.dll
ModLoad: 752a0000 752ac000 C:\Windows\system32\MSASN1.dll
(b2c.f3c): Break instruction exception - code 80000003 (first chance)
eax=00000000 ebx=00000000 ecx=001ef93c edx=771770f4 esi=fffffffe edi=00000000
eip=771d05a6 esp=001ef958 ebp=001ef984 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!LdrpDoDebuggerBreak+0x2c:
771d05a6 cc int 3
ModLoad: 75930000 7594f000 C:\Windows\system32\IMM32.DLL
<---- EVENT: break ld ---->
eax=01a86000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eeeb8
eip=771770f4 esp=001eedd0 ebp=001eee24 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77290000 7735c000 C:\Windows\system32\MSCTF.dll
<---- EVENT: break ld ---->
eax=01a94000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eeb18
eip=771770f4 esp=001eea30 ebp=001eea84 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75180000 7518c000 C:\Windows\system32\CRYPTBASE.DLL
<---- EVENT: break ld ---->
eax=03043000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef99c
eip=771770f4 esp=001ef8b4 ebp=001ef908 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e650000 6f0d6000 C:\Windows\system32\IEFRAME.dll
<---- EVENT: break ld ---->
eax=039f0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef930
eip=771770f4 esp=001ef848 ebp=001ef89c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75810000 75815000 C:\Windows\system32\PSAPI.DLL
<---- EVENT: break ld ---->
eax=039f6000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef590
eip=771770f4 esp=001ef4a8 ebp=001ef4fc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 71c80000 71cbc000 C:\Windows\system32\OLEACC.dll
<---- EVENT: break ld ---->
eax=03a10000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef590
eip=771770f4 esp=001ef4a8 ebp=001ef4fc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74180000 7431e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
eax=03aa6000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef218
eip=771770f4 esp=001ef130 ebp=001ef184 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75100000 7511b000 C:\Windows\system32\SspiCli.dll
<---- EVENT: break ld ---->
eax=03b44000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee58c
eip=771770f4 esp=001ee4a4 ebp=001ee4f8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75230000 7523b000 C:\Windows\system32\profapi.dll
<---- EVENT: break ld ---->
eax=03c6c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eb750
eip=771770f4 esp=001eb668 ebp=001eb6bc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 746f0000 74711000 C:\Windows\system32\ntmarta.dll
<---- EVENT: break ld ---->
eax=03c4c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee5a4
eip=771770f4 esp=001ee4bc ebp=001ee510 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75b60000 75ba5000 C:\Windows\system32\WLDAP32.dll
<---- EVENT: break ld ---->
eax=03c5a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee204
eip=771770f4 esp=001ee11c ebp=001ee170 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 757c0000 757f5000 C:\Windows\system32\ws2_32.DLL
<---- EVENT: break ld ---->
eax=03c64000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee498
eip=771770f4 esp=001ee3b0 ebp=001ee404 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77280000 77286000 C:\Windows\system32\NSI.dll
<---- EVENT: break ld ---->
eax=03dea000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee0f8
eip=771770f4 esp=001ee010 ebp=001ee064 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74b20000 74b64000 C:\Windows\system32\dnsapi.DLL
<---- EVENT: break ld ---->
eax=03e24000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee630
eip=771770f4 esp=001ee548 ebp=001ee59c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73540000 7355c000 C:\Windows\system32\iphlpapi.DLL
<---- EVENT: break ld ---->
eax=04342000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee630
eip=771770f4 esp=001ee548 ebp=001ee59c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73530000 73537000 C:\Windows\system32\WINNSI.DLL
<---- EVENT: break ld ---->
eax=0434c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee290
eip=771770f4 esp=001ee1a8 ebp=001ee1fc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 755f0000 75673000 C:\Windows\system32\CLBCatQ.DLL
<---- EVENT: break ld ---->
eax=043cb000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f310
eip=771770f4 esp=0465f228 ebp=0465f27c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72d40000 72d9a000 C:\Windows\System32\netprofm.dll
<---- EVENT: break ld ---->
eax=04406000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e548
eip=771770f4 esp=0465e460 ebp=0465e4b4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 739b0000 739c0000 C:\Windows\System32\nlaapi.dll
<---- EVENT: break ld ---->
eax=0441a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e1a8
eip=771770f4 esp=0465e0c0 ebp=0465e114 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74ca0000 74cb7000 C:\Windows\system32\CRYPTSP.dll
