Discussione Malware Possibile backdoor lato kernel?

Zeta 3.14

Utente Electrum
20 Aprile 2017
485
9
78
109
Ciao ragazzi, qualche giorno fa, dovendo sviluppare delle pagine php per delle API, ho avviato XAMPP che subito ha dato errore, dicendo che la porta 80 e` gia` bindata sul processo con PID 4. Con process hacker ho controllato e il PID 4 e` System. Potrebbe trattarsi di una backdoor lato kernel?


ntoskrnl.exe, 0xfffff801f2405000, 9,38 MB, NT Kernel & System
ACPI.sys, 0xfffff8062ea20000, 660 kB, Driver ACPI per NT
acpiex.sys, 0xfffff8062e9d0000, 140 kB, ACPIEx Driver
afd.sys, 0xfffff80630720000, 632 kB, Driver funzione ausiliaria di WinSock
afunix.sys, 0xfffff80630700000, 76 kB, AF_UNIX socket provider
AgileVpn.sys, 0xfffff801f89a0000, 156 kB, Gestione chiamate miniport VPN Agile RAS
ahcache.sys, 0xfffff80630cd0000, 276 kB, Application Compatibility Cache
AiChargerPlus.sys, 0xfffff80633d70000, 8 kB, ASUS Charger driver
amdppm.sys, 0xfffff80632850000, 224 kB, Processor Device Driver
AsIO.sys, 0xfffff80630cc0000, 24 kB,
asstahci64.sys, 0xfffff8062f4b0000, 100 kB, Asmedia 106x SATA Host Controller Driver
AsUpIO.sys, 0xfffff80630cb0000, 28 kB,
avgArPot.sys, 0xfffff80630c50000, 336 kB, AVG anti rootkit
avgbidsdrivera.sys, 0xfffff80630c10000, 228 kB, IDS Application Activity Monitor Driver.
avgbidsha.sys, 0xfffff8062f7b0000, 188 kB, Application Activity Monitor Helper Driver
avgbloga.sys, 0xfffff8062f760000, 320 kB, Logging Driver
avgbuniva.sys, 0xfffff8062f750000, 56 kB, Universal Driver
avgMonFlt.sys, 0xfffff80631d10000, 172 kB, AVG File System Minifilter for Windows 2003/Vista
avgRdr2.sys, 0xfffff806306e0000, 104 kB, AVG WFP Redirect Driver
avgRvrt.sys, 0xfffff8062f490000, 80 kB, AVG Revert
avgSnx.sys, 0xfffff8062f980000, 992 kB, AVG Virtualization Driver
avgSP.sys, 0xfffff8062f900000, 456 kB, AVG self protection module
avgStm.sys, 0xfffff80632a80000, 208 kB, Stream Filter
avgVmm.sys, 0xfffff8062f430000, 364 kB, AVG VM Monitor
bam.sys, 0xfffff80630bf0000, 80 kB, BAM Kernel Driver
BasicDisplay.sys, 0xfffff806313d0000, 88 kB, Microsoft Basic Display Driver
BasicRender.sys, 0xfffff806313f0000, 64 kB, Microsoft Basic Render Driver
Beep.SYS, 0xfffff8062fc10000, 40 kB, BEEP Driver
BOOTVID.dll, 0xfffff8062e570000, 44 kB, VGA Boot Driver
bowser.sys, 0xfffff80631ce0000, 132 kB, NT Lan Manager Datagram Receiver Driver
cdd.dll, 0xffff83599bf30000, 252 kB, Canonical Display Driver
cdrom.sys, 0xfffff8062f8d0000, 184 kB, SCSI CD-ROM Driver
CEA.sys, 0xfffff8062ec20000, 100 kB, Event Aggregation Kernel Mode Library
CI.dll, 0xfffff8062e720000, 724 kB, Code Integrity Module
CLASSPNP.SYS, 0xfffff8062f6e0000, 428 kB, SCSI Class System Dll
cldflt.sys, 0xfffff80631c50000, 440 kB, Cloud Files Mini Filter Driver
CLFS.SYS, 0xfffff8062e4b0000, 400 kB, Common Log File System Driver
clipsp.sys, 0xfffff8062e5f0000, 1,01 MB, CLIP Service
cmderd.sys, 0xfffff8062f8c0000, 40 kB, COMODO Internet Security Eradication Driver
cmdguard.sys, 0xfffff8062fb20000, 836 kB, COMODO Internet Security Sandbox Driver
cmdhlp.sys, 0xfffff806306d0000, 48 kB, COMODO Internet Security Helper Driver
cmimcext.sys, 0xfffff8062e700000, 56 kB, Driver di esportazione host estensione configurazione iniziale di Gestione configurazione kernel
