0:000> ~*k . 0 Id: 1524.14f4 Suspend: 0 Teb: fffdd000 Unfrozen ChildEBP RetAddr 001ed9dc 008b5335 user32!NtUserWaitMessage+0x15 001efa24 008b8b46 windbg!wmain+0x245 001efa68 7552339a windbg!_initterm_e+0x163 001efa74 775f9ef2 kernel32!BaseThreadInitThunk+0xe 001efab4 775f9ec5 ntdll!__RtlUserThreadStart+0x70 001efacc 00000000 ntdll!_RtlUserThreadStart+0x1b 1 Id: 1524.16e8 Suspend: 0 Teb: fffda000 Unfrozen ChildEBP RetAddr 01f6f9d4 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 01f6fb34 7552339a ntdll!TppWorkerThread+0x216 01f6fb40 775f9ef2 kernel32!BaseThreadInitThunk+0xe 01f6fb80 775f9ec5 ntdll!__RtlUserThreadStart+0x70 01f6fb98 00000000 ntdll!_RtlUserThreadStart+0x1b 2 Id: 1524.1314 Suspend: 0 Teb: fffd7000 Unfrozen ChildEBP RetAddr 034bf944 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 034bfaa4 7552339a ntdll!TppWorkerThread+0x216 034bfab0 775f9ef2 kernel32!BaseThreadInitThunk+0xe 034bfaf0 775f9ec5 ntdll!__RtlUserThreadStart+0x70 034bfb08 00000000 ntdll!_RtlUserThreadStart+0x1b 3 Id: 1524.1658 Suspend: 0 Teb: fffaf000 Unfrozen ChildEBP RetAddr 035cf944 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 035cfaa4 7552339a ntdll!TppWorkerThread+0x216 035cfab0 775f9ef2 kernel32!BaseThreadInitThunk+0xe 035cfaf0 775f9ec5 ntdll!__RtlUserThreadStart+0x70 035cfb08 00000000 ntdll!_RtlUserThreadStart+0x1b 4 Id: 1524.14d0 Suspend: 0 Teb: fffa9000 Unfrozen ChildEBP RetAddr 03aff808 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 03aff968 7552339a ntdll!TppWorkerThread+0x216 03aff974 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03aff9b4 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03aff9cc 00000000 ntdll!_RtlUserThreadStart+0x1b 5 Id: 1524.870 Suspend: 0 Teb: fffa6000 Unfrozen ChildEBP RetAddr 03bef66c 77612f51 ntdll!NtWaitForMultipleObjects+0x15 03bef800 7552339a ntdll!TppWaiterpThread+0x33d 03bef80c 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03bef84c 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03bef864 00000000 ntdll!_RtlUserThreadStart+0x1b 6 Id: 1524.ed4 Suspend: 0 Teb: fffa3000 Unfrozen ChildEBP RetAddr 03dcfc34 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 03dcfd94 7552339a ntdll!TppWorkerThread+0x216 03dcfda0 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03dcfde0 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03dcfdf8 00000000 ntdll!_RtlUserThreadStart+0x1b 7 Id: 1524.16ec Suspend: 0 Teb: fffa0000 Unfrozen ChildEBP RetAddr 03d3f968 768d31bb ntdll!NtDelayExecution+0x15 03d3f9d0 768d3a8b KERNELBASE!SleepEx+0x65 03d3f9e0 7658d98d KERNELBASE!Sleep+0xf 03d3f9ec 7658cd48 ole32!CROIDTable::WorkerThreadLoop+0x14 [d:\w7rtm\com\ole32\com\dcomrem\refcache.cxx @ 1345] 03d3fa08 7658d87a ole32!CRpcThread::WorkerLoop+0x26 [d:\w7rtm\com\ole32\com\dcomrem\threads.cxx @ 257] 03d3fa18 7552339a ole32!CRpcThreadCache::RpcWorkerThreadEntry+0x16 [d:\w7rtm\com\ole32\com\dcomrem\threads.cxx @ 63] 03d3fa24 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03d3fa64 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03d3fa7c 00000000 ntdll!_RtlUserThreadStart+0x1b 8 Id: 1524.15b4 Suspend: 0 Teb: fff9d000 Unfrozen ChildEBP RetAddr 03d8fd28 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 03d8fe88 7552339a ntdll!TppWorkerThread+0x216 03d8fe94 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03d8fed4 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03d8feec 00000000 ntdll!_RtlUserThreadStart+0x1b 9 Id: 1524.1428 Suspend: 0 Teb: fff9a000 Unfrozen ChildEBP RetAddr 0446fbc8 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 0446fd28 7552339a ntdll!TppWorkerThread+0x216 0446fd34 775f9ef2 kernel32!BaseThreadInitThunk+0xe 0446fd74 775f9ec5 ntdll!__RtlUserThreadStart+0x70 0446fd8c 00000000 ntdll!_RtlUserThreadStart+0x1b 10 Id: 1524.15f0 Suspend: 0 Teb: fff97000 Unfrozen ChildEBP RetAddr 03b9f828 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 03b9f988 7552339a ntdll!TppWorkerThread+0x216 03b9f994 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03b9f9d4 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03b9f9ec 00000000 ntdll!_RtlUserThreadStart+0x1b 11 Id: 1524.1024 Suspend: 0 Teb: fff94000 Unfrozen ChildEBP RetAddr 0434f7d8 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 0434f938 7552339a ntdll!TppWorkerThread+0x216 0434f944 775f9ef2 kernel32!BaseThreadInitThunk+0xe 0434f984 775f9ec5 ntdll!__RtlUserThreadStart+0x70 0434f99c 00000000 ntdll!_RtlUserThreadStart+0x1b 12 Id: 1524.9b8 Suspend: 0 Teb: fff91000 Unfrozen ChildEBP RetAddr 03e7fbd4 76bb790d user32!NtUserGetMessage+0x15 03e7fbf0 75939b1f user32!GetMessageW+0x33 03e7fc30 76cb43c0 shell32!MessagePumpThreadProc+0x3b 03e7fcb8 7552339a shlwapi!WrapperThreadProc+0x1b5 03e7fcc4 775f9ef2 kernel32!BaseThreadInitThunk+0xe 03e7fd04 775f9ec5 ntdll!__RtlUserThreadStart+0x70 03e7fd1c 00000000 ntdll!_RtlUserThreadStart+0x1b 13 Id: 1524.e58 Suspend: 0 Teb: fff8e000 Unfrozen ChildEBP RetAddr 0460f95c 77613352 ntdll!ZwWaitForWorkViaWorkerFactory+0x12 0460fabc 7552339a ntdll!TppWorkerThread+0x216 0460fac8 775f9ef2 kernel32!BaseThreadInitThunk+0xe 0460fb08 775f9ec5 ntdll!__RtlUserThreadStart+0x70 0460fb20 00000000 ntdll!_RtlUserThreadStart+0x1b 14 Id: 1524.e84 Suspend: 0 Teb: fffac000 Unfrozen ChildEBP RetAddr 0456d4c8 7552ef7f ntdll!ZwReadFile+0x15 0456d544 7552f263 kernel32!BaseDllOpenIniFileOnDisk+0x341 0456d584 7552e5a1 kernel32!BaseDllReadWriteIniFileOnDisk+0x2d 0456d59c 7552ea4c kernel32!BaseDllReadWriteIniFile+0xed 0456d5d0 5d9b341b kernel32!GetPrivateProfileStringW+0x35 0456e26c 5d9b3cca dbgeng!IdentifyTargetFromConfigFile+0x8b 0456e2c4 5d841ba2 dbgeng!IdentifyTargetFromFile+0x19a 0456f6ec 5d83ca9b dbgeng!FileInitialize+0x4b2 0456f720 5d83ca20 dbgeng!DebugClient::OpenDumpFileWithPrivateDumpHeader+0x6b 0456f73c 0088ac59 dbgeng!DebugClient::OpenDumpFileWide+0x20 0456f988 0088b5ab windbg!StartSession+0x149 0456f998 7552339a windbg!EngineLoop+0x1b 0456f9a4 775f9ef2 kernel32!BaseThreadInitThunk+0xe 0456f9e4 775f9ec5 ntdll!__RtlUserThreadStart+0x70 0456f9fc 00000000 ntdll!_RtlUserThreadStart+0x1b 0:000> !address BaseAddr EndAddr+1 RgnSize Type State Protect Usage --------------------------------------------------------------------------------------------- + 0 10000 10000 MEM_FREE PAGE_NOACCESS Free + 10000 20000 10000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 20000 21000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 21000 30000 f000 MEM_FREE PAGE_NOACCESS Free + 30000 31000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 31000 40000 f000 MEM_FREE PAGE_NOACCESS Free + 40000 41000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Other [API Set Map] + 41000 50000 f000 MEM_FREE PAGE_NOACCESS Free + 50000 54000 4000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [System Default Activation Context Data] + 54000 60000 c000 MEM_FREE PAGE_NOACCESS Free + 60000 62000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 62000 70000 e000 MEM_FREE PAGE_NOACCESS Free + 70000 71000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 71000 80000 f000 MEM_FREE PAGE_NOACCESS Free + 80000 81000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Other [Switch Context Data] + 81000 90000 f000 MEM_FREE PAGE_NOACCESS Free + 90000 91000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 91000 a0000 f000 MEM_FREE PAGE_NOACCESS Free + a0000 a2000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + a2000 b0000 e000 MEM_FREE PAGE_NOACCESS Free + b0000 b6000 6000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + b6000 c0000 a000 MEM_FREE PAGE_NOACCESS Free + c0000 ef000 2f000 MEM_PRIVATE MEM_RESERVE ef000 f1000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD f1000 100000 f000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 100000 167000 67000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 167000 170000 9000 MEM_FREE PAGE_NOACCESS Free + 170000 171000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 171000 180000 f000 MEM_FREE PAGE_NOACCESS Free + 180000 181000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 181000 190000 f000 MEM_FREE PAGE_NOACCESS Free + 190000 191000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 191000 1a0000 f000 MEM_FREE PAGE_NOACCESS Free + 1a0000 1a1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 1a1000 1b0000 f000 MEM_FREE PAGE_NOACCESS Free + 1b0000 1de000 2e000 MEM_PRIVATE MEM_RESERVE Stack [~0; 1524.14f4] 1de000 1df000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~0; 1524.14f4] 1df000 1f0000 11000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~0; 1524.14f4] + 1f0000 1f1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 1f1000 200000 f000 MEM_FREE PAGE_NOACCESS Free + 200000 20c000 c000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 20c000 210000 4000 MEM_FREE PAGE_NOACCESS Free + 210000 216000 6000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 216000 220000 a000 MEM_FREE PAGE_NOACCESS Free + 220000 221000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE 221000 230000 f000 MEM_PRIVATE MEM_RESERVE + 230000 232000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 232000 240000 e000 MEM_FREE PAGE_NOACCESS Free + 240000 242000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 242000 250000 e000 MEM_FREE PAGE_NOACCESS Free + 250000 2c8000 78000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE 2c8000 2d0000 8000 MEM_PRIVATE MEM_RESERVE + 2d0000 2eb000 1b000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 2eb000 2f0000 5000 MEM_FREE PAGE_NOACCESS Free + 2f0000 2f1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 2f1000 300000 f000 MEM_FREE PAGE_NOACCESS Free + 300000 301000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE 301000 320000 1f000 MEM_PRIVATE MEM_RESERVE + 320000 322000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 322000 330000 e000 MEM_FREE PAGE_NOACCESS Free + 330000 3b1000 81000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3b1000 3b6000 5000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3b6000 3bc000 6000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3bc000 3bd000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3bd000 3c7000 a000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c7000 3c9000 2000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c9000 3cf000 6000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3cf000 3d2000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3d2000 3e6000 14000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3e6000 3e7000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3e7000 415000 2e000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 415000 416000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 416000 417000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 417000 418000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 418000 41b000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 41b000 41c000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 41c000 430000 