adplus-dvertising
frame-decoration

Question

Why would a clever malicious program install itself as a filesystem filter?

a.

To present the antivirus program with fake versions of the files on disk

b.

To hide the fact that it has infected numerous files on the hard drive from the antivirus program

c.

Both a and b

d.

None of the above

Posted under Reverse Engineering

Answer: (c).Both a and b Explanation:A clever malicious program could install itself as a filesystem filter to intercept the antivirus program’s file system calls and present it with fake versions of the files on disk, thus hiding the fact that it has infected numerous files on the hard drive from the antivirus program.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. Why would a clever malicious program install itself as a filesystem filter?

Similar Questions

Discover Related MCQs

Q. Where must security and antivirus programs reside in order to prevent malicious programs from distorting their view of the system?

Q. What is firmware?

Q. Can firmware be updated at the customer site using a special firmware-updating program?

Q. What could a clever malicious program do to avoid detection by an antivirus program?

Q. Why must security and antivirus programs reside at a low enough level in the operating system?

Q. At what level could a malicious program theoretically infect a program?

Q. Why is it problematic if a malicious program alters an extremely low-level component?

Q. What is the main goal of backdoor access for many malicious programs?

Q. What are Denial-of-Service (DoS) attacks?

Q. What is the basic problem with malware?

Q. Why can't encryption-based approaches address the vulnerability of malware?

Q. What are some ways to hide malicious software?

Q. What is the most powerful analysis method for analyzing malware?

Q. What are antireversing techniques?

Q. What is the easiest way for antivirus programs to identify malicious programs?

Q. What is polymorphism?

Q. What is the weakness of polymorphism-based solutions?

Q. How does polymorphism prolong the analysis process of a malicious program?

Q. What is the potential weakness of the decryption code in a polymorphic program?

Q. What is required before entering a function that can be polymorphed?