cng.sys, 0xfffff8062e7e0000, 712 kB, Kernel Cryptography, Next Generation
CompositeBus.sys, 0xfffff80630d80000, 68 kB, Multi-Transport Composite Bus Enumerator
condrv.sys, 0xfffff801f7890000, 72 kB, Console Driver
crashdmp.sys, 0xfffff8062f800000, 108 kB, Crash Dump Driver
dfsc.sys, 0xfffff80630b40000, 164 kB, DFS Namespace Client Driver
disk.sys, 0xfffff8062f6c0000, 112 kB, PnP Disk Driver
drmk.sys, 0xfffff80633d40000, 132 kB, Microsoft Trusted Audio Drivers
dump_asstahci64.sys, 0xfffff80631a60000, 100 kB,
dump_diskdump.sys, 0xfffff80631a30000, 60 kB,
dump_dumpfve.sys, 0xfffff80631aa0000, 116 kB,
dxgkrnl.sys, 0xfffff806310d0000, 2,71 MB, DirectX Graphics Kernel
dxgmms2.sys, 0xfffff80631af0000, 792 kB, DirectX Graphics MMS
exfat.SYS, 0xfffff801f7a40000, 384 kB, Microsoft Extended FAT File System
fastfat.SYS, 0xfffff80630b90000, 384 kB, Fast FAT File System Driver
filecrypt.sys, 0xfffff8062faf0000, 80 kB, Windows sandboxing and encryption filter
fileinfo.sys, 0xfffff8062eed0000, 104 kB, FileInfo Filter Driver
FLTMGR.SYS, 0xfffff8062e580000, 420 kB, Gestione filtri file system Microsoft
Fs_Rec.sys, 0xfffff8062f190000, 52 kB, File System Recognizer Driver
fvevol.sys, 0xfffff8062f4d0000, 752 kB, BitLocker Drive Encryption Driver
fwpkclnt.sys, 0xfffff8062ff80000, 472 kB, FWP/IPsec Kernel-Mode API
gpuenergydrv.sys, 0xfffff80630b30000, 40 kB, GPU Energy Kernel Driver
hal.dll, 0xfffff801f2d66000, 560 kB, Hardware Abstraction Layer DLL
hcmon.sys, 0xfffff80632720000, 84 kB, VMware USB monitor
HDAudBus.sys, 0xfffff80633cb0000, 116 kB, High Definition Audio Bus Driver
HIDCLASS.SYS, 0xfffff80632590000, 204 kB, Libreria classe HID
HIDPARSE.SYS, 0xfffff806325d0000, 76 kB, Hid Parsing Library
hidusb.sys, 0xfffff80632570000, 72 kB, USB Miniport Driver for Input Devices
HTTP.sys, 0xfffff80630f20000, 1,01 MB, Stack del protocollo HTTP
intelpep.sys, 0xfffff8062eae0000, 188 kB, Intel Power Engine Plugin
IOMap64.sys, 0xfffff801f78b0000, 36 kB, ASUS Kernel Mode Driver for NT
iorate.sys, 0xfffff8062f690000, 68 kB, Filtro controllo velocità I/O
IUFileFilter.sys, 0xfffff801f7b00000, 40 kB, IUFileFilter
IURegProcessFilter.sys, 0xfffff801f78f0000, 32 kB, IURegProcessFilter
kbdclass.sys, 0xfffff80631a00000, 76 kB, Driver classe tastiera
kbdhid.sys, 0xfffff806325f0000, 64 kB, Driver del filtro della tastiera HID
kd.dll, 0xfffff801f3000000, 44 kB, Local Kernel Debugger
kdnic.sys, 0xfffff80630da0000, 52 kB, Microsoft Kernel Debugger Network Miniport
ks.sys, 0xfffff8062fa80000, 428 kB, Kernel CSA Library
ksecdd.sys, 0xfffff8062e460000, 168 kB, Kernel Security Support Provider Interface
ksecpkg.sys, 0xfffff8062f3c0000, 192 kB, Kernel Security Support Provider Interface Packages
ksthunk.sys, 0xfffff806328a0000, 60 kB, Kernel Streaming WOW Thunk Service
lltdio.sys, 0xfffff80632a60000, 88 kB, Link-Layer Topology Mapper I/O Driver
luafv.sys, 0xfffff80631bf0000, 156 kB, Driver filtro virtualizzazione file LUA
mcupdate_AuthenticAMD.dll, 0xfffff8062f3a0000, 124 kB, AMD Microcode Update Library
mmcss.sys, 0xfffff80632b80000, 76 kB, MMCSS Driver
monitor.sys, 0xfffff80631bc0000, 68 kB, Monitor Driver
mouclass.sys, 0xfffff80631ad0000, 68 kB, Driver Mouse Class
mouhid.sys, 0xfffff80631ac0000, 60 kB, Driver del filtro del mouse HID