14000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] + 430000 432000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 432000 440000 e000 MEM_FREE PAGE_NOACCESS Free + 440000 442000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 442000 490000 4e000 MEM_FREE PAGE_NOACCESS Free + 490000 491000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 5; Handle: 00490000; Type: Segment] 491000 4d0000 3f000 MEM_PRIVATE MEM_RESERVE Heap [ID: 5; Handle: 00490000; Type: Segment] + 4d0000 4e0000 10000 MEM_FREE PAGE_NOACCESS Free + 4e0000 4f0000 10000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 1; Handle: 004e0000; Type: Segment] + 4f0000 501000 11000 MEM_MAPPED MEM_COMMIT PAGE_READONLY 501000 670000 16f000 MEM_MAPPED MEM_RESERVE 670000 673000 3000 MEM_MAPPED MEM_COMMIT PAGE_READONLY 673000 678000 5000 MEM_MAPPED MEM_RESERVE + 678000 680000 8000 MEM_FREE PAGE_NOACCESS Free + 680000 801000 181000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 801000 810000 f000 MEM_FREE PAGE_NOACCESS Free + 810000 811000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 811000 820000 f000 MEM_FREE PAGE_NOACCESS Free + 820000 859000 39000 MEM_PRIVATE MEM_RESERVE 859000 85c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 85c000 860000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 860000 861000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 861000 8c4000 63000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8c4000 8ca000 6000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8ca000 8cb000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8cb000 8d0000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d0000 8d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d1000 8d2000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d2000 8d5000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d5000 8d7000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d7000 8d8000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d8000 8d9000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8d9000 8da000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8da000 8db000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] 8db000 8f7000 1c000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [windbg; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\windbg.exe"] + 8f7000 900000 9000 MEM_FREE PAGE_NOACCESS Free + 900000 a29000 129000 MEM_MAPPED MEM_COMMIT PAGE_READONLY a29000 1d00000 12d7000 MEM_MAPPED MEM_RESERVE + 1d00000 1d44000 44000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 1; Handle: 004e0000; Type: Segment] 1d44000 1e00000 bc000 MEM_PRIVATE MEM_RESERVE Heap [ID: 1; Handle: 004e0000; Type: Segment] + 1e00000 1e01000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE 1e01000 1e80000 7f000 MEM_PRIVATE MEM_RESERVE + 1e80000 1ea0000 20000 MEM_FREE PAGE_NOACCESS Free + 1ea0000 1eb2000 12000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 1eb2000 1ed0000 1e000 MEM_FREE PAGE_NOACCESS Free + 1ed0000 1eec000 1c000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 3; Handle: 01ed0000; Type: Segment] 1eec000 1f10000 24000 MEM_PRIVATE MEM_RESERVE Heap [ID: 3; Handle: 01ed0000; Type: Segment] + 1f10000 1f11000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 1f11000 1f30000 1f000 MEM_FREE PAGE_NOACCESS Free + 1f30000 1f68000 38000 MEM_PRIVATE MEM_RESERVE Stack [~1; 1524.16e8] 1f68000 1f69000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~1; 1524.16e8] 1f69000 1f70000 7000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~1; 1524.16e8] + 1f70000 1fb0000 40000 MEM_FREE PAGE_NOACCESS Free + 1fb0000 1fb1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 1fb1000 1fd0000 1f000 MEM_FREE PAGE_NOACCESS Free + 1fd0000 1fd1000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 2; Handle: 01fd0000; Type: Segment] 1fd1000 2010000 3f000 MEM_PRIVATE MEM_RESERVE Heap [ID: 2; Handle: 01fd0000; Type: Segment] + 2010000 2022000 12000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 2022000 2040000 1e000 MEM_FREE PAGE_NOACCESS Free + 2040000 2088000 48000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 2088000 2090000 8000 MEM_FREE PAGE_NOACCESS Free + 2090000 20c9000 39000 MEM_PRIVATE MEM_RESERVE 20c9000 20cc000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 20cc000 20d0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 20d0000 2110000 40000 MEM_FREE PAGE_NOACCESS Free + 2110000 2137000 27000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 4; Handle: 02110000; Type: Segment] 2137000 2150000 19000 MEM_PRIVATE MEM_RESERVE Heap [ID: 4; Handle: 02110000; Type: Segment] + 2150000 241f000 2cf000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 241f000 2420000 1000 MEM_FREE PAGE_NOACCESS Free + 2420000 2744000 324000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 2744000 2750000 c000 MEM_FREE PAGE_NOACCESS Free + 2750000 3080000 930000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3080000 3446000 3c6000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3446000 3480000 3a000 MEM_FREE PAGE_NOACCESS Free + 3480000 34b8000 38000 MEM_PRIVATE MEM_RESERVE Stack [~2; 1524.1314] 34b8000 34b9000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~2; 1524.1314] 34b9000 34c0000 7000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~2; 1524.1314] + 34c0000 3508000 48000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3508000 3540000 38000 MEM_FREE PAGE_NOACCESS Free + 3540000 3579000 39000 MEM_PRIVATE MEM_RESERVE 3579000 357c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 357c000 3580000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3580000 3590000 10000 MEM_FREE PAGE_NOACCESS Free + 3590000 35c8000 38000 MEM_PRIVATE MEM_RESERVE Stack [~3; 1524.1658] 35c8000 35c9000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~3; 1524.1658] 35c9000 35d0000 7000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~3; 1524.1658] + 35d0000 35e0000 10000 MEM_FREE PAGE_NOACCESS Free + 35e0000 35e4000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 6; Handle: 035e0000; Type: Segment] 35e4000 35f0000 c000 MEM_PRIVATE MEM_RESERVE Heap [ID: 6; Handle: 035e0000; Type: Segment] + 35f0000 3610000 20000 MEM_FREE PAGE_NOACCESS Free + 3610000 3614000 4000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3614000 3660000 4c000 MEM_FREE PAGE_NOACCESS Free + 3660000 3760000 100000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3760000 3764000 4000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3764000 3770000 c000 MEM_FREE PAGE_NOACCESS Free + 3770000 3771000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE 3771000 3780000 f000 MEM_MAPPED MEM_RESERVE + 3780000 37b9000 39000 MEM_PRIVATE MEM_RESERVE 37b9000 37bc000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 37bc000 37c0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 37c0000 37f0000 30000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 37f0000 3829000 39000 MEM_PRIVATE MEM_RESERVE 3829000 382c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 382c000 3830000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3830000 3831000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 7; Handle: 03830000; Type: Segment] 3831000 3870000 3f000 MEM_PRIVATE MEM_RESERVE Heap [ID: 7; Handle: 03830000; Type: Segment] + 3870000 3882000 12000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 8; Handle: 039a0000; Type: Segment] 3882000 3970000 ee000 MEM_PRIVATE MEM_RESERVE Heap [ID: 8; Handle: 039a0000; Type: Segment] + 3970000 3974000 4000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3974000 3980000 c000 MEM_FREE PAGE_NOACCESS Free + 3980000 3981000 1000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3981000 3990000 f000 MEM_FREE PAGE_NOACCESS Free + 3990000 3991000 1000 MEM_PRIVATE MEM_COMMIT PAGE_EXECUTE_READWRITE + 3991000 39a0000 f000 MEM_FREE PAGE_NOACCESS Free + 39a0000 39a8000 8000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 8; Handle: 039a0000; Type: Segment] 39a8000 39b0000 8000 MEM_PRIVATE MEM_RESERVE Heap [ID: 8; Handle: 039a0000; Type: Segment] + 39b0000 3a16000 66000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3a16000 3a20000 a000 MEM_FREE PAGE_NOACCESS Free + 3a20000 3a22000 2000 MEM_PRIVATE MEM_COMMIT PAGE_EXECUTE_READ + 3a22000 3a30000 e000 MEM_FREE PAGE_NOACCESS Free + 3a30000 3a32000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 3a32000 3a40000 e000 MEM_FREE PAGE_NOACCESS Free + 3a40000 3a41000 1000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 3a41000 3a50000 f000 MEM_FREE PAGE_NOACCESS Free + 3a50000 3a52000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 3a52000 3a60000 e000 MEM_FREE PAGE_NOACCESS Free + 3a60000 3a99000 39000 MEM_PRIVATE MEM_RESERVE 3a99000 3a9c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 3a9c000 3aa0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3aa0000 3aa1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 3aa1000 3ab0000 f000 MEM_FREE PAGE_NOACCESS Free + 3ab0000 3ab1000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3ab1000 3ac0000 f000 MEM_FREE PAGE_NOACCESS Free + 3ac0000 3afc000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~4; 1524.14d0] 3afc000 3afe000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~4; 1524.14d0] 3afe000 3b00000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~4; 1524.14d0] + 3b00000 3b10000 10000 MEM_FREE PAGE_NOACCESS Free + 3b10000 3b49000 39000 MEM_PRIVATE MEM_RESERVE 3b49000 3b4c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 3b4c000 3b50000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3b50000 3b60000 10000 MEM_FREE PAGE_NOACCESS Free + 3b60000 3b9b000 3b000 MEM_PRIVATE MEM_RESERVE Stack [~10; 1524.15f0] 3b9b000 3b9c000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~10; 1524.15f0] 3b9c000 3ba0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~10; 1524.15f0] + 3ba0000 3bb0000 10000 MEM_FREE PAGE_NOACCESS Free + 3bb0000 3bec000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~5; 1524.870] 3bec000 3bee000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~5; 1524.870] 3bee000 3bf0000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~5; 1524.870] + 3bf0000 3c14000 24000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c14000 3c17000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c17000 3c58000 41000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c58000 3c5a000 2000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c5a000 3c70000 16000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c70000 3c79000 9000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c79000 3c89000 10000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c89000 3c94000 b000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3c94000 3cbf000 2b000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3cbf000 3cc2000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3cc2000 3cc4000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3cc4000 