ntdll: Don't map the PE header as executable. Detecting noexec filesystems is not particularly useful since we fall back to read()+mprotect() anyway.