PAGE_FAULT_IN_NONPAGE AREA
E evidenziava il file WIN32K.SYS ...(verificare ecc ecc.)
Ho fatto una ricerca sulla RETE e si dice che imputabile a problemi con la memoria RAM
e si parlava di un file eseguibile di windows "VERIFIER.EXE" Che faceva un controllo dei componenti
Ho letto anche che aveva dato qualche prob.. ma visto che parte integrante del sistema operativo di XP
L'ho eseguito spuntando () CREA IMPOSTAZIONI STANDARD....
Mi chiedeva di ripartire.. l'ho fatto.... ma hogni volta mi dava SCHERMATA BLU ..ERRORE :
File PXRTS.sys... rovinato consultare ecc ecc
Provato piu volte sempre lo stesso ERRORE e XP non partiva piu'...
Sono ripartito in MODALITA' provvisoria... ho rilanciato VERIFIER.EXE e ho messo la spunta :
() ELIMINA IMPOSTAZIONI ESISTENTI...
Sono ripartito e il sistema E' RIPARTITO CORRETTAMENTE....
Così mi sono meeeo alla ricerca di info sul file "pxrts.sys"... ho trovato un po di tutto...
dal rimuovere a mana il file PXRTS.sys e tutti i suoi riferimenti (non l'ho fatto.. sono in attesa) ed eseguire PREVX..
ho esefuito PREVX .. ed ha trovato :
- il file che fa le join di file (plsc) script per messanger
- il file FileDiffer.dll di 10240 byte (non so' cosa sia)
- il file bpftpserver.exe (appunto server ftp che uso da molti anni)
qui ho trovato come prima cosa di eseguire GMER
Cosi ho eseguito GMER .. e vi allego il LOG... (non completo perche mi dava errore di eccesso lineeee..
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-05 14:46:34
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 Maxtor_6B200M0 rev.BANC1BM0
Running: gmer.exe; Driver: C:\DOCUME~1\Gilberto\IMPOST~1\Temp\fxtiipoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwAssignProcessToJobObject [0xAC9581CC]
SSDT BA00B46E ZwCreateKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwCreateThread [0xAC958206]
SSDT BA00B473 ZwDeleteKey
SSDT BA00B47D ZwDeleteValueKey
SSDT BA00B482 ZwLoadKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenProcess [0xAC95851A]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenThread [0xAC9583F6]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwProtectVirtualMemory [0xAC958292]
SSDT BA00B48C ZwReplaceKey
SSDT BA00B487 ZwRestoreKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwSetContextThread [0xAC95818E]
SSDT BA00B478 ZwSetValueKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateProcess [0xAC95864E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateThread [0xAC958316]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwWriteVirtualMemory [0xAC95834E]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB90C7000, 0x1BDE76, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[1808] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 00C17B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\WINDOWS\Explorer.EXE[1808] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 00C17090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 00C17800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 003C7940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 003C7A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003C78D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 003C7B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 003C7B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 003C7090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 003C7D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 003C6ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 003C6AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 003C7800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 003C6E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003C69D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 003C6D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 003C6DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 003C6C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 003C2740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 003C6CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 003C2720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 003C6C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 003C6D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003C70E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 003C6FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 003C6F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 003C2890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASocketW 71A339CB 3 Bytes JMP 003C2950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASocketW + 4 71A339CF 3 Bytes [8E, CC, CC]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003C28D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 003C2910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 003C2850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 003C2760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003C27F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 003C2790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003C27C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 003C2820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 003C7940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 003C7A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003C78D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 003C7B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 003C7B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 003C7090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 003C7D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 003C6ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 003C6AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 003C7800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 003C6E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003C69D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 003C6D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 003C6DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 003C6C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 003C2740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 003C6CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 003C2720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 003C6C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 003C6D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003C70E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 003C6FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 003C6F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 003C2890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASocketW 71A339CB 3 Bytes JMP 003C2950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASocketW + 4 71A339CF 3 Bytes [8E, CC, CC]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003C28D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 003C2910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 003C2850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 003C2760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003C27F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 003C2790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003C27C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 003C2820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 00357940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 00357A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003578D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 00357B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 00357B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 00357090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 00357D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 00356ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 00356AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 00357800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 00356E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003569D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 00356D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 00356DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 00356C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 00352740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 00356CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 00352720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 00356C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 00356D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003570E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 00356FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 00356F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 00352890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSASocketW 71A339CB 7 Bytes JMP 00352950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003528D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 00352910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 00352850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 00352760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003527F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 00352790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003527C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 00352820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[3780] kernel32.dll!SetUnhandledExceptionFilter 7C810386 5 Bytes JMP 0056DBBD C:\Programmi\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)
Rootkit scan 2010-12-05 14:46:34
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 Maxtor_6B200M0 rev.BANC1BM0
Running: gmer.exe; Driver: C:\DOCUME~1\Gilberto\IMPOST~1\Temp\fxtiipoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwAssignProcessToJobObject [0xAC9581CC]
SSDT BA00B46E ZwCreateKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwCreateThread [0xAC958206]
SSDT BA00B473 ZwDeleteKey
SSDT BA00B47D ZwDeleteValueKey
SSDT BA00B482 ZwLoadKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenProcess [0xAC95851A]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenThread [0xAC9583F6]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwProtectVirtualMemory [0xAC958292]
SSDT BA00B48C ZwReplaceKey
SSDT BA00B487 ZwRestoreKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwSetContextThread [0xAC95818E]
SSDT BA00B478 ZwSetValueKey