<---- EVENT: break ld ---->
eax=04961000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e71c
eip=771770f4 esp=0465e634 ebp=0465e688 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74a40000 74a7b000 C:\Windows\system32\rsaenh.dll
<---- EVENT: break ld ---->
eax=03d5c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e654
eip=771770f4 esp=0465e56c ebp=0465e5c0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75220000 7522e000 C:\Windows\system32\RpcRtRemote.dll
<---- EVENT: break ld ---->
eax=049a5000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e44c
eip=771770f4 esp=0465e364 ebp=0465e3b8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72d20000 72d28000 C:\Windows\System32\npmproxy.dll
<---- EVENT: break ld ---->
eax=04f38000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465e628
eip=771770f4 esp=0465e540 ebp=0465e594 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74720000 74729000 C:\Windows\system32\VERSION.dll
<---- EVENT: break ld ---->
eax=04f94000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef364
eip=771770f4 esp=001ef27c ebp=001ef2d0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74c60000 74c9c000 C:\Windows\system32\mswsock.dll
<---- EVENT: break ld ---->
eax=04fbd000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465efa8
eip=771770f4 esp=0465eec0 ebp=0465ef14 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75570000 755eb000 C:\Windows\system32\comdlg32.dll
<---- EVENT: break ld ---->
eax=04fa4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef964
eip=771770f4 esp=001ef87c ebp=001ef8d0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 747b0000 747b5000 C:\Windows\System32\wshtcpip.dll
<---- EVENT: break ld ---->
eax=0469c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f1e4
eip=771770f4 esp=0465f0fc ebp=0465f150 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74c50000 74c56000 C:\Windows\System32\wship6.dll
<---- EVENT: break ld ---->
eax=046ff000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f208
eip=771770f4 esp=0465f120 ebp=0465f174 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70360000 70393000 C:\Program Files\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
eax=0442e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef6fc
eip=771770f4 esp=001ef614 ebp=001ef668 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70fb0000 70fb6000 C:\Windows\system32\rasadhlp.dll
<---- EVENT: break ld ---->
eax=03c96000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465eb80
eip=771770f4 esp=0465ea98 ebp=0465eaec iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 71f80000 71fb8000 C:\Windows\System32\fwpuclnt.dll
<---- EVENT: break ld ---->
eax=01be9000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465ebf8
eip=771770f4 esp=0465eb10 ebp=0465eb64 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75130000 7517c000 C:\Windows\system32\apphelp.dll
<---- EVENT: break ld ---->
eax=04f0b000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ea038
eip=771770f4 esp=001e9f50 ebp=001e9fa4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73610000 7361f000 C:\Windows\system32\wkscli.dll
<---- EVENT: break ld ---->
eax=05811000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ebbac
eip=771770f4 esp=001ebac4 ebp=001ebb18 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73620000 73629000 C:\Windows\system32\netutils.dll
<---- EVENT: break ld ---->
eax=05856000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ebbb4
eip=771770f4 esp=001ebacc ebp=001ebb20 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 739b0000 739c0000 C:\Windows\system32\NLAapi.dll
<---- EVENT: break ld ---->
eax=05778000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eb7ec
eip=771770f4 esp=001eb704 ebp=001eb758 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e450000 6e4a2000 C:\Windows\system32\RASAPI32.dll
<---- EVENT: break ld ---->
eax=0575e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f610
eip=771770f4 esp=0465f528 ebp=0465f57c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6fc30000 6fc45000 C:\Windows\system32\rasman.dll
<---- EVENT: break ld ---->
eax=058e3000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f270
eip=771770f4 esp=0465f188 ebp=0465f1dc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 725b0000 725bd000 C:\Windows\system32\rtutils.dll
<---- EVENT: break ld ---->
eax=05768000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdd000 edi=0465f5b0
eip=771770f4 esp=0465f4c8 ebp=0465f51c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70390000 70396000 C:\Windows\system32\sensapi.dll
<---- EVENT: break ld ---->
eax=0588a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ec1a0
eip=771770f4 esp=001ec0b8 ebp=001ec10c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 711c0000 711d0000 C:\Windows\system32\napinsp.dll
