Process: emacs.exe PID: 6604 Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Total 375.320 85.248 32.456 14.464 17.992 15.256 Image 36.556 36.556 10.204 3.896 6.308 3.580 252 Private 266.424 8.828 8.780 8.776 4 4 31 Shareable 41.620 29.692 11.164 11.164 11.156 30 Mapped File 7.188 7.188 504 504 504 4 Heap 6.976 2.524 1.352 1.340 12 12 29 Stack 16.384 288 280 280 6 System 172 172 172 172 Free 1.721.940 74 Address Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Protection Details 00010000 Heap (Mapped) 64 64 12 12 12 1 Read/Write Heap ID: 1 00020000 Private 4 4 4 4 1 Read/Write 00030000 Thread Stack 8.192 268 264 264 3 Read/Write Thread ID: 6768 00030000 Reserved 7.924 Thread ID: 0 007ED000 Private 4 4 Read/Write/Guard Thread ID: 0 007EE000 Private 264 264 264 264 Read/Write Thread ID: 0 00830000 Shareable 16 16 16 16 16 1 Read 00840000 Shareable 8 8 8 8 1 Read 00850000 Private 4 4 4 4 1 Read/Write 00860000 Heap (Private) 1.024 844 732 732 2 Read/Write Heap ID: 0 (Default) 00860000 Private 844 844 732 732 Read/Write Heap ID: 0 (Default) 00933000 Reserved 180 Heap ID: 0 (Default) 00960000 Mapped File 3.580 3.580 376 376 376 1 Read C:\Windows\System32\locale.nls 00CE0000 Shareable 4 4 4 4 4 1 Read 00CF0000 Image 72 72 68 56 12 12 5 Execute/Copy on Write C:\Windows\System32\btpload32.dll 00CF0000 Image 4 4 4 4 4 Read Header 00CF1000 Image 32 32 32 32 Execute/Read .text 00CF9000 Image 12 12 12 12 Read .rdata 00CFC000 Image 12 12 12 12 Read/Write .data 00CFF000 Image 4 4 4 4 4 Read .rsrc 00D00000 Image 8 8 4 4 4 Read .reloc 00D10000 Shareable 4 4 4 4 4 1 Read 00D20000 Shareable 8 8 8 8 8 1 Read 00D30000 Shareable 8 8 8 8 8 1 Read 00D40000 Shareable 8 8 8 8 8 1 Read 00D50000 Shareable 8 8 8 8 8 1 Read 00D60000 Heap (Private) 64 24 24 24 2 Read/Write Heap ID: 5 00D60000 Private 24 24 24 24 Read/Write Heap ID: 0 (Default) 00D66000 Reserved 40 Heap ID: 0 (Default) 00D70000 Mapped File 4 4 4 4 4 1 Read C:\Windows\System32\oleaccrc.dll 00D80000 Heap (Private) 64 64 64 64 1 Read/Write Heap ID: 2 00D90000 Shareable 800 116 116 116 116 4 Read 00D90000 Mapped 104 104 104 104 104 Read 00DAA000 Reserved 664 00E50000 Mapped 12 12 12 12 12 Read 00E53000 Reserved 20 00E60000 Shareable 1.036 1.036 196 196 196 1 Read 00F70000 Shareable 4 4 4 4 4 1 Read 00F80000 Shareable 4 4 4 4 4 1 Read/Write 00F90000 Shareable 4 4 4 4 4 1 Read 00FA0000 Heap (Private) 64 4 4 4 2 Read/Write Heap ID: 6 00FA0000 Private 4 4 4 4 Read/Write Heap ID: 0 (Default) 00FA1000 Reserved 60 Heap ID: 0 (Default) 00FB0000 Image 244 244 240 208 32 32 6 Execute/Copy on Write C:\Windows\System32\btprof32.dll 00FB0000 Image 4 4 4 4 4 Read Header 00FB1000 Image 160 160 156 156 Execute/Read .text 00FD9000 Image 36 36 36 28 8 8 Read .rdata 00FE2000 Image 24 24 24 24 Read/Write .data 00FE8000 Image 4 4 4 4 4 Copy on write .tls 00FE9000 