mountmgr.sys, 0xfffff8062edd0000, 120 kB, Gestione punti di montaggio
mpsdrv.sys, 0xfffff80632bd0000, 100 kB, Microsoft Protection Service Driver
mrxsmb.sys, 0xfffff80632990000, 520 kB, Windows NT SMB Minirdr
mrxsmb20.sys, 0xfffff80632a20000, 244 kB, Longhorn SMB 2.0 Redirector
Msfs.SYS, 0xfffff80630620000, 64 kB, Mailslot driver
msisadrv.sys, 0xfffff8062eb60000, 44 kB, ISA Driver
mslldp.sys, 0xfffff80632ae0000, 104 kB, Driver Microsoft Link-Layer Discovery Protocol
msrpc.sys, 0xfffff8062e400000, 384 kB, Kernel Remote Procedure Call Provider
mssmbios.sys, 0xfffff80630b20000, 60 kB, System Management BIOS Driver
mup.sys, 0xfffff8062f660000, 144 kB, Driver MUP (Multiple UNC Provider)
ndis.sys, 0xfffff8062f1a0000, 1,25 MB, NDIS (Network Driver Interface Specification)
ndistapi.sys, 0xfffff801f7840000, 60 kB, NDIS 3.0 connection wrapper driver
ndisuio.sys, 0xfffff80632bb0000, 88 kB, Driver I/O modalità utente NDIS
NdisVirtualBus.sys, 0xfffff806328c0000, 52 kB, Enumeratore scheda di rete virtuale Microsoft
ndiswan.sys, 0xfffff801f7850000, 220 kB, MS PPP Framing Driver (Strong Encryption)
NDProxy.sys, 0xfffff801f8980000, 88 kB, NDIS Proxy
Ndu.sys, 0xfffff80631030000, 156 kB, Windows Network Data Usage Monitoring Driver
netbios.sys, 0xfffff80630890000, 72 kB, NetBIOS interface driver
netbt.sys, 0xfffff80630670000, 336 kB, MBT Transport driver
NETIO.SYS, 0xfffff8062f2f0000, 548 kB, Network I/O Subsystem
npf.sys, 0xfffff80632740000, 48 kB, npf.sys (NT5/6 AMD64) Kernel Driver
Npfs.SYS, 0xfffff80630600000, 108 kB, NPFS Driver
npsvctrig.sys, 0xfffff80630b10000, 52 kB, Named pipe service triggers
nsiproxy.sys, 0xfffff80630af0000, 72 kB, NSI Proxy
Ntfs.sys, 0xfffff8062ef30000, 2,36 MB, Driver file system NT
ntosext.sys, 0xfffff8062e710000, 48 kB, NTOS extension host driver
Null.SYS, 0xfffff8062fc00000, 40 kB, NULL Driver
nvhda64v.sys, 0xfffff80632500000, 220 kB, NVIDIA HDMI Audio Driver
nvlddmkm.sys, 0xfffff80632c00000, 16,68 MB, NVIDIA Windows Kernel Mode Driver, Version 397.31
nvvad64v.sys, 0xfffff80632890000, 56 kB, NVIDIA Virtual Audio Driver
nvvhci.sys, 0xfffff806328b0000, 60 kB, Virtual USB Host Controller driver
nwifi.sys, 0xfffff80630dd0000, 540 kB, Driver miniport NativeWiFi
pacer.sys, 0xfffff80630830000, 164 kB, Utilità di pianificazione pacchetti QoS
partmgr.sys, 0xfffff8062ec40000, 180 kB, Partition driver
pci.sys, 0xfffff8062eb70000, 384 kB, Enumeratore PCI Plug and Play per NT
pcw.sys, 0xfffff8062eb40000, 80 kB, Performance Counters for Windows Driver
pdc.sys, 0xfffff8062ebf0000, 160 kB, Power Dependency Coordinator Driver
peauth.sys, 0xfffff801f87e0000, 768 kB, Protected Environment Authentication and Authorization Export Driver
portcls.sys, 0xfffff80633cd0000, 400 kB, Port Class (Class Driver for Port/Miniport Devices)
PSHED.dll, 0xfffff8062e550000, 92 kB, Driver errori hardware specifici di piattaforma
qwavedrv.sys, 0xfffff801f78d0000, 76 kB, Driver di supporto Servizio audio/video Windows di qualità (qWave) Microsoft
rasl2tp.sys, 0xfffff801f89d0000, 128 kB, RAS L2TP mini-port/call-manager driver
raspppoe.sys, 0xfffff801f7820000, 108 kB, RAS PPPoE mini-port/call-manager driver
raspptp.sys, 0xfffff801f7800000, 124 kB, Peer-to-Peer Tunneling Protocol
