Topic: PC Media Predator Technical Preview
Mohon ijin momod dan mimin,
Ane liat di section ini belum ada topic khusus dengan judul pelaporan Bug PC Media Antivirus Predator Technical Preview, untuk itu ane berinisiatif membuat topic ini.
Pertama, Saya mau Lapor Bug PC Media Antivirus Predator Technical Preview yang ada di PC saya.
OS : Windows XP SP3 build 2600
RAM : 1GB
Masalah Pertama adalah PCMAV ini selalu Not Responding, mau click Buttom aja Susah...
Lalu file yang di scan ini2 juga. Mentok sampai objeck ini aja, bingung mau lihat nama file apa yang di scan. --"
Lalu Clamav yang tak bisa diupdate (File Clamav tidak saya tempatkan, saya inginnya library sama main bisa didownload lewat update PCMAV).
Lalu Program tak dapat dibuka, sebagai contoh notepad. sampai PCMAV Exit, process menggantung dan Program2 dapat dibuka setelah PCMAV Exit.
Berikut Screenshotnya untuk 2 masalah tersebut
Lalu ketika klik tray ketika main loading PCMAV, Ada 3 tulisan tray yg hilang.
Ketika PCMAV di exit, muncul MadExcept tetapi tidak menampilkan Log Bug Repot.
Ketika di Restart, Process PCMAV menggantung karena saya tunggu beberapa lama... PCMAV tidak muncul dilayar.
Berikut Log Bug Reportnya
date/time : 2012-03-26, 18:52:15, 78ms
computer name : INDRA
user name : Administrator <admin>
registered owner : Administrator
operating system : Windows XP Service Pack 3 build 2600
system language : English
system up time : 3 hours 19 minutes
program up time : 3 minutes 38 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 412/958 MB (free/total)
free disk space : (C:) 9.06 GB
display mode : 1024x768, 32 bit
process id : $b8
allocated memory : 32.95 MB
executable : PCMAV.exe
exec. date/time : 2012-03-19 13:36
version : 7.0.61078.27766
compiled with : Delphi XE2
madExcept version : 3.0n
PCMAV.exe.mad : $0003bfbc, $34804073, $1164c539
callstack crc : $9c14c702, $41f1a36d, $41f1a36d
exception number : 1
exception class : EPrivilege
exception message : Privileged instruction.
main thread ($d18):
0067006f +817 PCMAV.exe segment%98 public%13580
00406924 +008 PCMAV.exe segment%0 public%227
008dbd71 +0cd PCMAV.exe segment%265 public%20726
008d518a +01e PCMAV.exe segment%265 public%20623
005a23a5 +055 PCMAV.exe segment%79 public%9701
005a22cd +021 PCMAV.exe segment%79 public%9700
008da48b +007 PCMAV.exe segment%265 public%20682
0058ecaf +0a7 PCMAV.exe segment%77 public%9314
005902b3 +013 PCMAV.exe segment%77 public%9377
00591546 +082 PCMAV.exe segment%77 public%9426
00591495 +01d PCMAV.exe segment%77 public%9425
0048668c +014 PCMAV.exe segment%30 public%3805
7e418a0b +00a USER32.dll DispatchMessageW
005a7163 +0f3 PCMAV.exe segment%79 public%9876
005a718e +00a PCMAV.exe segment%79 public%9877
007825aa +19a PCMAV.exe segment%149 public%17411
008c9ce4 +218 PCMAV.exe segment%261 public%20545
008ca7c7 +0eb PCMAV.exe segment%261 public%20547
00483521 +12d PCMAV.exe segment%30 public%3629
005a690a +76e PCMAV.exe segment%79 public%9859
0048668c +014 PCMAV.exe segment%30 public%3805
7e42a034 +016 USER32.dll CallWindowProcW
00842a4c +034 PCMAV.exe segment%174 public%18475
7e418a0b +00a USER32.dll DispatchMessageW
005a7163 +0f3 PCMAV.exe segment%79 public%9876
005a718e +00a PCMAV.exe segment%79 public%9877
008da986 +15e PCMAV.exe segment%265 public%20693
004fd7f3 +06f PCMAV.exe segment%62 public%6006
00517c2a +01e PCMAV.exe segment%63 public%6738
005cd828 +068 PCMAV.exe segment%83 public%10707
00518718 +010 PCMAV.exe segment%63 public%6770
004fd298 +2d4 PCMAV.exe segment%62 public%5999
00501be3 +5b3 PCMAV.exe segment%62 public%6158
005178f4 +06c PCMAV.exe segment%63 public%6726
004fcebc +024 PCMAV.exe segment%62 public%5992
00501d33 +023 PCMAV.exe segment%62 public%6160
005027bf +00b PCMAV.exe segment%62 public%6168
004fd298 +2d4 PCMAV.exe segment%62 public%5999
00501be3 +5b3 PCMAV.exe segment%62 public%6158
00501238 +02c PCMAV.exe segment%62 public%6153
0048668c +014 PCMAV.exe segment%30 public%3805
7e4292de +044 USER32.dll SendMessageW
7e42a034 +016 USER32.dll CallWindowProcW
00501ce0 +0d8 PCMAV.exe segment%62 public%6159
004fdc48 +010 PCMAV.exe segment%62 public%6023
004fdbb2 +07e PCMAV.exe segment%62 public%6020
004fd298 +2d4 PCMAV.exe segment%62 public%5999
00501be3 +5b3 PCMAV.exe segment%62 public%6158
005178f4 +06c PCMAV.exe segment%63 public%6726
00501238 +02c PCMAV.exe segment%62 public%6153
0048668c +014 PCMAV.exe segment%30 public%3805
7e418a0b +00a USER32.dll DispatchMessageW
005a7163 +0f3 PCMAV.exe segment%79 public%9876
005a71a6 +00a PCMAV.exe segment%79 public%9878
005a74d9 +0c9 PCMAV.exe segment%79 public%9883
008eb1e4 +0d0 PCMAV.exe segment%393 public%20885
thread $45c:
