[Bug 35646] Multiple applications protected with Obsidium v1.4+ fail on startup, reporting "Debugger detected - please disable it and restart the application" (Condes 9, Universal mechanism)

wine-bugs at winehq.org wine-bugs at winehq.org
Fri Mar 28 15:15:42 CDT 2014


https://bugs.winehq.org/show_bug.cgi?id=35646

Anastasius Focht <focht at gmx.net> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
            Summary|Condes 9 fails on startup:  |Multiple applications
                   |"Debugger detected - please |protected with Obsidium
                   |disable it and restart the  |v1.4+ fail on startup,
                   |application" (Obsidium      |reporting "Debugger
                   |v1.4+)                      |detected - please disable
                   |                            |it and restart the
                   |                            |application" (Condes 9,
                   |                            |Universal mechanism)

--- Comment #2 from Anastasius Focht <focht at gmx.net> ---
Hello folks,

another app: 'Universal mechanism' (http://www.umlab.ru/) 

Reported here: https://forum.winehq.org/viewtopic.php?f=8&t=22155

Protection scan:

--- snip ---
-=[ ProtectionID v0.6.5.5 OCTOBER]=-
(c) 2003-2013 CDKiLLER & TippeX
Build 31/10/13-21:09:09
Ready...

Scanning -> Z:\home\focht\.wine\drive_c\Program Files\UM Software Lab\Universal
Mechanism\7\bin\UMInput.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 5174448 (04EF4B0h)
Byte(s)
-> File Appears to be Digitally Signed @ Offset 04EDBC8h, size : 018E8h / 06376
byte(s)
-> File has 4598693 (0462BA5h) bytes of appended data starting at offset
08B023h
[File Heuristics] -> Flag : 00000000000001011100001000110111 (0x0005C237)
[Entrypoint Section Entropy] : 7.99
[!] Obsidium v1.4.2.0 (or higher) detected !
- Scan Took : 0.368 Second(s) [000000170h tick(s)] [533 scan(s) done]

Scanning -> Z:\home\focht\.wine\drive_c\Program Files\UM Software Lab\Universal
Mechanism\7\bin\UMSimul.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 7850800 (077CB30h)
Byte(s)
-> File Appears to be Digitally Signed @ Offset 077B248h, size : 018E8h / 06376
byte(s)
-> File has 6905272 (0695DB8h) bytes of appended data starting at offset
0E5490h
[File Heuristics] -> Flag : 00000000000001011100001000110111 (0x0005C237)
[Entrypoint Section Entropy] : 7.99
[!] Obsidium v1.4.2.0 (or higher) detected !
- Scan Took : 0.448 Second(s) [0000001C0h tick(s)] [533 scan(s) done]
--- snip ---

Nasty stuff (see bug 24157) ... maybe later :)

$ sha1sum um7.1.2.1.exe 
6c869866399d333e06d199e2e86e08c009d64c02  um7.1.2.1.exe

$ du -sh um7.1.2.1.exe 
271M    um7.1.2.1.exe

$ wine --version
wine-1.7.15-112-g2aad5d7

Regards

-- 
Do not reply to this email, post in Bugzilla using the
above URL to reply.
You are receiving this mail because:
You are watching all bug changes.



More information about the wine-bugs mailing list