<---- EVENT: break ld ---->
eax=057a4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd3000 edi=0623ee90
eip=771770f4 esp=0623eda8 ebp=0623edfc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70ee0000 70ef2000 C:\Windows\system32\pnrpnsp.dll
<---- EVENT: break ld ---->
eax=046cc000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd3000 edi=0623ee90
eip=771770f4 esp=0623eda8 ebp=0623edfc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70dc0000 70dc8000 C:\Windows\System32\winrnr.dll
<---- EVENT: break ld ---->
eax=0503a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd3000 edi=0623ee90
eip=771770f4 esp=0623eda8 ebp=0623edfc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
Symbol search path is: srv*\\server\Symbols*http://msdl.microsoft.com/download/symbols;srv*\\server\Symbols*http://symbols.mozilla.org/firefox;srv*\\server\Symbols*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 003d0000 00476000 iexplore.exe
<---- EVENT: break cpr ---->
eax=003d1b0a ebx=7ffdb000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=771770d8 esp=001efce4 ebp=00000000 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000200
771770d8 89442404 mov dword ptr [esp+4],eax ss:0023:001efce8=00000000
ModLoad: 77130000 7726c000 ntdll.dll
<---- EVENT: break ld ---->
eax=003d1b0a ebx=7ffdb000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=771770d8 esp=001efce4 ebp=00000000 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000200
ntdll!RtlUserThreadStart:
771770d8 89442404 mov dword ptr [esp+4],eax ss:0023:001efce8=00000000
ModLoad: 6e080000 6e0e0000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
eax=001ef52c ebx=7720ec40 ecx=771cdf1c edx=00000003 esi=7ffdf000 edi=00000000
eip=771770f4 esp=001ef390 ebp=001ef748 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
Page heap: pid 0x9E4: page heap enabled with flags 0x3.
ModLoad: 76d70000 76e44000 C:\Windows\system32\kernel32.dll
<---- EVENT: break ld ---->
eax=00209000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef67c
eip=771770f4 esp=001ef594 ebp=001ef5e8 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75410000 7545b000 C:\Windows\system32\KERNELBASE.dll
<---- EVENT: break ld ---->
eax=0020f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef2dc
eip=771770f4 esp=001ef1f4 ebp=001ef248 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77090000 77130000 C:\Windows\system32\ADVAPI32.dll
<---- EVENT: break ld ---->
eax=0023f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75bb0000 75c5c000 C:\Windows\system32\msvcrt.dll
<---- EVENT: break ld ---->
eax=00243000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef15c
eip=771770f4 esp=001ef074 ebp=001ef0c8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 76080000 76099000 C:\Windows\SYSTEM32\sechost.dll
<---- EVENT: break ld ---->
eax=00255000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef15c
eip=771770f4 esp=001ef074 ebp=001ef0c8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70360000 7038d000 C:\Windows\system32\IEUI.dll
<---- EVENT: break ld ---->
eax=0687c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001edfc0
eip=771770f4 esp=001eded8 ebp=001edf2c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70330000 70335000 C:\Windows\system32\MSIMG32.dll
<---- EVENT: break ld ---->
eax=0688a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001edc20
eip=771770f4 esp=001edb38 ebp=001edb8c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75820000 758c2000 C:\Windows\system32\RPCRT4.dll
<---- EVENT: break ld ---->
eax=00265000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eedbc
eip=771770f4 esp=001eecd4 ebp=001eed28 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75fb0000 76079000 C:\Windows\system32\USER32.dll
<---- EVENT: break ld ---->
eax=00285000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 76d20000 76d6e000 C:\Windows\system32\GDI32.dll
<---- EVENT: break ld ---->
eax=0028b000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e8
eip=771770f4 esp=001ef000 ebp=001ef054 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77270000 7727a000 C:\Windows\system32\LPK.dll
<---- EVENT: break ld ---->
eax=00297000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eed48
eip=771770f4 esp=001eec60 ebp=001eecb4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 76e50000 76eed000 C:\Windows\system32\USP10.dll
<---- EVENT: break ld ---->
eax=002a5000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eea1c
eip=771770f4 esp=001ee934 ebp=001ee988 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75dc0000 75e17000 C:\Windows\system32\SHLWAPI.dll
<---- EVENT: break ld ---->
eax=002bf000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 760a0000 76cea000 C:\Windows\system32\SHELL32.dll
<---- EVENT: break ld ---->
eax=002d1000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75c60000 75dbc000 C:\Windows\system32\ole32.dll