7c90df48 +a ntdll.dll NtWaitForMultipleObjects
thread $b04:
7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
7c80a110 +13 kernel32.dll WaitForMultipleObjects
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
02f716e9 +00 IDMShellExt.dll
thread $efc (TWorkerThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00677a91 +19 PCMAV.exe segment%98 public%13639
004bc4c3 +2b PCMAV.exe segment%36 public%4586
00483662 +42 PCMAV.exe segment%30 public%3630
00408520 +28 PCMAV.exe segment%0 public%327
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
00677986 +16 PCMAV.exe segment%98 public%13635
thread $e24:
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
005da78f +2f PCMAV.exe segment%89 public%10955
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $a24:
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
006b2e31 +4d PCMAV.exe segment%101 public%14689
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $fe4:
7e4191ec +26 USER32.dll GetMessageW
006b21f7 +bb PCMAV.exe segment%101 public%14679
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $844:
7c90d9d8 +00a ntdll.dll NtReadFile
7c801873 +061 kernel32.dll ReadFile
0079460b +1e7 PCMAV.exe segment%150 public%17583
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
0079487f +233 PCMAV.exe segment%150 public%17584
thread $ef8:
7c90d9d8 +00a ntdll.dll NtReadFile
7c801873 +061 kernel32.dll ReadFile
0079460b +1e7 PCMAV.exe segment%150 public%17583
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
0079487f +233 PCMAV.exe segment%150 public%17584
thread $820:
7c90d9d8 +00a ntdll.dll NtReadFile
7c801873 +061 kernel32.dll ReadFile
0079460b +1e7 PCMAV.exe segment%150 public%17583
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
0079487f +233 PCMAV.exe segment%150 public%17584
thread $738 (TMyThreadedScanMem):
7c90df58 +00a ntdll.dll NtWaitForSingleObject
7c8025d5 +085 kernel32.dll WaitForSingleObjectEx
7c80253d +00d kernel32.dll WaitForSingleObject
00455626 +002 PCMAV.exe segment%26 public%2436
004557d3 +01f PCMAV.exe segment%26 public%2443
00407779 +065 PCMAV.exe segment%0 public%286
004077e8 +020 PCMAV.exe segment%0 public%287
00483fab +13b PCMAV.exe segment%30 public%3653
00484041 +029 PCMAV.exe segment%30 public%3654
008ca843 +00b PCMAV.exe segment%261 public%20548
004bc4c3 +02b PCMAV.exe segment%36 public%4586
00483662 +042 PCMAV.exe segment%30 public%3630
00408520 +028 PCMAV.exe segment%0 public%327
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
008ca6b1 +019 PCMAV.exe segment%261 public%20546
thread $adc:
7c90d218 +a ntdll.dll NtDelayExecution
thread $db8:
7c90df48 +a ntdll.dll NtWaitForMultipleObjects
thread $8c0:
7c90df48 +00a ntdll.dll NtWaitForMultipleObjects
7c80958a +000 kernel32.dll WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll WaitForMultipleObjects
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($d18) at:
769c887a +273 Userenv.dll RegisterGPNotification
processes:
000 Idle 0 0
004 System 0 0 normal
188 smss.exe 0 0 normal C:\WINDOWS\system32
2b4 csrss.exe 62 62 normal C:\WINDOWS\system32
2d0 winlogon.exe 51 14 high C:\WINDOWS\system32
2fc services.exe 4 2 normal C:\WINDOWS\system32
308 lsass.exe 4 2 normal C:\WINDOWS\system32
3d4 svchost.exe 4 1 normal C:\WINDOWS\system32
6c0 svchost.exe 4 1 normal C:\WINDOWS\system32
6e8 MsMpEng.exe 4 2 normal C:\Program Files\Microsoft Security Client\Antimalware
70c svchost.exe 11 30 normal C:\WINDOWS\System32
138 svchost.exe 4 1 normal C:\WINDOWS\system32
228 svchost.exe 4 2 normal C:\WINDOWS\system32
408 spoolsv.exe 4 4 normal C:\WINDOWS\system32
468 alg.exe 4 2 normal C:\WINDOWS\System32
59c ekrn.exe 11 11 normal C:\Program Files\ESET\ESET Smart Security
5fc Explorer.EXE 309 140 normal C:\WINDOWS
628 svchost.exe 4 1 normal C:\WINDOWS\System32
3b4 wscntfy.exe 35 11 normal C:\WINDOWS\system32
8d0 egui.exe 191 59 normal C:\Program Files\ESET\ESET Smart Security
8d8 VTTimer.exe 15 5 normal C:\WINDOWS\system32
8e0 taskmgr.exe 112 123 high C:\WINDOWS\system32
900 VTtrayp.exe 22 5 normal C:\WINDOWS\system32
97c SOUNDMAN.EXE 21 8 normal C:\WINDOWS
bec IDMan.exe 134 69 normal C:\Program Files\Internet Download Manager
c4c xwidget.exe 97 96 normal C:\Program Files\XWidget
ca4 ctfmon.exe 93 44 normal C:\WINDOWS\system32
ecc DllHost.exe 8 3 normal C:\WINDOWS\system32
b38 ping.exe 4 1 normal C:\WINDOWS\system32
a50 firefox.exe 559 77 normal C:\Program Files\Mozilla Firefox
630 plugin-container.exe 14 8 normal C:\Program Files\Mozilla Firefox
84c svchost.exe 4 4 normal C:\WINDOWS\system32
818 mspaint.exe 142 73 normal C:\WINDOWS\system32
0b8 PCMAV.exe 216 105 normal C:\Documents and Settings\Administrator\Desktop\PC Media Predator Technical Preview
