https://bugs.winehq.org/show_bug.cgi?id=37722
Bug ID: 37722 Summary: i have some type of root kit or malware i have found in the setup of my shell, it uses pulse audio and also bluetooth to send info SOMEWHERE, please take a look at what i have sent and provide some feedback, we will stop the f%ckers Product: Wine Version: unspecified Hardware: x86-64 OS: FreeBSD Status: UNCONFIRMED Severity: critical Priority: P2 Component: user32 Assignee: wine-bugs@winehq.org Reporter: jc.xxxiv@gmail.com
Created attachment 50217 --> https://bugs.winehq.org/attachment.cgi?id=50217 here is one file from /usr/sbin where the bastards have dug in
i am unable to gain root access to my system as this bug/malware/whtevr has embedded itself in my system like an annoying tic, please take a look at the enclosed file and tell me what you think, thank you
https://bugs.winehq.org/show_bug.cgi?id=37722
Nikolay Sivov bunglehead@gmail.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|UNCONFIRMED |RESOLVED Resolution|--- |INVALID
--- Comment #1 from Nikolay Sivov bunglehead@gmail.com --- Nice try, but no. Admin, please remove that.
https://bugs.winehq.org/show_bug.cgi?id=37722
Nikolay Sivov bunglehead@gmail.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |CLOSED Component|user32 |-unknown Severity|critical |normal
--- Comment #2 from Nikolay Sivov bunglehead@gmail.com --- Closing.
https://bugs.winehq.org/show_bug.cgi?id=37722
Anastasius Focht focht@gmx.net changed:
What |Removed |Added ---------------------------------------------------------------------------- CC| |focht@gmx.net Summary|i have some type of root |spam/malware |kit or malware i have found | |in the setup of my shell, | |it uses pulse audio and | |also bluetooth to send info | |SOMEWHERE, please take a | |look at what i have sent | |and provide some feedback, | |we will stop the f%ckers |
--- Comment #3 from Anastasius Focht focht@gmx.net --- Hello folks,
for completeness the virustotal.com scan of the attachment:
https://www.virustotal.com/en/file/2f6d68c9f1ad0058cbff96546580446890c778e93...
Wasn't flagged but could be custom made, unknown to scanners.
Regards
https://bugs.winehq.org/show_bug.cgi?id=37722
--- Comment #4 from Austin English austinenglish@gmail.com --- The content of attachment 50217 has been deleted for the following reason:
malware
https://bugs.winehq.org/show_bug.cgi?id=37722
--- Comment #5 from Austin English austinenglish@gmail.com --- (In reply to Nikolay Sivov from comment #1)
Nice try, but no. Admin, please remove that.
Done, and account is disabled.