Image 4 4 4 4 4 Read .rsrc 00FEA000 Image 12 12 12 12 12 Read .reloc 00FF0000 Mapped File 24 24 24 24 24 1 Read C:\Windows\Registration\R000000000007.clb 01000000 Image 9.996 9.996 5.688 3.128 2.560 28 Execute/Copy on Write C:\Users\Public\Software\GNU\emacs-22.3\bin\emacs.exe 01000000 Image 4 4 4 4 Read Header 01001000 Image 1.372 1.372 1.316 1.316 Execute/Read .text 01158000 Image 8 8 8 8 Read/Write .data 0115A000 Image 1.144 1.144 1.100 1.100 Copy on write .data 01278000 Image 4 4 4 4 Read/Write .data 01279000 Image 8 8 8 8 Copy on write .data 0127B000 Image 4 4 4 4 Read/Write .data 0127C000 Image 12 12 12 12 Copy on write .data 0127F000 Image 92 92 92 92 Read .rdata 01296000 Image 52 52 52 52 Read/Write .bss 012A3000 Image 128 128 Copy on write .bss 012C3000 Image 12 12 12 12 Read/Write .bss 012C6000 Image 4 4 Copy on write .bss 012C7000 Image 60 60 60 60 Read/Write .bss 012D6000 Image 100 100 Copy on write .bss 012EF000 Image 8 8 8 8 Read/Write .bss 012F1000 Image 12 12 12 12 Copy on write .idata 012F4000 Image 28 28 16 16 Copy on write .rsrc 012FB000 Image 2.344 2.344 No access .stab 01545000 Image 1.512 1.512 No access .stabstr 016BF000 Image 12 12 12 12 Read/Write EMHEAP 016C2000 Image 16 16 Copy on write EMHEAP 016C6000 Image 12 12 12 12 Read/Write EMHEAP 016C9000 Image 4 4 Copy on write EMHEAP 016CA000 Image 1.092 1.092 1.092 1.092 Read/Write EMHEAP 017DB000 Image 16 16 Copy on write EMHEAP 017DF000 Image 1.828 1.828 1.828 1.828 Read/Write EMHEAP 019A8000 Image 56 56 Copy on write EMHEAP 019B6000 Image 36 36 36 36 Read/Write EMHEAP 019BF000 Image 16 16 Copy on write EMHEAP 019D0000 Shareable 12.288 2.044 972 972 972 2 Read 019D0000 Mapped 2.044 2.044 972 972 972 Read 01BCF000 Reserved 10.244 025D0000 Heap (Private) 1.024 80 80 80 2 Read/Write Heap ID: 2 025D0000 Private 80 80 80 80 Read/Write Heap ID: 0 (Default) 025E4000 Reserved 944 Heap ID: 0 (Default) 026D0000 Heap (Private) 64 32 32 32 2 Read/Write Heap ID: 3 026D0000 Private 32 32 32 32 Read/Write Heap ID: 0 (Default) 026D8000 Reserved 32 Heap ID: 0 (Default) 026E0000 Mapped File 3.580 3.580 100 100 100 1 Read C:\Windows\System32\locale.nls 02A60000 Heap (Private) 256 104 104 104 2 Read/Write Heap ID: 9 02A60000 Private 104 104 104 104 Read/Write Heap ID: 0 (Default) 02A7A000 Reserved 152 Heap ID: 0 (Default) 02AA0000 Private 64 4 2 No access 02AA0000 Private 4 4 Read/Write 02AA1000 Reserved 60 02AB0000 Private 4 4 4 4 1 Read/Write 02AC0000 Private 128 16 12 12 2 No access 02AC0000 Private 16 16 12 12 Read/Write 02AC4000 Reserved 112 02AE0000 Private 128 4 4 4 2 Read/Write 02AE0000 Private 4 4 4 4 Read/Write 02AE1000 Reserved 124 02B00000 Private 4 4 4 4 1 Read/Write 02B10000 Heap (Private) 64 40 40 40 2 Read/Write Heap ID: 8 02B10000 Private 40 40 40 40 Read/Write Heap ID: 0 (Default) 02B1A000 Reserved 24 Heap