9f8 notepad.exe 15 5 normal C:\WINDOWS\system32
fc8 notepad.exe 15 5 normal C:\WINDOWS\system32
disassembling:
0066f858 public segment%98.public%13580 (PCMAV.exe): ; function entry point
0066f858 mov al, $f8
0066f85a add [eax], al
0066f85d add [eax], al
0066f85f add [eax], al
0066f861 add [eax], al
0066f863 add [eax], dh
0066f865 std
0066f866 add [eax+5], bl
0066f86a add [bp+si-3], al
0066f86e add [esi-2], bh
0066f872 add [edi+edi*8], dl
0066f876 add [edi+edi*8], bl
0066f87a add [eax+ecx-$7efc0000], cl
0066f882 add al, bl
0066f885 imul eax, [eax], $4069e0 ; segment%0.public%232 (PCMAV.exe)
0066f88c shr byte ptr [eax+eax*2], 1
0066f890 fcom dword ptr [ebp+$48]
0066f893 add ah, dl
0066f895 xchg ch, [ecx]
0066f898 or al, $47
0066f89a dec eax
0066f89b add al, dh
0066f89d insb
0066f89e inc eax
0066f89f add [eax], cl
0066f8a1 sbb al, $50
0066f8a3 add [eax+ebp*2+$68d00040], dh
0066f8aa inc eax
0066f8ab add [eax], dl
0066f8ad cmp [eax], ebp
0066f8b0 push edi
0066f8b2 push eax
0066f8b3 add [esp+ecx*2], al
0066f8b6 push 0
0066f8b8 hlt
0066f8b9 xchg ch, [ecx]
0066f8bc insb
0066f8bd dec edx
0066f8be imul eax, [eax], $695064 ; segment%98.public%14257 (PCMAV.exe)
0066f8c4 add cl, dh
0066f8c6 dec edi
0066f8c7 add [eax], bl
0066f8c9 push ebp
0066f8ca dec eax
0066f8cb add [edx*2+$53940048], bl
0066f8d2 dec eax
0066f8d3 add [edi+esi*4], bh
0066f8d6 dec edi
0066f8d7 add [eax], al
0066f8d9 push esi
0066f8da dec eax
0066f8db add al, dl
0066f8dd dec ebx
0066f8de dec eax
0066f8df add al, cl
0066f8e1 dec ebx
0066f8e2 dec eax
0066f8e3 add [eax], cl
0066f8e5 push esi
0066f8e6 dec eax
0066f8e7 add [ebp+edi+$6a], al
0066f8eb add [eax-$77ff95d4], bl
0066f8f1 push ecx
0066f8f2 push eax
0066f8f3 add [edi+edx*2+$56e00050], dl
0066f8fa push eax
0066f8fb add [eax], bh
0066f8fd loop loc_66f94e
0066f8fd
0066f8ff add [eax-$3d], al
0066f902 dec edi
0066f903 add [ebx+eax*8+$4f], al
0066f907 add [eax+ebp*4+$4b54004f], ch
0066f90e push eax
0066f90f add [ebx+ecx*2+$50], dh
0066f913 add [eax-$13ffafb9], cl
0066f919 cmpsd
0066f91a dec edi
0066f91b add [eax], bl
0066f91d out $4f, eax
0066f91f add [edi+$4f], al
0066f923 add [eax+$2d], ah
0066f926 push eax
0066f927 add [edi+esi*4], ah
0066f92a dec edi
0066f92b add [eax-$53ffb056], cl
0066f931 mov eax, $6aa4004f
0066f936 push eax
0066f937 add [ebx+edi*4-$45e7ffb1], ch
0066f93e dec edi
0066f93f add ah, dh
0066f941 jg loc_66f9ac
0066f941
0066f943 add al, ch
0066f945 cmpsd
0066f946 dec edi
0066f947 add al, cl
0066f949 out $4f, eax
0066f94b add ah, bl
0066f94d inc edi
0066f94b
0066f94e loc_66f94e:
0066f94e push eax
0066f94f add al, dh
0066f951 dec eax
0066f952 push eax
0066f953 add [eax+$42], cl
0066f956 push eax
0066f957 add ah, dl
0066f959 dec eax
0066f95a push eax
0066f95b add [eax-$f], bh
0066f95e dec edi
0066f95f add al, bl
0066f961 cld
0066f962 dec edi
0066f963 add [esp+ecx+$50], ch
0066f967 add [eax+edx*8+$9180068], bl
0066f96e push eax
0066f96f add [ecx+edx*8], ch
0066f972 push $500d0400
0066f96f
0066f973 loc_66f973:
0066f973 add [ecx+$d280050], al
0066f97a push eax
0066f97b add [ebp+ecx+$ba80050], bh
0066f982 push eax
0066f983 add [eax+$b], al
0066f986 push eax
0066f987 add [eax+$69], ah
0066f98a push eax
0066f98b add [eax], ah
0066f98d dec edx
0066f98e push eax
0066f98f add al, al
0066f991 ja +$50 ($66f9e3)
0066f991
0066f993 add al, bl
0066f995 push $10fc0050
0066f99a push eax
0066f99b add [esi+eax*2], dh
0066f99e push eax
0066f99f add [eax], ch
0066f9a1 push $50
0066f9a3 add [eax-$3fffafb7], cl
0066f9a9 push edx
0066f9aa imul eax, [eax], $68c05c ; segment%98.public%14078 (PCMAV.exe)
0066f9a9
0066f9ac loc_66f9ac:
0066f9ac pop esp
0066f9ad shr byte ptr [eax], $70
0066f9b1 shr dword ptr [eax], $d8
0066f9b5 shr dword ptr [eax], $2c
0066f9b9 dec edx
0066f9ba push 0
0066f9bc dec eax
0066f9bd ret $68-Update-
Ketika Loading Database, saya pilih Quick Scan.
date/time : 2012-03-26, 20:07:01, 843ms
computer name : INDRA
user name : Administrator <admin>
registered owner : Administrator
operating system : Windows XP Service Pack 3 build 2600
system language : English
system up time : 23 minutes 30 seconds
program up time : 40 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 128/958 MB (free/total)
free disk space : (C:) 8.94 GB
display mode : 1024x768, 32 bit
process id : $d2c
allocated memory : 21.80 MB
executable : PCMAV.exe
exec. date/time : 2012-03-19 13:36
version : 7.0.61078.27766
compiled with : Delphi XE2
madExcept version : 3.0n
PCMAV.exe.mad : $0003bfbc, $34804073, $1164c539
callstack crc : $23a58092, $936e4963, $936e4963
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 007A51B6 in module 'PCMAV.exe'. Read of address 0000000C.
