The point is that there is no "after decryption", at any given moment in time only a small portion of the code is decrypted.
There has been some malware that did just that - it was still possible to record the trace of instructions being executed along with the current instruction pointer to be able to reconstruct the binary quite well.