https://bugs.winehq.org/show_bug.cgi?id=25851
Anastasius Focht focht@gmx.net changed:
What |Removed |Added ---------------------------------------------------------------------------- Summary|Zararadio start up error |ZaraRadio 1.6.x crashes on | |startup Keywords| |download URL| |https://web.archive.org/web | |/20190421090735/http://www. | |zarastudio.es/zararadiofr/Z | |araRadioFreeEdition.exe Resolution|DUPLICATE |FIXED Version|unspecified |1.2 CC| |focht@gmx.net
--- Comment #10 from Anastasius Focht focht@gmx.net --- Hello folks,
the conclusion is wrong. That app from 2010 was never a .NET app/managed executable. Also the initial backtraces from OP indicates it.
https://web.archive.org/web/2/http://www.zarastudio.es/zararadiofr/ZaraRadio...
--- snip --- $ pwd /home/focht/.wine/drive_c/Program Files (x86)/ZaraSoft/ZaraRadio
$ file * basscd.dll: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows bass.dll: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows basswma.dll: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows exchndl.dll: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows Humidity: directory Lang: directory licencia.txt: ISO-8859 text, with very long lines, with CRLF line terminators mingwm10.dll: PE32 executable (DLL) (console) Intel 80386, for MS Windows sqlite3.dll: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows Temperature: directory Time: directory tips.txt: ASCII text, with CRLF line terminators unins000.dat: InnoSetup Log ZaraRadio, version 0x2d, 3288 bytes, n550\focht, "C:\Program Files (x86)\ZaraSoft\ZaraRadio" unins000.exe: PE32 executable (GUI) Intel 80386, for MS Windows ZaraRadio.chm: MS Windows HtmlHelp Data ZaraRadio.exe: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows --- snip ---
ProtectionID scan:
--- snip --- -=[ ProtectionID v0.6.9.0 DECEMBER]=- (c) 2003-2017 CDKiLLER & TippeX Build 24/12/17-21:05:42 Ready... Scanning -> C:\Program Files (x86)\ZaraSoft\ZaraRadio\ZaraRadio.exe File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 6004224 (05B9E00h) Byte(s) | Machine: 0x14C (I386) Compilation TimeStamp : 0x4CE15F41 -> Mon 15th Nov 2010 16:26:41 (GMT) [TimeStamp] 0x4CE15F41 -> Mon 15th Nov 2010 16:26:41 (GMT) | PE Header | - | Offset: 0x00000088 | VA: 0x00400088 | - [File Heuristics] -> Flag #1 : 00000000000001001100000000100000 (0x0004C020) [Entrypoint Section Entropy] : 5.97 (section #0) ".text " | Size : 0x47DD48 (4709704) byte(s) [DllCharacteristics] -> Flag : (0x0000) -> NONE [SectionCount] 6 (0x6) | ImageSize 0x5DF000 (6156288) byte(s) [VersionInfo] Company Name : ZaraSoft [VersionInfo] Product Name : ZaraRadio [VersionInfo] Product Version : 1.6 [VersionInfo] File Description : Automatización de radios ZaraRadio [VersionInfo] Legal Copyrights : © ZaraSoft 2010. Todos los derechos reservados. [ModuleReport] [IAT] Modules -> BASS.dll | BASSCD.dll | BASSWMA.dll | sqlite3.dll | ADVAPI32.DLL | COMCTL32.DLL | COMDLG32.DLL | GDI32.dll | KERNEL32.dll | mingwm10.dll | msvcrt.dll | MSIMG32.DLL | msvcrt.dll | OLE32.dll | OLEAUT32.DLL | SHELL32.DLL | USER32.dll | WINMM.DLL [CompilerDetect] -> MinGW [!] File appears to have no protection or is using an unknown protection - Scan Took : 1.821 Second(s) [00000049Bh (1179) tick(s)] [506 of 580 scan(s) done] --- snip ---
Our "special" friend from comment #7 most likely worked with an infected WINEPREFIX (download with malware piggybacks).
De-duplicating and closing again.
$ sha1sum ZaraRadioFreeEdition.exe 3eab2923a30427e3cccc72f348cc4b88224df4d4 ZaraRadioFreeEdition.exe
$ du -sh ZaraRadioFreeEdition.exe 3.5M ZaraRadioFreeEdition.exe
$ wine --version wine-4.6-111-g0664b062c6
Regards