Process: emacs.exe PID: 7068 Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Total 400.344 363.360 291.112 270.448 20.664 17.636 Image 58.468 58.468 12.568 5.820 6.748 3.728 297 Private 266.936 261.936 261.876 261.872 4 4 31 Shareable 43.964 31.900 13.432 13.432 13.424 30 Mapped File 7.188 7.188 468 468 468 4 Heap 6.976 2.568 1.476 1.464 12 12 28 Stack 16.384 872 864 864 6 System 428 428 428 428 Free 1.697.172 77 Address Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Protection Details 00010000 Heap (Mapped) 64 64 12 12 12 1 Read/Write Heap ID: 1 00020000 Private 4 4 4 4 1 Read/Write 00030000 Thread Stack 8.192 852 848 848 3 Read/Write Thread ID: 304 00030000 Reserved 7.340 Thread ID: 0 0075B000 Private 4 4 Read/Write/Guard Thread ID: 0 0075C000 Private 848 848 848 848 Read/Write Thread ID: 0 00830000 Shareable 16 16 16 16 16 1 Read 00840000 Shareable 8 8 8 8 1 Read 00850000 Private 4 4 4 4 1 Read/Write 00860000 Shareable 4 4 4 4 4 1 Read 00870000 Heap (Private) 64 16 16 16 2 Read/Write Heap ID: 3 00870000 Private 16 16 16 16 Read/Write Heap ID: 0 (Default) 00874000 Reserved 48 Heap ID: 0 (Default) 00880000 Image 72 72 68 56 12 12 5 Execute/Copy on Write C:\Windows\System32\btpload32.dll 00880000 Image 4 4 4 4 4 Read Header 00881000 Image 32 32 32 32 Execute/Read .text 00889000 Image 12 12 12 12 Read .rdata 0088C000 Image 12 12 12 12 Read/Write .data 0088F000 Image 4 4 4 4 4 Read .rsrc 00890000 Image 8 8 4 4 4 Read .reloc 008A0000 Shareable 4 4 4 4 4 1 Read 008B0000 Heap (Private) 1.024 692 660 660 2 Read/Write Heap ID: 0 (Default) 008B0000 Private 692 692 660 660 Read/Write Heap ID: 0 (Default) 0095D000 Reserved 332 Heap ID: 0 (Default) 009B0000 Mapped File 3.580 3.580 340 340 340 1 Read C:\Windows\System32\locale.nls 00D30000 Shareable 8 8 8 8 8 1 Read 00D40000 Shareable 8 8 8 8 8 1 Read 00D50000 Shareable 8 8 8 8 8 1 Read 00D60000 Shareable 8 8 8 8 8 1 Read 00D70000 Mapped File 4 4 4 4 4 1 Read C:\Windows\System32\oleaccrc.dll 00D80000 Shareable 4 4 4 4 4 1 Read 00D90000 Heap (Private) 64 64 64 64 1 Read/Write Heap ID: 2 00DA0000 Shareable 800 116 112 112 112 4 Read 00DA0000 Mapped 104 104 100 100 100 Read 00DBA000 Reserved 664 00E60000 Mapped 12 12 12 12 12 Read 00E63000 Reserved 20 00E70000 Shareable 1.036 1.036 184 184 184 1 Read 00F80000 Image 244 244 240 208 32 32 6 Execute/Copy on Write C:\Windows\System32\btprof32.dll 00F80000 Image 4 4 4 4 4 Read Header 00F81000 Image 160 160 156 156 Execute/Read .text 00FA9000 Image 36 36 36 28 8 8 Read .rdata 00FB2000 Image 24 24 24 24 Read/Write .data 00FB8000 Image 4 4 4 4 4 Copy on write .tls 00FB9000 Image 4 4 4 4 4 Read .rsrc 00FBA000 Image 12 12 12 12 12 Read .reloc 00FC0000 Shareable 4 4 4 4 4 1 Read/Write 00FD0000 Shareable 4 4 4 4 4 