main thread ($1a8):
007a51b6 +07e PCMAV.exe segment%155 public%17676
008c9be0 +114 PCMAV.exe segment%261 public%20545
008ca7c7 +0eb PCMAV.exe segment%261 public%20547
00483521 +12d PCMAV.exe segment%30 public%3629
005a690a +76e PCMAV.exe segment%79 public%9859
0048668c +014 PCMAV.exe segment%30 public%3805
7e418a0b +00a USER32.dll DispatchMessageW
005a7163 +0f3 PCMAV.exe segment%79 public%9876
005a718e +00a PCMAV.exe segment%79 public%9877
008d9f0c +15c PCMAV.exe segment%265 public%20674
0058ecaf +0a7 PCMAV.exe segment%77 public%9314
005902b3 +013 PCMAV.exe segment%77 public%9377
00591546 +082 PCMAV.exe segment%77 public%9426
00591495 +01d PCMAV.exe segment%77 public%9425
0048668c +014 PCMAV.exe segment%30 public%3805
7e418a0b +00a USER32.dll DispatchMessageW
005a7163 +0f3 PCMAV.exe segment%79 public%9876
005a718e +00a PCMAV.exe segment%79 public%9877
0054f130 +238 PCMAV.exe segment%74 public%7970
0048668c +014 PCMAV.exe segment%30 public%3805
7c90e470 +010 ntdll.dll KiUserCallbackDispatcher
008d5aab +5bb PCMAV.exe segment%265 public%20629
00406f7a +002 PCMAV.exe segment%0 public%260
004dacd6 +05a PCMAV.exe segment%52 public%5330
00406924 +008 PCMAV.exe segment%0 public%227
004dac74 +018 PCMAV.exe segment%52 public%5329
004dcc41 +0bd PCMAV.exe segment%52 public%5375
004dbcd2 +06e PCMAV.exe segment%52 public%5344
005cbc13 +5c3 PCMAV.exe segment%83 public%10648
004fcebc +024 PCMAV.exe segment%62 public%5992
00500fe1 +10d PCMAV.exe segment%62 public%6149
005010f0 +0bc PCMAV.exe segment%62 public%6150
00503cae +026 PCMAV.exe segment%62 public%6249
004fd298 +2d4 PCMAV.exe segment%62 public%5999
00501be3 +5b3 PCMAV.exe segment%62 public%6158
0059e072 +5f2 PCMAV.exe segment%79 public%9586
004fcebc +024 PCMAV.exe segment%62 public%5992
004fb89a +026 PCMAV.exe segment%62 public%5908
0059d90a +03a PCMAV.exe segment%79 public%9581
005a74c3 +0b3 PCMAV.exe segment%79 public%9883
008eb1e4 +0d0 PCMAV.exe segment%393 public%20885
thread $e24:
7c90df48 +a ntdll.dll NtWaitForMultipleObjects
thread $eb4:
7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
7c80a110 +13 kernel32.dll WaitForMultipleObjects
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
02f716e9 +00 IDMShellExt.dll
thread $2b0 (TWorkerThread):
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00677a91 +19 PCMAV.exe segment%98 public%13639
004bc4c3 +2b PCMAV.exe segment%36 public%4586
00483662 +42 PCMAV.exe segment%30 public%3630
00408520 +28 PCMAV.exe segment%0 public%327
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
00677986 +16 PCMAV.exe segment%98 public%13635
thread $934:
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
005da78f +2f PCMAV.exe segment%89 public%10955
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $f5c:
7c90df58 +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
006b2e31 +4d PCMAV.exe segment%101 public%14689
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $f78:
7e4191ec +26 USER32.dll GetMessageW
006b21f7 +bb PCMAV.exe segment%101 public%14679
005da352 +36 PCMAV.exe segment%89 public%10934
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
005da09d +6d PCMAV.exe segment%89 public%10932
thread $de4 (TRunningItemThread):
7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
7c80a110 +13 kernel32.dll WaitForMultipleObjects
007ac20b +2b PCMAV.exe segment%157 public%17725
007ac48d +39 PCMAV.exe segment%157 public%17737
004bc4c3 +2b PCMAV.exe segment%36 public%4586
00483662 +42 PCMAV.exe segment%30 public%3630
00408520 +28 PCMAV.exe segment%0 public%327
004bc3a5 +0d PCMAV.exe segment%36 public%4584
004bc40f +37 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
007ac3bf +23 PCMAV.exe segment%157 public%17735
thread $d04 (TMyThreadedScanMem):
7c90df58 +00a ntdll.dll NtWaitForSingleObject
7c8025d5 +085 kernel32.dll WaitForSingleObjectEx
7c80253d +00d kernel32.dll WaitForSingleObject
00455626 +002 PCMAV.exe segment%26 public%2436
004557d3 +01f PCMAV.exe segment%26 public%2443
00407779 +065 PCMAV.exe segment%0 public%286
004077e8 +020 PCMAV.exe segment%0 public%287
00483fab +13b PCMAV.exe segment%30 public%3653
00484041 +029 PCMAV.exe segment%30 public%3654
008ca843 +00b PCMAV.exe segment%261 public%20548
004bc4c3 +02b PCMAV.exe segment%36 public%4586
00483662 +042 PCMAV.exe segment%30 public%3630
00408520 +028 PCMAV.exe segment%0 public%327
004bc3a5 +00d PCMAV.exe segment%36 public%4584
