Re: PC Media AV 5.0 Valhalla
^ pake tag img
[img=PunBB bbcode test]http://virusindonesia.com/forum/img/test.png[/img]Ajang diskusi malware di Indonesia & reverse code engineering.
You are not logged in. Please login or register.
^ pake tag img
[img=PunBB bbcode test]http://virusindonesia.com/forum/img/test.png[/img]^ pake tag img
[img=PunBB bbcode test]http://virusindonesia.com/forum/img/test.png[/img]
maap masih lom ngerti....mulai dr print screen lalu?
mas mo tanya.....cara nempelin screen shootnya bijimana ya?
upload dulu gambarnya ke website, misalnya ke photoserver.ws, terus pake tag img dan masukin linknya diantara tag [img]dan[/img]
ahaaaaa..akhirnya bs jg....thx ya...
ini saya lampirkan screenshootnya...d situ terlihat loading yg sangat lama stelah saya enable pcmav.....saya pake windows xp sp3 32bit..makasih utk tanggapannya

@yuri : Sudah mencoba merefresh situs Yahoo tersebut atau membuka situs lainnya?
@yuri : Sudah mencoba merefresh situs Yahoo tersebut atau membuka situs lainnya?
bukan hanya tiap situs, tp pake IE jg teteup loading terus...refresh uda...clear cache jg udin..
saat lagi loading lama dan tak berujung itu, pcmav langsung saya disable....dan langsung lancarrrrrrrrrrrrrr againnnn
@yuri :
Bisa disebutkan keterangan Build di tampilan utama PCMAV?
ketika Anda tidak bisa browsing, Anda dapat mencoba membuka situs di bawah ini dan infokan kepada kami hasilnya.
copy dan paste alamat url berikut di browser:
[url]https://secure.wikimedia.org/wikipedia/en/wiki/Main_Page[/url]
[url]http://restricted.virusindonesia.com/[/url]pcmav langsung saya disable....dan langsung lancarrrrrrrrrrrrrr againnnn
Bagaimana jika Anda enable kembali RTP pada PCMAV atau merestart komputer tanpa mengaktifkan program netcut yang terlihat di browser Anda.
Loading lama saat membuka situs merupakan permasalahan cukup unik dalam proses pemfilteran HTTP mengingat adanya timeout pada HTTP request.
@yuri :
Bisa disebutkan keterangan Build di tampilan utama PCMAV?
ketika Anda tidak bisa browsing, Anda dapat mencoba membuka situs di bawah ini dan infokan kepada kami hasilnya.copy dan paste alamat url berikut di browser:
[url]https://secure.wikimedia.org/wikipedia/en/wiki/Main_Page[/url] [url]http://restricted.virusindonesia.com/[/url]yuri wrote:pcmav langsung saya disable....dan langsung lancarrrrrrrrrrrrrr againnnn
Bagaimana jika Anda enable kembali RTP pada PCMAV atau merestart komputer tanpa
mengaktifkan program netcut yang terlihat di browser Anda.Loading lama saat membuka situs merupakan permasalahan cukup unik dalam proses pemfilteran HTTP mengingat adanya timeout pada HTTP request.
berikut build pcmav

berikut tampilan link wikimedia . sbelumnya pcmav enable dan berhasil buka link..kmudian pcmav di disable lalu link di reload..tampilan loading sudah selama 10 menit.

untuk program netcut....itu td kbetulan saja sedang saya gunakan..sbelumnya kasus tetap terjadi walaupun tdk mengaktifkan netcut...pada percobaan di atas saya tidak mengaktifkan netcut
thx buat tanggapannya
berikut tampilan link wikimedia . sbelumnya pcmav enable dan berhasil buka link..kmudian pcmav di disable lalu link di reload..tampilan loading sudah selama 10 menit.
Saya kurang mengerti dengan tulisan Anda. Intinya Anda sudah bisa browsing saat ini setelah melakukan disable - enable pada RTP PCMAV?
yuri wrote:berikut tampilan link wikimedia . sbelumnya pcmav enable dan berhasil buka link..kmudian pcmav di disable lalu link di reload..tampilan loading sudah selama 10 menit.
Saya kurang mengerti dengan tulisan Anda. Intinya Anda sudah bisa browsing saat ini setelah melakukan disable - enable pada RTP PCMAV?
maksud saya...saat pcmav di disable, link wikimedia berhasil d buka...stelah itu pcmav saya enable dan saya refresh link wikimedia yg sudah terbuka td, hasilnya sperti yg nampak di screenshoot(tab browsing berupa loading)
@yuri, anda udah coba pakai browser lain? kemungkinan dari Mozillanya.
yuri wrote:mas mo tanya.....cara nempelin screen shootnya bijimana ya?
upload dulu gambarnya ke website, misalnya ke photoserver.ws, terus pake tag img dan masukin linknya diantara tag [img]dan[/img]
Kalau mau tampilkan screen shoot dalam bentuk notepad bagaimana ya? Ada yg bisa kasih saran?
saya ketemu bug pada PC Media AV 5 dalam bentuk notepad yg tersimpan dalam satu folder dengan PCMAV 5. Bagaimana caranya untuk menampilkannya di forum ini ya?
saya ketemu bug pada PC Media AV 5 dalam bentuk notepad yg tersimpan dalam satu folder dengan PCMAV 5. Bagaimana caranya untuk menampilkannya di forum ini ya?