<---- EVENT: break ld ---->
eax=01770000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75950000 75b51000 C:\Windows\system32\iertutil.dll
<---- EVENT: break ld ---->
eax=0178a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72220000 7224b000 C:\Program Files\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
eax=05846000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffae000 edi=0702ee6c
eip=771770f4 esp=0702ed84 ebp=0702edd8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75680000 757c0000 C:\Windows\system32\urlmon.dll
<---- EVENT: break ld ---->
eax=0179a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef488
eip=771770f4 esp=001ef3a0 ebp=001ef3f4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75460000 7548f000 C:\Windows\system32\XmlLite.dll
<---- EVENT: break ld ---->
eax=0179e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e8
eip=771770f4 esp=001ef000 ebp=001ef054 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75e20000 75f15000 C:\Windows\system32\WININET.dll
<---- EVENT: break ld ---->
eax=017aa000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e8
eip=771770f4 esp=001ef000 ebp=001ef054 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75f20000 75faf000 C:\Windows\system32\OLEAUT32.dll
<---- EVENT: break ld ---->
eax=017c2000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e8
eip=771770f4 esp=001ef000 ebp=001ef054 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 752b0000 753d1000 C:\Windows\system32\CRYPT32.dll
<---- EVENT: break ld ---->
eax=017e8000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e8
eip=771770f4 esp=001ef000 ebp=001ef054 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 752a0000 752ac000 C:\Windows\system32\MSASN1.dll
<---- EVENT: break ld ---->
eax=017fa000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eed48
eip=771770f4 esp=001eec60 ebp=001eecb4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75930000 7594f000 C:\Windows\system32\IMM32.DLL
<---- EVENT: break ld ---->
eax=01970000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001eed78
eip=771770f4 esp=001eec90 ebp=001eece4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77290000 7735c000 C:\Windows\system32\MSCTF.dll
<---- EVENT: break ld ---->
eax=0197e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee9d8
eip=771770f4 esp=001ee8f0 ebp=001ee944 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73df0000 73e30000 C:\Windows\system32\UxTheme.dll
<---- EVENT: break ld ---->
eax=06e04000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001edb60
eip=771770f4 esp=001eda78 ebp=001edacc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75180000 7518c000 C:\Windows\system32\CRYPTBASE.DLL
<---- EVENT: break ld ---->
eax=02fcd000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef85c
eip=771770f4 esp=001ef774 ebp=001ef7c8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e650000 6f0d6000 C:\Windows\system32\IEFRAME.dll
<---- EVENT: break ld ---->
eax=03009000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef7f8
eip=771770f4 esp=001ef710 ebp=001ef764 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75810000 75815000 C:\Windows\system32\PSAPI.DLL
<---- EVENT: break ld ---->
eax=03df0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef458
eip=771770f4 esp=001ef370 ebp=001ef3c4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 71c80000 71cbc000 C:\Windows\system32\OLEACC.dll
<---- EVENT: break ld ---->
eax=03e0a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef458
eip=771770f4 esp=001ef370 ebp=001ef3c4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74180000 7431e000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
eax=03ea0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef0e0
eip=771770f4 esp=001eeff8 ebp=001ef04c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75570000 755eb000 C:\Windows\system32\comdlg32.dll
<---- EVENT: break ld ---->
eax=03ee4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef80c
eip=771770f4 esp=001ef724 ebp=001ef778 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e610000 6e645000 C:\Program Files\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
eax=03f5e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef798
eip=771770f4 esp=001ef6b0 ebp=001ef704 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75220000 7522e000 C:\Windows\system32\RpcRtRemote.dll
<---- EVENT: break ld ---->
eax=04213000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef330
eip=771770f4 esp=001ef248 ebp=001ef29c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6dae0000 6db13000 C:\Program Files\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
eax=03f9e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ef5a0
eip=771770f4 esp=001ef4b8 ebp=001ef50c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 755f0000 75673000 C:\Windows\system32\CLBCatQ.DLL
<---- EVENT: break ld ---->
