Virus detection

Issue #21 closed
Oldřich Nejezchleba created an issue


when I scan generated localized binary resource module here:

I get this warning: Symantec: Bloodhound.W32.EP

Is there a solution?

Thank you.

Comments (3)

  1. Anders@Melander

    The generated resources modules are just completely empty DLL stubs (no data, no code, nothing) with some resources (the localized forms and strings) appended to them so it’s actually technically impossible for them to be infected unless something on your system infected them. The DLL stub is the file EmptyResourceModule.dll in the Source\Resources folder.

    I wouldn’t worry about Symantec: Bloodhound.W32.EP though since it’s a heuristic virus signature which just means that something in the file “looks like a virus”.

    The only way to minimize false positives like these is to digitally sign the files and even that is no guarantee.

  2. Anders Melander repo owner

    Refs #21 Try to detect when an anti-virus program deletes the temporary file used by BeginUpdateResource/EndUpdateResource and notify the user.

    → <<cset 6f7884dc99c9>>

  3. Log in to comment