Di paste aja isi di dalam file text tsb, pake tag code biar halaman ga jadi penuh.
fish wrote:saya ketemu bug pada PC Media AV 5 dalam bentuk notepad yg tersimpan dalam satu folder dengan PCMAV 5. Bagaimana caranya untuk menampilkannya di forum ini ya?
Di paste aja isi di dalam file text tsb, pake tag code biar halaman ga jadi penuh.
contoh cara tag-nya bagaimana?
Saya menemukan bugreport seperti ini
date/time : 2011-04-04, 17:26:25, 375ms
computer name : AXIOO-NB
user name : axioo <admin>
registered owner : axioo
operating system : Windows XP Service Pack 2 build 2600
system language : English
system up time : 1 hour 19 minutes
program up time : 1 hour 18 minutes
processors : 2x Intel(R) Atom(TM) CPU N280 @ 1.66GHz
physical memory : 612/1015 MB (free/total)
free disk space : (C:) 34,48 GB (E:) 85,80 GB
display mode : 1024x600, 32 bit
process id : $9b0
allocated memory : 176,85 MB
command line : "E:\SOFTWARE\ANTIVIRUS\$!p)c$^m@&v'\PCMAV.exe" /RTP
executable : PCMAV.exe
exec. date/time : 2011-02-22 09:39
version : 5.0.0.0
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
PCMAV.exe.mad : $000260e0, $14f23e56, $a75feb77
callstack crc : $52a93456, $60484222, $60484222
count : 2
exception number : 1
exception class : EOutOfResources
exception message : Cannot remove shell notification icon.
main thread ($9b4):
00491861 +0c9 PCMAV.exe segment%48 public%4351
006023ba +01e PCMAV.exe segment%268 public%12180
004a6b63 +2bb PCMAV.exe segment%54 public%4991
004aab5a +4fa PCMAV.exe segment%54 public%5138
004bca4b +553 PCMAV.exe segment%58 public%5750
004aa284 +02c PCMAV.exe segment%54 public%5133
00475ee8 +014 PCMAV.exe segment%31 public%3532
7c90e470 +010 ntdll.dll KiUserCallbackDispatcher
77d4dfb9 +04e USER32.dll DefWindowProcA
004c39ee +02a PCMAV.exe segment%58 public%5985
004c40c7 +67b PCMAV.exe segment%58 public%5987
00475ee8 +014 PCMAV.exe segment%31 public%3532
7c90e470 +010 ntdll.dll KiUserCallbackDispatcher
77d4cff3 +0f6 USER32.dll PeekMessageA
004c4728 +014 PCMAV.exe segment%58 public%6000
004c484a +00a PCMAV.exe segment%58 public%6002
004c4b5b +0b3 PCMAV.exe segment%58 public%6007
00684280 +1dc PCMAV.exe segment%417 public%13118
thread $f48 (TgtTimerThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $f50 (TWndProc): <suspended>
00614e03 +1f PCMAV.exe segment%274 public%12335
thread $f60:
7c90d9d8 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
00546ce9 +1e5 PCMAV.exe segment%105 public%8436
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
>> created by thread $f5c at:
00546f58 +22c PCMAV.exe segment%105 public%8437
thread $f68 (TgtTimerThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $fa4:
7c90d218 +a ntdll.dll NtDelayExecution
thread $fa8:
7c90da48 +a ntdll.dll NtRemoveIoCompletion
thread $fac:
7c90df48 +a ntdll.dll NtWaitForMultipleObjects
thread $c94 (TRegMonitorThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
00613d8a +12 PCMAV.exe segment%271 public%12324
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
00613c74 +18 PCMAV.exe segment%271 public%12321
thread $c98 (TRegMonitorThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
00613d8a +12 PCMAV.exe segment%271 public%12324
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
00613c74 +18 PCMAV.exe segment%271 public%12321
thread $f04:
7c90daa8 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
77e87695 +00 RPCRT4.dll
thread $758:
7c90d218 +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by main thread ($9b4) at:
775543ba +00 ole32.dll
thread $740:
7c90d9d8 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
00546ce9 +1e5 PCMAV.exe segment%105 public%8436
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