004bc40f +037 PCMAV.exe segment%36 public%4585
>> created by main thread ($1a8) at:
008ca6b1 +019 PCMAV.exe segment%261 public%20546
processes:
000 Idle 0 0
004 System 0 0 normal
1b0 smss.exe 0 0 normal C:\WINDOWS\system32
2b4 csrss.exe 0 0
2d0 winlogon.exe 51 14 high C:\WINDOWS\system32
2fc services.exe 4 2 normal C:\WINDOWS\system32
308 lsass.exe 4 2 normal C:\WINDOWS\system32
3d8 svchost.exe 4 1 normal C:\WINDOWS\system32
6c4 svchost.exe 0 0
6ec MsMpEng.exe 4 2 normal C:\Program Files\Microsoft Security Client\Antimalware
710 svchost.exe 11 29 normal C:\WINDOWS\System32
104 svchost.exe 0 0
224 svchost.exe 0 0
408 spoolsv.exe 4 4 normal C:\WINDOWS\system32
56c alg.exe 0 0
5a8 Explorer.EXE 348 242 normal C:\WINDOWS
5bc ekrn.exe 11 13 normal C:\Program Files\ESET\ESET Smart Security
628 svchost.exe 4 1 normal C:\WINDOWS\System32
7f0 TuneUpUtilitiesService32.exe 4 5 normal C:\Program Files\TuneUp Utilities 2012
24c wscntfy.exe 35 11 normal C:\WINDOWS\system32
484 TuneUpUtilitiesApp32.exe 220 99 normal C:\Program Files\TuneUp Utilities 2012
808 egui.exe 188 59 normal C:\Program Files\ESET\ESET Smart Security
81c VTTimer.exe 15 5 normal C:\WINDOWS\system32
82c VTtrayp.exe 22 5 normal C:\WINDOWS\system32
840 SOUNDMAN.EXE 21 8 normal C:\WINDOWS
848 IDMan.exe 147 109 normal C:\Program Files\Internet Download Manager
850 xwidget.exe 97 96 normal C:\Program Files\XWidget
860 ctfmon.exe 145 70 normal C:\WINDOWS\system32
86c WinSnap.exe 58 73 normal C:\Program Files\WinSnap
948 ping.exe 4 1 normal C:\WINDOWS\system32
490 mspaint.exe 96 65 normal C:\WINDOWS\system32
668 svchost.exe 4 3 normal C:\WINDOWS\system32
9fc taskmgr.exe 107 123 normal C:\WINDOWS\system32
c1c notepad.exe 31 21 normal C:\WINDOWS\system32
f48 firefox.exe 246 47 normal C:\Program Files\Mozilla Firefox
8d4 chrome.exe 97 71 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
568 chrome.exe 15 1 below normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
b34 chrome.exe 9 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
ca4 chrome.exe 9 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
978 chrome.exe 9 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
4b0 chrome.exe 45 1 below normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
c80 chrome.exe 25 1 below normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
a3c chrome.exe 8 7 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
d2c PCMAV.exe 214 97 below normal C:\Documents and Settings\Administrator\Desktop\PC Media Predator Technical Preview
disassembling:
007a5138 public segment%155.public%17676 (PCMAV.exe): ; function entry point
007a5138 push ebp
007a5139 mov ebp, esp
007a513b push ecx
007a513c mov ecx, $26
007a513b
007a5141 loc_7a5141:
007a5141 push 0
007a5143 push 0
007a5145 dec ecx
007a5146 jnz loc_7a5141
007a5146
007a5148 xchg ecx, [ebp-4]
007a514b push ebx
007a514c push esi
007a514d mov [ebp-$94], ecx
007a5153 mov [ebp-$90], edx
007a5159 mov [ebp-$8c], eax
007a515f lea eax, [ebp-$88]
007a5165 mov edx, [$7a1c68]
007a516b call -$39b0b8 ($40a0b8) ; segment%0.public%441 (PCMAV.exe)
007a516b
007a5170 xor eax, eax
007a5172 push ebp
007a5173 push $7a5860 ; segment%0.public%300 (PCMAV.exe)
007a5178 push dword ptr fs:[eax]
007a517b mov fs:[eax], esp
007a517e mov byte ptr [ebp-$95], 0
007a5185 mov eax, [ebp-$90]
007a518b mov byte ptr [eax], 0
007a518e mov byte ptr [ebp-$bd], 1
007a5195 mov eax, [ebp-$94]
007a519b mov eax, [eax]
007a519d mov dl, 1
007a519f call -$329ae4 ($47b6c0) ; segment%30.public%3370 (PCMAV.exe)
007a519f
007a51a4 mov eax, [ebp-$94]
007a51aa mov eax, [eax]
007a51ac mov byte ptr [eax+$39], 0
007a51b0 mov eax, [ebp-$8c]
007a51b6 > mov eax, [eax+$c]
007a51b9 call -$2e8a ($7a2334) ; segment%154.public%17642 (PCMAV.exe)
007a51b9
007a51be lea edx, [ebp-4]
007a51c1 mov eax, $7a5884
007a51c6 call -$5456f ($750c5c) ; segment%133.public%16904 (PCMAV.exe)
007a51c6
007a51cb mov dword ptr [ebp-$a0], 3
007a51d5 mov dword ptr [ebp-$c8], $900a78
007a51cb
007a51df loc_7a51df:
007a51df lea eax, [ebp-$18]
007a51e2 mov edx, [ebp-$c8]
007a51e8 mov edx, [edx]
007a51ea call -$39c753 ($408a9c) ; segment%0.public%355 (PCMAV.exe)
007a51ea
007a51ef mov eax, [ebp-4]
007a51f2 mov edx, [eax]
007a51f4 call dword ptr [edx+$70]
007a51f4
007a51f7 dec eax
007a51f8 test eax, eax
007a51fa jl loc_7a5756
007a51fa
007a5200 inc eax