1 Read 00FE0000 Heap (Private) 64 64 64 64 1 Read/Write Heap ID: 5 00FF0000 Mapped File 24 24 24 24 24 1 Read C:\Windows\Registration\R000000000007.clb 01000000 Image 32.060 32.060 7.856 5.012 2.844 43 Execute/Copy on Write C:\Users\Public\Software\GNU\emacs-23.0.92\bin\emacs.exe 01000000 Image 4 4 4 4 Read Header 01001000 Image 1.512 1.512 1.420 1.420 Execute/Read .text 0117B000 Image 12 12 12 12 Read/Write .data 0117E000 Image 672 672 656 656 Copy on write .data 01226000 Image 4 4 4 4 Read/Write .data 01227000 Image 608 608 556 556 Copy on write .data 012BF000 Image 4 4 4 4 Read/Write .data 012C0000 Image 8 8 8 8 Copy on write .data 012C2000 Image 4 4 4 4 Read/Write .data 012C3000 Image 8 8 8 8 Copy on write .data 012C5000 Image 4 4 4 4 Read/Write .data 012C6000 Image 96 96 96 96 Read .rdata 012DE000 Image 36 36 36 36 Read/Write .bss 012E7000 Image 144 144 Copy on write .bss 0130B000 Image 12 12 12 12 Read/Write .bss 0130E000 Image 4 4 Copy on write .bss 0130F000 Image 12 12 12 12 Read/Write .bss 01312000 Image 4 4 4 4 Copy on write .bss 01313000 Image 64 64 64 64 Read/Write .bss 01323000 Image 8 8 8 8 Copy on write .idata 01325000 Image 56 56 16 16 Copy on write .rsrc 01333000 Image 4 4 No access /4 01334000 Image 112 112 No access /19 01350000 Image 1.816 1.816 No access /35 01516000 Image 72 72 No access /47 01528000 Image 280 280 No access /61 0156E000 Image 100 100 No access /73 01587000 Image 48 48 No access /86 01593000 Image 21.052 21.052 No access /97 02A22000 Image 116 116 No access /112 02A3F000 Image 136 136 136 136 Read/Write EMHEAP 02A61000 Image 44 44 Copy on write EMHEAP 02A6C000 Image 588 588 588 588 Read/Write EMHEAP 02AFF000 Image 4 4 4 4 Copy on write EMHEAP 02B00000 Image 40 40 40 40 Read/Write EMHEAP 02B0A000 Image 104 104 Copy on write EMHEAP 02B24000 Image 12 12 12 12 Read/Write EMHEAP 02B27000 Image 60 60 44 44 Copy on write EMHEAP 02B36000 Image 576 576 576 576 Read/Write EMHEAP 02BC6000 Image 24 24 Copy on write EMHEAP 02BCC000 Image 3.004 3.004 3.004 3.004 Read/Write EMHEAP 02EBB000 Image 8 8 8 8 Copy on write EMHEAP 02EBD000 Image 4 4 4 4 Read/Write EMHEAP 02EBE000 Image 4 4 4 4 Copy on write EMHEAP 02EBF000 Image 4 4 4 4 Read/Write EMHEAP 02EC0000 Image 4 4 4 4 Copy on write EMHEAP 02EC1000 Image 4 4 4 4 Read/Write EMHEAP 02EC2000 Image 4 4 4 4 Copy on write EMHEAP 02EC3000 Image 452 452 452 452 Read/Write EMHEAP 02F34000 Image 56 56 Copy on write EMHEAP 02F42000 Image 40 40 40 40 Read/Write EMHEAP 02F4C000 Image 12 12 Copy on write EMHEAP 02F50000 Shareable 12.288 1.908 896 896 896 2 Read 02F50000 Mapped 1.908 1.908 896 896 896 Read 0312D000 Reserved 10.380 03B50000 Mapped File 3.580 3.580 100 100 100 1 Read C:\Windows\System32\locale.nls 03ED0000 Heap (Private) 1.024 