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateProcess [0xAC95864E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateThread [0xAC958316]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwWriteVirtualMemory [0xAC95834E]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB90C7000, 0x1BDE76, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[1808] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 00C17B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\WINDOWS\Explorer.EXE[1808] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 00C17090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 00C17800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 003C7940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 003C7A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003C78D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 003C7B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 003C7B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 003C7090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 003C7D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 003C6ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 003C6AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 003C7800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 003C6E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003C69D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 003C6D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 003C6DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 003C6C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 003C2740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 003C6CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 003C2720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 003C6C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 003C6D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003C70E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 003C6FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 003C6F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 003C2890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASocketW 71A339CB 3 Bytes JMP 003C2950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASocketW + 4 71A339CF 3 Bytes [8E, CC, CC]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003C28D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 003C2910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 003C2850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 003C2760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003C27F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 003C2790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003C27C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2952] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 003C2820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[2988] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3256] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 003C7940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile + 6 7C91D688 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateFile + B 7C91D68D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 003C7A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 1 Byte [28]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + 6 7C91DC5B 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtMapViewOfSection + B 7C91DC60 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003C78D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile + 6 7C91DD03 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenFile + B 7C91DD08 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcess + 6 7C91DD81 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcess + B 7C91DD86 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessToken + 6 7C91DD96 4 Bytes CALL 7B91F49C
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessToken + B 7C91DD9B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessTokenEx + 6 7C91DDAB 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenProcessTokenEx + B 7C91DDB0 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 003C7B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThread + 6 7C91DDFF 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThread + B 7C91DE04 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadToken + 6 7C91DE14 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadToken + B 7C91DE19 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadTokenEx + 6 7C91DE29 4 Bytes CALL 7B91F530
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtOpenThreadTokenEx + B 7C91DE2E 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryAttributesFile + 6 7C91DEE6 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryAttributesFile + B 7C91DEEB 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryFullAttributesFile + 6 7C91DFB8 4 Bytes CALL 7B91F6BD
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtQueryFullAttributesFile + B 7C91DFBD 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationFile + 6 7C91E5DF 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationFile + B 7C91E5E4 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationThread + 6 7C91E648 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtSetInformationThread + B 7C91E64D 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 1 Byte [68]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + 6 7C91E966 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtUnmapViewOfSection + B 7C91E96B 1 Byte [E2]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 003C7B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 003C7090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 003C7D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 003C6ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 003C6AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 003C7800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 003C6E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003C69D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 003C6D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 003C6DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 003C6C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 003C2740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 003C6CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 003C2720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 003C6C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 003C6D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003C70E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 003C6FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 003C6F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 003C2890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASocketW 71A339CB 3 Bytes JMP 003C2950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASocketW + 4 71A339CF 3 Bytes [8E, CC, CC]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003C28D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 003C2910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 003C2850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 003C2760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003C27F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 003C2790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003C27C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3292] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 003C2820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtCreateFile 7C91D682 5 Bytes JMP 00357940 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtCreateSection 7C91D793 5 Bytes JMP 00357A60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes JMP 003578D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtOpenSection 7C91DDBA 5 Bytes JMP 00357B00 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ntdll.dll!NtWriteFile 7C91E9F3 5 Bytes JMP 00357B40 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] kernel32.dll!CreateThread 7C81082F 5 Bytes JMP 00357090 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] kernel32.dll!OutputDebugStringA 7C859B5C 5 Bytes JMP 00357D60 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostMessageW 77D18CA3 5 Bytes JMP 00356ED0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageW 77D1B762 5 Bytes JMP 00356AA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SetWindowTextW 77D1BADE 5 Bytes JMP 00357800 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostMessageA 77D1DB62 5 Bytes JMP 00356E90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageA 77D1E2AE 5 Bytes JMP 003569D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutW 77D1E71C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutW 77D1E71C 5 Bytes JMP 00356D20 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageCallbackW 77D1EA4B 5 Bytes JMP 00356DC0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageW 77D1EB8C 1 Byte [E9]
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageW 77D1EB8C 5 Bytes JMP 00356C90 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostThreadMessageW 77D1FDEA 5 Bytes JMP 00352740 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageTimeoutA 77D1FF21 5 Bytes JMP 00356CD0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!PostThreadMessageA 77D3EBB0 5 Bytes JMP 00352720 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendNotifyMessageA 77D53668 5 Bytes JMP 00356C50 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] USER32.dll!SendMessageCallbackA 77D6ACD1 5 Bytes JMP 00356D70 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] GDI32.dll!ExtTextOutW 77E47EC6 5 Bytes JMP 003570E0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] ADVAPI32.dll!CredEnumerateW 77F87E49 7 Bytes JMP 00356FB0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] CRYPT32.dll!CryptUnprotectData 77A740A1 7 Bytes JMP 00356F30 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!sendto 71A32C69 5 Bytes JMP 00352890 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSASocketW 71A339CB 7 Bytes JMP 00352950 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!connect 71A3406A 5 Bytes JMP 003528D0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 00352910 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WS2_32.dll!WSAConnect 71A40C69 5 Bytes JMP 00352850 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestA 771976B8 5 Bytes JMP 00352760 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestExW 771A53EB 5 Bytes JMP 003527F0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!InternetWriteFile 771C7953 5 Bytes JMP 00352790 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestW 771E1808 5 Bytes JMP 003527C0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Documents and Settings\Gilberto\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe[3772] WININET.dll!HttpSendRequestExA 771E190D 5 Bytes JMP 00352820 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)
.text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[3780] kernel32.dll!SetUnhandledExceptionFilter 7C810386 5 Bytes JMP 0056DBBD C:\Programmi\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)
resto in attesa di vostre istruzioni...
ciao