rassstp.sys, 0xfffff801f8960000, 108 kB, RAS SSTP Miniport Call Manager
rdbss.sys, 0xfffff806308b0000, 472 kB, Driver sottosistema buffer unità di redirector
rdpbus.sys, 0xfffff806328e0000, 56 kB, Microsoft RDP Bus Device driver
rdpvideominiport.sys, 0xfffff80631be0000, 52 kB, Microsoft RDP Video Miniport driver
rdyboost.sys, 0xfffff8062f610000, 304 kB, ReadyBoost Driver
rspndr.sys, 0xfffff80632ac0000, 104 kB, Link-Layer Topology Responder Driver for NDIS 6
rt640x64.sys, 0xfffff80632760000, 868 kB, Realtek 8101E/8168/8169 NDIS 6.40 64-bit Driver
RTKVHD64.sys, 0xfffff80631ff0000, 4,49 MB, Realtek(r) High Definition Audio Function Driver
serenum.sys, 0xfffff80632640000, 60 kB, Serial Port Enumerator
serial.sys, 0xfffff80632620000, 112 kB, Driver di dispositivo seriale
SgrmAgent.sys, 0xfffff8062ea00000, 84 kB, System Guard Runtime Monitor Agent Driver
SleepStudyHelper.sys, 0xfffff8062e9c0000, 60 kB, Sleep Study Helper
spaceport.sys, 0xfffff8062ec70000, 612 kB, Storage Spaces Driver
srv.sys, 0xfffff801f88a0000, 576 kB, Server driver
srv2.sys, 0xfffff80630e60000, 752 kB, Driver server Smb 2.0
srvnet.sys, 0xfffff80632b30000, 288 kB, Server Network driver
storahci.sys, 0xfffff8062edf0000, 168 kB, MS AHCI Storport Miniport Driver
storport.sys, 0xfffff8062ee20000, 572 kB, Microsoft Storage Port Driver
storqosflt.sys, 0xfffff80631cc0000, 100 kB, Filtro QoS archiviazione
swenum.sys, 0xfffff806328d0000, 48 kB, Plug and Play Software Device Enumerator
tap0901.sys, 0xfffff80630d70000, 48 kB, TAP-Windows Virtual Network Driver (NDIS 6.0)
tbs.sys, 0xfffff8062fb10000, 52 kB, Export driver for kernel mode TPM API
tcpip.sys, 0xfffff8062fcd0000, 2,64 MB, Driver TCP/IP
tcpipreg.sys, 0xfffff801f8930000, 76 kB, TCP/IP Registry Compatibility Driver
TDI.SYS, 0xfffff80630660000, 64 kB, TDI Wrapper
tdx.sys, 0xfffff80630630000, 140 kB, TDI Translation Driver
tm.sys, 0xfffff8062e520000, 144 kB, Kernel Transaction Manager Driver
ucx01000.sys, 0xfffff806326c0000, 240 kB, USB Controller Extension
umbus.sys, 0xfffff80630db0000, 84 kB, User-Mode Bus Enumerator
umpass.sys, 0xfffff801f7af0000, 44 kB, Generic pass-through driver
usbccgp.sys, 0xfffff80632540000, 188 kB, USB Common Class Generic Parent Driver
USBD.SYS, 0xfffff80632980000, 56 kB, Universal Serial Bus Driver
usbehci.sys, 0xfffff80632600000, 108 kB, EHCI eUSB Miniport Driver
usbhub.sys, 0xfffff806328f0000, 524 kB, Driver hub predefinito per USB
UsbHub3.sys, 0xfffff80632470000, 568 kB, Driver hub USB3
usbohci.sys, 0xfffff80633d80000, 60 kB, OHCI USB Miniport Driver
USBPORT.SYS, 0xfffff80633d90000, 424 kB, Driver porta USB 1.1 & 2.0
USBXHCI.SYS, 0xfffff80632650000, 444 kB, Driver USB XHCI
VBoxDrv.sys, 0xfffff806309f0000, 0,98 MB, VirtualBox Support Driver
VBoxNetAdp6.sys, 0xfffff80630d20000, 260 kB, VirtualBox NDIS 6.0 Host-Only Network Adapter Driver
VBoxNetLwf.sys, 0xfffff806307c0000, 264 kB, VirtualBox NDIS 6.0 Lightweight Filter Driver
VBoxUSBMon.sys, 0xfffff806309b0000, 204 kB, VirtualBox USB Monitor Driver
vcs64.sys, 0xfffff801f8950000, 24 kB,
vdrvroot.sys, 0xfffff8062ebd0000, 72 kB, Virtual Drive Root Enumerator
veracrypt.sys, 0xfffff80630930000, 468 kB, VeraCrypt Driver
vmbkmclr.sys, 0xfffff806313b0000, 104 kB, Hyper-V VMBus Root KMCL
vmci.sys, 0xfffff8062ed90000, 104 kB, VMware PCI VMCI Bus Device