ID: 0 (Default) 02B20000 Shareable 704 704 268 268 268 1 Read 02BD0000 Private 4 4 4 4 1 Read/Write 02BE0000 Heap (Private) 64 16 16 16 2 Read/Write Heap ID: 4 02BE0000 Private 16 16 16 16 Read/Write Heap ID: 0 (Default) 02BE4000 Reserved 48 Heap ID: 0 (Default) 02BF0000 Private 512 4 4 4 2 Read/Write 02BF0000 Private 4 4 4 4 Read/Write 02BF1000 Reserved 508 02C70000 Image 72 72 68 52 16 16 7 Execute/Copy on Write C:\Program Files\Lenovo\HOTKEY\HKVOLKEY.dll 02C70000 Image 4 4 4 4 4 Read Header 02C71000 Image 36 36 36 36 Execute/Read .text 02C7A000 Image 8 8 8 4 4 4 Read .rdata 02C7C000 Image 4 4 4 4 Read/Write .data 02C7D000 Image 4 4 Copy on write .data 02C7E000 Image 8 8 8 8 Read/Write .data 02C80000 Image 4 4 4 4 4 Read .rsrc 02C81000 Image 4 4 4 4 4 Read .reloc 02C90000 Heap (Private) 1.024 1.024 16 16 1 Read/Write Heap ID: 7 02D90000 Heap (Private) 1.024 48 48 48 2 Read/Write Heap ID: 3 02D90000 Private 48 48 48 48 Read/Write Heap ID: 0 (Default) 02D9C000 Reserved 976 Heap ID: 0 (Default) 02E90000 Private 4 4 4 4 1 Read/Write 02EA0000 Private 4 4 4 4 1 Read/Write 02EB0000 Private 4 4 4 4 1 Read/Write 02EC0000 Private 4 4 4 4 1 Read/Write 02ED0000 Private 4 4 4 4 1 Read/Write 02F00000 Heap (Private) 1.024 72 72 72 2 Read/Write Heap ID: 8 02F00000 Private 72 72 72 72 Read/Write Heap ID: 0 (Default) 02F12000 Reserved 952 Heap ID: 0 (Default) 03000000 Heap (Private) 1.024 72 72 72 2 Read/Write Heap ID: 11 03000000 Private 72 72 72 72 Read/Write Heap ID: 0 (Default) 03012000 Reserved 952 Heap ID: 0 (Default) 031E0000 Heap (Private) 64 28 28 28 2 Read/Write Heap ID: 11 031E0000 Private 28 28 28 28 Read/Write Heap ID: 0 (Default) 031E7000 Reserved 36 Heap ID: 0 (Default) 032E0000 Heap (Private) 64 8 8 8 2 Read/Write Heap ID: 10 032E0000 Private 8 8 8 8 Read/Write Heap ID: 0 (Default) 032E2000 Reserved 56 Heap ID: 0 (Default) 03400000 Shareable 4.096 4.096 1 Read 03800000 Shareable 4.096 4.096 156 156 156 1 Read 03C00000 Private 4.096 12 12 12 4 Read/Write 03C00000 Private 4 4 4 4 Read/Write 03C01000 Reserved 16 03C05000 Private 8 8 8 8 Read/Write 03C07000 Reserved 4.068 04000000 Shareable 4.096 4.096 64 64 64 1 Read 04400000 Thread Stack 8.192 20 16 16 3 Read/Write Thread ID: 2732 04400000 Reserved 8.172 Thread ID: 0 04BFB000 Private 4 4 Read/Write/Guard Thread ID: 0 04BFC000 Private 16 16 16 16 Read/Write Thread ID: 0 04C00000 Shareable 4.096 4.096 64 64 64 1 Read 05000000 Shareable 2.712 2.712 2.700 2.700 2.700 1 Read/Write 052B0000 Shareable 1.980 1.980 1.980 1.980 1.980 1 Read/Write 054A0000 Shareable 1.980 1.980 1.980 1.980 1.980 1 Read/Write 05780000 Shareable 2.496 2.496 2.484 2.484 2.484 1 Read/Write 10000000 Image 68 68 60 12 48 48 5 Execute/Copy on Write C:\PROGRA~1\KL\WS\r3hook.dll 10000000 Image 4 4 4 4 4 Read Header 10001000 Image 36 36 36 36 36 Execute/Read .text 1000A000 