Microsoft (R) Windows Debugger Version 6.2.8229.0 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
CommandLine: "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Symbol search path is: srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`01360000 00000000`01418000 iexplore.exe
ModLoad: 00000000`773c0000 00000000`77569000 ntdll.dll
ModLoad: 00000000`775a0000 00000000`77720000 ntdll32.dll
ModLoad: 00000000`00080000 00000000`000ee000 C:\Windows\system32\verifier.dll
Page heap: pid 0xB38: page heap enabled with flags 0x3.
ModLoad: 00000000`74c90000 00000000`74ccf000 C:\Windows\SYSTEM32\wow64.dll
ModLoad: 00000000`74c30000 00000000`74c8c000 C:\Windows\SYSTEM32\wow64win.dll
ModLoad: 00000000`74c20000 00000000`74c28000 C:\Windows\SYSTEM32\wow64cpu.dll
(b38.4f0): Break instruction exception - code 80000003 (first chance)
ntdll!LdrpDoDebuggerBreak+0x30:
00000000`7746cb60 cc int 3
ModLoad: 00000000`76f90000 00000000`770af000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75520000 00000000`75630000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76f90000 00000000`770af000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`772c0000 00000000`773ba000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73480000 00000000`734e0000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Page heap: pid 0xB38: page heap enabled with flags 0x3.
ModLoad: 00000000`75520000 00000000`75630000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ee0000 00000000`74f27000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76850000 00000000`768f0000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75240000 00000000`752ec000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a20000 00000000`76a39000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75630000 00000000`75720000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748c0000 00000000`74920000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748b0000 00000000`748bc000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76b60000 00000000`76c60000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76990000 00000000`76a20000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`77570000 00000000`7757a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75420000 00000000`754bd000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`754c0000 00000000`75517000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75890000 00000000`764da000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74f30000 00000000`7508c000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a40000 00000000`76b51000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76900000 00000000`7698f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`765a0000 00000000`76758000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74d10000 00000000`74e2b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75880000 00000000`75883000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
(b38.4f0): WOW64 breakpoint - code 4000001f (first chance)
ModLoad: 72f90000 72fdc000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73550000 00000000`73567000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`753c0000 00000000`75420000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`752f0000 00000000`753bc000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73880000 00000000`741cd000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76760000 00000000`76765000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70c00000 00000000`70c3c000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72320000 00000000`724be000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76c60000 00000000`76cdb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74a50000 00000000`74ad0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72aa0000 00000000`72aa8000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ba0000 00000000`74bab000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75720000 75755000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 768f0000 768f6000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72060000 720a4000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 73000000 7301c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74920000 74927000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74950000 74963000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 720b0000 720d1000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 76770000 767b5000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74990000 00000000`7499e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74b30000 00000000`74b46000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74af0000 74b2b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`767c0000 00000000`76843000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71430000 00000000`71463000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`0a4a0000 00000000`0aded000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6c7d0000 00000000`6d394000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c10000 00000000`74c19000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73420000 00000000`73472000 C:\Windows\SysWOW64\RASAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73400000 00000000`73415000 C:\Windows\SysWOW64\rasman.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74410000 00000000`7441d000 C:\Windows\SysWOW64\rtutils.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73710000 00000000`73716000 C:\Windows\SysWOW64\sensapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`0a0b0000 00000000`0a168000 iexplore.exe
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Symbol search path is: srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`01360000 00000000`01418000 iexplore.exe
<---- EVENT: break cpr ---->
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`773c0000 00000000`77569000 ntdll.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`775a0000 00000000`77720000 ntdll32.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`00080000 00000000`000ee000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Page heap: pid 0x1228: page heap enabled with flags 0x3.
ModLoad: 00000000`74c90000 00000000`74ccf000 C:\Windows\SYSTEM32\wow64.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c30000 00000000`74c8c000 C:\Windows\SYSTEM32\wow64win.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c20000 00000000`74c28000 C:\Windows\SYSTEM32\wow64cpu.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76f90000 00000000`770af000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75520000 00000000`75630000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76f90000 00000000`770af000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`772c0000 00000000`773ba000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73480000 00000000`734e0000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72e80000 00000000`72ead000 C:\Windows\SysWOW64\IEUI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Page heap: pid 0x1228: page heap enabled with flags 0x3.
