PC Saya Windows XP SP2, RAM 1GB dan Pentium D 2,66 GHz. Untuk pemakai PCMAV Asgard Beta+Clamav Cukup Besar dalam Penggunaan CPU Usage setelah beberapa menit dalam melakukan scanning. Karena CPU Usage yang tinggi, membuat beberapa program Not Responding . Untuk PCMAV Asgard Beta, hanya sekali Not Responding.
Untuk PCMAV Asgard Final di Rilis kapan ya? Apakah Plugin PCMAV Valhalla seperti LockedHandlesViewer, PEViewer, dan ProcessMonitor yang akan disertakan pada PCMAV Asgard? Soalnya di PCMAV Asgard Beta tidak disertakan.
Lalu Nama Backround pada Plugin kenapa Warna Ungu ya? Mungkin lebih cocok warna Emas atau Kuning yang merupakan ciri khas PCMAV...

DirLock itu apa ya sesuai screenshot? maaf klo OOT. Soalnya baru kali ini menemukan File yang di suspect DirLock dengan file yang berbeda dan banyak. Padahal jika dilihat-lihat, file tersebut biasa2 saja. Mungkin bisa berikan penjelasan saya tentang hal ini...
---Update---
Bug Report
date/time : 2011-09-24, 11:18:18, 984ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 10 minutes 21 seconds
program up time : 7 minutes 55 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 554/958 MB (free/total)
free disk space : (C:) 55,90 GB
display mode : 1024x768, 32 bit
process id : $aec
allocated memory : 229,09 MB
executable : PCMAV.exe
exec. date/time : 2011-09-07 14:34
version : 6.0.0.0
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
PCMAV.exe.mad : $00026e2c, $3c4d3f27, $5122db36
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $80c6d9d7, $529a65b1, $529a65b1
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 0059083C in module 'PCMAV.exe'. Read of address 00000004.
main thread ($af4):
0059083c +004 PCMAV.exe segment%187 public%9922
00590895 +009 PCMAV.exe segment%187 public%9923
00684126 +05e PCMAV.exe segment%291 public%13038
004a704c +064 PCMAV.exe segment%54 public%4998
0048c920 +00c PCMAV.exe segment%43 public%4251
0048c9a4 +048 PCMAV.exe segment%43 public%4255
0048c8fc +028 PCMAV.exe segment%43 public%4250
0048caf1 +009 PCMAV.exe segment%43 public%4261
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
0048c408 +06c PCMAV.exe segment%43 public%4230
004a67d4 +024 PCMAV.exe segment%54 public%4987
004aac8f +023 PCMAV.exe segment%54 public%5140
004ab65b +00b PCMAV.exe segment%54 public%5147
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
004aa268 +02c PCMAV.exe segment%54 public%5133
00475ecc +014 PCMAV.exe segment%31 public%3532
77d4e361 +016 USER32.dll CallWindowProcA
004aac3b +0d7 PCMAV.exe segment%54 public%5139
004a746c +010 PCMAV.exe segment%54 public%5015
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
0048c408 +06c PCMAV.exe segment%43 public%4230
004aa268 +02c PCMAV.exe segment%54 public%5133
00475ecc +014 PCMAV.exe segment%31 public%3532
77d4bcc7 +00a USER32.dll DispatchMessageA
004c47f4 +0fc PCMAV.exe segment%58 public%6000
004c482e +00a PCMAV.exe segment%58 public%6002
004c4b3f +0b3 PCMAV.exe segment%58 public%6007
0069027d +1c9 PCMAV.exe segment%423 public%13231
thread $b28 (TWndProc): <suspended>
00667843 +1f PCMAV.exe segment%282 public%12790
thread $640:
7c90e286 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
005b674d +1e5 PCMAV.exe segment%208 public%10609
00452b5d +00d PCMAV.exe segment%23 public%2340
00452bc7 +037 PCMAV.exe segment%23 public%2341
>> created by thread $b2c at:
005b69bc +22c PCMAV.exe segment%208 public%10610
thread $3d0:
7c90d85a +a ntdll.dll NtDelayExecution
