The infected file is probably encrypted, and including file descriptions/icons helps bypass Anti-Virus fingerprints, but after a varied amount of time, the A.V stub/update is processed and if the file is indeed infected and discovered (usually by virustotal scans) its reported to the A.V list included and they get a notification and if it is indeed a bad installment, it gets removed from your computer with confirmation from you.
But smart hackers use SFX to change the hosts file value to prevent vocal updates from the Anti Virus sites. If its used, there is no communication from your computer to the anti-virus your using (that is if the site is included in the blocked sites list) .