https://bugs.winehq.org/show_bug.cgi?id=39857
Bug ID: 39857 Summary: nina_DL.exe (app packed with Enigma Virtual Box) crashes on startup. Product: Wine Version: 1.8 Hardware: x86 URL: http://dl.tkoolmv.com/sample-nina/ OS: Linux Status: UNCONFIRMED Severity: normal Priority: P2 Component: -unknown Assignee: wine-bugs@winehq.org Reporter: sagawa.aki+winebugs@gmail.com Distribution: Ubuntu
It's the game executable called 'Nina to Kagimori no Yusha' (ニナと鍵守の勇者). The file is distributed as a sample game built with RPG Tkool MV, Japanese version of RPG Maker MV.
Wine output: % wine nina_DL.exe err:seh:setup_exception_record stack overflow 1632 bytes in thread 0009 eip 7bc46d9f esp 00240cd0 stack 0x240000-0x241000-0x340000
How to reproduce: 1. click the download link at the download URL to obtain the nina_DL.zip because an archive link is not fixed. 2. unzip nina_DL.zip 3. wine nina_DL.exe
File hash value: % sha1sum nina_DL.exe 558702a7a9a0bcfebf8482632cb67cac6b53fd8d nina_DL.exe % sha1sum nina_DL.zip 90de9c9180b5899e44afdd4f349353b247b2fa71 nina_DL.zip
ProtectionID says Enigma Virtual Box is used: -=[ ProtectionID v0.6.7.5 DECEMBER]=- (c) 2003-2015 CDKiLLER & TippeX Build 24/12/15-14:14:44 Ready... Scanning -> C:\work\nina_DL.exe File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 241319936 (0E624000h) Byte(s) | Machine: 0x14C (I386) Compilation TimeStamp : 0x55B872F9 -> Wed 29th Jul 2015 06:30:17 (GMT) [TimeStamp] 0x55B872F9 -> Wed 29th Jul 2015 06:30:17 (GMT) | PE Header | - | Offset: 0x00000150 | VA: 0x00400150 | - [TimeStamp] 0x55B872BD -> Wed 29th Jul 2015 06:29:17 (GMT) | Export | - | Offset: 0x02A93DF4 | VA: 0x02E957F4 | - [TimeStamp] 0x55B872F9 -> Wed 29th Jul 2015 06:30:17 (GMT) | DebugDirectory | - | Offset: 0x022F2404 | VA: 0x026F3E04 | - -> Section [0x8] '.enigma1' has a higher physical size than virtual size.. [!] Executable uses TLS callbacks (1 total... 0 invalid addresses) [!] Executable uses SEH Tables (/SAFESEH) (8 calculated 8 recorded... 0 invalid addresses) [File Heuristics] -> Flag #1 : 00000100000000011101100100100000 (0x0401D920) [Entrypoint Section Entropy] : 6.62 (section #0) ".text " | Size : 0x22F1065 (36638821) byte(s) [DllCharacteristics] -> Flag : (0x8140) -> ASLR | DEP | TSA [SectionCount] 10 (0xA) | ImageSize 0x2D03000 (47198208) byte(s) [Export] 99% of function(s) (1110 of 1111) are in file | 0 are forwarded | 1062 code | 49 data | 0 uninit data | 0 unknown | [Debug Info] (record 1 of 1) (file offset 0x22F2400) Characteristics : 0x0 | TimeDateStamp : 0x55B872F9 (Wed 29th Jul 2015 06:30:17 (GMT)) | MajorVer : 0 / MinorVer : 0 -> (0.0) Type : 2 (0x2) -> CodeView | Size : 0x53 (83) AddressOfRawData : 0x2A8C730 | PointerToRawData : 0x2A8AD30 CvSig : 0x53445352 | SigGuid 7BDFAE61-42AA-4C42-B3FEA1430E7861C2 Age : 0x5 | Pdb : D:\slave\win32_nw12\node-webkit\src\out\Release\nw.exe.pdb [!] Warning : Import Table is bad !!! [!] Enigma Virtual Box v1.70 or higher bundled ! (skip many [CdKeySerial] message...) [CompilerDetect] -> Visual C++ 12.0 (Visual Studio 2012) - Scan Took : 84.203 Second(s) [000014B3Dh (84797) tick(s)] [503 of 577 scan(s) done]