ModLoad: 00000000`75520000 00000000`75630000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72ab0000 00000000`72ab5000 C:\Windows\SysWOW64\MSIMG32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ee0000 00000000`74f27000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76850000 00000000`768f0000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75240000 00000000`752ec000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a20000 00000000`76a39000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75630000 00000000`75720000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748c0000 00000000`74920000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748b0000 00000000`748bc000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76b60000 00000000`76c60000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76990000 00000000`76a20000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`77570000 00000000`7757a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75420000 00000000`754bd000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`754c0000 00000000`75517000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75890000 00000000`764da000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74f30000 00000000`7508c000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a40000 00000000`76b51000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76900000 00000000`7698f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`765a0000 00000000`76758000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74d10000 00000000`74e2b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75880000 00000000`75883000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72f90000 72fdc000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73550000 00000000`73567000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`753c0000 00000000`75420000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`752f0000 00000000`753bc000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`08ea0000 00000000`08edc000 C:\Windows\SysWOW64\oleacc.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73880000 00000000`741cd000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76760000 00000000`76765000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70c00000 00000000`70c3c000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72320000 00000000`724be000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76c60000 00000000`76cdb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72b80000 00000000`72bb1000 C:\Program Files (x86)\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72e50000 00000000`72e7f000 C:\Windows\SysWOW64\xmllite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74a50000 00000000`74ad0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72aa0000 72aa8000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 71020000 7118f000 C:\Windows\SysWOW64\explorerframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ba0000 00000000`74bab000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`736e0000 00000000`7370f000 C:\Windows\SysWOW64\DUser.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 73620000 736d2000 C:\Windows\SysWOW64\DUI70.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`0e6f0000 00000000`0e84c000 C:\Windows\SysWOW64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75720000 00000000`75755000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`768f0000 00000000`768f6000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72060000 00000000`720a4000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73000000 00000000`7301c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74920000 00000000`74927000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74990000 00000000`7499e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70ae0000 00000000`70bdb000 C:\Windows\SysWOW64\WindowsCodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74950000 00000000`74963000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6c7d0000 00000000`6d394000 C:\Windows\SysWOW64\MSHTML.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c10000 00000000`74c19000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`750a0000 00000000`7523d000 C:\Windows\syswow64\setupapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ce0000 00000000`74d07000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74e30000 74e42000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 707e0000 7089a000 C:\Windows\SysWOW64\d2d1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 6fb50000 6fc5b000 C:\Windows\SysWOW64\DWrite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72a20000 72a44000 C:\Program Files (x86)\Internet Explorer\sqmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71190000 00000000`71213000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 764e0000 7650d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75760000 7587e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75090000 7509c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74b30000 74b46000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72a20000 72a4c000 C:\Windows\SysWOW64\d3d10_1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`729e0000 00000000`72a1a000 C:\Windows\SysWOW64\d3d10_1core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 701f0000 7029a000 C:\Windows\SysWOW64\aticfx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74af0000 74b2b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 733f0000 733fb000 C:\Windows\SysWOW64\atiuxpag.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6f750000 00000000`6fb4d000 C:\Windows\SysWOW64\atidxx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`767c0000 00000000`76843000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71430000 00000000`71463000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`10a40000 00000000`1138d000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`14150000 00000000`14d14000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`720b0000 00000000`720d1000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76770000 00000000`767b5000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73720000 00000000`7377f000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73720000 00000000`7377f000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71820000 00000000`7188c000 C:\Windows\SysWOW64\ieapfltr.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`732d0000 00000000`732db000 C:\Windows\SysWOW64\msimtf.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`729b0000 00000000`729db000 C:\Windows\SysWOW64\msls31.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`713c0000 00000000`713ee000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74650000 00000000`74745000 C:\Windows\SysWOW64\PROPSYS.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`713c0000 00000000`713ee000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 750a0000 7523d000 C:\Windows\syswow64\SETUPAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ce0000 00000000`74d07000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74e30000 00000000`74e42000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74650000 00000000`74745000 C:\Windows\SysWOW64\propsys.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`11f40000 00000000`1209c000 C:\Windows\SysWOW64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`737e0000 00000000`73805000 C:\Windows\SysWOW64\POWRPROF.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71190000 00000000`71213000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`764e0000 00000000`7650d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75760000 00000000`7587e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75090000 7509c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 6e630000 6e732000 C:\Windows\SysWOW64\d3d10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70e90000 00000000`70ec3000 C:\Windows\SysWOW64\d3d10core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74b50000 00000000`74b8c000 C:\Windows\SysWOW64\mswsock.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74b90000 00000000`74b95000 C:\Windows\SysWOW64\wshtcpip.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72990000 00000000`72996000 C:\Windows\SysWOW64\wship6.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`706f0000 00000000`706f6000 C:\Windows\SysWOW64\rasadhlp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70ae0000 00000000`70bdb000 C:\Windows\SysWOW64\windowscodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`706b0000 00000000`706e8000 C:\Windows\SysWOW64\fwpuclnt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6e560000 00000000`6e626000 C:\Windows\SysWOW64\NaturalLanguage6.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6e0b0000 00000000`6e55c000 C:\Windows\SysWOW64\NLSData0009.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6de20000 00000000`6e0a3000 C:\Windows\SysWOW64\NLSLexicons0009.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73420000 00000000`73472000 C:\Windows\SysWOW64\RASAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73400000 00000000`73415000 C:\Windows\SysWOW64\rasman.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74410000 00000000`7441d000 C:\Windows\SysWOW64\rtutils.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73710000 00000000`73716000 C:\Windows\SysWOW64\sensapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`0c430000 00000000`0c4e8000 iexplore.exe
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Symbol search path is: srv**http://msdl.microsoft.com/download/symbols;srv**http://symbols.mozilla.org/firefox;srv**http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is:
ModLoad: 00000000`01360000 00000000`01418000 iexplore.exe
<---- EVENT: break cpr ---->
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`773c0000 00000000`77569000 ntdll.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`775a0000 00000000`77720000 ntdll32.dll
<---- EVENT: break ld ---->
ntdll!RtlUserThreadStart:
00000000`773ec500 4883ec48 sub rsp,48h
ModLoad: 00000000`00080000 00000000`000ee000 C:\Windows\system32\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Page heap: pid 0xFD0: page heap enabled with flags 0x3.
