FakeAV authors have graduated over the years from not using any packers to using some of the most complex polymorphic packers that we have seen. We observe that during the evolution of FakeAV the majority of changes have occurred in the Anti-Emulation and Anti-Reverse engineering (RE) tricks. In this section, we will look at some of these tricks used by FakeAV packers over the last eighteen months. Malware authors are aware of this and will insert specific anti-emulation instructions into their code in order to try and break emulation by anti-virus software.”]
Source: https://nakedsecurity.sophos.com/fake-anti-virus-the-journey-from-trojan-to-a-persistent-threat-4/