VMNET.SYS, 0xfffff80632b20000, 48 kB, VMware virtual network driver (64-bit)
vmnetuserif.sys, 0xfffff80631da0000, 44 kB, VMware network application interface driver (64-bit)
vmx86.sys, 0xfffff80632700000, 116 kB, VMware kernel driver
volmgr.sys, 0xfffff8062ed10000, 100 kB, Driver gestione volumi
volmgrx.sys, 0xfffff8062ed30000, 376 kB, Estensione del driver gestore dei volumi
volsnap.sys, 0xfffff8062f5a0000, 412 kB, Driver Copia Shadow del volume
volume.sys, 0xfffff8062f590000, 44 kB, Volume driver
vsock.sys, 0xfffff8062edb0000, 92 kB, VMware vSockets Service
vwififlt.sys, 0xfffff80630810000, 104 kB, Virtual WiFi Filter Driver
wanarp.sys, 0xfffff80632b00000, 108 kB, MS Remote Access and Routing ARP Driver
watchdog.sys, 0xfffff80631390000, 80 kB, Watchdog Driver
wcifs.sys, 0xfffff80631c20000, 160 kB, Windows Container Isolation FS Filter Driver
Wdf01000.sys, 0xfffff8062e8a0000, 912 kB, Runtime framework driver modalità kernel
WDFLDR.SYS, 0xfffff8062e990000, 76 kB, Kernel Mode Driver Framework Loader
werkernel.sys, 0xfffff8062e490000, 68 kB, Windows Error Reporting Kernel Driver
wfplwfs.sys, 0xfffff8062f400000, 180 kB, WFP NDIS 6.30 Lightweight Filter Driver
win32k.sys, 0xffff83599ba90000, 496 kB, Full/Desktop Multi-User Win32 Driver
win32kbase.sys, 0xffff83599bc00000, 2,2 MB, Driver kernel Win32k di base
win32kfull.sys, 0xffff83599c640000, 3,56 MB, Full/Desktop Win32k Kernel Driver
WinD64.sys, 0xfffff80632ba0000, 28 kB,
WindowsTrustedRT.sys, 0xfffff8062eb10000, 88 kB, Windows Trusted Runtime Interface Driver
WindowsTrustedRTProxy.sys, 0xfffff8062eb30000, 44 kB, Windows Trusted Runtime Service Proxy Driver
wmiacpi.sys, 0xfffff80632840000, 48 kB, Windows Management Interface for ACPI
WMILIB.SYS, 0xfffff8062ead0000, 48 kB, WMILIB WMI support library Dll
Wof.sys, 0xfffff8062eef0000, 236 kB, Filtro overlay Windows
WpdUpFltr.sys, 0xfffff80631d90000, 52 kB, Windows Portable Device Upper Class Filter Driver
WppRecorder.sys, 0xfffff8062e9b0000, 56 kB, WPP Trace Recorder
WUDFRd.sys, 0xfffff80631d40000, 288 kB, Windows Driver Foundation - User-mode Driver Framework Reflector

744, 0,39, 200, dxgmms2.sys!VidMmInterface+0x4a4e0,
748, 0,39, 4, dxgmms2.sys!VidMmInterface+0x488c0,
80, , 59, ntoskrnl.exe!MmQuerySystemSize+0x3d0,
22028, , 46, avgArPot.sys+0x96c4,
740, , 28, nvlddmkm.sys+0x145a4c,
76, , 27, ntoskrnl.exe!HviIsHypervisorVendorMicrosoft+0xff0,
19524, , 18, ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
668, , 9, RTKVHD64.sys+0x31414,
2212, , 5, mmcss.sys+0x35b0,
572, , 5, ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
732, , 4, nvlddmkm.sys+0x115bd8,
72, , 3, ntoskrnl.exe!RtlInitAnsiStringEx+0x190,
400, , 2, avgSnx.sys+0x5d5a4,
11724, , 1, ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
6516, , 1, Ndu.sys+0xfa70,
396, , 1, avgSnx.sys+0x5d5a4,
284, , 1, ndis.sys!NdisInitializeTimer+0x1640,
268, , 1, ndis.sys!NdisInitializeTimer+0x1640,
36, , 1, ntoskrnl.exe!RtlIoDecodeMemIoResource+0x60,
23388, , , HTTP.sys+0x66120,
21996, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
21796, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
21476, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
21468, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