96 96 96 2 Read/Write Heap ID: 2 03ED0000 Private 96 96 96 96 Read/Write Heap ID: 0 (Default) 03EE8000 Reserved 928 Heap ID: 0 (Default) 03FD0000 Private 64 4 2 No access 03FD0000 Private 4 4 Read/Write 03FD1000 Reserved 60 03FE0000 Private 4 4 4 4 1 Read/Write 03FF0000 Heap (Private) 64 4 4 4 2 Read/Write Heap ID: 6 03FF0000 Private 4 4 4 4 Read/Write Heap ID: 0 (Default) 03FF1000 Reserved 60 Heap ID: 0 (Default) 04000000 Private 128 16 12 12 2 No access 04000000 Private 16 16 12 12 Read/Write 04004000 Reserved 112 04020000 Private 128 4 4 4 2 Read/Write 04020000 Private 4 4 4 4 Read/Write 04021000 Reserved 124 04040000 Heap (Private) 256 104 104 104 2 Read/Write Heap ID: 9 04040000 Private 104 104 104 104 Read/Write Heap ID: 0 (Default) 0405A000 Reserved 152 Heap ID: 0 (Default) 04080000 Heap (Private) 64 24 24 24 2 Read/Write Heap ID: 4 04080000 Private 24 24 24 24 Read/Write Heap ID: 0 (Default) 04086000 Reserved 40 Heap ID: 0 (Default) 04090000 Shareable 704 704 268 268 268 1 Read 04140000 Image 72 72 68 52 16 16 7 Execute/Copy on Write C:\Program Files\Lenovo\HOTKEY\HKVOLKEY.dll 04140000 Image 4 4 4 4 4 Read Header 04141000 Image 36 36 36 36 Execute/Read .text 0414A000 Image 8 8 8 4 4 4 Read .rdata 0414C000 Image 4 4 4 4 Read/Write .data 0414D000 Image 4 4 Copy on write .data 0414E000 Image 8 8 8 8 Read/Write .data 04150000 Image 4 4 4 4 4 Read .rsrc 04151000 Image 4 4 4 4 4 Read .reloc 04160000 Private 4 4 4 4 1 Read/Write 04170000 Heap (Private) 1.024 1.024 16 16 1 Read/Write Heap ID: 7 04270000 Heap (Private) 1.024 196 196 196 2 Read/Write Heap ID: 5 04270000 Private 196 196 196 196 Read/Write Heap ID: 0 (Default) 042A1000 Reserved 828 Heap ID: 0 (Default) 04370000 Private 512 4 4 4 2 Read/Write 04370000 Private 4 4 4 4 Read/Write 04371000 Reserved 508 043F0000 Private 4 4 4 4 1 Read/Write 04400000 Private 4 4 4 4 1 Read/Write 04410000 Private 4 4 4 4 1 Read/Write 04420000 Private 4 4 4 4 1 Read/Write 04430000 Heap (Private) 64 8 8 8 2 Read/Write Heap ID: 10 04430000 Private 8 8 8 8 Read/Write Heap ID: 0 (Default) 04432000 Reserved 56 Heap ID: 0 (Default) 04440000 Private 4 4 4 4 1 Read/Write 04450000 Heap (Private) 64 40 40 40 2 Read/Write Heap ID: 8 04450000 Private 40 40 40 40 Read/Write Heap ID: 0 (Default) 0445A000 Reserved 24 Heap ID: 0 (Default) 04460000 Heap (Private) 1.024 72 72 72 2 Read/Write Heap ID: 8 04460000 Private 72 72 72 72 Read/Write Heap ID: 0 (Default) 04472000 Reserved 952 Heap ID: 0 (Default) 04560000 Shareable 4.096 4.096 64 64 64 1 Read 04960000 Heap (Private) 1.024 72 72 72 2 Read/Write Heap ID: 11 04960000 Private 72 72 72 72 Read/Write Heap ID: 0 (Default) 04972000 Reserved 952 Heap ID: 0 (Default) 04A60000 Private 4 4 4 4 1 Read/Write 04B50000 Heap (Private) 