https://bugs.winehq.org/show_bug.cgi?id=44057
--- Comment #4 from jghodd jghodd@gmail.com --- I'd suggest maybe one of the GUIDs, but I'm not getting the false positive on the 64-bit build, only the 32-bit. I'm guessing it would have to be a binary pattern, but what are the chances this exact pattern shows up randomly in at least 4 builds performed in at least 2 different environments. It has to be a *defined* pattern that only occurs in 32-bit builds. Perhaps it is a GUID, but the 32-bit representation happens to match the malware signature.