From 1918601e4c0c38688cfc6c41b9dc3ee3f2bcbfa7 Mon Sep 17 00:00:00 2001 From: Niclas Karlsson MATE Date: Wed, 16 Aug 2000 12:54:03 +0000 Subject: [PATCH] WATCOM compiled programs leave VirtualSize to zero which triggers the virus check. Use SizeOfRawData instead. --- loader/pe_image.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/loader/pe_image.c b/loader/pe_image.c index 3b025b574d3..8775c1f423f 100644 --- a/loader/pe_image.c +++ b/loader/pe_image.c @@ -521,7 +521,7 @@ HMODULE PE_LoadImage( HANDLE hFile, LPCSTR filename, DWORD flags ) { if (nt->OptionalHeader.AddressOfEntryPoint < sec->VirtualAddress) continue; - if (nt->OptionalHeader.AddressOfEntryPoint < sec->VirtualAddress+sec->Misc.VirtualSize) + if (nt->OptionalHeader.AddressOfEntryPoint < sec->VirtualAddress+sec->SizeOfRawData) break; } if (i == nt->FileHeader.NumberOfSections)