64 28 28 28 2 Read/Write Heap ID: 11 04B50000 Private 28 28 28 28 Read/Write Heap ID: 0 (Default) 04B57000 Reserved 36 Heap ID: 0 (Default) 04C00000 Shareable 4.096 4.096 1 Read 05000000 Shareable 4.096 4.096 156 156 156 1 Read 05400000 Private 4.096 12 12 12 4 Read/Write 05400000 Private 4 4 4 4 Read/Write 05401000 Reserved 16 05405000 Private 8 8 8 8 Read/Write 05407000 Reserved 4.068 05800000 Thread Stack 8.192 20 16 16 3 Read/Write Thread ID: 3284 05800000 Reserved 8.172 Thread ID: 0 05FFB000 Private 4 4 Read/Write/Guard Thread ID: 0 05FFC000 Private 16 16 16 16 Read/Write Thread ID: 0 06000000 Shareable 4.096 4.096 96 96 96 1 Read 06400000 Shareable 2.712 2.712 2.700 2.700 2.700 1 Read/Write 066B0000 Shareable 2.540 2.540 2.528 2.528 2.528 1 Read/Write 06930000 Shareable 2.280 2.280 2.272 2.272 2.272 1 Read/Write 07760000 Shareable 3.980 3.980 3.980 3.980 3.980 1 Read/Write 10000000 Image 68 68 60 12 48 48 5 Execute/Copy on Write C:\PROGRA~1\KL\WS\r3hook.dll 10000000 Image 4 4 4 4 4 Read Header 10001000 Image 36 36 36 36 36 Execute/Read .text 1000A000 Image 12 12 8 4 4 4 Read .rdata 1000D000 Image 8 8 8 8 Read/Write .data 1000F000 Image 4 4 4 4 4 Read .rsrc 10010000 Image 4 4 Read .reloc 10050000 Private 261.824 261.772 261.720 261.720 2 No access 10050000 Private 261.772 261.772 261.720 261.720 Read/Write 1FFF3000 Reserved 52 6D570000 Image 156 156 112 16 96 6 Execute/Copy on Write C:\Windows\System32\crtdll.dll 6D570000 Image 4 4 4 4 Read Header 6D571000 Image 116 116 88 4 84 Execute/Read .text 6D58E000 Image 8 8 8 8 Read/Write .data 6D590000 Image 12 12 4 4 Copy on write .data 6D593000 Image 4 4 4 4 Read/Write .data 6D594000 Image 4 4 4 4 Read .rsrc 6D595000 Image 8 8 Read .reloc 6FFF0000 Private 64 64 64 64 1 Execute/Read/Write 70A80000 Image 56 56 52 8 44 8 Execute/Copy on Write C:\Users\Public\Software\GNU\emacs-23.0.92\bin\libXpm.dll 70A80000 Image 4 4 4 4 Read Header 70A81000 Image 28 28 28 28 Execute/Read .text 70A88000 Image 4 4 4 4 Copy on write .data 70A89000 Image 4 4 4 4 Read .rdata 70A8A000 Image 4 4 4 4 Read/Write .bss 70A8B000 Image 4 4 4 4 Read .edata 70A8C000 Image 4 4 4 4 Read/Write .idata 70A8D000 Image 4 4 Read .reloc 712F0000 Image 880 880 100 20 80 80 8 Execute/Copy on Write C:\Windows\System32\dbghelp.dll 712F0000 Image 4 4 4 4 4 Read Header 712F1000 Image 732 732 76 4 72 72 Execute/Read .text 713A8000 Image 4 4 4 4 Read/Write .data 713A9000 Image 4 4 Copy on write .data 713AA000 Image 8 8 8 8 Read/Write .data 713AC000 Image 88 88 Copy on write .data 713C2000 Image 4 4 4 4 Read/Write .data 713C3000 Image 4 4 4 4 4 Read .rsrc 713C4000 Image 32 32 Read .reloc 72230000 Image 76 76 52 8 44 44 4 Execute/Copy on Write C:\Windows\System32\ntlanman.dll 72230000 Image 4 4 4 4 4 