eax=04356000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee1ac
eip=771770f4 esp=001ee0c4 ebp=001ee118 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73f50000 74045000 C:\Windows\system32\propsys.dll
<---- EVENT: break ld ---->
eax=0462f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed3e8
eip=771770f4 esp=001ed300 ebp=001ed354 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 76ef0000 7708d000 C:\Windows\system32\SETUPAPI.dll
<---- EVENT: break ld ---->
eax=0466b000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd8000 edi=04e8f710
eip=771770f4 esp=04e8f628 ebp=04e8f67c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75490000 754b7000 C:\Windows\system32\CFGMGR32.dll
<---- EVENT: break ld ---->
eax=04671000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd8000 edi=04e8f370
eip=771770f4 esp=04e8f288 ebp=04e8f2dc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75550000 75562000 C:\Windows\system32\DEVOBJ.dll
<---- EVENT: break ld ---->
eax=0468f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd8000 edi=04e8f370
eip=771770f4 esp=04e8f288 ebp=04e8f2dc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75230000 7523b000 C:\Windows\system32\profapi.dll
<---- EVENT: break ld ---->
eax=04cb0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed0f8
eip=771770f4 esp=001ed010 ebp=001ed064 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 76ef0000 7708d000 C:\Windows\system32\SETUPAPI.dll
<---- EVENT: break ld ---->
eax=082b2000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd4000 edi=0612f938
eip=771770f4 esp=0612f850 ebp=0612f8a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75490000 754b7000 C:\Windows\system32\CFGMGR32.dll
<---- EVENT: break ld ---->
eax=087c2000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd4000 edi=0612f598
eip=771770f4 esp=0612f4b0 ebp=0612f504 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75550000 75562000 C:\Windows\system32\DEVOBJ.dll
<---- EVENT: break ld ---->
eax=087e0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd4000 edi=0612f598
eip=771770f4 esp=0612f4b0 ebp=0612f504 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73f50000 74045000 C:\Windows\system32\propsys.dll
<---- EVENT: break ld ---->
eax=08858000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffad000 edi=071ccf48
eip=771770f4 esp=071cce60 ebp=071cceb4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 71550000 716bf000 C:\Windows\system32\explorerframe.dll
<---- EVENT: break ld ---->
eax=0920c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed618
eip=771770f4 esp=001ed530 ebp=001ed584 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 739f0000 73a1f000 C:\Windows\system32\DUser.dll
<---- EVENT: break ld ---->
eax=0927e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed278
eip=771770f4 esp=001ed190 ebp=001ed1e4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73a20000 73ad2000 C:\Windows\system32\DUI70.dll
<---- EVENT: break ld ---->
eax=093e0000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed278
eip=771770f4 esp=001ed190 ebp=001ed1e4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75100000 7511b000 C:\Windows\system32\SspiCli.dll
<---- EVENT: break ld ---->
eax=04685000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049ff438
eip=771770f4 esp=049ff350 ebp=049ff3a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74ca0000 74cb7000 C:\Windows\system32\CRYPTSP.dll
<---- EVENT: break ld ---->
eax=055f6000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5f4b4
eip=771770f4 esp=04c5f3cc ebp=04c5f420 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6d4b0000 6d54c000 C:\Windows\system32\msfeeds.dll
<---- EVENT: break ld ---->
eax=095da000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ee0cc
eip=771770f4 esp=001edfe4 ebp=001ee038 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74a40000 74a7b000 C:\Windows\system32\rsaenh.dll
<---- EVENT: break ld ---->
eax=052cb000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5f3ec
eip=771770f4 esp=04c5f304 ebp=04c5f358 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 757c0000 757f5000 C:\Windows\system32\ws2_32.DLL
<---- EVENT: break ld ---->
eax=056fc000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049ff344
eip=771770f4 esp=049ff25c ebp=049ff2b0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 77280000 77286000 C:\Windows\system32\NSI.dll
<---- EVENT: break ld ---->
eax=0570a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049fefa4
eip=771770f4 esp=049feebc ebp=049fef10 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74b20000 74b64000 C:\Windows\system32\dnsapi.DLL
<---- EVENT: break ld ---->
eax=05765000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049ff4dc
eip=771770f4 esp=049ff3f4 ebp=049ff448 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73540000 7355c000 C:\Windows\system32\iphlpapi.DLL