3cc5000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3cc5000 3ccb000 6000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3ccb000 3ccc000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3ccc000 3cf0000 24000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] + 3cf0000 3d00000 10000 MEM_FREE PAGE_NOACCESS Free + 3d00000 3d3c000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~7; 1524.16ec] 3d3c000 3d3e000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~7; 1524.16ec] 3d3e000 3d40000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~7; 1524.16ec] + 3d40000 3d42000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 3d42000 3d50000 e000 MEM_FREE PAGE_NOACCESS Free + 3d50000 3d8a000 3a000 MEM_PRIVATE MEM_RESERVE Stack [~8; 1524.15b4] 3d8a000 3d8b000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~8; 1524.15b4] 3d8b000 3d90000 5000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~8; 1524.15b4] + 3d90000 3dcc000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~6; 1524.ed4] 3dcc000 3dce000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~6; 1524.ed4] 3dce000 3dd0000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~6; 1524.ed4] + 3dd0000 3dd2000 2000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Activation Context Data] + 3dd2000 3df0000 1e000 MEM_FREE PAGE_NOACCESS Free + 3df0000 3df5000 5000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3df5000 3e00000 b000 MEM_FREE PAGE_NOACCESS Free + 3e00000 3e39000 39000 MEM_PRIVATE MEM_RESERVE 3e39000 3e3c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 3e3c000 3e40000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3e40000 3e7b000 3b000 MEM_PRIVATE MEM_RESERVE Stack [~12; 1524.9b8] 3e7b000 3e7c000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~12; 1524.9b8] 3e7c000 3e80000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~12; 1524.9b8] + 3e80000 3ec0000 40000 MEM_FREE PAGE_NOACCESS Free + 3ec0000 3ef9000 39000 MEM_PRIVATE MEM_RESERVE 3ef9000 3efc000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 3efc000 3f00000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 3f00000 3f7f000 7f000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3f7f000 3f82000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3f82000 3fbe000 3c000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3fbe000 3fc1000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3fc1000 3fca000 9000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 3fca000 3fcb000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 3fcb000 4053000 88000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 4053000 4056000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 4056000 4065000 f000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 4065000 4068000 3000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 4068000 407f000 17000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 407f000 4083000 4000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 4083000 4089000 6000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 4089000 4090000 7000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 4090000 40b9000 29000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 40b9000 40ba000 1000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 40ba000 40c3000 9000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 40c3000 40f9000 36000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 40f9000 40fa000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 40fa000 4100000 6000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] + 4100000 4280000 180000 MEM_FREE PAGE_NOACCESS Free + 4280000 42b9000 39000 MEM_PRIVATE MEM_RESERVE 42b9000 42bc000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 42bc000 42c0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 42c0000 4300000 40000 MEM_FREE PAGE_NOACCESS Free + 4300000 4301000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 4301000 4310000 f000 MEM_FREE PAGE_NOACCESS Free + 4310000 434c000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~11; 1524.1024] 434c000 434e000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~11; 1524.1024] 434e000 4350000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~11; 1524.1024] + 4350000 4389000 39000 MEM_PRIVATE MEM_RESERVE 4389000 438c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 438c000 4390000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 4390000 43d0000 40000 MEM_FREE PAGE_NOACCESS Free + 43d0000 43d4000 4000 MEM_MAPPED MEM_COMMIT PAGE_READONLY + 43d4000 43f0000 1c000 MEM_FREE PAGE_NOACCESS Free + 43f0000 4429000 39000 MEM_PRIVATE MEM_RESERVE 4429000 442c000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 442c000 4430000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 4430000 4467000 37000 MEM_PRIVATE MEM_RESERVE Stack [~9; 1524.1428] 4467000 4468000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~9; 1524.1428] 4468000 4470000 8000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~9; 1524.1428] + 4470000 44a0000 30000 MEM_FREE PAGE_NOACCESS Free + 44a0000 44a1000 1000 MEM_MAPPED MEM_COMMIT PAGE_READWRITE + 44a1000 44e0000 3f000 MEM_FREE PAGE_NOACCESS Free + 44e0000 4518000 38000 MEM_PRIVATE MEM_RESERVE 4518000 451a000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 451a000 4520000 6000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 4520000 4530000 10000 MEM_FREE PAGE_NOACCESS Free + 4530000 456c000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~14; 1524.e84] 456c000 456d000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~14; 1524.e84] 456d000 4570000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~14; 1524.e84] + 4570000 45d0000 60000 MEM_FREE PAGE_NOACCESS Free + 45d0000 460c000 3c000 MEM_PRIVATE MEM_RESERVE Stack [~13; 1524.e58] 460c000 460e000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [~13; 1524.e58] 460e000 4610000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [~13; 1524.e58] + 4610000 4680000 70000 MEM_FREE PAGE_NOACCESS Free + 4680000 46b9000 39000 MEM_PRIVATE MEM_RESERVE 46b9000 46bc000 3000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD 46bc000 46c0000 4000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + 46c0000 49c0000 300000 MEM_PRIVATE MEM_RESERVE + 49c0000 4a60000 a0000 MEM_FREE PAGE_NOACCESS Free + 4a60000 4a72000 12000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE 4a72000 4b60000 ee000 MEM_PRIVATE MEM_RESERVE + 4b60000 4c60000 100000 MEM_FREE PAGE_NOACCESS Free + 4c60000 4c61000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 4c61000 4c79000 18000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] 4c79000 4c8e000 15000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Heap [ID: 0; Handle: 00330000; Type: Segment] 4c8e000 5060000 3d2000 MEM_PRIVATE MEM_RESERVE Heap [ID: 0; Handle: 00330000; Type: Segment] + 5060000 10000000 afa0000 MEM_FREE PAGE_NOACCESS Free + 10000000 10001000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 10001000 10047000 46000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 10047000 1005a000 13000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 1005a000 1005b000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 1005b000 100a9000 4e000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 100a9000 100ab000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] 100ab000 100cb000 20000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [p4exp; "C:\Program Files\Perforce\p4exp.dll"] + 100cb000 5d740000 4d675000 MEM_FREE PAGE_NOACCESS Free + 5d740000 5d741000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5d741000 5da65000 324000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da65000 5da67000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da67000 5da68000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da68000 5da74000 c000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da74000 5da79000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da79000 5da80000 7000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da80000 5da81000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da81000 5da88000 7000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da88000 5da89000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da89000 5da8a000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da8a000 5da8b000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da8b000 5da8c000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da8c000 5da8d000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da8d000 5da8f000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da8f000 5da90000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da90000 5da91000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da91000 5da96000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da96000 5da97000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da97000 5da98000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5da98000 5daa3000 b000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5daa3000 5daa6000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5daa6000 5daa9000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5daa9000 5daad000 4000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] 5daad000 5dadb000 2e000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dbgeng; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbgeng.dll"] + 5dadb000 61020000 3545000 MEM_FREE PAGE_NOACCESS Free + 61020000 61021000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [EhStorAPI; "C:\Windows\System32\EhStorAPI.dll"] 61021000 61030000 f000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [EhStorAPI; "C:\Windows\System32\EhStorAPI.dll"] 61030000 61031000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [EhStorAPI; "C:\Windows\System32\EhStorAPI.dll"] 61031000 61042000 11000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [EhStorAPI; "C:\Windows\System32\EhStorAPI.dll"] + 61042000 61300000 2be000 MEM_FREE PAGE_NOACCESS Free + 61300000 61301000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [PortableDeviceApi; "C:\Windows\System32\PortableDeviceApi.dll"] 61301000 6136f000 6e000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [PortableDeviceApi; "C:\Windows\System32\PortableDeviceApi.dll"] 6136f000 61371000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [PortableDeviceApi; "C:\Windows\System32\PortableDeviceApi.dll"] 61371000 61389000 18000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [PortableDeviceApi; "C:\Windows\System32\PortableDeviceApi.dll"] + 61389000 61390000 7000 MEM_FREE PAGE_NOACCESS Free + 61390000 61391000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [NetworkExplorer; "C:\Windows\System32\NetworkExplorer.dll"] 61391000 6139a000 9000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [NetworkExplorer; "C:\Windows\System32\NetworkExplorer.dll"] 6139a000 6139b000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [NetworkExplorer; "C:\Windows\System32\NetworkExplorer.dll"] 