thread $ae0 (TRegMonitorThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00678e82 +12 PCMAV.exe segment%288 public%12949
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
00678d6c +18 PCMAV.exe segment%288 public%12946
thread $adc (TRegMonitorThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00678e82 +12 PCMAV.exe segment%288 public%12949
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
00678d6c +18 PCMAV.exe segment%288 public%12946
thread $afc:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
77d4bbf8 +00 USER32.dll MsgWaitForMultipleObjectsEx
77d4bca8 +1a USER32.dll MsgWaitForMultipleObjects
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by thread $ad8 at:
100048c3 +00 catchnet.dll
thread $b60:
7c90e286 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
005b674d +1e5 PCMAV.exe segment%208 public%10609
00452b5d +00d PCMAV.exe segment%23 public%2340
00452bc7 +037 PCMAV.exe segment%23 public%2341
>> created by thread $ad8 at:
005b69bc +22c PCMAV.exe segment%208 public%10610
thread $b64:
7c90e397 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
77e8760d +00 RPCRT4.dll
thread $b68:
7c90d85a +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
775543ba +00 ole32.dll
thread $f1c:
7c90e9a9 +a ntdll.dll NtWaitForMultipleObjects
thread $f24:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by thread $f18 at:
769c8951 +00 USERENV.dll
thread $ab4:
7c90e397 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by thread $b64 at:
77e8760d +00 RPCRT4.dll
thread $a1c:
7c90e397 +0a ntdll.dll NtReplyWaitReceivePortEx
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by thread $7c at:
77e8760d +00 RPCRT4.dll
thread $ce4 (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
thread $ec8 (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
thread $ed0 (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
thread $b24 (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($af4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
processes:
000 Idle 0 0
004 System 0 0 normal
6a0 smss.exe 0 0 normal C:\WINDOWS\system32
700 csrss.exe 61 60 normal C:\WINDOWS\system32
71c winlogon.exe 44 14 high C:\WINDOWS\system32
748 services.exe 4 2 normal C:\WINDOWS\system32
754 lsass.exe 4 1 normal C:\WINDOWS\system32
088 svchost.exe 4 1 normal C:\WINDOWS\system32
100 svchost.exe 4 4 normal C:\WINDOWS\system32
1d8 svchost.exe 11 35 normal C:\WINDOWS\system32
2c8 svchost.exe 4 1 normal C:\WINDOWS\system32
32c svchost.exe 4 1 normal C:\WINDOWS\system32
404 spoolsv.exe 4 4 normal C:\WINDOWS\system32
4bc ekrn.exe 7 13 normal C:\Program Files\ESET\ESET Smart Security
518 slmdmsr.exe 4 1 normal C:\WINDOWS\system32
648 SearchIndexer.exe 4 8 normal C:\WINDOWS\system32
380 wscntfy.exe 26 9 normal C:\WINDOWS\system32
3a4 Explorer.EXE 375 267 normal C:\WINDOWS
534 SOUNDMAN.EXE 18 8 normal C:\WINDOWS
540 VTTimer.exe 12 5 normal C:\WINDOWS\system32
54c VTtrayp.exe 12 5 normal C:\WINDOWS\system32
510 egui.exe 180 55 normal C:\Program Files\ESET\ESET Smart Security
5a0 ctfmon.exe 18 11 normal C:\WINDOWS\system32
9ec alg.exe 5 2 normal C:\WINDOWS\System32
aec PCMAV.exe 265 193 normal C:\Documents and Settings\Administrator\My Documents\Asgard Beta
cpu registers:
eax = 00000000
ebx = 00000001
ecx = 0012f438
edx = 00000001
esi = 00000000
edi = 00000000
eip = 0059083c
esp = 0012f46c
ebp = 0012f5e0
stack dump:
0012f46c 8e 01 00 00 01 00 00 00 - 9a 08 59 00 96 01 00 00 ..........Y.....
0012f47c 8e 01 00 00 90 80 19 01 - 2b 41 68 00 3c f6 12 00 ........+Ah.<...
