adplus-dvertising
frame-decoration

Question

What could a clever malicious program do to avoid detection by an antivirus program?

a.

Install itself as a filesystem filter that intercepts file system calls

b.

Create fake versions of infected files on the hard drive

c.

Hide the fact that it has infected numerous files on the hard drive

d.

All of the above

Posted under Reverse Engineering

Answer: (d).All of the above Explanation:A clever malicious program could install itself as a filesystem filter that intercepts file system calls and present the antivirus program with fake versions of the files on disk, thus hiding the fact that it has infected numerous files on the hard drive.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What could a clever malicious program do to avoid detection by an antivirus program?

Similar Questions

Discover Related MCQs

Q. Why must security and antivirus programs reside at a low enough level in the operating system?

Q. At what level could a malicious program theoretically infect a program?

Q. Why is it problematic if a malicious program alters an extremely low-level component?

Q. What is the main goal of backdoor access for many malicious programs?

Q. What are Denial-of-Service (DoS) attacks?

Q. What is the basic problem with malware?

Q. Why can't encryption-based approaches address the vulnerability of malware?

Q. What are some ways to hide malicious software?

Q. What is the most powerful analysis method for analyzing malware?

Q. What are antireversing techniques?

Q. What is the easiest way for antivirus programs to identify malicious programs?

Q. What is polymorphism?

Q. What is the weakness of polymorphism-based solutions?

Q. How does polymorphism prolong the analysis process of a malicious program?

Q. What is the potential weakness of the decryption code in a polymorphic program?

Q. What is required before entering a function that can be polymorphed?

Q. What is metamorphism in the context of malware?

Q. What is the benefit of using metamorphism in malware?

Q. What is required for a metamorphic engine to work?

Q. What kind of alterations can be automatically applied to a program by a metamorphic engine?