007a5201 mov [ebp-$c4], eax
007a5207 mov dword ptr [ebp-$a4], 0
007a5201
007a5211 loc_7a5211:
007a5211 lea ecx, [ebp-8]
007a5214 mov edx, [ebp-$a4]
007a521a mov eax, [ebp-4]
007a521d mov ebx, [eax]
007a521f call dword ptr [ebx+$d8]
007a521f
007a5225 lea edx, [ebp-$f4]
007a522b mov eax, [ebp-8]
007a522e mov ecx, [eax]
007a5230 call dword ptr [ecx+$a0]
007a5230
007a5236 mov edx, [ebp-$f4]
007a523c lea eax, [ebp-$f0]
007a5242 call -$39ba1b ($40982c) ; segment%0.public%421 (PCMAV.exe)
007a5242
007a5247 mov eax, [ebp-$f0]
007a524d lea edx, [ebp-$ec]
007a5253 call -$3560a4 ($44f1b4) ; segment%26.public%2256 (PCMAV.exe)
007a5253
007a5258 mov eax, [ebp-$ec]
007a525e lea edx, [ebp-$e8]
007a5264 call -$358261 ($44d008) ; segment%26.public%2181 (PCMAV.exe)
007a5264
007a5269 mov eax, [ebp-$e8]
007a526f mov edx, [ebp-$18]
007a5272 call -$39b71f ($409b58) ; segment%0.public%431 (PCMAV.exe)
007a5272
007a5277 jnz loc_7a5744
007a5277
007a527d mov eax, [ebp-8]
007a5280 mov edx, [eax]
007a5282 call dword ptr [edx+$80]
007a5282
007a5288 mov [ebp-$ac], eax
007a528e lea edx, [ebp-$c]
007a5291 mov eax, [ebp-8]
007a5294 mov ecx, [eax]
007a5296 call dword ptr [ecx+$110]
007a5296
007a529c mov eax, [ebp-$c]
007a529f mov edx, [eax]
007a52a1 call dword ptr [edx+$70]
007a52a1
007a52a4 mov esi, eax
007a52a6 dec esi
007a52a7 test esi, esi
007a52a9 jl loc_7a555a
007a52a9
007a52af inc esi
007a52b0 mov dword ptr [ebp-$a8], 0
007a52af
007a52ba loc_7a52ba:
007a52ba mov eax, [$904798]
007a52bf mov eax, [eax]
007a52c1 call -$1fe142 ($5a7184) ; segment%79.public%9877 (PCMAV.exe)
007a52c1
007a52c6 lea ecx, [ebp-$10]
007a52c9 mov edx, [ebp-$a8]
007a52cf mov eax, [ebp-$c]
007a52d2 mov ebx, [eax]
007a52d4 call dword ptr [ebx+$d8]
007a52d4
007a52da mov eax, [ebp-$10]
007a52dd mov edx, [eax]
007a52df call dword ptr [edx+$80]
007a52df
007a52e5 mov ebx, eax
007a52e7 mov edx, ebx
007a52e9 mov eax, [ebp-$8c]
007a52ef call -$eb0 ($7a4444) ; segment%155.public%17671 (PCMAV.exe)
007a52ef
007a52f4 mov [ebp-$9c], eax
007a52fa lea eax, [ebp-$14]
007a52fd push eax
007a52fe mov ecx, ebx
007a5300 mov edx, [ebp-$ac]
007a5306 mov eax, [ebp-$8c]
007a530c call -$d9d ($7a4574) ; segment%155.public%17672 (PCMAV.exe)
007a530c
007a5311 cmp dword ptr [ebp-$14], 0
007a5315 jz loc_7a5329
007a5315
007a5317 mov dl, 1
007a5319 mov eax, [ebp-$14]
007a531c call -$356aa5 ($44e87c) ; segment%26.public%2235 (PCMAV.exe)
007a531c
007a5321 test al, al
007a5323 jnz loc_7a554d
007a5323
007a5329 loc_7a5329:
007a5329 xor ebx, ebx
007a532b lea eax, [ebp-$e4]
007a5331 xor ecx, ecx
007a5333 mov edx, $1c
007a5338 call -$39ffe5 ($405358) ; segment%0.public%174 (PCMAV.exe)
007a5338
007a533d jmp loc_7a5519
007a533d
007a533d ; ---------------------------------------------------------
007a533d
007a5342 loc_7a5342:
007a5342 mov eax, [ebp-$dc]
007a5348 or eax, 4
007a534b or eax, $10
007a534e jz loc_7a550d
007a534e
007a5354 cmp dword ptr [ebp-$d4], $1000
007a535e jnz loc_7a550d
007a535e
007a5364 mov eax, [ebp-$e4]
007a536a mov [ebp-$b8], eax
007a5370 mov eax, [ebp-$e4]
007a5376 add eax, [ebp-$d8]
007a537c mov [ebp-$bc], eax
007a5382 mov eax, [ebp-$b8]
007a5388 cmp eax, [ebp-$9c]
007a538e ja loc_7a550d
007a538e
007a5394 mov eax, [ebp-$bc]
007a539a cmp eax, [ebp-$9c]
007a53a0 jbe loc_7a550d
007a53a0
007a53a6 push 4
007a53a8 push $1000
007a53ad mov eax, [ebp-$d8]
007a53b3 push eax
007a53b4 push 0
007a53b6 call -$392e2f ($41258c) ; segment%4.public%974 (PCMAV.exe)
007a53b6
007a53bb mov [ebp-$b4], eax
007a53c1 cmp dword ptr [ebp-$b4], 0
007a53c8 jz loc_7a550d
007a53c8
007a53ce lea eax, [ebp-$20]
007a53d1 xor ecx, ecx
007a53d3 mov edx, [ebp-$d8]
007a53d9 call -$39c172 ($40926c) ; segment%0.public%395 (PCMAV.exe)
007a53d9
007a53de lea eax, [ebp-$b0]
007a53e4 push eax
007a53e5 mov eax, [ebp-$d8]
007a53eb push eax
007a53ec mov eax, [ebp-$20]
007a53ef push eax
007a53f0 mov eax, [ebp-$e4]
007a53f6 push eax
007a53f7 lea edx, [ebp-$f8]
007a53fd mov eax, [ebp-8]
007a5400 mov ecx, [eax]
007a5402 call dword ptr [ecx+$88]
007a5402
007a5408 mov eax, [ebp-$f8]
007a540e mov edx, [eax]
007a5410 call dword ptr [edx+$78]
007a5410
007a5413 push eax
007a5414 call -$392f9d ($41247c) ; segment%4.public%940 (PCMAV.exe)
007a5414
007a5419 test eax, eax
007a541b jz loc_7a54fa
007a541b
007a5421 mov eax, [ebp-$b0]
007a5427 cmp eax, [ebp-$d8]
007a542d jnz loc_7a54fa
007a542d
007a5433 push 1
007a5435 lea eax, [ebp-$100]