21084, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
20740, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
20520, , , dxgkrnl.sys!DxgkOpenBundleObjectNtHandleFromName+0x28590,
19804, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
19008, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
18864, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
18704, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
17964, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
17652, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
16076, , , HTTP.sys+0x66120,
15976, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
15624, , , HTTP.sys+0x66120,
15024, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
14864, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
13592, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
12420, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
12340, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
12260, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
11984, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
11908, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
11720, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
11516, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
11268, , , Wdf01000.sys+0xa62b0,
11096, , , avgbidsdrivera.sys+0x19250,
10236, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
8932, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
8584, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
8292, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
8284, , , raspptp.sys+0x6af0,
8224, , , AgileVpn.sys+0x1c010,
8220, , , AgileVpn.sys+0x1c010,
8216, , , AgileVpn.sys+0x1c010,
8212, , , AgileVpn.sys+0x1c010,
8208, , , AgileVpn.sys+0x1c010,
8204, , , AgileVpn.sys+0x1c010,
8200, , , AgileVpn.sys+0x1c010,
8196, , , AgileVpn.sys+0x1c010,
7872, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
7860, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
7856, , , AgileVpn.sys+0x1c010,
7852, , , AgileVpn.sys+0x1c010,
7848, , , AgileVpn.sys+0x1c010,
7784, , , AgileVpn.sys+0x1c010,
7776, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
7684, , , AgileVpn.sys+0x1c010,
7656, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
7592, , , AgileVpn.sys+0x1c010,
7476, , , AgileVpn.sys+0x1c010,
7472, , , AgileVpn.sys+0x1c010,
7444, , , AgileVpn.sys+0x1c010,
7440, , , AgileVpn.sys+0x1c010,
7428, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
7404, , , AgileVpn.sys+0x1c010,
6300, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6296, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6292, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6288, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6284, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6280, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6276, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6272, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6268, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6264, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6260, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6256, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6252, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6248, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6244, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6240, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6236, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
