2 Ways to Fuck AVP - By LiFEwiRE

Here 2 short ways to fake AVP, both used for this:

Your virus will survive longer when the AV'ers have to change their scanner itself instead of just updating the VirusData files.

I don't know if these tricks are already known, but I hope you'll learn something of it.

Trick 1.
Make your virus still able to infect AVP*.exe, but disable infecting of _AVP*.exe, only the last one has a self check.

Trick 2.
You can delete the data files (*.AVC) to annoy the user of the scanner, but they'll see some errors from AVP, and they'll notice something is wrong (assuming AVP isn't yet able to detect your virus).

Some better trick is copying EICAR.AVC over *.AVC, except kernel.avc, the user won't notice anything, nor AVP will. (Only the number of known viruses is really low:)