007a543b mov edx, [$900ac8] ; 'A0CF252481C21173A0CF252481C21173E7C8AA3464283264C1B768EFE95004B6F1069F8D9023FBE8BFE591A6CB762EDD41BC'
007a5441 call -$39bc1a ($40982c) ; segment%0.public%421 (PCMAV.exe)
007a5441
007a5446 mov eax, [ebp-$100]
007a544c lea edx, [ebp-$fc]
007a5452 call -$af0fb ($6f635c) ; segment%112.public%15854 (PCMAV.exe)
007a5452
007a5457 mov eax, [ebp-$fc]
007a545d push eax
007a545e lea eax, [ebp-$104]
007a5464 mov edx, [ebp-$20]
007a5467 call -$39bc40 ($40982c) ; segment%0.public%421 (PCMAV.exe)
007a5467
007a546c mov eax, [ebp-$104]
007a5472 xor ecx, ecx
007a5474 pop edx
007a5475 call -$af2ee ($6f618c) ; segment%112.public%15852 (PCMAV.exe)
007a5475
007a547a test eax, eax
007a547c jz loc_7a54fa
007a547c
007a547e cmp byte ptr [ebp-$95], 0
007a5485 jnz loc_7a548e
007a5485
007a5487 mov byte ptr [ebp-$95], 1
007a5485
007a548e loc_7a548e:
007a548e cmp byte ptr [ebp-$bd], 0
007a5495 jz loc_7a54ca
007a5495
007a5497 push 0
007a5499 push $ffffffff
007a549b push $ffffffff
007a549d push 0
007a549f movzx ecx, word ptr [$7a5888]
007a54a6 mov dl, 2
007a54a8 mov eax, $7a5898
007a54ad call -$25d9da ($547ad8) ; segment%73.public%7866 (PCMAV.exe)
007a54ad
007a54b2 cmp eax, 6
007a54b5 jz loc_7a54c3
007a54b5
007a54b7 mov byte ptr [ebp-$95], 1
007a54be jmp loc_7a5769
007a54be
007a54be ; ---------------------------------------------------------
007a54be
007a54c3 loc_7a54c3:
007a54c3 mov byte ptr [ebp-$bd], 0
007a54be
007a54ca loc_7a54ca:
007a54ca mov eax, [ebp-$10]
007a54cd mov edx, [eax]
007a54cf call dword ptr [edx+$9c]
007a54cf
007a54d5 test al, al
007a54d7 jz loc_7a54e6
007a54d7
007a54d9 xor edx, edx
007a54db mov eax, [ebp-$10]
007a54de mov ecx, [eax]
007a54e0 call dword ptr [ecx+$108]
007a54e0
007a54e6 loc_7a54e6:
007a54e6 mov eax, [ebp-$90]
007a54ec cmp byte ptr [eax], 0
007a54ef jnz loc_7a54fa
007a54ef
007a54f1 mov eax, [ebp-$90]
007a54f7 mov byte ptr [eax], 1
007a54f1
007a54fa loc_7a54fa:
007a54fa push $8000
007a54ff push 0
007a5501 mov eax, [ebp-$b4]
007a5507 push eax
007a5508 call -$392f79 ($412594) ; segment%4.public%975 (PCMAV.exe)
007a5508
007a550d loc_7a550d:
007a550d mov ebx, [ebp-$e4]
007a5513 add ebx, [ebp-$d8]
007a550d
007a5519 loc_7a5519:
007a5519 push $1c
007a551b lea eax, [ebp-$e4]
007a5521 push eax
007a5522 push ebx
007a5523 lea edx, [ebp-$108]
007a5529 mov eax, [ebp-8]
007a552c mov ecx, [eax]
007a552e call dword ptr [ecx+$88]
007a552e
007a5534 mov eax, [ebp-$108]
007a553a mov edx, [eax]
007a553c call dword ptr [edx+$78]
007a553c
007a553f push eax
007a5540 call -$392f89 ($4125bc) ; segment%4.public%980 (PCMAV.exe)
007a5540
007a5545 test eax, eax
007a5547 ja loc_7a5342
007a5547
007a554d loc_7a554d:
007a554d inc dword ptr [ebp-$a8]
007a5553 dec esi
007a5554 jnz loc_7a52ba
007a5554
007a555a loc_7a555a:
007a555a cmp byte ptr [ebp-$95], 0
007a5561 jz loc_7a5744
007a5561
007a5567 mov eax, [ebp-$8c]
007a556d mov eax, [eax+$c]
007a5570 mov esi, [eax+$10]
007a5573 dec esi
007a5574 test esi, esi
007a5576 jl loc_7a5744
007a5576
007a557c inc esi
007a557d xor ebx, ebx
007a557c
007a557f loc_7a557f:
007a557f lea ecx, [ebp-$88]
007a5585 mov eax, [ebp-$8c]
007a558b mov eax, [eax+$c]
007a558e mov edx, ebx
007a5590 call -$32cd ($7a22c8) ; segment%154.public%17640 (PCMAV.exe)
007a5590
007a5595 mov eax, [ebp-$88]
007a559b cmp eax, [ebp-$ac]
007a55a1 jnz loc_7a573c
007a55a1
007a55a7 mov dl, 1
007a55a9 mov eax, [ebp-$80]
007a55ac call -$356d35 ($44e87c) ; segment%26.public%2235 (PCMAV.exe)
007a55ac
007a55b1 test al, al
007a55b3 jz loc_7a573c
007a55b3
007a55b9 lea edx, [ebp-$110]
007a55bf mov eax, [ebp-$80]
007a55c2 call -$3563d3 ($44f1f4) ; segment%26.public%2257 (PCMAV.exe)
007a55c2
007a55c7 mov eax, [ebp-$110]
007a55cd lea edx, [ebp-$10c]
007a55d3 call -$3585d0 ($44d008) ; segment%26.public%2181 (PCMAV.exe)
007a55d3
007a55d8 mov eax, [ebp-$10c]
007a55de mov edx, $7a59bc
007a55e3 call -$39ba90 ($409b58) ; segment%0.public%431 (PCMAV.exe)
007a55e3
007a55e8 jnz loc_7a573c
007a55e8
007a55ee movzx ecx, word ptr [ebp-$82]
007a55f5 mov edx, [ebp-$ac]
007a55fb mov eax, [ebp-$8c]
007a5601 call -$132a ($7a42dc) ; segment%155.public%17669 (PCMAV.exe)
007a5601
007a5606 test eax, eax
007a5608 lea eax, [ebp-$114]
007a560e mov edx, [ebp-$80]
007a5611 call -$39bdb6 ($409860) ; segment%0.public%423 (PCMAV.exe)
007a5611
007a5616 mov ecx, [ebp-$114]
007a561c mov edx, $1f01ff