<---- EVENT: break ld ---->
eax=05793000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049ff4dc
eip=771770f4 esp=049ff3f4 ebp=049ff448 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73530000 73537000 C:\Windows\system32\WINNSI.DLL
<---- EVENT: break ld ---->
eax=0579d000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffda000 edi=049ff13c
eip=771770f4 esp=049ff054 ebp=049ff0a8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72150000 7217e000 C:\Windows\system32\MLANG.dll
<---- EVENT: break ld ---->
eax=09af2000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001e9510
eip=771770f4 esp=001e9428 ebp=001e947c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72220000 7224b000 C:\Program Files\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
eax=046c5000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5f190
eip=771770f4 esp=04c5f0a8 ebp=04c5f0fc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75800000 75803000 C:\Windows\system32\Normaliz.dll
<---- EVENT: break ld ---->
eax=09b44000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ea06c
eip=771770f4 esp=001e9f84 ebp=001e9fd8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75130000 7517c000 C:\Windows\system32\apphelp.dll
<---- EVENT: break ld ---->
eax=05bca000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5aedc
eip=771770f4 esp=04c5adf4 ebp=04c5ae48 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e450000 6e4a2000 C:\Windows\system32\RASAPI32.dll
<---- EVENT: break ld ---->
eax=05e54000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5cf34
eip=771770f4 esp=04c5ce4c ebp=04c5cea0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6fc30000 6fc45000 C:\Windows\system32\rasman.dll
<---- EVENT: break ld ---->
eax=05e64000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5cb94
eip=771770f4 esp=04c5caac ebp=04c5cb00 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 725b0000 725bd000 C:\Windows\system32\rtutils.dll
<---- EVENT: break ld ---->
eax=0427f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5ced0
eip=771770f4 esp=04c5cde8 ebp=04c5ce3c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70390000 70396000 C:\Windows\system32\sensapi.dll
<---- EVENT: break ld ---->
eax=0559f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5d000
eip=771770f4 esp=04c5cf18 ebp=04c5cf6c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74c60000 74c9c000 C:\Windows\system32\mswsock.dll
<---- EVENT: break ld ---->
eax=05f66000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd3000 edi=062bf11c
eip=771770f4 esp=062bf034 ebp=062bf088 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 747b0000 747b5000 C:\Windows\System32\wshtcpip.dll
<---- EVENT: break ld ---->
eax=05f9a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd3000 edi=062bf358
eip=771770f4 esp=062bf270 ebp=062bf2c4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75800000 75803000 C:\Windows\system32\Normaliz.dll
<---- EVENT: break ld ---->
eax=05fa6000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5d1e8
eip=771770f4 esp=04c5d100 ebp=04c5d154 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 739b0000 739c0000 C:\Windows\system32\NLAapi.dll
<---- EVENT: break ld ---->
eax=05f98000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c610
eip=771770f4 esp=04c5c528 ebp=04c5c57c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70fb0000 70fb6000 C:\Windows\system32\rasadhlp.dll
<---- EVENT: break ld ---->
eax=0536b000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c360
eip=771770f4 esp=04c5c278 ebp=04c5c2cc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73610000 7361f000 C:\Windows\system32\wkscli.dll
<---- EVENT: break ld ---->
eax=0643c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c320
eip=771770f4 esp=04c5c238 ebp=04c5c28c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 711c0000 711d0000 C:\Windows\system32\napinsp.dll
<---- EVENT: break ld ---->
eax=06008000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaf000 edi=0693ea7c
eip=771770f4 esp=0693e994 ebp=0693e9e8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73620000 73629000 C:\Windows\system32\netutils.dll
<---- EVENT: break ld ---->
eax=0602e000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c328
eip=771770f4 esp=04c5c240 ebp=04c5c294 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70ee0000 70ef2000 C:\Windows\system32\pnrpnsp.dll
<---- EVENT: break ld ---->
eax=04336000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaf000 edi=0693ea7c
eip=771770f4 esp=0693e994 ebp=0693e9e8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 70dc0000 70dc8000 C:\Windows\System32\winrnr.dll
<---- EVENT: break ld ---->
eax=069bf000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaf000 edi=0693ea7c
eip=771770f4 esp=0693e994 ebp=0693e9e8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74c50000 74c56000 C:\Windows\System32\wship6.dll