ModLoad: 00000000`74c90000 00000000`74ccf000 C:\Windows\SYSTEM32\wow64.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c30000 00000000`74c8c000 C:\Windows\SYSTEM32\wow64win.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c20000 00000000`74c28000 C:\Windows\SYSTEM32\wow64cpu.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76f90000 00000000`770af000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75520000 00000000`75630000 WOW64_IMAGE_SECTION
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76f90000 00000000`770af000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`772c0000 00000000`773ba000 NOT_AN_IMAGE
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73480000 00000000`734e0000 C:\Windows\syswow64\verifier.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
Page heap: pid 0xFD0: page heap enabled with flags 0x3.
ModLoad: 00000000`75520000 00000000`75630000 C:\Windows\syswow64\kernel32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ee0000 00000000`74f27000 C:\Windows\syswow64\KERNELBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76850000 00000000`768f0000 C:\Windows\syswow64\ADVAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75240000 00000000`752ec000 C:\Windows\syswow64\msvcrt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a20000 00000000`76a39000 C:\Windows\SysWOW64\sechost.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75630000 00000000`75720000 C:\Windows\syswow64\RPCRT4.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748c0000 00000000`74920000 C:\Windows\syswow64\SspiCli.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`748b0000 00000000`748bc000 C:\Windows\syswow64\CRYPTBASE.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76b60000 00000000`76c60000 C:\Windows\syswow64\USER32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76990000 00000000`76a20000 C:\Windows\syswow64\GDI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`77570000 00000000`7757a000 C:\Windows\syswow64\LPK.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75420000 00000000`754bd000 C:\Windows\syswow64\USP10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`754c0000 00000000`75517000 C:\Windows\syswow64\SHLWAPI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75890000 00000000`764da000 C:\Windows\syswow64\SHELL32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74f30000 00000000`7508c000 C:\Windows\syswow64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76a40000 00000000`76b51000 C:\Windows\syswow64\urlmon.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76900000 00000000`7698f000 C:\Windows\syswow64\OLEAUT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`765a0000 00000000`76758000 C:\Windows\syswow64\iertutil.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74d10000 00000000`74e2b000 C:\Windows\syswow64\WININET.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`75880000 00000000`75883000 C:\Windows\syswow64\Normaliz.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72f90000 72fdc000 C:\Windows\SysWOW64\apphelp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73550000 00000000`73567000 C:\Windows\AppPatch\emet.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`753c0000 00000000`75420000 C:\Windows\SysWOW64\IMM32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`752f0000 00000000`753bc000 C:\Windows\syswow64\MSCTF.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73880000 00000000`741cd000 C:\Windows\SysWOW64\IEFRAME.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76760000 00000000`76765000 C:\Windows\syswow64\PSAPI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70c00000 00000000`70c3c000 C:\Windows\SysWOW64\OLEACC.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72320000 00000000`724be000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76c60000 00000000`76cdb000 C:\Windows\syswow64\comdlg32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72b80000 00000000`72bb1000 C:\Program Files (x86)\Internet Explorer\IEShims.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74a50000 00000000`74ad0000 C:\Windows\SysWOW64\uxtheme.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72aa0000 00000000`72aa8000 C:\Windows\SysWOW64\Secur32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74ba0000 00000000`74bab000 C:\Windows\SysWOW64\profapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75720000 75755000 C:\Windows\syswow64\WS2_32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 768f0000 768f6000 C:\Windows\syswow64\NSI.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72060000 720a4000 C:\Windows\SysWOW64\dnsapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 73000000 7301c000 C:\Windows\SysWOW64\iphlpapi.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74920000 74927000 C:\Windows\SysWOW64\WINNSI.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74990000 00000000`7499e000 C:\Windows\SysWOW64\RpcRtRemote.