0012f48c 14 c9 48 00 f0 21 28 01 - 52 70 4a 00 f0 21 28 01 ..H..!(.RpJ..!(.
0012f49c 25 c9 48 00 f0 21 28 01 - a9 c9 48 00 f0 21 28 01 %.H..!(...H..!(.
0012f4ac 3c f6 12 00 01 c9 48 00 - f7 ca 48 00 4a 6b 4a 00 <.....H...H.JkJ.
0012f4bc 3c f6 12 00 10 f8 12 00 - f0 21 28 01 0a 80 00 00 <........!(.....
0012f4cc 64 f5 12 00 d2 90 3f 77 - 0a 80 00 00 a8 02 0d 00 d.....?w........
0012f4dc fc ff ff ff 00 00 00 00 - cc f5 12 00 56 8b 3f 77 ............V.?w
0012f4ec 62 96 3f 77 14 00 00 00 - f8 d8 ac 00 0e 00 00 00 b.?w............
0012f4fc 00 00 00 00 56 8b 3f 77 - 1b b3 d4 77 e3 94 d4 77 ....V.?w...w...w
0012f50c 49 66 d6 77 00 00 00 00 - a8 02 0d 00 00 00 00 00 If.w............
0012f51c 00 00 00 00 81 00 ff ff - b3 02 00 00 01 00 00 00 ................
0012f52c 0e 00 00 00 f0 21 28 01 - 54 f5 12 00 66 e3 d4 77 .....!(.T...f..w
0012f53c 81 00 ff ff a8 02 0d 00 - 56 8b 3f 77 00 00 00 00 ........V.?w....
0012f54c 00 00 00 00 01 00 00 00 - a8 f6 12 00 40 ac 4a 00 ............@.J.
0012f55c 81 00 ff ff 8c 7d 00 00 - 90 f5 12 00 09 87 d4 77 .....}.........w
0012f56c a8 02 0d 00 f3 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f57c 56 8b 3f 77 cd ab ba dc - 00 00 00 00 cc f5 12 00 V.?w............
0012f58c 56 8b 3f 77 f8 f5 12 00 - 20 00 00 00 ec f5 12 00 V.?w............
0012f59c f8 fb fd 7f 00 00 00 00 - cc f5 12 00 aa f0 90 7c ...............|
disassembling:
00590838 public segment%187.public%9922 (PCMAV.exe): ; function entry point
00590838 push ebx
00590839 push esi
0059083a mov esi, eax
0059083c > mov eax, [esi+4]
0059083f mov ebx, [eax+4]
00590842 cmp byte ptr [ebx+$290], 0
00590849 jnz loc_590885
00590849
0059084b mov eax, ebx
0059084d call -$e2e8e ($4ad9c4) ; segment%54.public%5281 (PCMAV.exe)
0059084d
00590852 test al, al
00590854 jz loc_590885
00590854
00590856 mov eax, ebx
00590858 call -$e3239 ($4ad624) ; segment%54.public%5267 (PCMAV.exe)
00590858
0059085d mov ebx, eax
0059085f mov eax, esi
00590861 call +$4f2 ($590d58) ; segment%187.public%9934 (PCMAV.exe)
00590861
00590866 mov esi, eax
00590868 push $f000
0059086d push esi
0059086e push $102c
00590873 push ebx
00590874 call -$1874fd ($40937c) ; segment%3.public%1003 (PCMAV.exe)
00590874
00590879 shr eax, $c
0059087c dec eax
0059087d test eax, eax
0059087f setnz al
00590882 pop esi
00590883 pop ebx
00590884 ret
00590884
00590884 ; ---------------------------------------------------------
00590884
00590885 loc_590885:
00590885 movzx eax, byte ptr [esi+$2a]
00590889 pop esi
0059088a pop ebx
0059088b ret

Gambar diatas adalah bug ketika klik kanan pada shortcut, baik di shorcut desktop maupun shortcut startmenu. Sepertinya bug tersebut berasal dari PCMAV Asgard Beta...
Last edited by indraramadhan094 (06-10-2011 19:04:16)