<---- EVENT: break ld ---->
eax=069cd000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaf000 edi=0693ead8
eip=771770f4 esp=0693e9f0 ebp=0693ea44 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 71f80000 71fb8000 C:\Windows\System32\fwpuclnt.dll
<---- EVENT: break ld ---->
eax=05e4c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaf000 edi=0693e4c8
eip=771770f4 esp=0693e3e0 ebp=0693e434 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 72150000 7217e000 C:\Windows\system32\MLANG.dll
<---- EVENT: break ld ---->
eax=06002000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c798
eip=771770f4 esp=04c5c6b0 ebp=04c5c704 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 746f0000 74711000 C:\Windows\system32\ntmarta.dll
<---- EVENT: break ld ---->
eax=06454000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c76c
eip=771770f4 esp=04c5c684 ebp=04c5c6d8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75b60000 75ba5000 C:\Windows\system32\WLDAP32.dll
<---- EVENT: break ld ---->
eax=041cd000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c3cc
eip=771770f4 esp=04c5c2e4 ebp=04c5c338 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74720000 74729000 C:\Windows\system32\VERSION.dll
<---- EVENT: break ld ---->
eax=04d20000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c514
eip=771770f4 esp=04c5c42c ebp=04c5c480 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73df0000 73e30000 C:\Windows\system32\UxTheme.dll
<---- EVENT: break ld ---->
eax=069bd000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c90c
eip=771770f4 esp=04c5c824 ebp=04c5c878 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 712e0000 7138c000 C:\Program Files\Classic Shell\ClassicExplorer32.dll
<---- EVENT: break ld ---->
eax=071f5000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c348
eip=771770f4 esp=04c5c260 ebp=04c5c2b4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73920000 73933000 C:\Windows\system32\dwmapi.dll
<---- EVENT: break ld ---->
eax=07205000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c01c
eip=771770f4 esp=04c5bf34 ebp=04c5bf88 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 716c0000 716f2000 C:\Windows\system32\WINMM.dll
<---- EVENT: break ld ---->
eax=07215000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c01c
eip=771770f4 esp=04c5bf34 ebp=04c5bf88 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73630000 73641000 C:\Windows\system32\NETAPI32.dll
<---- EVENT: break ld ---->
eax=07223000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c01c
eip=771770f4 esp=04c5bf34 ebp=04c5bf88 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74e40000 74e59000 C:\Windows\system32\srvcli.dll
<---- EVENT: break ld ---->
eax=05ecc000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5bc7c
eip=771770f4 esp=04c5bb94 ebp=04c5bbe8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 753e0000 7540f000 C:\Windows\system32\WINTRUST.dll
<---- EVENT: break ld ---->
eax=07259000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c01c
eip=771770f4 esp=04c5bf34 ebp=04c5bf88 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73920000 73933000 C:\Windows\system32\DWMAPI.DLL
<---- EVENT: break ld ---->
eax=06438000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5cecc
eip=771770f4 esp=04c5cde4 ebp=04c5ce38 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75190000 751ef000 C:\Windows\system32\SXS.DLL
<---- EVENT: break ld ---->
eax=09890000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdc000 edi=04bde508
eip=771770f4 esp=04bde420 ebp=04bde474 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 75190000 751ef000 C:\Windows\system32\SXS.DLL
<---- EVENT: break ld ---->
eax=07c76000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c080
eip=771770f4 esp=04c5bf98 ebp=04c5bfec iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6f770000 6f8a3000 C:\Windows\System32\msxml3.dll
<---- EVENT: break ld ---->
eax=0a0b4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffdf000 edi=001ed208
eip=771770f4 esp=001ed120 ebp=001ed174 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6b060000 6b623000 C:\Windows\System32\mshtml.dll
<---- EVENT: break ld ---->
eax=0554a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5bd60
eip=771770f4 esp=04c5bc78 ebp=04c5bccc iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6e050000 6e07a000 C:\Windows\System32\msls31.dll
<---- EVENT: break ld ---->
eax=07d74000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5b9c0
eip=771770f4 esp=04c5b8d8 ebp=04c5b92c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6d440000 6d4af000 C:\Windows\System32\ieapfltr.dll
<---- EVENT: break ld ---->
eax=0825a000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5bbe8
eip=771770f4 esp=04c5bb00 ebp=04c5bb54 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74f00000 74f08000 C:\Windows\System32\Secur32.dll
<---- EVENT: break ld ---->
