Author Topic: How do viruses and other malware stay hidden from antivirus?  (Read 939 times)

0 Members and 1 Guest are viewing this topic.

Offline badass87

  • NULL
  • Posts: 2
  • Cookies: -1
    • View Profile
Please give me a detailed answer.  I'm not trying to write any malware (even if I wanted to, I never would as I clearly don't understand it fully), I'm just interested in computer security and I've don't get how stuff hides from the antivirus on a technical level.  Everywhere I look for an explanation, it never actually explains the technical stuff, and it always just says something like "it hides from the antivirus".  Could anyone here explain some typical techniques used by malware to hide from antivirus software?  Looking for stuff like working with memory in a way that it goes undetected or installing to a certain location in the filesystem (those probably aren't actual methods, but just as examples of the technical description I'm looking for).  Also, how does malware sometimes kill antivirus software?

Thanks for your time.
« Last Edit: June 08, 2014, 05:49:18 pm by badass87 »

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: How do viruses and other malware stay hidden from antivirus?
« Reply #1 on: June 08, 2014, 06:59:20 pm »
Go and write an intro first, we have an intro board also.

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: How do viruses and other malware stay hidden from antivirus?
« Reply #2 on: June 08, 2014, 07:05:02 pm »
Smoke and mirrors aka obfuscation.
Also search up (on Google or here) self-hiding malware. You'll find your answer.

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile

Offline Corrupted_Fear

  • Knight
  • **
  • Posts: 336
  • Cookies: 34
  • Is dangerous to go alone! Take this! @xxxx[{:::::>
    • View Profile
Re: How do viruses and other malware stay hidden from antivirus?
« Reply #4 on: June 08, 2014, 08:54:48 pm »
short answer, it looks for patterns and common known code that are in programs. For example, things that are produced by MSF, have a similar code structure. The AV knows this, and catches programs that it see's have that code structure.

Long answer, if you really want to know how it works, get something you know is infected, and clean it and scrub it until you find the code that the AV detects, change it around so that it still works but looks different, and by then you will fully understand the general principles.

by | Angel | Devil |

"Welcome to le trove that is my home. Welcome to EvilZone." -- DeepCopy