ANALYSING THE PACKER LAYERS OF ROGUE ANTI-VIRUS PROGRAMS
Rachit Mathur, Zheng Zhang · 2011
It is well known that FakeAlert programs have become a real problem to deal with. The major problem for static signature scanners has been their ever-changing layers of decryptors. This paper focuses on the code analysis of the decryptor layers of such programs. It takes a comprehensive look at how the malware family evolved over the past years and the anti-RE tricks they employ to continually evade detection.