Read Header 72231000 Image 60 60 40 4 36 36 Execute/Read .text 72240000 Image 4 4 4 4 Read/Write .data 72241000 Image 4 4 4 4 4 Read .rsrc 72242000 Image 4 4 Read .reloc 72250000 Image 60 60 44 8 36 20 4 Execute/Copy on Write C:\Windows\System32\davclnt.dll 72250000 Image 4 4 4 4 4 Read Header 72251000 Image 44 44 32 4 28 12 Execute/Read .text 7225C000 Image 4 4 4 4 Read/Write .data 7225D000 Image 4 4 4 4 4 Read .rsrc 7225E000 Image 4 4 Read .reloc 72260000 Image 32 32 28 8 20 20 4 Execute/Copy on Write C:\Windows\System32\drprov.dll 72260000 Image 4 4 4 4 4 Read Header 72261000 Image 16 16 16 4 12 12 Execute/Read .text 72265000 Image 4 4 4 4 Read/Write .data 72266000 Image 4 4 4 4 4 Read .rsrc 72267000 Image 4 4 Read .reloc 722D0000 Image 44 44 40 8 32 32 4 Execute/Copy on Write C:\Windows\System32\cscapi.dll 722D0000 Image 4 4 4 4 4 Read Header 722D1000 Image 28 28 28 4 24 24 Execute/Read .text 722D8000 Image 4 4 4 4 Read/Write .data 722D9000 Image 4 4 4 4 4 Read .rsrc 722DA000 Image 4 4 Read .reloc 72D30000 Image 264 264 80 12 68 68 5 Execute/Copy on Write C:\Windows\System32\winspool.drv 72D30000 Image 4 4 4 4 4 Read Header 72D31000 Image 192 192 64 4 60 60 Execute/Read .text 72D61000 Image 4 4 Copy on write .data 72D62000 Image 8 8 8 8 Read/Write .data 72D64000 Image 44 44 4 4 4 Read .rsrc 72D6F000 Image 12 12 Read .reloc 742F0000 Image 228 228 36 8 28 28 5 Execute/Copy on Write C:\Windows\System32\oleacc.dll 742F0000 Image 4 4 4 4 4 Read Header 742F1000 Image 176 176 24 4 20 20 Execute/Read .text 7431D000 Image 4 4 Execute/Read .orpc 7431E000 Image 4 4 4 4 Read/Write .data 7431F000 Image 4 4 Copy on write .data 74320000 Image 24 24 4 4 4 Read .rsrc 74326000 Image 12 12 Read .reloc 74800000 Image 200 200 40 12 28 28 5 Execute/Copy on Write C:\Windows\System32\winmm.dll 74800000 Image 4 4 4 4 4 Read Header 74801000 Image 152 152 24 4 20 20 Execute/Read .text 74827000 Image 8 8 8 8 Read/Write .data 74829000 Image 4 4 Copy on write .data 7482A000 Image 4 4 Read .guids 7482B000 Image 16 16 4 4 4 Read .rsrc 7482F000 Image 12 12 Read .reloc 749A0000 Image 252 252 136 8 128 128 5 Execute/Copy on Write C:\Windows\System32\uxtheme.dll 749A0000 Image 4 4 4 4 4 Read Header 749A1000 Image 220 220 120 4 116 116 Execute/Read .text 749D8000 Image 4 4 4 4 Read/Write .data 749D9000 Image 12 12 4 4 4 Copy on write .data 749DC000 Image 4 4 4 4 4 Read .rsrc 749DD000 Image 8 8 Read .reloc 75620000 Image 80 80 60 8 52 52 4 Execute/Copy on Write C:\Windows\System32\mpr.dll 75620000 Image 4 4 4 4 4 Read Header 75621000 Image 64 64 48 4 44 44 Execute/Read .text 75631000 Image 4 4 4 4 Read/Write .data 75632000 Image 4 4 4 4 4 Read .rsrc 75633000 Image 4 4 Read .reloc 756C0000 Image 468 468 72 32 40 40 7 Execute/Copy on