6139b000 61528000 18d000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [NetworkExplorer; "C:\Windows\System32\NetworkExplorer.dll"] + 61528000 61590000 68000 MEM_FREE PAGE_NOACCESS Free + 61590000 61591000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [SearchFolder; "C:\Windows\System32\SearchFolder.dll"] 61591000 61623000 92000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [SearchFolder; "C:\Windows\System32\SearchFolder.dll"] 61623000 61624000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [SearchFolder; "C:\Windows\System32\SearchFolder.dll"] 61624000 61630000 c000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [SearchFolder; "C:\Windows\System32\SearchFolder.dll"] + 61630000 658c0000 4290000 MEM_FREE PAGE_NOACCESS Free + 658c0000 658c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [thumbcache; "C:\Windows\SysWOW64\thumbcache.dll"] 658c1000 658d3000 12000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [thumbcache; "C:\Windows\SysWOW64\thumbcache.dll"] 658d3000 658d4000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [thumbcache; "C:\Windows\SysWOW64\thumbcache.dll"] 658d4000 658d6000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [thumbcache; "C:\Windows\SysWOW64\thumbcache.dll"] + 658d6000 65a80000 1aa000 MEM_FREE PAGE_NOACCESS Free + 65a80000 65a81000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [actxprxy; "C:\Windows\SysWOW64\actxprxy.dll"] 65a81000 65abd000 3c000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [actxprxy; "C:\Windows\SysWOW64\actxprxy.dll"] 65abd000 65ac4000 7000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [actxprxy; "C:\Windows\SysWOW64\actxprxy.dll"] 65ac4000 65ace000 a000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [actxprxy; "C:\Windows\SysWOW64\actxprxy.dll"] + 65ace000 65dd0000 302000 MEM_FREE PAGE_NOACCESS Free + 65dd0000 65dd1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [StructuredQuery; "C:\Windows\System32\StructuredQuery.dll"] 65dd1000 65e26000 55000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [StructuredQuery; "C:\Windows\System32\StructuredQuery.dll"] 65e26000 65e27000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [StructuredQuery; "C:\Windows\System32\StructuredQuery.dll"] 65e27000 65e2c000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [StructuredQuery; "C:\Windows\System32\StructuredQuery.dll"] + 65e2c000 66260000 434000 MEM_FREE PAGE_NOACCESS Free + 66260000 66261000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 66261000 66374000 113000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 66374000 66379000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 66379000 6638d000 14000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 6638d000 6638e000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 6638e000 6638f000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 6638f000 66390000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 66390000 66391000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] 66391000 663a1000 10000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dbghelp; "C:\Program Files (x86)\Debugging Tools for Windows (x86)\dbghelp.dll"] + 663a1000 663f0000 4f000 MEM_FREE PAGE_NOACCESS Free + 663f0000 663f1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msftedit; "C:\Windows\System32\msftedit.dll"] 663f1000 66473000 82000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msftedit; "C:\Windows\System32\msftedit.dll"] 66473000 66474000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msftedit; "C:\Windows\System32\msftedit.dll"] 66474000 66475000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msftedit; "C:\Windows\System32\msftedit.dll"] 66475000 66484000 f000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msftedit; "C:\Windows\System32\msftedit.dll"] + 66484000 67650000 11cc000 MEM_FREE PAGE_NOACCESS Free + 67650000 67651000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [davhlpr; "C:\Windows\System32\davhlpr.dll"] 67651000 67655000 4000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [davhlpr; "C:\Windows\System32\davhlpr.dll"] 67655000 67656000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [davhlpr; "C:\Windows\System32\davhlpr.dll"] 67656000 67658000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [davhlpr; "C:\Windows\System32\davhlpr.dll"] + 67658000 67660000 8000 MEM_FREE PAGE_NOACCESS Free + 67660000 67661000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [davclnt; "C:\Windows\System32\davclnt.dll"] 67661000 67673000 12000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [davclnt; "C:\Windows\System32\davclnt.dll"] 67673000 67674000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [davclnt; "C:\Windows\System32\davclnt.dll"] 67674000 67677000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [davclnt; "C:\Windows\System32\davclnt.dll"] + 67677000 67680000 9000 MEM_FREE PAGE_NOACCESS Free + 67680000 67681000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntlanman; "C:\Windows\System32\ntlanman.dll"] 67681000 67691000 10000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ntlanman; "C:\Windows\System32\ntlanman.dll"] 67691000 67692000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntlanman; "C:\Windows\System32\ntlanman.dll"] 67692000 67694000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntlanman; "C:\Windows\System32\ntlanman.dll"] + 67694000 676a0000 c000 MEM_FREE PAGE_NOACCESS Free + 676a0000 676a1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [drprov; "C:\Windows\System32\drprov.dll"] 676a1000 676a5000 4000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [drprov; "C:\Windows\System32\drprov.dll"] 676a5000 676a6000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [drprov; "C:\Windows\System32\drprov.dll"] 676a6000 676a8000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [drprov; "C:\Windows\System32\drprov.dll"] + 676a8000 69030000 1988000 MEM_FREE PAGE_NOACCESS Free + 69030000 69031000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [mpr; "C:\Windows\System32\mpr.dll"] 69031000 6903f000 e000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [mpr; "C:\Windows\System32\mpr.dll"] 6903f000 69040000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [mpr; "C:\Windows\System32\mpr.dll"] 69040000 69042000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [mpr; "C:\Windows\System32\mpr.dll"] + 69042000 69d60000 d1e000 MEM_FREE PAGE_NOACCESS Free + 69d60000 69d61000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msls31; "C:\Windows\System32\msls31.dll"] 69d61000 69d88000 27000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msls31; "C:\Windows\System32\msls31.dll"] 69d88000 69d89000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msls31; "C:\Windows\System32\msls31.dll"] 69d89000 69d8b000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msls31; "C:\Windows\System32\msls31.dll"] + 69d8b000 69db0000 25000 MEM_FREE PAGE_NOACCESS Free + 69db0000 69db1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shdocvw; "C:\Windows\System32\shdocvw.dll"] 69db1000 69dbe000 d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [shdocvw; "C:\Windows\System32\shdocvw.dll"] 69dbe000 69dbf000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [shdocvw; "C:\Windows\System32\shdocvw.dll"] 69dbf000 69dde000 1f000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shdocvw; "C:\Windows\System32\shdocvw.dll"] + 69dde000 69ea0000 c2000 MEM_FREE PAGE_NOACCESS Free + 69ea0000 69ea1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dui70; "C:\Windows\System32\dui70.dll"] 69ea1000 69f46000 a5000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [dui70; "C:\Windows\System32\dui70.dll"] 69f46000 69f48000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dui70; "C:\Windows\System32\dui70.dll"] 69f48000 69f49000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [dui70; "C:\Windows\System32\dui70.dll"] 69f49000 69f52000 9000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dui70; "C:\Windows\System32\dui70.dll"] + 69f52000 69f60000 e000 MEM_FREE PAGE_NOACCESS Free + 69f60000 69f61000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [duser; "C:\Windows\System32\duser.dll"] 69f61000 69f85000 24000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [duser; "C:\Windows\System32\duser.dll"] 69f85000 69f88000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [duser; "C:\Windows\System32\duser.dll"] 69f88000 69f8f000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [duser; "C:\Windows\System32\duser.dll"] + 69f8f000 69f90000 1000 MEM_FREE PAGE_NOACCESS Free + 69f90000 69f91000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [explorerframe; "C:\Windows\System32\explorerframe.dll"] 69f91000 6a08d000 fc000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [explorerframe; "C:\Windows\System32\explorerframe.dll"] 6a08d000 6a08f000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [explorerframe; "C:\Windows\System32\explorerframe.dll"] 6a08f000 6a0ff000 70000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [explorerframe; "C:\Windows\System32\explorerframe.dll"] + 6a0ff000 6a130000 31000 MEM_FREE PAGE_NOACCESS Free + 6a130000 6a131000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [xmllite; "C:\Windows\System32\xmllite.dll"] 6a131000 6a159000 28000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [xmllite; "C:\Windows\System32\xmllite.dll"] 6a159000 6a15a000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [xmllite; "C:\Windows\System32\xmllite.dll"] 6a15a000 6a15c000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [xmllite; "C:\Windows\System32\xmllite.dll"] 6a15c000 6a15f000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [xmllite; "C:\Windows\System32\xmllite.dll"] + 6a15f000 6a370000 211000 MEM_FREE PAGE_NOACCESS Free + 6a370000 6a371000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ieproxy; "C:\Program Files (x86)\Internet Explorer\ieproxy.dll"] 6a371000 6a39a000 29000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ieproxy; "C:\Program Files (x86)\Internet Explorer\ieproxy.dll"] 6a39a000 6a39e000 4000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ieproxy; "C:\Program Files (x86)\Internet Explorer\ieproxy.dll"] 6a39e000 6a3a3000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ieproxy; "C:\Program Files (x86)\Internet Explorer\ieproxy.dll"] + 6a3a3000 6b020000 c7d000 MEM_FREE PAGE_NOACCESS Free + 6b020000 6b021000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [oleacc; "C:\Windows\System32\oleacc.dll"] 6b021000 6b051000 30000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [oleacc; "C:\Windows\System32\oleacc.dll"] 6b051000 6b052000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [oleacc; "C:\Windows\System32\oleacc.dll"] 6b052000 6b053000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [oleacc; "C:\Windows\System32\oleacc.dll"] 6b053000 6b05c000 