ok... so if there's a head or decryptor present then why not just scan for it's string instead of looking for encrypted part of the virus