007a5621 mov eax, [ebp-$8c]
007a5627 call -$14f0 ($7a413c) ; segment%155.public%17668 (PCMAV.exe)
007a5627
007a562c test al, al
007a562e jnz loc_7a56a0
007a562e
007a5630 lea eax, [ebp-$11c]
007a5636 mov edx, [ebp-$80]
007a5639 call -$39bdde ($409860) ; segment%0.public%423 (PCMAV.exe)
007a5639
007a563e mov eax, [ebp-$11c]
007a5644 lea edx, [ebp-$118]
007a564a call -$2ed73 ($7768dc) ; segment%146.public%17313 (PCMAV.exe)
007a564a
007a564f mov eax, [ebp-$118]
007a5655 xor edx, edx
007a5657 mov ecx, [eax]
007a5659 call dword ptr [ecx+$a0]
007a5659
007a565f lea eax, [ebp-$128]
007a5665 mov edx, [ebp-$80]
007a5668 call -$39be0d ($409860) ; segment%0.public%423 (PCMAV.exe)
007a5668
007a566d mov eax, [ebp-$128]
007a5673 lea edx, [ebp-$124]
007a5679 call -$2eda2 ($7768dc) ; segment%146.public%17313 (PCMAV.exe)
007a5679
007a567e mov eax, [ebp-$124]
007a5684 lea edx, [ebp-$120]
007a568a mov ecx, [eax]
007a568c call dword ptr [ecx+$8c]
007a568c
007a5692 mov eax, [ebp-$120]
007a5698 mov edx, [eax]
007a569a call dword ptr [edx+$104]
007a569a
007a56a0 loc_7a56a0:
007a56a0 push 0
007a56a2 lea ecx, [ebp-$1c]
007a56a5 mov edx, [ebp-$80]
007a56a8 mov eax, [ebp-$8c]
007a56ae call -$c43 ($7a4a70) ; segment%155.public%17675 (PCMAV.exe)
007a56ae
007a56b3 test al, al
007a56b5 jz loc_7a573c
007a56b5
007a56bb lea eax, [ebp-$12c]
007a56c1 mov ecx, [ebp-$80]
007a56c4 mov edx, $7a59d4
007a56c9 call -$39bd0e ($4099c0) ; segment%0.public%428 (PCMAV.exe)
007a56c9
007a56ce mov edx, [ebp-$12c]
007a56d4 mov eax, [ebp-$8c]
007a56da call -$187f ($7a3e60) ; segment%155.public%17664 (PCMAV.exe)
007a56da
007a56df push dword ptr [ebp-$1c]
007a56e2 push $7a5a08
007a56e7 push dword ptr [ebp-$80]
007a56ea lea eax, [ebp-$130]
007a56f0 mov edx, 3
007a56f5 call -$39bcb2 ($409a48) ; segment%0.public%429 (PCMAV.exe)
007a56f5
007a56fa mov edx, [ebp-$130]
007a5700 mov eax, [ebp-$8c]
007a5706 mov eax, [eax+4]
007a5709 mov ecx, [eax]
007a570b call dword ptr [ecx+$38]
007a570b
007a570e push dword ptr [ebp-$1c]
007a5711 push $7a5a08
007a5716 push dword ptr [ebp-$80]
007a5719 lea eax, [ebp-$134]
007a571f mov edx, 3
007a5724 call -$39bce1 ($409a48) ; segment%0.public%429 (PCMAV.exe)
007a5724
007a5729 mov edx, [ebp-$134]
007a572f mov eax, [ebp-$94]
007a5735 mov eax, [eax]
007a5737 mov ecx, [eax]
007a5739 call dword ptr [ecx+$38]
007a5739
007a573c loc_7a573c:
007a573c inc ebx
007a573d dec esi
007a573e jnz loc_7a557f
007a573e
007a5744 loc_7a5744:
007a5744 inc dword ptr [ebp-$a4]
007a574a dec dword ptr [ebp-$c4]
007a5750 jnz loc_7a5211
007a5750
007a5756 loc_7a5756:
007a5756 add dword ptr [ebp-$c8], 4
007a575d dec dword ptr [ebp-$a0]
007a5763 jnz loc_7a51df
007a5763
007a5769 loc_7a5769:
007a5769 xor eax, eax
007a576b pop edx
007a576c pop ecx
007a576d pop ecx
007a576e mov fs:[eax], edx
007a5771 push $7a586a
007a576e
007a5776 loc_7a5776:
007a5776 lea eax, [ebp-$134]
007a577c mov edx, 3
007a5781 call -$39d0b2 ($4086d4) ; segment%0.public%337 (PCMAV.exe)
007a5781
007a5786 lea eax, [ebp-$128]
007a578c call -$39d0d5 ($4086bc) ; segment%0.public%336 (PCMAV.exe)
007a578c
007a5791 lea eax, [ebp-$124]
007a5797 call -$3992d8 ($40c4c4) ; segment%0.public%516 (PCMAV.exe)
007a5797
007a579c lea eax, [ebp-$120]
007a57a2 call -$3992e3 ($40c4c4) ; segment%0.public%516 (PCMAV.exe)
007a57a2
007a57a7 lea eax, [ebp-$11c]
007a57ad call -$39d0f6 ($4086bc) ; segment%0.public%336 (PCMAV.exe)
007a57ad
007a57b2 lea eax, [ebp-$118]
007a57b8 call -$3992f9 ($40c4c4) ; segment%0.public%516 (PCMAV.exe)
007a57b8
007a57bd lea eax, [ebp-$114]
007a57c3 call -$39d10c ($4086bc) ; segment%0.public%336 (PCMAV.exe)
007a57c3
007a57c8 lea eax, [ebp-$110]
007a57ce mov edx, 2
007a57d3 call -$39d104 ($4086d4) ; segment%0.public%337 (PCMAV.exe)
007a57d3
007a57d8 lea eax, [ebp-$108]
007a57de call -$39931f ($40c4c4) ; segment%0.public%516 (PCMAV.exe)
007a57de
007a57e3 lea eax, [ebp-$104]
007a57e9 mov edx, 3
007a57ee call -$39d11f ($4086d4) ; segment%0.public%337 (PCMAV.exe)
007a57ee
007a57f3 lea eax, [ebp-$f8]
007a57f9 call -$39933a ($40c4c4) ; segment%0.public%516 (PCMAV.exe)
007a57f9
[...]Cukup sekian laporan bug dari saya, Klo ada lagi nanti saya laporkan. Klo admin/momod kurang jelas silahkan tanya. maaf klo pelaporan bugnya kurang jelas. ![]()
Last edited by indraramadhan094 (26-03-2012 20:18:55)
Follow Akun Twitter Majalah PC Media : https://twitter.com/PCMedia_ID