9000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [oleacc; "C:\Windows\System32\oleacc.dll"] + 6b05c000 6b060000 4000 MEM_FREE PAGE_NOACCESS Free + 6b060000 6b061000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b061000 6b413000 3b2000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b413000 6b415000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b415000 6b416000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b416000 6b417000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b417000 6b41b000 4000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ieframe; "C:\Windows\System32\ieframe.dll"] 6b41b000 6b9ad000 592000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ieframe; "C:\Windows\System32\ieframe.dll"] + 6b9ad000 6bbc0000 213000 MEM_FREE PAGE_NOACCESS Free + 6bbc0000 6bbc1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [linkinfo; "C:\Windows\System32\linkinfo.dll"] 6bbc1000 6bbc6000 5000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [linkinfo; "C:\Windows\System32\linkinfo.dll"] 6bbc6000 6bbc7000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [linkinfo; "C:\Windows\System32\linkinfo.dll"] 6bbc7000 6bbc9000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [linkinfo; "C:\Windows\System32\linkinfo.dll"] + 6bbc9000 70370000 47a7000 MEM_FREE PAGE_NOACCESS Free + 70370000 70371000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntshrui; "C:\Windows\System32\ntshrui.dll"] 70371000 703a0000 2f000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ntshrui; "C:\Windows\System32\ntshrui.dll"] 703a0000 703a1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntshrui; "C:\Windows\System32\ntshrui.dll"] 703a1000 703a2000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ntshrui; "C:\Windows\System32\ntshrui.dll"] 703a2000 703e0000 3e000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntshrui; "C:\Windows\System32\ntshrui.dll"] + 703e0000 704d0000 f0000 MEM_FREE PAGE_NOACCESS Free + 704d0000 704d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [EhStorShell; "C:\Windows\System32\EhStorShell.dll"] 704d1000 704dd000 c000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [EhStorShell; "C:\Windows\System32\EhStorShell.dll"] 704dd000 704de000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [EhStorShell; "C:\Windows\System32\EhStorShell.dll"] 704de000 70501000 23000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [EhStorShell; "C:\Windows\System32\EhStorShell.dll"] + 70501000 70510000 f000 MEM_FREE PAGE_NOACCESS Free + 70510000 70511000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [slc; "C:\Windows\System32\slc.dll"] 70511000 70517000 6000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [slc; "C:\Windows\System32\slc.dll"] 70517000 70518000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [slc; "C:\Windows\System32\slc.dll"] 70518000 7051a000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [slc; "C:\Windows\System32\slc.dll"] + 7051a000 70540000 26000 MEM_FREE PAGE_NOACCESS Free + 70540000 70541000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cscapi; "C:\Windows\System32\cscapi.dll"] 70541000 70548000 7000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [cscapi; "C:\Windows\System32\cscapi.dll"] 70548000 70549000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [cscapi; "C:\Windows\System32\cscapi.dll"] 70549000 7054b000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cscapi; "C:\Windows\System32\cscapi.dll"] + 7054b000 72be0000 2695000 MEM_FREE PAGE_NOACCESS Free + 72be0000 72be1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72be1000 72ccd000 ec000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72ccd000 72cce000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72cce000 72ccf000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72ccf000 72cd0000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72cd0000 72cd1000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] 72cd1000 72cdb000 a000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [WindowsCodecs; "C:\Windows\System32\WindowsCodecs.dll"] + 72cdb000 73880000 ba5000 MEM_FREE PAGE_NOACCESS Free + 73880000 73881000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [propsys; "C:\Windows\System32\propsys.dll"] 73881000 738f9000 78000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [propsys; "C:\Windows\System32\propsys.dll"] 738f9000 738fb000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [propsys; "C:\Windows\System32\propsys.dll"] 738fb000 73975000 7a000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [propsys; "C:\Windows\System32\propsys.dll"] + 73975000 73b20000 1ab000 MEM_FREE PAGE_NOACCESS Free + 73b20000 73b21000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b21000 73b30000 f000 MEM_IMAGE MEM_RESERVE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b30000 73b68000 38000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b68000 73b70000 8000 MEM_IMAGE MEM_RESERVE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b70000 73b71000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b71000 73b72000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b72000 73b80000 e000 MEM_IMAGE MEM_RESERVE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b80000 73b82000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b82000 73b90000 e000 MEM_IMAGE MEM_RESERVE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b90000 73b92000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] 73b92000 73ba0000 e000 MEM_IMAGE MEM_RESERVE Image [uxtheme; "C:\Windows\System32\uxtheme.dll"] + 73ba0000 73e90000 2f0000 MEM_FREE PAGE_NOACCESS Free + 73e90000 73e91000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] 73e91000 73ec5000 34000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] 73ec5000 73f0e000 49000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] 73f0e000 73f0f000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] 73f0f000 73f11000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] 73f11000 73f17000 6000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcp80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll"] + 73f17000 73f20000 9000 MEM_FREE PAGE_NOACCESS Free + 73f20000 73f21000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73f21000 73f84000 63000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73f84000 73faf000 2b000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73faf000 73fb0000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73fb0000 73fb1000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73fb1000 73fb2000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73fb2000 73fb3000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73fb3000 73fb6000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] 73fb6000 73fbb000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcr80; "C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll"] + 73fbb000 74200000 245000 MEM_FREE PAGE_NOACCESS Free + 74200000 74201000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dwmapi; "C:\Windows\System32\dwmapi.dll"] 74201000 7420c000 b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [dwmapi; "C:\Windows\System32\dwmapi.dll"] 7420c000 7420e000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [dwmapi; "C:\Windows\System32\dwmapi.dll"] 7420e000 74213000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [dwmapi; "C:\Windows\System32\dwmapi.dll"] + 74213000 744e0000 2cd000 MEM_FREE PAGE_NOACCESS Free + 744e0000 744e1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [winsta; "C:\Windows\System32\winsta.dll"] 744e1000 74503000 22000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [winsta; "C:\Windows\System32\winsta.dll"] 74503000 74504000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [winsta; "C:\Windows\System32\winsta.dll"] 74504000 74505000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [winsta; "C:\Windows\System32\winsta.dll"] 74505000 74506000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [winsta; "C:\Windows\System32\winsta.dll"] 74506000 74509000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [winsta; "C:\Windows\System32\winsta.dll"] + 74509000 74510000 7000 MEM_FREE PAGE_NOACCESS Free + 74510000 74511000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [winmm; "C:\Windows\System32\winmm.dll"] 74511000 74538000 27000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [winmm; "C:\Windows\System32\winmm.dll"] 74538000 7453a000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [winmm; "C:\Windows\System32\winmm.dll"] 7453a000 7453b000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [winmm; "C:\Windows\System32\winmm.dll"] 7453b000 74542000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [winmm; "C:\Windows\System32\winmm.dll"] + 74542000 74550000 e000 MEM_FREE PAGE_NOACCESS Free + 74550000 74551000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [comctl32; "C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll"] 74551000 7469c000 14b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [comctl32; "C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll"] 7469c000 7469e000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [comctl32; "C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll"] 7469e000 7469f000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [comctl32; "C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll"] 7469f000 746ee000 4f000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [comctl32; "C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll"] + 746ee000 74710000 22000 MEM_FREE PAGE_NOACCESS Free + 74710000 74711000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [wkscli; "C:\Windows\System32\wkscli.dll"] 74711000 7471c000 b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [wkscli; "C:\Windows\System32\wkscli.dll"] 7471c000 7471d000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [wkscli; "C:\Windows\System32\wkscli.dll"] 7471d000 7471f000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [wkscli; "C:\Windows\System32\wkscli.dll"] + 7471f000 74720000 1000 MEM_FREE PAGE_NOACCESS Free + 74720000 74721000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [srvcli; "C:\Windows\System32\srvcli.dll"] 74721000 7472e000 d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [srvcli; "C:\Windows\System32\srvcli.dll"] 7472e000 74733000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [srvcli; "C:\Windows\System32\srvcli.dll"] 74733000 74737000 4000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [srvcli; "C:\Windows\System32\srvcli.dll"] 74737000 74739000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [srvcli; "C:\Windows\System32\srvcli.dll"] + 74739000 74740000 7000 MEM_FREE PAGE_NOACCESS Free + 74740000 74741000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [netutils; "C:\Windows\System32\netutils.dll"] 74741000 74746000 5000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [netutils; "C:\Windows\System32\netutils.dll"] 