Write C:\Windows\System32\netapi32.dll 756C0000 Image 4 4 4 4 4 Read Header 756C1000 Image 400 400 36 4 32 32 Execute/Read .text 75725000 Image 8 8 8 8 Read/Write .data 75727000 Image 12 12 Copy on write .data 7572A000 Image 20 20 20 20 Read/Write .data 7572F000 Image 8 8 Copy on write .data 75731000 Image 4 4 4 4 4 Read .rsrc 75732000 Image 12 12 Read .reloc 757F0000 Image 1.656 1.656 200 16 184 184 7 Execute/Copy on Write C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll 757F0000 Image 4 4 4 4 4 Read Header 757F1000 Image 1.280 1.280 176 4 172 172 Execute/Read .text 75931000 Image 4 4 4 4 Read/Write .data 75932000 Image 4 4 Copy on write .data 75933000 Image 8 8 8 8 Read/Write .data 75935000 Image 40 40 4 4 4 Copy on write .data 7593F000 Image 260 260 4 4 4 Read .rsrc 75980000 Image 56 56 Read .reloc 75B90000 Image 176 176 56 8 48 48 4 Execute/Copy on Write C:\Windows\System32\apphelp.dll 75B90000 Image 4 4 4 4 4 Read Header 75B91000 Image 156 156 44 4 40 40 Execute/Read .text 75BB8000 Image 4 4 4 4 Read/Write .data 75BB9000 Image 4 4 4 4 4 Read .rsrc 75BBA000 Image 8 8 Read .reloc 75BF0000 Image 80 80 28 8 20 20 4 Execute/Copy on Write C:\Windows\System32\secur32.dll 75BF0000 Image 4 4 4 4 4 Read Header 75BF1000 Image 64 64 16 4 12 12 Execute/Read .text 75C01000 Image 4 4 4 4 Read/Write .data 75C02000 Image 4 4 4 4 4 Read .rsrc 75C03000 Image 4 4 Read .reloc 75D50000 Image 28 28 20 8 12 12 4 Execute/Copy on Write C:\Windows\System32\psapi.dll 75D50000 Image 4 4 4 4 4 Read Header 75D51000 Image 12 12 8 4 4 4 Execute/Read .text 75D54000 Image 4 4 4 4 Read/Write .data 75D55000 Image 4 4 4 4 4 Read .rsrc 75D56000 Image 4 4 Read .reloc 75D80000 Image 11.328 11.328 232 48 184 180 7 Execute/Copy on Write C:\Windows\System32\shell32.dll 75D80000 Image 4 4 4 4 4 Read Header 75D81000 Image 3.528 3.528 156 8 148 144 Execute/Read .text 760F3000 Image 32 32 32 32 Read/Write .data 760FB000 Image 36 36 Copy on write .data 76104000 Image 8 8 8 8 Read/Write .data 76106000 Image 16 16 8 8 8 Copy on write .data 7610A000 Image 7.516 7.516 24 24 24 Read .rsrc 76861000 Image 188 188 Read .reloc 76990000 Image 1.296 1.296 192 24 168 168 5 Execute/Copy on Write C:\Windows\System32\ole32.dll 76990000 Image 4 4 4 4 4 Read Header 76991000 Image 1.176 1.176 156 4 152 152 Execute/Read .text 76AB7000 Image 28 28 8 8 8 Execute/Read .orpc 76ABE000 Image 20 20 20 20 Read/Write .data 76AC3000 Image 8 8 Copy on write .data 76AC5000 Image 8 8 4 4 4 Read .rsrc 76AC7000 Image 52 52 Read .reloc 76AE0000 Image 300 300 100 8 92 92 5 Execute/Copy on Write C:\Windows\System32\gdi32.dll 76AE0000 Image 4 4 4 4 4 Read Header 76AE1000 Image 276 276 84 4 80 80 Execute/Read .text 76B26000 Image 4 4 4 4 Read/Write .data 76B27000 Image 4 