>> created by thread $c90 at:
00546f58 +22c PCMAV.exe segment%105 public%8437
thread $7a8 (TgtTimerThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by thread $c90 at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $f30:
7c90daa8 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by thread $f04 at:
77e87695 +00 RPCRT4.dll
thread $ff8:
7c90daa8 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by thread $f30 at:
77e87695 +00 RPCRT4.dll
thread $574:
7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
7c8094f8 +00 kernel32.dll WaitForMultipleObjectsEx
7c80a080 +13 kernel32.dll WaitForMultipleObjects
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
>> created by thread $ca4 at:
769c8951 +00 userenv.dll
processes:
000 Idle 0 0
004 System 0 0 normal
1e8 smss.exe 0 0 normal C:\WINDOWS\system32
2b8 csrss.exe 45 60 normal C:\WINDOWS\system32
2d0 winlogon.exe 46 14 high C:\WINDOWS\system32
2fc services.exe 4 2 normal C:\WINDOWS\system32
308 lsass.exe 4 2 normal C:\WINDOWS\system32
3a4 svchost.exe 4 2 normal C:\WINDOWS\system32
3d8 svchost.exe 4 4 normal C:\WINDOWS\system32
400 svchost.exe 11 28 normal C:\WINDOWS\System32
440 svchost.exe 4 1 normal C:\WINDOWS\system32
460 svchost.exe 4 1 normal C:\WINDOWS\system32
498 AvastSvc.exe 4 7 normal C:\Program Files\Alwil Software\Avast5
564 Explorer.EXE 310 177 normal C:\WINDOWS
68c spoolsv.exe 4 4 normal C:\WINDOWS\system32
6d4 svchost.exe 4 1 normal C:\WINDOWS\system32
720 GtDetectSc.exe 4 1 normal C:\Program Files\Option\GlobeTrotter Connect
748 svchost.exe 4 172 normal C:\WINDOWS\system32
76c svchost.exe 4 3 below normal C:\WINDOWS\system32
788 jqs.exe 4 2 idle C:\Program Files\Java\jre6\bin
7b0 GoogleUpdate.exe 4 3 normal C:\Program Files\Google\Update
7c4 NBService.exe 4 2 normal C:\Program Files\Common Files\Nero\Nero BackItUp 4
09c svchost.exe 4 3 normal C:\WINDOWS\System32
180 OsdService.exe 4 3 normal C:\Program Files\ECS\OSD_1.5.3
19c svchost.exe 4 3 normal C:\WINDOWS\System32
210 PsiService_2.exe 4 1 normal c:\Program Files\Common Files\Protexis\License Service
228 RalinkRegistryWriter.exe 4 1 normal C:\Program Files\Ralink\Common
254 svchost.exe 4 2 normal C:\WINDOWS\system32
294 wdfmgr.exe 4 1 normal C:\WINDOWS\system32
2e4 YahooAUService.exe 4 4 normal C:\Program Files\Yahoo!\SoftwareUpdate
6b8 GrooveMonitor.exe 11 4 normal C:\Program Files\Microsoft Office\Office12
918 ctfmon.exe 28 11 normal C:\WINDOWS\system32
9b0 PCMAV.exe 263 155 normal E:\SOFTWARE\ANTIVIRUS\$!p)c$^m@&v'
9d8 hpqtra08.exe 17 30 normal C:\Program Files\HP\Digital Imaging\bin
a0c RaUI.exe 23 14 normal C:\Program Files\Ralink\Common
a18 GlobeTrotter Connect.exe 167 83 normal C:\Program Files\Option\GlobeTrotter Connect
af8 alg.exe 4 2 normal C:\WINDOWS\System32
b40 osd.exe 40 31 normal C:\Program Files\ECS\OSD_1.5.3
b94 ServiceLayer.exe 11 7 normal C:\Program Files\Common Files\PCSuite\Services
bc0 MPAPI3s.exe 11 7 normal C:\PROGRA~1\COMMON~1\Nokia\MPAPI
cbc wmiprvse.exe 7 6 normal C:\WINDOWS\system32\wbem
f6c ymsgr_tray.exe 95 12 normal C:\PROGRA~1\Yahoo!\MESSEN~1
094 hpqSTE08.exe 11 17 normal C:\Program Files\HP\Digital Imaging\bin
6a8 hpqbam08.exe 11 7 normal C:\Program Files\HP\Digital Imaging\bin
184 hpqgpc01.exe 8 6 normal C:\Program Files\HP\Digital Imaging\bin
848 logonui.exe 45 12 normal C:\WINDOWS\system32
cpu registers:
eax = 01287878
ebx = 00000000
ecx = 01287878
edx = 00491861
esi = 01193530
edi = 0012fb9c
eip = 00491861
esp = 0012f900
ebp = 0012f94c
stack dump:
0012f900 61 18 49 00 de fa ed 0e - 01 00 00 00 07 00 00 00 a.I.............
0012f910 14 f9 12 00 61 18 49 00 - 78 78 28 01 00 00 00 00 ....a.I.xx(.....
0012f920 30 35 19 01 9c fb 12 00 - 4c f9 12 00 30 f9 12 00 05......L...0...