74746000 74747000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [netutils; "C:\Windows\System32\netutils.dll"] 74747000 74749000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [netutils; "C:\Windows\System32\netutils.dll"] + 74749000 748c0000 177000 MEM_FREE PAGE_NOACCESS Free + 748c0000 748c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [apphelp; "C:\Windows\System32\apphelp.dll"] 748c1000 748fd000 3c000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [apphelp; "C:\Windows\System32\apphelp.dll"] 748fd000 748fe000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [apphelp; "C:\Windows\System32\apphelp.dll"] 748fe000 74900000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [apphelp; "C:\Windows\System32\apphelp.dll"] 74900000 7490c000 c000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [apphelp; "C:\Windows\System32\apphelp.dll"] + 7490c000 74910000 4000 MEM_FREE PAGE_NOACCESS Free + 74910000 74911000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [profapi; "C:\Windows\System32\profapi.dll"] 74911000 74918000 7000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [profapi; "C:\Windows\System32\profapi.dll"] 74918000 74919000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [profapi; "C:\Windows\System32\profapi.dll"] 74919000 7491b000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [profapi; "C:\Windows\System32\profapi.dll"] + 7491b000 74920000 5000 MEM_FREE PAGE_NOACCESS Free + 74920000 74921000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [secur32; "C:\Windows\System32\secur32.dll"] 74921000 74925000 4000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [secur32; "C:\Windows\System32\secur32.dll"] 74925000 74926000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [secur32; "C:\Windows\System32\secur32.dll"] 74926000 74928000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [secur32; "C:\Windows\System32\secur32.dll"] + 74928000 74930000 8000 MEM_FREE PAGE_NOACCESS Free + 74930000 74931000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [RpcRtRemote; "C:\Windows\System32\RpcRtRemote.dll"] 74931000 7493b000 a000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [RpcRtRemote; "C:\Windows\System32\RpcRtRemote.dll"] 7493b000 7493c000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [RpcRtRemote; "C:\Windows\System32\RpcRtRemote.dll"] 7493c000 7493e000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [RpcRtRemote; "C:\Windows\System32\RpcRtRemote.dll"] + 7493e000 74940000 2000 MEM_FREE PAGE_NOACCESS Free + 74940000 74941000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [rsaenh; "C:\Windows\System32\rsaenh.dll"] 74941000 74975000 34000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [rsaenh; "C:\Windows\System32\rsaenh.dll"] 74975000 74976000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [rsaenh; "C:\Windows\System32\rsaenh.dll"] 74976000 74978000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [rsaenh; "C:\Windows\System32\rsaenh.dll"] 74978000 7497b000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [rsaenh; "C:\Windows\System32\rsaenh.dll"] + 7497b000 74980000 5000 MEM_FREE PAGE_NOACCESS Free + 74980000 74981000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cryptsp; "C:\Windows\System32\cryptsp.dll"] 74981000 74993000 12000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [cryptsp; "C:\Windows\System32\cryptsp.dll"] 74993000 74994000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [cryptsp; "C:\Windows\System32\cryptsp.dll"] 74994000 74996000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cryptsp; "C:\Windows\System32\cryptsp.dll"] + 74996000 749a0000 a000 MEM_FREE PAGE_NOACCESS Free + 749a0000 749a1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntmarta; "C:\Windows\System32\ntmarta.dll"] 749a1000 749bc000 1b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ntmarta; "C:\Windows\System32\ntmarta.dll"] 749bc000 749bd000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntmarta; "C:\Windows\System32\ntmarta.dll"] 749bd000 749be000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ntmarta; "C:\Windows\System32\ntmarta.dll"] 749be000 749c1000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntmarta; "C:\Windows\System32\ntmarta.dll"] + 749c1000 74ad0000 10f000 MEM_FREE PAGE_NOACCESS Free + 74ad0000 74ad1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [version; "C:\Windows\System32\version.dll"] 74ad1000 74ad6000 5000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [version; "C:\Windows\System32\version.dll"] 74ad6000 74ad7000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [version; "C:\Windows\System32\version.dll"] 74ad7000 74ad9000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [version; "C:\Windows\System32\version.dll"] + 74ad9000 74ae0000 7000 MEM_FREE PAGE_NOACCESS Free + 74ae0000 74ae1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY 74ae1000 74ae4000 3000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ 74ae4000 74ae5000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 74ae5000 74ae8000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY + 74ae8000 74af0000 8000 MEM_FREE PAGE_NOACCESS Free + 74af0000 74af1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY 74af1000 74b3e000 4d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ 74b3e000 74b3f000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 74b3f000 74b42000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY 74b42000 74b43000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 74b43000 74b4c000 9000 MEM_IMAGE MEM_COMMIT PAGE_READONLY + 74b4c000 74b50000 4000 MEM_FREE PAGE_NOACCESS Free + 74b50000 74b51000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY 74b51000 74b89000 38000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ 74b89000 74b8b000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 74b8b000 74b8f000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY + 74b8f000 74c90000 101000 MEM_FREE PAGE_NOACCESS Free + 74c90000 74c91000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [CRYPTBASE; "C:\Windows\SysWOW64\CRYPTBASE.dll"] 74c91000 74c99000 8000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [CRYPTBASE; "C:\Windows\SysWOW64\CRYPTBASE.dll"] 74c99000 74c9a000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [CRYPTBASE; "C:\Windows\SysWOW64\CRYPTBASE.dll"] 74c9a000 74c9c000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [CRYPTBASE; "C:\Windows\SysWOW64\CRYPTBASE.dll"] + 74c9c000 74ca0000 4000 MEM_FREE PAGE_NOACCESS Free + 74ca0000 74ca1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74ca1000 74cb0000 f000 MEM_IMAGE MEM_RESERVE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cb0000 74cc6000 16000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cc6000 74cd0000 a000 MEM_IMAGE MEM_RESERVE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cd0000 74cd1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cd1000 74ce0000 f000 MEM_IMAGE MEM_RESERVE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74ce0000 74ce1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74ce1000 74cf0000 f000 MEM_IMAGE MEM_RESERVE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cf0000 74cf2000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] 74cf2000 74d00000 e000 MEM_IMAGE MEM_RESERVE Image [sspicli; "C:\Windows\SysWOW64\sspicli.dll"] + 74d00000 74d01000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [clbcatq; "C:\Windows\SysWOW64\clbcatq.dll"] 74d01000 74d78000 77000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [clbcatq; "C:\Windows\SysWOW64\clbcatq.dll"] 74d78000 74d7b000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [clbcatq; "C:\Windows\SysWOW64\clbcatq.dll"] 74d7b000 74d7c000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [clbcatq; "C:\Windows\SysWOW64\clbcatq.dll"] 74d7c000 74d83000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [clbcatq; "C:\Windows\SysWOW64\clbcatq.dll"] + 74d83000 74d90000 d000 MEM_FREE PAGE_NOACCESS Free + 74d90000 74d91000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [imm32; "C:\Windows\System32\imm32.dll"] 74d91000 74da0000 f000 MEM_IMAGE MEM_RESERVE Image [imm32; "C:\Windows\System32\imm32.dll"] 74da0000 74db7000 17000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [imm32; "C:\Windows\System32\imm32.dll"] 74db7000 74dc0000 9000 MEM_IMAGE MEM_RESERVE Image [imm32; "C:\Windows\System32\imm32.dll"] 74dc0000 74dc1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [imm32; "C:\Windows\System32\imm32.dll"] 74dc1000 74dd0000 f000 MEM_IMAGE MEM_RESERVE Image [imm32; "C:\Windows\System32\imm32.dll"] 74dd0000 74dd5000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [imm32; "C:\Windows\System32\imm32.dll"] 74dd5000 74de0000 b000 MEM_IMAGE MEM_RESERVE Image [imm32; "C:\Windows\System32\imm32.dll"] 74de0000 74de1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [imm32; "C:\Windows\System32\imm32.dll"] 74de1000 74df0000 f000 MEM_IMAGE MEM_RESERVE Image [imm32; "C:\Windows\System32\imm32.dll"] + 74df0000 74e50000 60000 MEM_FREE PAGE_NOACCESS Free + 74e50000 74e51000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ws2_32; "C:\Windows\SysWOW64\ws2_32.dll"] 74e51000 74e77000 26000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ws2_32; "C:\Windows\SysWOW64\ws2_32.dll"] 74e77000 74e78000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ws2_32; "C:\Windows\SysWOW64\ws2_32.dll"] 74e78000 74e85000 d000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ws2_32; "C:\Windows\SysWOW64\ws2_32.dll"] + 74e85000 74e90000 b000 MEM_FREE PAGE_NOACCESS Free + 74e90000 74e91000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msctf; "C:\Windows\SysWOW64\msctf.dll"] 74e91000 74f14000 83000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msctf; "C:\Windows\SysWOW64\msctf.dll"] 74f14000 74f16000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msctf; "C:\Windows\SysWOW64\msctf.dll"] 74f16000 74f5c000 46000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msctf; "C:\Windows\SysWOW64\msctf.dll"] + 74f5c000 74f60000 4000 MEM_FREE PAGE_NOACCESS Free + 74f60000 74f61000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [wintrust; "C:\Windows\SysWOW64\wintrust.dll"] 74f61000 74f89000 28000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [wintrust; "C:\Windows\SysWOW64\wintrust.dll"] 74f89000 74f8a000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [wintrust; "C:\Windows\SysWOW64\wintrust.dll"] 74f8a000 74f8d000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [wintrust; "C:\Windows\SysWOW64\wintrust.dll"] + 74f8d000 75260000 2d3000 MEM_FREE PAGE_NOACCESS Free + 75260000 75261000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [advapi32; "C:\Windows\SysWOW64\advapi32.dll"] 75261000 752d3000 72000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [advapi32; "C:\Windows\SysWOW64\advapi32.dll"] 752d3000 752d4000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [advapi32; "C:\Windows\SysWOW64\advapi32.dll"] 