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74950000 00000000`74963000 C:\Windows\SysWOW64\dwmapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6c7d0000 00000000`6d394000 C:\Windows\SysWOW64\MSHTML.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74c10000 00000000`74c19000 C:\Windows\SysWOW64\VERSION.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`750a0000 00000000`7523d000 C:\Windows\syswow64\setupapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74ce0000 74d07000 C:\Windows\syswow64\CFGMGR32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74e30000 74e42000 C:\Windows\syswow64\DEVOBJ.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 707e0000 7089a000 C:\Windows\SysWOW64\d2d1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 6fb50000 6fc5b000 C:\Windows\SysWOW64\DWrite.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74b30000 74b46000 C:\Windows\SysWOW64\CRYPTSP.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 71190000 71213000 C:\Windows\SysWOW64\dxgi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 764e0000 7650d000 C:\Windows\syswow64\WINTRUST.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75760000 7587e000 C:\Windows\syswow64\CRYPT32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 75090000 7509c000 C:\Windows\syswow64\MSASN1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74af0000 74b2b000 C:\Windows\SysWOW64\rsaenh.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 72a20000 72a4c000 C:\Windows\SysWOW64\d3d10_1.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`729e0000 00000000`72a1a000 C:\Windows\SysWOW64\d3d10_1core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 701f0000 7029a000 C:\Windows\SysWOW64\aticfx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`733f0000 00000000`733fb000 C:\Windows\SysWOW64\atiuxpag.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`767c0000 00000000`76843000 C:\Windows\syswow64\CLBCatQ.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6f750000 00000000`6fb4d000 C:\Windows\SysWOW64\atidxx32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71430000 00000000`71463000 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`10c50000 00000000`1159d000 C:\Windows\SysWOW64\ieframe.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`14150000 00000000`14d14000 C:\Windows\SysWOW64\mshtml.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`720b0000 00000000`720d1000 C:\Windows\SysWOW64\ntmarta.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`76770000 00000000`767b5000 C:\Windows\syswow64\WLDAP32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73720000 00000000`7377f000 C:\Windows\SysWOW64\SXS.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`71820000 00000000`7188c000 C:\Windows\SysWOW64\ieapfltr.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`732d0000 00000000`732db000 C:\Windows\SysWOW64\msimtf.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`729b0000 00000000`729db000 C:\Windows\SysWOW64\msls31.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`713c0000 00000000`713ee000 C:\Windows\SysWOW64\MLANG.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74650000 00000000`74745000 C:\Windows\SysWOW64\PROPSYS.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`121d0000 00000000`1232c000 C:\Windows\SysWOW64\ole32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73420000 00000000`73472000 C:\Windows\SysWOW64\RASAPI32.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73400000 00000000`73415000 C:\Windows\SysWOW64\rasman.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74410000 00000000`7441d000 C:\Windows\SysWOW64\rtutils.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`73710000 00000000`73716000 C:\Windows\SysWOW64\sensapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6e630000 00000000`6e732000 C:\Windows\SysWOW64\d3d10.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70e90000 00000000`70ec3000 C:\Windows\SysWOW64\d3d10core.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`70ae0000 00000000`70bdb000 C:\Windows\SysWOW64\windowscodecs.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`09270000 00000000`092a5000 C:\Windows\SysWOW64\ws2_32.DLL
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`74b50000 00000000`74b8c000 C:\Windows\SysWOW64\mswsock.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 74b90000 74b95000 C:\Windows\SysWOW64\wshtcpip.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 749e0000 749f0000 C:\Windows\SysWOW64\NLAapi.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`706f0000 00000000`706f6000 C:\Windows\SysWOW64\rasadhlp.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`72990000 00000000`72996000 C:\Windows\SysWOW64\wship6.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`706b0000 00000000`706e8000 C:\Windows\SysWOW64\fwpuclnt.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
ModLoad: 00000000`6dc60000 00000000`6de1b000 C:\Windows\SysWOW64\jscript9.dll
<---- EVENT: break ld ---->
ntdll!NtMapViewOfSection+0xa:
00000000`7741159a c3 ret
(fd0.1140): Access violation - code c0000005 (first chance)