0012f930 f4 fa 12 00 d0 4f 40 00 - 4c f9 12 00 24 fb 12 00 .....O@.L...$...
0012f940 f0 28 22 01 00 00 00 00 - 00 00 00 00 84 fa 12 00 .(".............
0012f950 bd 23 60 00 f0 28 22 01 - 24 fb 12 00 66 6b 4a 00 .#`..(".$...fkJ.
0012f960 9c fb 12 00 bb 0f 59 01 - 24 fb 12 00 11 00 00 00 ......Y.$.......
0012f970 cc 09 25 00 00 00 00 00 - d0 0b 00 00 00 00 00 00 ..%.............
0012f980 05 40 00 80 b4 09 00 00 - b4 5e 18 00 a8 f9 12 00 .@.......^......
0012f990 51 e9 73 74 e2 01 01 00 - b4 f9 12 00 a1 b2 d4 77 Q.st...........w
0012f9a0 8e 03 02 00 11 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f9b0 00 00 00 00 b1 8b d4 77 - 68 00 da 77 0f 01 00 00 .......wh..w....
0012f9c0 fc f9 12 00 74 b2 d4 77 - 50 b2 d4 77 11 00 00 00 ....t..wP..w....
0012f9d0 cc 09 25 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ..%.............
0012f9e0 01 00 00 00 cc f9 12 00 - 00 00 00 00 b8 fb 12 00 ................
0012f9f0 94 04 d7 77 58 b2 d4 77 - ff ff ff ff 50 b2 d4 77 ...wX..w....P..w
0012fa00 e9 06 45 77 8e 03 02 00 - 11 00 00 00 00 00 00 00 ..Ew............
0012fa10 00 00 00 00 9c fb 12 00 - 66 f8 44 77 f4 06 45 77 ........f.Dw..Ew
0012fa20 6e 64 52 65 63 65 69 76 - 65 43 6f 6e 65 63 74 69 ndReceiveConecti
0012fa30 6f 6e 2e 45 76 65 6e 74 - 2e 45 4c 4a 2e 49 43 00 on.Event.ELJ.IC.
disassembling:
00491798 public segment%48.public%4351 (PCMAV.exe): ; function entry point
00491798 push ebp
00491799 mov ebp, esp
0049179b push 0
0049179d push 0
0049179f push ebx
004917a0 push esi
004917a1 mov ebx, edx
004917a3 mov esi, eax
004917a5 xor eax, eax
004917a7 push ebp
004917a8 push $49188f ; segment%0.public%227 (PCMAV.exe)
004917ad push dword ptr fs:[eax]
004917b0 mov fs:[eax], esp
004917b3 cmp bl, [esi+$23c]
004917b9 jz loc_491874
004917b9
004917bf mov [esi+$23c], bl
004917c5 cmp byte ptr [esi+$30], 0
004917c9 jz loc_4917e0
004917c9
004917cb cmp byte ptr [esi+$30], 0
004917cf jz loc_4917e7
004917cf
004917d1 mov eax, [esi+$220]
004917d7 mov edx, [eax]
004917d9 call dword ptr [edx+$1c]
004917d9
004917dc test al, al
004917de jz loc_4917e7
004917de
004917e0 loc_4917e0:
004917e0 mov eax, esi
004917e2 call +$6b1 ($491e98) ; segment%48.public%4365 (PCMAV.exe)
004917e2
004917e7 loc_4917e7:
004917e7 test byte ptr [esi+$1c], $10
004917eb jnz loc_491874
004917eb
004917f1 cmp byte ptr [esi+$23c], 0
004917f8 jz loc_49182a
004917f8
004917fa xor edx, edx
004917fc mov eax, esi
004917fe call +$569 ($491d6c) ; segment%48.public%4360 (PCMAV.exe)
004917fe
00491803 test al, al
00491805 jnz loc_491861
00491805
00491807 lea edx, [ebp-4]
0049180a mov eax, [$6955dc]
0049180f call -$89ac4 ($407d50) ; segment%0.public%388 (PCMAV.exe)
0049180f
00491814 mov ecx, [ebp-4]
00491817 mov dl, 1
00491819 mov eax, [$4683b0]
0049181e call -$340cf ($45d754) ; segment%26.public%2614 (PCMAV.exe)
0049181e
00491823 call -$8c734 ($4050f4) ; segment%0.public%230 (PCMAV.exe)
00491823
00491828 jmp loc_491861
00491828
00491828 ; ---------------------------------------------------------
00491828
0049182a loc_49182a:
0049182a test byte ptr [esi+$1c], 1
0049182e jnz loc_491861
0049182e
00491830 mov edx, 2
00491835 mov eax, esi
00491837 call +$530 ($491d6c) ; segment%48.public%4360 (PCMAV.exe)
00491837
0049183c test al, al
0049183e jnz loc_491861
0049183e
00491840 lea edx, [ebp-8]
00491843 mov eax, [$695f5c]
00491848 call -$89afd ($407d50) ; segment%0.public%388 (PCMAV.exe)
00491848
0049184d mov ecx, [ebp-8]
00491850 mov dl, 1
00491852 mov eax, [$4683b0]
00491857 call -$34108 ($45d754) ; segment%26.public%2614 (PCMAV.exe)
00491857
0049185c call -$8c76d ($4050f4) ; segment%0.public%230 (PCMAV.exe)
0049185c
00491861 loc_491861:
00491861 > cmp byte ptr [esi+$30], 0
00491865 jz loc_491874
00491865
00491867 mov edx, ebx
00491869 mov eax, [esi+$230]
0049186f call -$a44 ($490e30) ; segment%48.public%4324 (PCMAV.exe)
0049186f
00491874 loc_491874:
00491874 xor eax, eax
00491876 pop edx
00491877 pop ecx
00491878 pop ecx
00491879 mov fs:[eax], edx
0049187c push $491896
00491879
00491881 loc_491881:
00491881 lea eax, [ebp-8]
00491884 mov edx, 2
00491889 call -$8c0ea ($4057a4) ; segment%0.public%254 (PCMAV.exe)
00491889
0049188e ret
0049188e
0049188e ; ---------------------------------------------------------
0049188e
0049188f jmp -$8c944 ($404f50) ; segment%0.public%227 (PCMAV.exe)
0049188f
00491894 jmp loc_491881
00491894
00491894 ; ---------------------------------------------------------
00491894
00491896 pop esi
00491897 pop ebx
00491898 pop ecx
00491899 pop ecx
0049189a pop ebp
0049189b retPermasalahannya ada dimana ya? Mohon pencerahannya. Thanks.
@yuri, anda udah coba pakai browser lain? kemungkinan dari Mozillanya.
pada komen saya di atas ( no.56 ) sudah saya jelaskan klo saya jg menggunakan Internet Exsplorer...dan hasilnya sama saja...terima kasih utk tanggapannya
@fish :
Dari keterangan error, PCMAV aktif lebih awal dari proses Explorer.exe karena sesuatu hal pada saat Windows melakukan booting. Terima kasih laporannya.
@yuri :
Apakah Anda masih tidak dapat membuka situs jika RTP PCMAV aktif? Saya asumsikan Anda telah merestart komputer Anda.
Jika masih mengalami permasalahan, silahkan tutup PCMAV, buka regedit dan hapus HKEY_CURRENT_USER\Software\PC Media Antivirus. Lakukan restart komputer. Jika Anda menggunakan program firewall dsb, Anda dapat menginformasikannya juga.
FYI, PCMAV seharusnya tidak memproses link pertama yang saya berikan.
kok kosong ??
Error ini akan segera diproses.
tty.
saat menggunakan trainer muncul bugreport seperti ini
date/time : 2011-04-19, 12:12:45, 500ms
computer name : WOKEY-PC
user name : Procyon <admin>
registered owner : Procyon
operating system : Windows 7 build 7600
system language : Indonesian
system up time : 2 hours 20 minutes
program up time : 2 hours 20 minutes
processors : 4x AMD Athlon(tm) II X4 640 Processor
physical memory : 806/2047 MB (free/total)
free disk space : (C:) 27,78 GB
display mode : 1440x900, 32 bit
process id : $864
allocated memory : 84,80 MB
command line : "C:\Users\Procyon\Documents\Valhalla 5\PCMAV.exe" /RTP
executable : PCMAV.exe
exec. date/time : 2011-02-22 09:39
version : 5.0.0.0
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
PCMAV.exe.mad : $000260e0, $14f23e56, $a75feb77
callstack crc : $077ee70c, $a2da2861, $a2da2861
exception number : 1
exception class : EStringListError
exception message : List index out of bounds (1).
main thread ($868):
0046ddad +021 PCMAV.exe segment%31 public%3190
00600c59 +089 PCMAV.exe segment%265 public%12168
004bc0e1 +015 PCMAV.exe segment%58 public%5736
004c03bd +0a9 PCMAV.exe segment%58 public%5854
004a6b63 +2bb PCMAV.exe segment%54 public%4991
004aab5a +4fa PCMAV.exe segment%54 public%5138
004bca4b +553 PCMAV.exe segment%58 public%5750
004a67f0 +024 PCMAV.exe segment%54 public%4987
004aa022 +112 PCMAV.exe segment%54 public%5130
004aa165 +0e5 PCMAV.exe segment%54 public%5131
004ac9ea +026 PCMAV.exe segment%54 public%5224
004a6b63 +2bb PCMAV.exe segment%54 public%4991
004aab5a +4fa PCMAV.exe segment%54 public%5138
004bca4b +553 PCMAV.exe segment%58 public%5750
004a67f0 +024 PCMAV.exe segment%54 public%4987
004a53f2 +026 PCMAV.exe segment%54 public%4913
004bc382 +03a PCMAV.exe segment%58 public%5745
004c0c47 +007 PCMAV.exe segment%58 public%5865
004c0e7d +14d PCMAV.exe segment%58 public%5869
00600e24 +074 PCMAV.exe segment%266 public%12173
00474665 +0fd PCMAV.exe segment%31 public%3424
004c40bf +673 PCMAV.exe segment%58 public%5987
00475ee8 +014 PCMAV.exe segment%31 public%3532
77023573 +00a USER32.dll DispatchMessageA
004c4810 +0fc PCMAV.exe segment%58 public%6000
004c484a +00a PCMAV.exe segment%58 public%6002
004c4b5b +0b3 PCMAV.exe segment%58 public%6007
00684280 +1dc PCMAV.exe segment%417 public%13118
75681192 +010 kernel32.dll BaseThreadInitThunk
thread $ba0 (TgtTimerThread):
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
7567efad +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($868) at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $ba4 (TWndProc): <suspended>
00614e03 +1f PCMAV.exe segment%274 public%12335
thread $bb0:
77125caa +0a ntdll.dll NtWaitForMultipleObjects
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $bc8:
771256ca +00a ntdll.dll NtReplyWaitReceivePort
00546508 +030 PCMAV.exe segment%105 public%8432
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $bbc at:
005469d3 +263 PCMAV.exe segment%105 public%8433
thread $bcc: <priority:1>
77125cca +00a ntdll.dll NtWaitForSingleObject
75531796 +066 KERNELBASE.dll WaitForSingleObjectEx
7567effe +03e kernel32.dll WaitForSingleObjectEx
7567efad +00d kernel32.dll WaitForSingleObject
0054618a +012 PCMAV.exe segment%105 public%8431
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $bbc at:
005469f4 +284 PCMAV.exe segment%105 public%8433
thread $bdc (TgtTimerThread):
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
7567efad +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($868) at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $c04:
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $c20 (TRegMonitorThread):
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
7567efad +0d kernel32.dll WaitForSingleObject
00613d8a +12 PCMAV.exe segment%271 public%12324
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($868) at:
00613c74 +18 PCMAV.exe segment%271 public%12321
thread $c24 (TRegMonitorThread):
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
7567efad +0d kernel32.dll WaitForSingleObject
00613d8a +12 PCMAV.exe segment%271 public%12324
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($868) at:
00613c74 +18 PCMAV.exe segment%271 public%12321
thread $d84:
771256ca +00a ntdll.dll NtReplyWaitReceivePort
00546508 +030 PCMAV.exe segment%105 public%8432
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $c1c at:
005469d3 +263 PCMAV.exe segment%105 public%8433
thread $d88: <priority:1>
77125cca +00a ntdll.dll NtWaitForSingleObject
75531796 +066 KERNELBASE.dll WaitForSingleObjectEx
7567effe +03e kernel32.dll WaitForSingleObjectEx
7567efad +00d kernel32.dll WaitForSingleObject
0054618a +012 PCMAV.exe segment%105 public%8431
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $c1c at:
005469f4 +284 PCMAV.exe segment%105 public%8433
thread $d8c (TgtTimerThread):
77125cca +0a ntdll.dll NtWaitForSingleObject
75531796 +66 KERNELBASE.dll WaitForSingleObjectEx
7567effe +3e kernel32.dll WaitForSingleObjectEx
7567efad +0d kernel32.dll WaitForSingleObject
005d536c +10 PCMAV.exe segment%221 public%11307
00452c7b +2b PCMAV.exe segment%23 public%2341
00474774 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $c1c at:
005d52f3 +1b PCMAV.exe segment%221 public%11304
thread $d90:
77124a7a +0a ntdll.dll NtDelayExecution
75531870 +4f KERNELBASE.dll SleepEx
75531813 +0a KERNELBASE.dll Sleep
00452b5d +0d PCMAV.exe segment%23 public%2339
00452bc7 +37 PCMAV.exe segment%23 public%2340
75681192 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($868) at:
75c664f2 +00 ole32.dll
thread $e2c:
77125cca +00a ntdll.dll NtWaitForSingleObject
75531796 +066 KERNELBASE.dll WaitForSingleObjectEx
7567effe +03e kernel32.dll WaitForSingleObjectEx
7567efad +00d kernel32.dll WaitForSingleObject
005460d3 +017 PCMAV.exe segment%105 public%8430
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $bcc at:
005462f1 +179 PCMAV.exe segment%105 public%8431
thread $e34:
77125cda +0a ntdll.dll NtWaitForWorkViaWorkerFactory
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $a3c:
77125cda +0a ntdll.dll NtWaitForWorkViaWorkerFactory
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $a88:
77125cda +0a ntdll.dll NtWaitForWorkViaWorkerFactory
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $934:
77125cda +0a ntdll.dll NtWaitForWorkViaWorkerFactory
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $66c:
77125cda +0a ntdll.dll NtWaitForWorkViaWorkerFactory
75681192 +10 kernel32.dll BaseThreadInitThunk
thread $fc0:
77125cca +00a ntdll.dll NtWaitForSingleObject
75531796 +066 KERNELBASE.dll WaitForSingleObjectEx
7567effe +03e kernel32.dll WaitForSingleObjectEx
7567efad +00d kernel32.dll WaitForSingleObject
00474e14 +07c PCMAV.exe segment%31 public%3442
00600eb0 +024 PCMAV.exe segment%267 public%12175
0054610e +052 PCMAV.exe segment%105 public%8430
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $d88 at:
005462f1 +179 PCMAV.exe segment%105 public%8431
thread $cb0 (AskingThread):
77125cca +00a ntdll.dll NtWaitForSingleObject
75531796 +066 KERNELBASE.dll WaitForSingleObjectEx
7567effe +03e kernel32.dll WaitForSingleObjectEx
7567efad +00d kernel32.dll WaitForSingleObject
00474c2f +113 PCMAV.exe segment%31 public%3436
00474cd6 +01e PCMAV.exe segment%31 public%3437
00600daa +006 PCMAV.exe segment%266 public%12172
00452c7b +02b PCMAV.exe segment%23 public%2341
00474774 +034 PCMAV.exe segment%31 public%3425
004056f4 +028 PCMAV.exe segment%0 public%250
00452b5d +00d PCMAV.exe segment%23 public%2339
00452bc7 +037 PCMAV.exe segment%23 public%2340
75681192 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $fc0 at:
00600e69 +02d PCMAV.exe segment%266 public%12174
processes:
000 Idle 0 0 0
004 System 0 0 0
118 smss.exe 0 0 0 normal C:\Windows\system32
17c csrss.exe 0 0 0 normal C:\Windows\system32
1c8 wininit.exe 0 0 0 high C:\Windows\system32
1d0 csrss.exe 1 174 80 normal C:\Windows\system32
1fc services.exe 0 0 0 normal C:\Windows\system32
204 lsass.exe 0 0 0 normal C:\Windows\system32
20c lsm.exe 0 0 0 normal C:\Windows\system32
278 svchost.exe 0 0 0 normal C:\Windows\system32
2ac winlogon.exe 1 6 0 high C:\Windows\system32
2f4 svchost.exe 0 0 0 normal C:\Windows\system32
338 atiesrxx.exe 0 0 0 normal C:\Windows\system32
374 svchost.exe 0 0 0 normal C:\Windows\System32
398 svchost.exe 0 0 0 normal C:\Windows\System32
3b4 svchost.exe 0 0 0 normal C:\Windows\system32
44c svchost.exe 0 0 0 normal C:\Windows\system32
4d4 svchost.exe 0 0 0 normal C:\Windows\system32
528 atieclxx.exe 1 9 7 normal C:\Windows\system32
558 spoolsv.exe 0 0 0 normal C:\Windows\System32
58c svchost.exe 0 0 0 normal C:\Windows\system32
5e0 ASO3DefragSrv.exe 0 0 0 normal C:\Program Files\Advanced System Optimizer 3
648 RTPSvc.exe 0 0 0 normal C:\Windows\system32
688 svchost.exe 0 0 0 normal C:\Windows\system32
7e8 svchost.exe 0 0 0 normal C:\Windows\system32
180 taskhost.exe 1 26 20 normal C:\Windows\system32
3b0 Dwm.exe 1 18 2 high C:\Windows\system32
424 taskeng.exe 1 10 3 normal C:\Windows\system32
624 Explorer.EXE 1 795 424 normal C:\Windows
85c AWC.exe 1 752 257 normal C:\Program Files\IObit\Advanced SystemCare 3
864 PCMAV.exe 1 228 165 below normal C:\Users\Procyon\Documents\Valhalla 5
8e4 SUPERAntiSpyware.exe 1 42 42 normal C:\Program Files\SUPERAntiSpyware
8fc MOM.exe 1 10 9 normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
9f0 CCC.exe 1 39 42 normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
b24 svchost.exe 0 0 0 normal C:\Windows\system32
f64 DkService.exe 0 0 0 below normal C:\Program Files\Diskeeper Corporation\Diskeeper
da8 wuauclt.exe 1 12 7 normal C:\Windows\system32
634 taskhost.exe 1 9 4 normal C:\Windows\system32
c30 BRIGADE.exe 1 96 53 normal C:\Program Files\BRIGADE
cfc Rainbow Six Vegas Trainer.exe 1 29 22 normal F:\Permainan\Tom Clancy's Rainbow Six Vegas 2\Binaries
fcc audiodg.exe 0 0 0
858 R6Vegas2_game.exe 1 40 27 normal F:\Permainan\Tom Clancy's Rainbow Six Vegas 2\Binaries
cpu registers:
eax = 0319a020
ebx = 01a0b108
ecx = 00000000
edx = 0046ddad
esi = 00000001
edi = 00000001
eip = 0046ddad
esp = 0012f804
ebp = 0012f864
stack dump:
0012f804 ad dd 46 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..F.............
0012f814 18 f8 12 00 ad dd 46 00 - 20 a0 19 03 08 b1 a0 01 ......F.........
0012f824 01 00 00 00 01 00 00 00 - 64 f8 12 00 34 f8 12 00 ........d...4...
0012f834 01 00 00 00 00 00 00 00 - 74 6d 46 00 c0 f2 9e 01 ........tmF.....
0012f844 0a c8 46 00 7c f8 12 00 - d0 4f 40 00 64 f8 12 00 ..F.|....O@.d...
0012f854 98 f8 12 00 01 00 00 00 - c0 f2 9e 01 00 00 00 00 ................
0012f864 a8 f8 12 00 ad dd 46 00 - 24 8b 46 00 c0 f2 9e 01 ......F.$.F.....
0012f874 80 20 99 01 5c 0c 60 00 - b8 f8 12 00 d0 4f 40 00 ....\.`......O@.
0012f884 a8 f8 12 00 80 20 99 01 - cc c0 4b 00 80 20 99 01 ..........K.....
0012f894 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f8a4 00 00 00 00 f0 f8 12 00 - e7 c0 4b 00 90 fa 12 00 ..........K.....
0012f8b4 c2 03 4c 00 c4 f8 12 00 - a0 4d 40 00 f0 f8 12 00 ..L......M@.....
0012f8c4 d0 f8 12 00 53 09 4c 00 - f0 f8 12 00 ac fa 12 00 ....S.L.........
0012f8d4 70 09 4c 00 f0 f8 12 00 - 80 20 99 01 80 20 99 01 p.L.............
0012f8e4 90 fa 12 00 00 00 00 00 - 80 20 99 01 1c fa 12 00 ................
0012f8f4 66 6b 4a 00 80 20 99 01 - 04 00 00 00 90 fa 12 00 fkJ.............
0012f904 80 20 99 01 03 00 00 00 - 00 2f 96 01 47 00 00 00 ........./..G...
0012f914 00 00 00 00 50 fa 12 00 - 47 00 00 00 00 00 00 00 ....P...G.......
0012f924 00 00 00 00 00 00 00 00 - a8 f9 12 00 40 f9 12 00 ............@...
0012f934 5c f9 12 00 d8 98 07 77 - e0 83 02 77 a8 f9 12 00 \......w...w....
disassembling:
0046dd8c public segment%31.public%3190 (PCMAV.exe): ; function entry point
0046dd8c push ebx
0046dd8d push esi
0046dd8e push edi
0046dd8f mov edi, ecx
0046dd91 mov esi, edx
0046dd93 mov ebx, eax
0046dd95 test esi, esi
0046dd97 jl loc_46dd9e
0046dd97
0046dd99 cmp esi, [ebx+$1c]
0046dd9c jl loc_46ddad
0046dd9c
0046dd9e loc_46dd9e:
0046dd9e mov edx, [$695fa8]
0046dda4 mov ecx, esi
0046dda6 mov eax, ebx
0046dda8 call -$15d5 ($46c7d8) ; segment%31.public%3137 (PCMAV.exe)
0046dda8
0046ddad loc_46ddad:
0046ddad > mov eax, edi
0046ddaf mov edx, [ebx+$18]
0046ddb2 mov edx, [edx+esi*8]
0046ddb5 call -$685e6 ($4057d4) ; segment%0.public%255 (PCMAV.exe)
0046ddb5
0046ddba pop edi
0046ddbb pop esi
0046ddbc pop ebx
0046ddbd retiseng-iseng saya coba 2 virus yang sama di dalam file .zip berbeda. saya coba scan sekaligus malah hanya muncul 1 yang ke detek seperti gambar di bawah ini.
gabriel2.zip kenapa tidak ke detek?
Last edited by wokey (19-04-2011 15:37:32)
sy menemukan mslah pd tampilan pcmav, yaitu saat loading selesai, tampil setelah itu message box "ulr.bad".
Saya menggunakn Pcmav dgn plugin clamav 0.97.
Mohon pencerahanny. trimks.
sy menemukan mslah pd tampilan pcmav, yaitu saat loading selesai, tampil setelah itu message box "ulr.bad".
Saya menggunakn Pcmav dgn plugin clamav 0.97.
Mohon pencerahanny. trimks.
Bisa disebutkan secara lengkap pesan error yang diterima agar kami dapat lebih mudah menganalisanya.
Mas Fajar Gimana Cara Exit Permanent PVMAV 5,Masalahnya Ane Lupa Password Utk LockSetting. Pls Urgent ![]()
@musabrin : silahkan download program kecil ini yang meng-generate ID dan paste ID tsb ke forum ini dan sebaiknya di bagian Konsultasi.
PC Media © 2010 - 2013. Powered by PunBB.
[ Generated in 0.056 seconds, 10 queries executed ]