752d4000 752d7000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [advapi32; "C:\Windows\SysWOW64\advapi32.dll"] 752d7000 75300000 29000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [advapi32; "C:\Windows\SysWOW64\advapi32.dll"] + 75300000 75301000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [sechost; "C:\Windows\SysWOW64\sechost.dll"] 75301000 75314000 13000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [sechost; "C:\Windows\SysWOW64\sechost.dll"] 75314000 75315000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [sechost; "C:\Windows\SysWOW64\sechost.dll"] 75315000 75317000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [sechost; "C:\Windows\SysWOW64\sechost.dll"] 75317000 75319000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [sechost; "C:\Windows\SysWOW64\sechost.dll"] + 75319000 75320000 7000 MEM_FREE PAGE_NOACCESS Free + 75320000 75321000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [iertutil; "C:\Windows\SysWOW64\iertutil.dll"] 75321000 754bc000 19b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [iertutil; "C:\Windows\SysWOW64\iertutil.dll"] 754bc000 754bf000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [iertutil; "C:\Windows\SysWOW64\iertutil.dll"] 754bf000 754d8000 19000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [iertutil; "C:\Windows\SysWOW64\iertutil.dll"] + 754d8000 754e0000 8000 MEM_FREE PAGE_NOACCESS Free + 754e0000 754e1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cfgmgr32; "C:\Windows\SysWOW64\cfgmgr32.dll"] 754e1000 75503000 22000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [cfgmgr32; "C:\Windows\SysWOW64\cfgmgr32.dll"] 75503000 75504000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [cfgmgr32; "C:\Windows\SysWOW64\cfgmgr32.dll"] 75504000 75507000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [cfgmgr32; "C:\Windows\SysWOW64\cfgmgr32.dll"] + 75507000 75510000 9000 MEM_FREE PAGE_NOACCESS Free + 75510000 75520000 10000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 75520000 755e1000 c1000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 755e1000 755f0000 f000 MEM_IMAGE MEM_RESERVE Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 755f0000 755f1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 755f1000 755f2000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 755f2000 75600000 e000 MEM_IMAGE MEM_RESERVE Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 75600000 75601000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 75601000 75610000 f000 MEM_IMAGE MEM_RESERVE Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 75610000 7561b000 b000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] 7561b000 75620000 5000 MEM_IMAGE MEM_RESERVE Image [kernel32; "C:\Windows\SysWOW64\kernel32.dll"] + 75620000 75621000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msasn1; "C:\Windows\SysWOW64\msasn1.dll"] 75621000 75629000 8000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msasn1; "C:\Windows\SysWOW64\msasn1.dll"] 75629000 7562a000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msasn1; "C:\Windows\SysWOW64\msasn1.dll"] 7562a000 7562c000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msasn1; "C:\Windows\SysWOW64\msasn1.dll"] + 7562c000 75630000 4000 MEM_FREE PAGE_NOACCESS Free + 75630000 75631000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [usp10; "C:\Windows\SysWOW64\usp10.dll"] 75631000 7568c000 5b000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [usp10; "C:\Windows\SysWOW64\usp10.dll"] 7568c000 7568e000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [usp10; "C:\Windows\SysWOW64\usp10.dll"] 7568e000 756cd000 3f000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [usp10; "C:\Windows\SysWOW64\usp10.dll"] + 756cd000 756d0000 3000 MEM_FREE PAGE_NOACCESS Free + 756d0000 756d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 756d1000 756e0000 f000 MEM_IMAGE MEM_RESERVE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 756e0000 75729000 49000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75729000 75730000 7000 MEM_IMAGE MEM_RESERVE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75730000 75731000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75731000 75740000 f000 MEM_IMAGE MEM_RESERVE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75740000 75741000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75741000 75750000 f000 MEM_IMAGE MEM_RESERVE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75750000 75752000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] 75752000 75760000 e000 MEM_IMAGE MEM_RESERVE Image [gdi32; "C:\Windows\SysWOW64\gdi32.dll"] + 75760000 75761000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75761000 75770000 f000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75770000 75806000 96000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75806000 75810000 a000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75810000 75813000 3000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75813000 75820000 d000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75820000 75821000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75821000 75830000 f000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75830000 75834000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75834000 75840000 c000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75840000 75845000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] 75845000 75850000 b000 MEM_IMAGE MEM_RESERVE Image [rpcrt4; "C:\Windows\SysWOW64\rpcrt4.dll"] + 75850000 75880000 30000 MEM_FREE PAGE_NOACCESS Free + 75880000 75881000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shell32; "C:\Windows\SysWOW64\shell32.dll"] 75881000 75c4a000 3c9000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [shell32; "C:\Windows\SysWOW64\shell32.dll"] 75c4a000 75c4f000 5000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [shell32; "C:\Windows\SysWOW64\shell32.dll"] 75c4f000 75c51000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [shell32; "C:\Windows\SysWOW64\shell32.dll"] 75c51000 764ca000 879000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shell32; "C:\Windows\SysWOW64\shell32.dll"] + 764ca000 764d0000 6000 MEM_FREE PAGE_NOACCESS Free + 764d0000 764d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [oleaut32; "C:\Windows\SysWOW64\oleaut32.dll"] 764d1000 76556000 85000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [oleaut32; "C:\Windows\SysWOW64\oleaut32.dll"] 76556000 76558000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [oleaut32; "C:\Windows\SysWOW64\oleaut32.dll"] 76558000 7655f000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [oleaut32; "C:\Windows\SysWOW64\oleaut32.dll"] + 7655f000 76560000 1000 MEM_FREE PAGE_NOACCESS Free + 76560000 76561000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ole32; "C:\Windows\SysWOW64\ole32.dll"] 76561000 766a6000 145000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ole32; "C:\Windows\SysWOW64\ole32.dll"] 766a6000 766aa000 4000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ole32; "C:\Windows\SysWOW64\ole32.dll"] 766aa000 766bc000 12000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ole32; "C:\Windows\SysWOW64\ole32.dll"] + 766bc000 766c0000 4000 MEM_FREE PAGE_NOACCESS Free + 766c0000 766c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [lpk; "C:\Windows\SysWOW64\lpk.dll"] 766c1000 766c7000 6000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [lpk; "C:\Windows\SysWOW64\lpk.dll"] 766c7000 766c8000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [lpk; "C:\Windows\SysWOW64\lpk.dll"] 766c8000 766ca000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [lpk; "C:\Windows\SysWOW64\lpk.dll"] + 766ca000 766d0000 6000 MEM_FREE PAGE_NOACCESS Free + 766d0000 766d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [Wldap32; "C:\Windows\SysWOW64\Wldap32.dll"] 766d1000 7670e000 3d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [Wldap32; "C:\Windows\SysWOW64\Wldap32.dll"] 7670e000 7670f000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [Wldap32; "C:\Windows\SysWOW64\Wldap32.dll"] 7670f000 76715000 6000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [Wldap32; "C:\Windows\SysWOW64\Wldap32.dll"] + 76715000 76720000 b000 MEM_FREE PAGE_NOACCESS Free + 76720000 76721000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [setupapi; "C:\Windows\SysWOW64\setupapi.dll"] 76721000 767d0000 af000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [setupapi; "C:\Windows\SysWOW64\setupapi.dll"] 767d0000 767d1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [setupapi; "C:\Windows\SysWOW64\setupapi.dll"] 767d1000 767d5000 4000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [setupapi; "C:\Windows\SysWOW64\setupapi.dll"] 767d5000 768bd000 e8000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [setupapi; "C:\Windows\SysWOW64\setupapi.dll"] + 768bd000 768c0000 3000 MEM_FREE PAGE_NOACCESS Free + 768c0000 768c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [KERNELBASE; "C:\Windows\SysWOW64\KERNELBASE.dll"] 768c1000 76900000 3f000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [KERNELBASE; "C:\Windows\SysWOW64\KERNELBASE.dll"] 76900000 76902000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [KERNELBASE; "C:\Windows\SysWOW64\KERNELBASE.dll"] 76902000 76906000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [KERNELBASE; "C:\Windows\SysWOW64\KERNELBASE.dll"] + 76906000 76910000 a000 MEM_FREE PAGE_NOACCESS Free + 76910000 76911000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [comdlg32; "C:\Windows\SysWOW64\comdlg32.dll"] 76911000 76967000 56000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [comdlg32; "C:\Windows\SysWOW64\comdlg32.dll"] 76967000 76969000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [comdlg32; "C:\Windows\SysWOW64\comdlg32.dll"] 76969000 7696b000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [comdlg32; "C:\Windows\SysWOW64\comdlg32.dll"] 7696b000 7698b000 20000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [comdlg32; "C:\Windows\SysWOW64\comdlg32.dll"] + 7698b000 76990000 5000 MEM_FREE PAGE_NOACCESS Free + 76990000 76991000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [devobj; "C:\Windows\SysWOW64\devobj.dll"] 76991000 7699f000 e000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [devobj; "C:\Windows\SysWOW64\devobj.dll"] 7699f000 769a0000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [devobj; "C:\Windows\SysWOW64\devobj.dll"] 769a0000 769a2000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [devobj; "C:\Windows\SysWOW64\devobj.dll"] + 769a2000 769b0000 e000 MEM_FREE PAGE_NOACCESS Free + 769b0000 769b1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [psapi; "C:\Windows\SysWOW64\psapi.dll"] 769b1000 769b2000 1000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [psapi; "C:\Windows\SysWOW64\psapi.dll"] 769b2000 