4 4 4 4 Copy on write .data 76B28000 Image 4 4 4 4 4 Read .rsrc 76B29000 Image 8 8 Read .reloc 76B30000 Image 528 528 228 16 212 212 5 Execute/Copy on Write C:\Windows\System32\clbcatq.dll 76B30000 Image 4 4 4 4 4 Read Header 76B31000 Image 480 480 208 4 204 204 Execute/Read .text 76BA9000 Image 12 12 12 12 Read/Write .data 76BAC000 Image 4 4 Copy on write .data 76BAD000 Image 8 8 4 4 4 Read .rsrc 76BAF000 Image 20 20 Read .reloc 76CF0000 Image 776 776 208 8 200 200 4 Execute/Copy on Write C:\Windows\System32\rpcrt4.dll 76CF0000 Image 4 4 4 4 4 Read Header 76CF1000 Image 688 688 184 4 180 180 Execute/Read .text 76D9D000 Image 44 44 12 12 12 Execute/Read .orpc 76DA8000 Image 4 4 4 4 Read/Write .data 76DA9000 Image 12 12 4 4 4 Read .rsrc 76DAC000 Image 24 24 Read .reloc 76DC0000 Image 460 460 44 8 36 36 5 Execute/Copy on Write C:\Windows\System32\comdlg32.dll 76DC0000 Image 4 4 4 4 4 Read Header 76DC1000 Image 316 316 28 4 24 24 Execute/Read .text 76E10000 Image 4 4 4 4 Read/Write .data 76E11000 Image 12 12 Copy on write .data 76E14000 Image 108 108 8 8 8 Read .rsrc 76E2F000 Image 16 16 Read .reloc 76E90000 Image 36 36 20 8 12 12 4 Execute/Copy on Write C:\Windows\System32\lpk.dll 76E90000 Image 4 4 4 4 4 Read Header 76E91000 Image 20 20 8 4 4 4 Execute/Read .text 76E96000 Image 4 4 4 4 Read/Write .data 76E97000 Image 4 4 4 4 4 Read .rsrc 76E98000 Image 4 4 Read .reloc 76EA0000 Image 564 564 64 16 48 48 4 Execute/Copy on Write C:\Windows\System32\oleaut32.dll 76EA0000 Image 4 4 4 4 4 Read Header 76EA1000 Image 516 516 44 4 40 40 Execute/Read .text 76F22000 Image 4 4 Execute/Read .orpc 76F23000 Image 12 12 12 12 Read/Write .data 76F26000 Image 4 4 4 4 4 Read .rsrc 76F27000 Image 24 24 Read .reloc 76F30000 Image 800 800 280 12 268 268 4 Execute/Copy on Write C:\Windows\System32\msctf.dll 76F30000 Image 4 4 4 4 4 Read Header 76F31000 Image 516 516 248 4 244 244 Execute/Read .text 76FB2000 Image 8 8 8 8 Read/Write .data 76FB4000 Image 252 252 20 20 20 Read .rsrc 76FF3000 Image 20 20 Read .reloc 77000000 Image 680 680 280 20 260 248 9 Execute/Copy on Write C:\Windows\System32\msvcrt.dll 77000000 Image 4 4 4 4 4 Read Header 77001000 Image 628 628 252 4 248 240 Execute/Read .text 7709E000 Image 4 4 4 4 Read/Write .data 7709F000 Image 4 4 Copy on write .data 770A0000 Image 8 8 8 8 Read/Write .data 770A2000 Image 4 4 4 4 Copy on write .data 770A3000 Image 4 4 4 4 Read/Write .data 770A4000 Image 4 4 Copy on write .data 770A5000 Image 4 4 4 4 4 Read .rsrc 770A6000 Image 16 16 Read .reloc 770E0000 Image 792 792 180 20 160 160 7 Execute/Copy on Write C:\Windows\System32\advapi32.dll 770E0000 Image 4 4 4 4 4 Read Header 770E1000 Image 612 612 148 4 144 144 Execute/Read .text 7717A000 Image 4 4 4 4 Read/Write .data 7717B000 Image 4 4 Copy on write .data 7717C000 Image 12 12 12 12 Read/Write .data 7717F000 Image 40 40 8 8 8 Copy on write .data 77189000 Image 92 92 4 4 4 Read .rsrc 771A0000 Image 24 24 Read .reloc 77340000 Image 120 120 40 8 32 32 4 Execute/Copy on Write C:\Windows\System32\imm32.dll 77340000 Image 4 4 4 4 4 Read Header 77341000 Image 88 88 28 4 24 24 Execute/Read .text 77357000 Image 4 4 4 4 Read/Write .data 77358000 Image 20 20 4 4 4 Read .rsrc 7735D000 Image 4 4 Read .reloc 77360000 Image 500 500 120 16 104 104 7 Execute/Copy on Write C:\Windows\System32\usp10.dll 77360000 Image 4 4 4 4 4 Read Header 77361000 Image 344 344 96 4 92 92 Execute/Read .text 773B7000 Image 4 4 4 4 Read/Write .data 773B8000 Image 12 12 Copy on write .data 773BB000 Image 8 8 8 8 Read/Write .data 773BD000 Image 40 40 Copy on write .data 773C7000 Image 8 8 4 4 4 Read Shared 773C9000 Image 72 72 4 4 4 Read .rsrc 773DB000 Image 8 8 Read .reloc 773E0000 Image 352 352 120 12 108 108 4 Execute/Copy on Write C:\Windows\System32\shlwapi.dll 773E0000 Image 4 4 4 4 4 Read Header 773E1000 Image 324 324 104 4 100 100 Execute/Read .text 77432000 Image 8 8 8 8 Read/Write .data 77434000 Image 4 4 4 4 4 Read .rsrc 77435000 Image 12 12 Read .reloc 77440000 Image 628 628 240 8 232 228 5 Execute/Copy on Write C:\Windows\System32\user32.dll 77440000 Image 4 4 4 4 4 Read Header 77441000 Image 416 416 216 4 212 208 Execute/Read .text 774A9000 Image 4 4 4 4 Read/Write .data 774AA000 Image 4 4 4 4 4 Copy on write .data 774AB000 Image 184 184 12 12 12 Read .rsrc 774D9000 Image 16 16 Read .reloc 774E0000 Image 1.180 1.180 440 36 404 404 7 Execute/Copy on Write C:\Windows\System32\ntdll.dll 774E0000 Image 4 4 4 4 Execute/Read/Write Header 774E1000 Image 776 776 412 12 400 400 Execute/Read .text 775A3000 Image 4 4 Execute/Read RT 775A4000 Image 12 12 12 12 Read/Write .data 775A7000 Image 4 4 Copy on write .data 775A8000 Image 8 8 8 8 Read/Write .data 775AA000 Image 20 20 4 4 4 Copy on write .data 775AF000 Image 332 332 Read .rsrc 77602000 Image 20 20 Read .reloc 77610000 Image 876 876 332 16 316 316 4 Execute/Copy on Write C:\Windows\System32\kernel32.dll 77610000 Image 4 4 4 4 4 Read Header 77611000 Image 816 816 312 4 308 308 Execute/Read .text 776DD000 Image 12 12 12 12 Read/Write .data 776E0000 Image 4 4 4 4 4 Read .rsrc 776E1000 Image 40 40 Read .reloc 776F0000 Private 4 4 4 4 1 Execute/Read/Write 7F6F0000 Shareable 1.024 24 24 24 24 2 Read 7F6F0000 Mapped 24 24 24 24 24 Read 7F6F6000 Reserved 1.000 7FFB0000 Shareable 140 140 76 76 76 1 Read 7FFDD000 Private 4 4 4 4 1 Read/Write 7FFDE000 Private 4 4 4 4 1 Read/Write 7FFDF000 Private 4 4 4 4 1 Read/Write 7FFE0000 Private 64 4 4 4 4 2 Read 7FFE0000 Private 4 4 4 4 4 Read 7FFE1000 Reserved 60