Image 12 12 8 4 4 4 Read .rdata 1000D000 Image 8 8 8 8 Read/Write .data 1000F000 Image 4 4 4 4 4 Read .rsrc 10010000 Image 4 4 Read .reloc 100D0000 Private 261.312 8.664 8.624 8.624 2 No access 100D0000 Private 8.664 8.664 8.624 8.624 Read/Write 10946000 Reserved 252.648 6D570000 Image 156 156 112 16 96 6 Execute/Copy on Write C:\Windows\System32\crtdll.dll 6D570000 Image 4 4 4 4 Read Header 6D571000 Image 116 116 88 4 84 Execute/Read .text 6D58E000 Image 8 8 8 8 Read/Write .data 6D590000 Image 12 12 4 4 Copy on write .data 6D593000 Image 4 4 4 4 Read/Write .data 6D594000 Image 4 4 4 4 Read .rsrc 6D595000 Image 8 8 Read .reloc 6FFF0000 Private 64 64 64 64 1 Execute/Read/Write 70A80000 Image 500 500 52 8 44 9 Execute/Copy on Write C:\Users\Public\Software\GNU\emacs-22.3\bin\libXpm.dll 70A80000 Image 4 4 4 4 Read Header 70A81000 Image 28 28 28 28 Execute/Read .text 70A88000 Image 4 4 4 4 Copy on write .data 70A89000 Image 4 4 4 4 Read .rdata 70A8A000 Image 4 4 4 4 Read/Write .bss 70A8B000 Image 4 4 4 4 Read .edata 70A8C000 Image 4 4 4 4 Read/Write .idata 70A8D000 Image 4 4 Read .reloc 70A8E000 Image 108 108 No access .stab 70AA9000 Image 336 336 No access .stabstr 712F0000 Image 880 880 100 20 80 80 8 Execute/Copy on Write C:\Windows\System32\dbghelp.dll 712F0000 Image 4 4 4 4 4 Read Header 712F1000 Image 732 732 76 4 72 72 Execute/Read .text 713A8000 Image 4 4 4 4 Read/Write .data 713A9000 Image 4 4 Copy on write .data 713AA000 Image 8 8 8 8 Read/Write .data 713AC000 Image 88 88 Copy on write .data 713C2000 Image 4 4 4 4 Read/Write .data 713C3000 Image 4 4 4 4 4 Read .rsrc 713C4000 Image 32 32 Read .reloc 72D30000 Image 264 264 80 12 68 68 5 Execute/Copy on Write C:\Windows\System32\winspool.drv 72D30000 Image 4 4 4 4 4 Read Header 72D31000 Image 192 192 64 4 60 60 Execute/Read .text 72D61000 Image 4 4 Copy on write .data 72D62000 Image 8 8 8 8 Read/Write .data 72D64000 Image 44 44 4 4 4 Read .rsrc 72D6F000 Image 12 12 Read .reloc 742F0000 Image 228 228 36 8 28 28 5 Execute/Copy on Write C:\Windows\System32\oleacc.dll 742F0000 Image 4 4 4 4 4 Read Header 742F1000 Image 176 176 24 4 20 20 Execute/Read .text 7431D000 Image 4 4 Execute/Read .orpc 7431E000 Image 4 4 4 4 Read/Write .data 7431F000 Image 4 4 Copy on write .data 74320000 Image 24 24 4 4 4 Read .rsrc 74326000 Image 12 12 Read .reloc 74800000 Image 200 200 40 12 28 28 5 Execute/Copy on Write C:\Windows\System32\winmm.dll 74800000 Image 4 4 4 4 4 Read Header 74801000 Image 152 152 24 4 20 20 Execute/Read .text 74827000 Image 8 8 8 8 Read/Write .data 74829000 Image 4 4 Copy on write .data 7482A000 Image 4 4 Read .guids 7482B000 Image 16 16 4 4 4 Read .rsrc 7482F000 Image 12 12 Read .reloc 749A0000 Image 252 252 148 8 140 140 5 Execute/Copy on Write C:\Windows\System32\uxtheme.dll 749A0000 Image 4 4 4 4 4 Read Header 749A1000 