769b3000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [psapi; "C:\Windows\SysWOW64\psapi.dll"] 769b3000 769b5000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [psapi; "C:\Windows\SysWOW64\psapi.dll"] + 769b5000 769c0000 b000 MEM_FREE PAGE_NOACCESS Free + 769c0000 769c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 769c1000 76a60000 9f000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 76a60000 76a61000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 76a61000 76a62000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 76a62000 76a65000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 76a65000 76a67000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] 76a67000 76a6c000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [msvcrt; "C:\Windows\SysWOW64\msvcrt.dll"] + 76a6c000 76a80000 14000 MEM_FREE PAGE_NOACCESS Free + 76a80000 76a81000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [crypt32; "C:\Windows\SysWOW64\crypt32.dll"] 76a81000 76b36000 b5000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [crypt32; "C:\Windows\SysWOW64\crypt32.dll"] 76b36000 76b37000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [crypt32; "C:\Windows\SysWOW64\crypt32.dll"] 76b37000 76b38000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [crypt32; "C:\Windows\SysWOW64\crypt32.dll"] 76b38000 76b9e000 66000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [crypt32; "C:\Windows\SysWOW64\crypt32.dll"] + 76b9e000 76ba0000 2000 MEM_FREE PAGE_NOACCESS Free + 76ba0000 76ba1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76ba1000 76bb0000 f000 MEM_IMAGE MEM_RESERVE Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76bb0000 76c1d000 6d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c1d000 76c20000 3000 MEM_IMAGE MEM_RESERVE Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c20000 76c21000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c21000 76c30000 f000 MEM_IMAGE MEM_RESERVE Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c30000 76c8b000 5b000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c8b000 76c90000 5000 MEM_IMAGE MEM_RESERVE Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c90000 76c94000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [user32; "C:\Windows\SysWOW64\user32.dll"] 76c94000 76ca0000 c000 MEM_IMAGE MEM_RESERVE Image [user32; "C:\Windows\SysWOW64\user32.dll"] + 76ca0000 76ca1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shlwapi; "C:\Windows\SysWOW64\shlwapi.dll"] 76ca1000 76cf2000 51000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [shlwapi; "C:\Windows\SysWOW64\shlwapi.dll"] 76cf2000 76cf3000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [shlwapi; "C:\Windows\SysWOW64\shlwapi.dll"] 76cf3000 76cf7000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [shlwapi; "C:\Windows\SysWOW64\shlwapi.dll"] + 76cf7000 76fb0000 2b9000 MEM_FREE PAGE_NOACCESS Free + 76fb0000 770cf000 11f000 MEM_PRIVATE MEM_RESERVE + 770cf000 770d0000 1000 MEM_FREE PAGE_NOACCESS Free + 770d0000 771ca000 fa000 MEM_PRIVATE MEM_RESERVE + 771ca000 773e0000 216000 MEM_FREE PAGE_NOACCESS Free + 773e0000 773e1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY 773e1000 774e3000 102000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ 774e3000 77512000 2f000 MEM_IMAGE MEM_COMMIT PAGE_READONLY 77512000 77513000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 77513000 77514000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY 77514000 77515000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 77515000 77517000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY 77517000 77518000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 77518000 77519000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY 77519000 7751b000 2000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE 7751b000 7751e000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY 7751e000 77589000 6b000 MEM_IMAGE MEM_COMMIT PAGE_READONLY + 77589000 77590000 7000 MEM_FREE PAGE_NOACCESS Free + 77590000 77591000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [nsi; "C:\Windows\SysWOW64\nsi.dll"] 77591000 77593000 2000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [nsi; "C:\Windows\SysWOW64\nsi.dll"] 77593000 77594000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [nsi; "C:\Windows\SysWOW64\nsi.dll"] 77594000 77596000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [nsi; "C:\Windows\SysWOW64\nsi.dll"] + 77596000 775c0000 2a000 MEM_FREE PAGE_NOACCESS Free + 775c0000 775c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 775c1000 775d0000 f000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 775d0000 776a6000 d6000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776a6000 776b0000 a000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776b0000 776b1000 1000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776b1000 776c0000 f000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c0000 776c1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c1000 776c2000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c2000 776c3000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c3000 776c4000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c4000 776c7000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c7000 776c8000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c8000 776c9000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776c9000 776d0000 7000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 776d0000 77727000 57000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 77727000 77730000 9000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 77730000 77735000 5000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] 77735000 77740000 b000 MEM_IMAGE MEM_RESERVE Image [ntdll; "C:\Windows\SysWOW64\ntdll.dll"] + 77740000 7efe0000 78a0000 MEM_FREE PAGE_NOACCESS Free + 7efe0000 7efe5000 5000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [Read Only Shared Memory] 7efe5000 7f0e0000 fb000 MEM_MAPPED MEM_RESERVE + 7f0e0000 7ffe0000 f00000 MEM_PRIVATE MEM_RESERVE + 7ffe0000 7ffe1000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READONLY Other [User Shared Data] 7ffe1000 7fff0000 f000 MEM_PRIVATE MEM_RESERVE + 7fff0000 fd6de000 7d6ee000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fd6de000 fd7de000 100000 MEM_PRIVATE MEM_RESERVE + fd7de000 fff8c000 27ae000 MEM_FREE PAGE_NOACCESS Free + fff8c000 fff8e000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff8e000 fff8f000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~13; 1524.e58] + fff8f000 fff91000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff91000 fff92000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~12; 1524.9b8] + fff92000 fff94000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff94000 fff95000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~11; 1524.1024] + fff95000 fff97000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff97000 fff98000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~10; 1524.15f0] + fff98000 fff9a000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff9a000 fff9b000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~9; 1524.1428] + fff9b000 fff9d000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fff9d000 fff9e000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~8; 1524.15b4] + fff9e000 fffa0000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffa0000 fffa1000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~7; 1524.16ec] + fffa1000 fffa3000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffa3000 fffa4000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~6; 1524.ed4] + fffa4000 fffa6000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffa6000 fffa7000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~5; 1524.870] + fffa7000 fffa9000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffa9000 fffaa000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~4; 1524.14d0] + fffaa000 fffac000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffac000 fffad000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~14; 1524.e84] + fffad000 fffaf000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffaf000 fffb0000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~3; 1524.1658] + fffb0000 fffd3000 23000 MEM_MAPPED MEM_COMMIT PAGE_READONLY Other [NLS Tables] + fffd3000 fffd5000 2000 MEM_FREE PAGE_NOACCESS Free + fffd5000 fffd7000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffd7000 fffd8000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~2; 1524.1314] + fffd8000 fffda000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffda000 fffdb000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~1; 1524.16e8] + fffdb000 fffdd000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE fffdd000 fffde000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE TEB [~0; 1524.14f4] + fffde000 fffdf000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE PEB [1524] + fffdf000 fffe0000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE + fffe0000 ffff0000 10000 MEM_PRIVATE MEM_RESERVE PAGE_NOACCESS 0:000> dc 7fff0000 7fff0000 45474150 34365544 0000000f 000023f0 PAGEDU64.....#.. 7fff0010 46a71000 00000000 00000000 fffffa80 ...F............ 7fff0020 bcf43a60 fffff803 bcf0fc10 fffff803 `:.............. 7fff0030 00008664 00000002 000000ef 45474150 d...........PAGE 7fff0040 018b6540 fffffa80 00000000 00000000 @e.............. 7fff0050 00000000 00000000 00000000 00000000 ................ 7fff0060 00000000 00000000 00000000 00000000 ................ 7fff0070 00000000 00000000 00000000 00000000 ................ 0:000> .writemem c:\TEMP\windbg.dmp 7fff0000 L?7d6ee000 Writing 7d6ee000 bytes. 0:000> !runaway f User Mode Time Thread Time 0:14f4 0 days 0:00:00.624 9:1428 0 days 0:00:00.109 8:15b4 0 days 0:00:00.062 1:16e8 0 days 0:00:00.062 10:15f0 0 days 0:00:00.015 3:1658 0 days 0:00:00.015 2:1314 0 days 0:00:00.015 14:e84 0 days 0:00:00.000 13:e58 0 days 0:00:00.000 12:9b8 0 days 0:00:00.000 11:1024 0 days 0:00:00.000 7:16ec 0 days 0:00:00.000 6:ed4 0 days 0:00:00.000 5:870 0 days 0:00:00.000 4:14d0 0 days 0:00:00.000 Kernel Mode Time Thread Time 14:e84 0 days 0:00:08.127 0:14f4 0 days 0:00:00.577 8:15b4 0 days 0:00:00.109 9:1428 0 days 0:00:00.078 1:16e8 0 days 0:00:00.078 10:15f0 0 days 0:00:00.015 3:1658 0 days 0:00:00.015 2:1314 0 days 0:00:00.015 13:e58 0 days 0:00:00.000 12:9b8 0 days 0:00:00.000 11:1024 0 days 0:00:00.000 7:16ec 0 days 0:00:00.000 6:ed4 0 days 0:00:00.000 5:870 0 days 0:00:00.000 4:14d0 0 days 0:00:00.000 Elapsed Time Thread Time 0:14f4 0 days 0:04:15.041 1:16e8 0 days 0:00:42.483 3:1658 0 days 0:00:42.452 2:1314 0 days 0:00:42.452 5:870 0 days 0:00:42.327 4:14d0 0 days 0:00:42.327 7:16ec 0 days 0:00:42.218 6:ed4 0 days 0:00:42.218 11:1024 0 days 0:00:42.124 10:15f0 0 days 0:00:42.124 9:1428 0 days 0:00:42.124 8:15b4 0 days 0:00:42.124 12:9b8 0 days 0:00:42.046 13:e58 0 days 0:00:40.533 14:e84 0 days 0:00:35.338 0:000> q quit: