http://bugs.winehq.org/show_bug.cgi?id=8178
--- Comment #26 from Anastasius Focht <focht(a)gmx.net> 2011-05-22 12:26:35 CDT ---
Hello,
--- quote ---
What's in that .exe? I'm tempted to delete it, since it's not
clear what's in it, and you didn't describe it at all.
--- quote ---
that binary is a compiled (password protected) AutoIt script.
AV scanners can't really decompile these scripts hence some flag it
precautionary as "trojan":
http://www.autoitscript.com/forum/topic/34658-are-my-autoit-exes-really-inf…
Raw scan (not unpacked):
http://www.virustotal.com/file-scan/report.html?id=9b47462b62f7a094fdab42b9…
Interestingly when I manually unpacked the thing (UPX) it gave less hits:
http://www.virustotal.com/file-scan/report.html?id=50815f7712bbbaf7dfccdca8…
Now to the real thing ... it looks to me like a script someone made to create
an inventory of Windows PCs.
1. if no parameters given -> do nothing -> exit
2. when given a "zone" command line parameter: map a Windows file server
network share from Universitat de Barcelona (spain) with hard coded credentials
(that's what I got from following DNS info)
3. run an executable from that share (from the name it looks like some kind of
inventory tool)
4. wait for some specific process to exit (probably a sub-process spawned from
the initial agent process).
5. write back a file back to a specific share location (probably inventory
list)
6. *boom* ... hehe no, just exit
Depending on the remote binaries it executes it _might_ be harmful or
legitimate.
I did not exploit the credentials to fetch the remote binaries ...
It should be deleted anyway.
Regards
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=8178
--- Comment #25 from Dan Kegel <dank(a)kegel.com> 2011-05-22 10:57:26 CDT ---
What's in that .exe? I'm tempted to delete it, since it's not
clear what's in it, and you didn't describe it at all.
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=2527
--- Comment #27 from Jim Doutt <jdoutt(a)whoi.edu> 2011-05-22 05:34:00 CDT ---
Created an attachment (id=34855)
--> (http://bugs.winehq.org/attachment.cgi?id=34855)
screenshot showing problem
The grey rectangle above the blue peaks is were text information should be.
I'm running Ubuntu Hardy Heron and WINE 1.3.20 compiled form source.
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=7102
felix.huber(a)schyf.de changed:
What |Removed |Added
----------------------------------------------------------------------------
Component|kernel32 |ole32
Version|0.9.28. |1.3.20
--- Comment #13 from felix.huber(a)schyf.de 2011-05-22 02:19:26 CDT ---
It's even worse, see previous log.
WW 6 starts, but opening or creating an empty document, results in
"insufficient memory". When closing, the previous crash log shows up, no matter
whether ole32xxx was set to native or builtin. The OS was set to WIN98.
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=7102
felix.huber(a)schyf.de changed:
What |Removed |Added
----------------------------------------------------------------------------
Attachment #27987|0 |1
is obsolete| |
--- Comment #12 from felix.huber(a)schyf.de 2011-05-22 02:14:58 CDT ---
Created an attachment (id=34850)
--> (http://bugs.winehq.org/attachment.cgi?id=34850)
Crash log when closing Winword 6
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=25643
Summary: Dream Pinball 3D freezes when you launch the ball
Product: Wine
Version: 1.3.10
Platform: x86
URL: http://www.bigdownload.com/games/dream-pinball-3d/pc/d
ream-pinball-3d-demo/
OS/Version: Linux
Status: UNCONFIRMED
Severity: normal
Priority: P2
Component: -unknown
AssignedTo: wine-bugs(a)winehq.org
ReportedBy: gyebro69(a)gmail.com
Created an attachment (id=32658)
--> (http://bugs.winehq.org/attachment.cgi?id=32658)
terminal output
Installation, starting the game and choosing a theme from the menu all works
fine. As soon as I press <Enter> to launch the ball the game freezes.
The same problem persists with Wine-0.9.47, 1.0.1, 1.2.2 and so on.
To reproduce the issue in the demo:
1. After installation start the demo by dp3d_demo.exe.
2. <New game>, then select <Amber Moon> and wait until the game is loaded. The
camera animation works and sound is playing. Press <Enter> to shoot the ball:
the game will hang (although sound is still playing on).
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=8854
GyB <gyebro69(a)gmail.com> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |gyebro69(a)gmail.com
--- Comment #70 from GyB <gyebro69(a)gmail.com> 2011-05-21 22:22:11 CDT ---
*** Bug 25643 has been marked as a duplicate of this bug. ***
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=27195
Summary: XMPlay: interface refreshing about 2-4 FPS with Wine
1.3.19+
Product: Wine
Version: 1.3.19
Platform: x86-64
OS/Version: Linux
Status: UNCONFIRMED
Severity: normal
Priority: P2
Component: -unknown
AssignedTo: wine-bugs(a)winehq.org
ReportedBy: goodgod261(a)wp.pl
Nothing in the XMPlay interface refreshes fast enough. Visualizations, volume
meter, time. Nothing. App that should have (and had) practically unlimited FPS,
refreshes its content few times a second, causing problems with aforesaid
things... Regression, I guess. Version 1.3.18 was refreshing interface
properly.
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.
http://bugs.winehq.org/show_bug.cgi?id=27204
Summary: Portable Firefox 4.0.1 fails to find several existing
dlls
Product: Wine
Version: 1.3.19
Platform: x86
OS/Version: Linux
Status: UNCONFIRMED
Severity: normal
Priority: P2
Component: -unknown
AssignedTo: wine-bugs(a)winehq.org
ReportedBy: winebugzilla.kyoo(a)xoxy.net
Created an attachment (id=34761)
--> (http://bugs.winehq.org/attachment.cgi?id=34761)
Output when running firefoxportable.
When attempting to run Firefox Portable 4.0.1 from its directory (cd
FirefoxPortable; wine FirefoxPortable.exe), it fails to find several dlls that
exist in the subdirectory Firefox:
smime3.dll
ssl3.dll
nss3.dll
nssutil3.dll
plc4.dll
plds4.dll
mozalloc.dll
mozcpp19.dll
and so closes immediately after showing the Portable Apps splash. Firefox
4.0.1 (non-portable) runs without issues under wine for me.
--
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.