eax=08274000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5b848
eip=771770f4 esp=04c5b760 ebp=04c5b7b4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 716c0000 716f2000 C:\Windows\system32\WINMM.dll
<---- EVENT: break ld ---->
eax=085d3000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5b80c
eip=771770f4 esp=04c5b724 ebp=04c5b778 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74050000 74089000 C:\Windows\system32\MMDevAPI.DLL
<---- EVENT: break ld ---->
eax=05fce000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffab000 edi=08a7f394
eip=771770f4 esp=08a7f2ac ebp=08a7f300 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6faf0000 6fafb000 C:\Windows\system32\msimtf.dll
<---- EVENT: break ld ---->
eax=0867d000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c59718
eip=771770f4 esp=04c59630 ebp=04c59684 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6d380000 6d432000 C:\Windows\System32\jscript.dll
<---- EVENT: break ld ---->
eax=08b0c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5c138
eip=771770f4 esp=04c5c050 ebp=04c5c0a4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 6f770000 6f8a3000 C:\Windows\System32\msxml3.dll
<---- EVENT: break ld ---->
eax=08d08000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd9000 edi=04c5b078
eip=771770f4 esp=04c5af90 ebp=04c5afe4 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 712e0000 7138c000 C:\Program Files\Classic Shell\ClassicExplorer32.dll
<---- EVENT: break ld ---->
eax=09b9c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffa9000 edi=0a65c018
eip=771770f4 esp=0a65bf30 ebp=0a65bf84 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 73630000 73641000 C:\Windows\system32\NETAPI32.dll
<---- EVENT: break ld ---->
eax=0a2c2000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffa9000 edi=0a65bcec
eip=771770f4 esp=0a65bc04 ebp=0a65bc58 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74e40000 74e59000 C:\Windows\system32\srvcli.dll
<---- EVENT: break ld ---->
eax=0a2c8000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffa9000 edi=0a65b94c
eip=771770f4 esp=0a65b864 ebp=0a65b8b8 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 753e0000 7540f000 C:\Windows\system32\WINTRUST.dll
<---- EVENT: break ld ---->
eax=0a2f4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffa9000 edi=0a65bcec
eip=771770f4 esp=0a65bc04 ebp=0a65bc58 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74880000 74897000 C:\Windows\system32\USERENV.dll
<---- EVENT: break ld ---->
eax=0afe9000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2a364
eip=771770f4 esp=08f2a27c ebp=08f2a2d0 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 753e0000 7540f000 C:\Windows\system32\wintrust.dll
<---- EVENT: break ld ---->
eax=0a770000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2aac0
eip=771770f4 esp=08f2a9d8 ebp=08f2aa2c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74ab0000 74aef000 C:\Windows\system32\schannel.DLL
<---- EVENT: break ld ---->
eax=0af87000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2aad4
eip=771770f4 esp=08f2a9ec ebp=08f2aa40 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74970000 74978000 C:\Windows\system32\credssp.dll
<---- EVENT: break ld ---->
eax=0bde4000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2a6c0
eip=771770f4 esp=08f2a5d8 ebp=08f2a62c iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74dd0000 74e08000 C:\Windows\system32\ncrypt.dll
<---- EVENT: break ld ---->
eax=0bc7f000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd8000 edi=04e8a9b4
eip=771770f4 esp=04e8a8cc ebp=04e8a920 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74db0000 74dc7000 C:\Windows\system32\bcrypt.dll
<---- EVENT: break ld ---->
eax=0bc83000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffd8000 edi=04e8a614
eip=771770f4 esp=04e8a52c ebp=04e8a580 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74980000 749bd000 C:\Windows\system32\bcryptprimitives.dll
<---- EVENT: break ld ---->
eax=0bf64000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2a308
eip=771770f4 esp=08f2a220 ebp=08f2a274 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
ModLoad: 74860000 74876000 C:\Windows\system32\GPAPI.dll
<---- EVENT: break ld ---->
eax=0d8a8000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2a0fc
eip=771770f4 esp=08f2a014 ebp=08f2a068 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
(9e4.6dc): Unknown exception - code 0000071a (first chance)
ModLoad: 71200000 7121c000 C:\Windows\system32\cryptnet.dll
<---- EVENT: break ld ---->
eax=0dd5c000 ebx=00000000 ecx=001f1000 edx=00000000 esi=7ffaa000 edi=08f2a104
eip=771770f4 esp=08f2a01c ebp=08f2a070 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:
771770f4 c3 ret
(9e4.f6c): Access violation - code c0000005 (first chance)
(9e4.f6c): Access violation - code c0000005 (!!! second chance !!!)