<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="Obfuscation (software) - Page 10 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=Obfuscation_(software)&amp;p=9">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Obfuscation_%28software%29&amp;p=11">3.Next</a>
</p>
<p>or data section. When a user runs the dropper, it performs the XOR operation again with the same key to reconstruct the original malware, then either executes it directly from memory or writes it to disk before running it.</p>

<p>This process removes several indicators that antivirus software relies on. The <a href="page.php?w=DOS_MZ_executable">MZ header</a>{{px2mdash}}px2}}}}?the 2-byte signature "MZ" which marks the beginning of every Windows executable{{px2mdash}}px2}}}}?gets completely obscured by the XOR operation. Security programs frequently</p><p>
<a accesskey="1" href="page.php?w=Obfuscation_(software)&amp;p=9">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Obfuscation_%28software%29&amp;p=11">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