Image 220 220 132 4 128 128 Execute/Read .text 749D8000 Image 4 4 4 4 Read/Write .data 749D9000 Image 12 12 4 4 4 Copy on write .data 749DC000 Image 4 4 4 4 4 Read .rsrc 749DD000 Image 8 8 Read .reloc 75620000 Image 80 80 28 8 20 20 4 Execute/Copy on Write C:\Windows\System32\mpr.dll 75620000 Image 4 4 4 4 4 Read Header 75621000 Image 64 64 16 4 12 12 Execute/Read .text 75631000 Image 4 4 4 4 Read/Write .data 75632000 Image 4 4 4 4 4 Read .rsrc 75633000 Image 4 4 Read .reloc 756C0000 Image 468 468 72 32 40 40 7 Execute/Copy on Write C:\Windows\System32\netapi32.dll 756C0000 Image 4 4 4 4 4 Read Header 756C1000 Image 400 400 36 4 32 32 Execute/Read .text 75725000 Image 8 8 8 8 Read/Write .data 75727000 Image 12 12 Copy on write .data 7572A000 Image 20 20 20 20 Read/Write .data 7572F000 Image 8 8 Copy on write .data 75731000 Image 4 4 4 4 4 Read .rsrc 75732000 Image 12 12 Read .reloc 757F0000 Image 1.656 1.656 200 16 184 184 7 Execute/Copy on Write C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll 757F0000 Image 4 4 4 4 4 Read Header 757F1000 Image 1.280 1.280 176 4 172 172 Execute/Read .text 75931000 Image 4 4 4 4 Read/Write .data 75932000 Image 4 4 Copy on write .data 75933000 Image 8 8 8 8 Read/Write .data 75935000 Image 40 40 4 4 4 Copy on write .data 7593F000 Image 260 260 4 4 4 Read .rsrc 75980000 Image 56 56 Read .reloc 75B90000 Image 176 176 56 8 48 48 4 Execute/Copy on Write C:\Windows\System32\apphelp.dll 75B90000 Image 4 4 4 4 4 Read Header 75B91000 Image 156 156 44 4 40 40 Execute/Read .text 75BB8000 Image 4 4 4 4 Read/Write .data 75BB9000 Image 4 4 4 4 4 Read .rsrc 75BBA000 Image 8 8 Read .reloc 75D50000 Image 28 28 20 8 12 12 4 Execute/Copy on Write C:\Windows\System32\psapi.dll 75D50000 Image 4 4 4 4 4 Read Header 75D51000 Image 12 12 8 4 4 4 Execute/Read .text 75D54000 Image 4 4 4 4 Read/Write .data 75D55000 Image 4 4 4 4 4 Read .rsrc 75D56000 Image 4 4 Read .reloc 75D80000 Image 11.328 11.328 220 48 172 172 7 Execute/Copy on Write C:\Windows\System32\shell32.dll 75D80000 Image 4 4 4 4 4 Read Header 75D81000 Image 3.528 3.528 144 8 136 136 Execute/Read .text 760F3000 Image 32 32 32 32 Read/Write .data 760FB000 Image 36 36 Copy on write .data 76104000 Image 8 8 8 8 Read/Write .data 76106000 Image 16 16 8 8 8 Copy on write .data 7610A000 Image 7.516 7.516 24 24 24 Read .rsrc 76861000 Image 188 188 Read .reloc 76990000 Image 1.296 1.296 200 24 176 176 5 Execute/Copy on Write C:\Windows\System32\ole32.dll 76990000 Image 4 4 4 4 4 Read Header 76991000 Image 1.176 1.176 164 4 160 160 Execute/Read .text 76AB7000 Image 28 28 8 8 8 Execute/Read .orpc 76ABE000 Image 20 20 20 20 Read/Write .data 76AC3000 Image 8 8 Copy on write .data 76AC5000 Image 8 8 4 4 4 Read .rsrc 76AC7000 Image 52 52 Read .reloc 76AE0000 Image 300 300 100 8 92 92 5 Execute/Copy on Write