The reason it's detected as a virus is because it is encrypted, thus your AV cannot read it and considers it a threat, the hack also uses some APIs that are used to manipulate CA, which is also seen as a threat.
Dave encrypts his assembled code to prevent people from reverse engineering it.