6124, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
6000, , , Ndu.sys+0xebb0,
5976, , , hcmon.sys+0x6d8c,
5972, , , mpsdrv.sys+0x2af0,
5928, , , HTTP.sys+0x20a0,
5924, , , HTTP.sys+0x66120,
5920, , , HTTP.sys+0x66120,
5460, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
5456, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
5448, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
5440, , , ntoskrnl.exe!LpcRequestWaitReplyPort+0x6d0,
5124, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
5104, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
4608, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
4020, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
3344, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
3092, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
2960, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
2944, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
2580, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
2136, , , ntoskrnl.exe!IoResolveDependency+0x1330,
1832, , , AgileVpn.sys+0x1c010,
1828, , , AgileVpn.sys+0x1c010,
1820, , , AgileVpn.sys+0x1c010,
1788, , , AgileVpn.sys+0x1c010,
1784, , , AgileVpn.sys+0x1c010,
1756, , , avgbidsdrivera.sys+0x1e2a0,
1728, , , avgMonFlt.sys+0x9140,
1708, , , storqosflt.sys+0x11cd0,
1676, , , luafv.sys+0x119a0,
1612, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
1396, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
824, , , msrpc.sys!I_RpcExceptionFilter+0x3a10,
764, , , dxgmms2.sys!VidMmInterface+0x488c0,
760, , , dxgmms2.sys!VidMmInterface+0x4a4e0,
756, , , BasicRender.sys+0x47f0,
752, , , dxgkrnl.sys!DxgkOpenBundleObjectNtHandleFromName+0x28590,
712, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x4540,
704, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
684, , , nvhda64v.sys+0x33dc,
680, , , nvhda64v.sys+0x33dc,
676, , , nvhda64v.sys+0x33dc,
672, , , nvhda64v.sys+0x33dc,
652, , , RTKVHD64.sys+0x15ff4,
648, , , RTKVHD64.sys+0x15ff4,
644, , , RTKVHD64.sys+0x15ff4,
640, , , RTKVHD64.sys+0x15ff4,
636, , , RTKVHD64.sys+0x15ff4,
632, , , RTKVHD64.sys+0x15ff4,
628, , , RTKVHD64.sys+0x15ff4,
624, , , RTKVHD64.sys+0x15ff4,
620, , , RTKVHD64.sys+0x15ff4,
616, , , RTKVHD64.sys+0x15ff4,
612, , , RTKVHD64.sys+0x15ff4,
608, , , RTKVHD64.sys+0x15ff4,
604, , , nvvad64v.sys+0x82b4,
576, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
540, , , ntoskrnl.exe!RtlAvlRemoveNode+0x7ba0,
536, , , dxgkrnl.sys!DpiUnmapIommuIdentityRange+0xe20,
524, , , ntoskrnl.exe!SeFilterToken+0x47e0,
504, , , avgbidsdrivera.sys+0xfec0,
500, , , bam.sys+0xae30,
496, , , VBoxDrv.sys!RTThreadSelf+0x120,
492, , , veracrypt.sys+0xfd90,
488, , , veracrypt.sys+0xfd90,
484, , , veracrypt.sys+0xfd90,
480, , , veracrypt.sys+0xfd90,
476, , , veracrypt.sys+0xfd90,
472, , , veracrypt.sys+0xfd90,
468, , , veracrypt.sys+0xfd90,
464, , , veracrypt.sys+0xfd90,
460, , , rdbss.sys!RxDoesRedirSupportLogicalViews+0x50,
436, , , avgRdr2.sys+0x9c1c,
432, , , cmdhlp.sys+0x26bc,