C:\Windows\System32\gdi32.dll 76AE0000 Image 4 4 4 4 4 Read Header 76AE1000 Image 276 276 84 4 80 80 Execute/Read .text 76B26000 Image 4 4 4 4 Read/Write .data 76B27000 Image 4 4 4 4 4 Copy on write .data 76B28000 Image 4 4 4 4 4 Read .rsrc 76B29000 Image 8 8 Read .reloc 76B30000 Image 528 528 228 16 212 212 5 Execute/Copy on Write C:\Windows\System32\clbcatq.dll 76B30000 Image 4 4 4 4 4 Read Header 76B31000 Image 480 480 208 4 204 204 Execute/Read .text 76BA9000 Image 12 12 12 12 Read/Write .data 76BAC000 Image 4 4 Copy on write .data 76BAD000 Image 8 8 4 4 4 Read .rsrc 76BAF000 Image 20 20 Read .reloc 76CF0000 Image 776 776 204 8 196 196 4 Execute/Copy on Write C:\Windows\System32\rpcrt4.dll 76CF0000 Image 4 4 4 4 4 Read Header 76CF1000 Image 688 688 180 4 176 176 Execute/Read .text 76D9D000 Image 44 44 12 12 12 Execute/Read .orpc 76DA8000 Image 4 4 4 4 Read/Write .data 76DA9000 Image 12 12 4 4 4 Read .rsrc 76DAC000 Image 24 24 Read .reloc 76DC0000 Image 460 460 44 8 36 36 5 Execute/Copy on Write C:\Windows\System32\comdlg32.dll 76DC0000 Image 4 4 4 4 4 Read Header 76DC1000 Image 316 316 28 4 24 24 Execute/Read .text 76E10000 Image 4 4 4 4 Read/Write .data 76E11000 Image 12 12 Copy on write .data 76E14000 Image 108 108 8 8 8 Read .rsrc 76E2F000 Image 16 16 Read .reloc 76E90000 Image 36 36 20 8 12 12 4 Execute/Copy on Write C:\Windows\System32\lpk.dll 76E90000 Image 4 4 4 4 4 Read Header 76E91000 Image 20 20 8 4 4 4 Execute/Read .text 76E96000 Image 4 4 4 4 Read/Write .data 76E97000 Image 4 4 4 4 4 Read .rsrc 76E98000 Image 4 4 Read .reloc 76EA0000 Image 564 564 64 16 48 48 4 Execute/Copy on Write C:\Windows\System32\oleaut32.dll 76EA0000 Image 4 4 4 4 4 Read Header 76EA1000 Image 516 516 44 4 40 40 Execute/Read .text 76F22000 Image 4 4 Execute/Read .orpc 76F23000 Image 12 12 12 12 Read/Write .data 76F26000 Image 4 4 4 4 4 Read .rsrc 76F27000 Image 24 24 Read .reloc 76F30000 Image 800 800 280 12 268 268 4 Execute/Copy on Write C:\Windows\System32\msctf.dll 76F30000 Image 4 4 4 4 4 Read Header 76F31000 Image 516 516 248 4 244 244 Execute/Read .text 76FB2000 Image 8 8 8 8 Read/Write .data 76FB4000 Image 252 252 20 20 20 Read .rsrc 76FF3000 Image 20 20 Read .reloc 77000000 Image 680 680 292 20 272 252 9 Execute/Copy on Write C:\Windows\System32\msvcrt.dll 77000000 Image 4 4 4 4 4 Read Header 77001000 Image 628 628 264 4 260 244 Execute/Read .text 7709E000 Image 4 4 4 4 Read/Write .data 7709F000 Image 4 4 Copy on write .data 770A0000 Image 8 8 8 8 Read/Write .data 770A2000 Image 4 4 4 4 Copy on write .data 770A3000 Image 4 4 4 4 Read/Write .data 770A4000 Image 4 4 Copy on write .data 770A5000 Image 4 4 4 4 4 Read .rsrc 770A6000 Image 16 16 Read .reloc 770E0000 Image 792 792 172 20 152 152 7 Execute/Copy on Write C:\Windows\System32\advapi32.dll 770E0000 Image 4 4 4 4 4 Read Header 770E1000 Image 612 612 140 4 136 136 Execute/Read .text 7717A000 Image 4 4 4 4 Read/Write .data 7717B000 Image 4 4 Copy on write .data 7717C000 Image 12 12 12 12 Read/Write .data 7717F000 Image 40 40 8 8 8 Copy on write .data 77189000 Image 92 92 4 4 4 Read .rsrc 771A0000 Image 24 24 Read .reloc 77340000 Image 120 120 40 8 32 32 4 Execute/Copy on Write C:\Windows\System32\imm32.dll 77340000 Image 4 4 4 4 4 Read Header 77341000 Image 88 88 28 4 24 24 Execute/Read .text 77357000 Image 4 4 4 4 Read/Write .data 77358000 Image 20 20 4 4 4 Read .rsrc 7735D000 Image 4 4 Read .reloc 77360000 Image 500 500 104 16 88 88 7 Execute/Copy on Write C:\Windows\System32\usp10.dll 77360000 Image 4 4 4 4 4 Read Header 77361000 Image 344 344 80 4 76 76 Execute/Read .text 773B7000 Image 4 4 4 4 Read/Write .data 773B8000 Image 12 12 Copy on write .data 773BB000 Image 8 8 8 8 Read/Write .data 773BD000 Image 40 40 Copy on write .data 773C7000 Image 8 8 4 4 4 Read Shared 773C9000 Image 72 72 4 4 4 Read .rsrc 773DB000 Image 8 8 Read .reloc 773E0000 Image 352 352 120 12 108 108 4 Execute/Copy on Write C:\Windows\System32\shlwapi.dll 773E0000 Image 4 4 4 4 4 Read Header 773E1000 Image 324 324 104 4 100 100 Execute/Read .text 77432000 Image 8 8 8 8 Read/Write .data 77434000 Image 4 4 4 4 4 Read .rsrc 77435000 Image 12 12 Read .reloc 77440000 Image 628 628 244 8 236 236 5 Execute/Copy on Write C:\Windows\System32\user32.dll 77440000 Image 4 4 4 4 4 Read Header 77441000 Image 416 416 220 4 216 216 Execute/Read .text 774A9000 Image 4 4 4 4 Read/Write .data 774AA000 Image 4 4 4 4 4 Copy on write .data 774AB000 Image 184 184 12 12 12 Read .rsrc 774D9000 Image 16 16 Read .reloc 774E0000 Image 1.180 1.180 448 36 412 412 7 Execute/Copy on Write C:\Windows\System32\ntdll.dll 774E0000 Image 4 4 4 4 Execute/Read/Write Header 774E1000 Image 776 776 420 12 408 408 Execute/Read .text 775A3000 Image 4 4 Execute/Read RT 775A4000 Image 12 12 12 12 Read/Write .data 775A7000 Image 4 4 Copy on write .data 775A8000 Image 8 8 8 8 Read/Write .data 775AA000 Image 20 20 4 4 4 Copy on write .data 775AF000 Image 332 332 Read .rsrc 77602000 Image 20 20 Read .reloc 77610000 Image 876 876 356 16 340 332 4 Execute/Copy on Write C:\Windows\System32\kernel32.dll 77610000 Image 4 4 4 4 4 Read Header 77611000 Image 816 816 336 4 332 324 Execute/Read .text 776DD000 Image 12 12 12 12 Read/Write .data 776E0000 Image 4 4 4 4 4 Read .rsrc 776E1000 Image 40 40 Read .reloc 776F0000 Private 4 4 4 4 1 Execute/Read/Write 7F6F0000 Shareable 1.024 24 24 24 24 2 Read 7F6F0000 Mapped 24 24 24 24 24 Read 7F6F6000 Reserved 1.000 7FFB0000 Shareable 140 140 84 84 84 1 Read 7FFDD000 Private 4 4 4 4 1 Read/Write 7FFDE000 Private 4 4 4 4 1 Read/Write 7FFDF000 Private 4 4 4 4 1 Read/Write 7FFE0000 Private 64 4 4 4 4 2 Read 7FFE0000 Private 4 4 4 4 4 Read 7FFE1000 Reserved 60