428, , , cmdhlp.sys+0x177c,
424, , , watchdog.sys!SMgrRegisterSessionChangeCallout+0x70,
420, , , cmdguard.sys+0x95674,
416, , , cmdguard.sys+0x699f4,
412, , , cmdguard.sys+0x697f4,
408, , , cmdguard.sys+0x7d8d0,
404, , , avgSnx.sys+0x4abc4,
392, , , avgSP.sys+0x2fdc4,
372, , , avgbidsha.sys+0x129d0,
368, , , avgbloga.sys+0x21b0,
348, , , ntoskrnl.exe!RtlIoDecodeMemIoResource+0x220,
344, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x43c0,
340, , , volsnap.sys+0x46000,
336, , , volsnap.sys+0x46000,
332, , , volsnap.sys+0x46000,
328, , , volsnap.sys+0x46000,
324, , , volsnap.sys+0x46000,
320, , , volsnap.sys+0x46000,
316, , , volsnap.sys+0x46000,
312, , , volsnap.sys+0x46000,
308, , , volsnap.sys+0x46000,
296, , , ndis.sys!NdisInitializeTimer+0x1640,
292, , , ndis.sys!NdisInitializeTimer+0x1640,
288, , , ndis.sys!NdisInitializeTimer+0x1640,
280, , , ndis.sys!NdisInitializeTimer+0x1640,
276, , , ndis.sys!NdisInitializeTimer+0x1640,
272, , , ndis.sys!NdisInitializeTimer+0x1640,
264, , , vsock.sys+0x404c,
260, , , vmci.sys!DllInitialize+0x6ac8,
256, , , ACPI.sys+0x30910,
252, , , pci.sys+0xa0c0,
212, , , ACPI.sys+0x42f50,
208, , , ntoskrnl.exe!PoFxProcessorNotification+0x40,
204, , , ntoskrnl.exe!PoFxProcessorNotification+0x40,
200, , , ntoskrnl.exe!PoFxProcessorNotification+0x40,
196, , , ntoskrnl.exe!PoFxProcessorNotification+0x40,
188, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
184, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
180, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
176, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
172, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
168, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
164, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
160, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
156, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
152, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
148, , , ntoskrnl.exe!RtlSetOwnerSecurityDescriptor+0x3500,
136, , , ntoskrnl.exe!RtlSecondsSince1970ToTime+0x1e0,
132, , , ntoskrnl.exe!RtlSecondsSince1970ToTime+0x1e0,
116, , , ntoskrnl.exe!RtlInitAnsiStringEx+0xac0,
112, , , ntoskrnl.exe!RtlInitAnsiStringEx+0xac0,
108, , , ntoskrnl.exe!RtlInitAnsiStringEx+0xac0,
104, , , ntoskrnl.exe!RtlInitAnsiStringEx+0x450,
68, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
64, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
60, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
56, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
52, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
48, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
44, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
40, , , ntoskrnl.exe!KeInitializeThreadedDpc+0x850,
28, , , ntoskrnl.exe!RtlCultureNameToLCID+0x320,
24, , , ntoskrnl.exe!IoQueryFullDriverPath+0x330,
20, , , ntoskrnl.exe!PoFxReportDevicePoweredOn+0xa50,
16, , , ntoskrnl.exe!PoFxReportDevicePoweredOn+0xa50,
12, , , ntoskrnl.exe!KeRegisterBugCheckCallback+0x270,
Messaggio unito automaticamente:

Come non detto, scusate il disturbo. Una piccola ricerca mi ha portato a questo post: https://stackoverflow.com/questions/1430141/port-80-is-being-used-by-system-pid-4-what-is-that

Chiudo.