Help - Search - Members - Calendar
Full Version: Test your Anti Virus
BleepingComputer.com > Software > Tips and Tricks
   
Funnel Web
A Trick To Check Ur Antivirus Is Working Properly
Open notepad
Copy this code in the text file....

"X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*"

without quotes

then save it with the name fakevirus.exe

If this file got deleted immediately ....that means your antivirus is working 100%

Just to say that mine zapped it straight away thumbup.gif
Monty007
Interesting but I would suspect that most programs would pick this up.
Junior2007
No problem here, Avast snagged it right away.
Andrew
More info: http://www.eicar.org/anti_virus_test_file.htm
BWK
ESET NOD32 Antivirus 4 picked it as soon as name was entered.
SFB
One should be aware that you might not be allowed access to the file in order to delete it after it has been picked up by the AV.
xblindx
Avira caught it instantly.
Bezukhov
Thank you, Funnel Web. That was both fun and instructive.
ryan_bigl
AVG isn't picking it up and Malwarebytes saw nothing wrong with it -_-

Iobit Security 360 and Windows Defender saw something wrong with it when I scanned it though
Stang777
Ryan, I don't know about AVG but Malwarebytes sees the Eicar test file as a waste of time to put it in their detection rules. They only focus on actual threats and the Eicar test files have been around so long that they know it isn't one. It is possible that any program that does not pick it up has also excluded it from their detection rules.
MadDawg
AVG picks it up immediately if I create it on the desktop. If I save it to a folder, I have to scan it manually open the folder.
Keith1
I saved it in a folder myself. AVG 9.0 and MalwareBytes didn't find it. I think stang777 gave the reason for that.

Interesting though - A-Squared found it. Just tossing this in for informational purposes.
ltdave
i saved it in 'my documents' and after closing notepad it was there...

as soon as i scrolled over it, AVG 8.5.436 popped up their 'threat warning' window...

i clicked remove or heal and it was gone...

does that mean MY avg is working?

EDITED:

i just tried it again, saving it to my desktop, and as soon as i minimized the other windows (to allow me to see the desktop) the AVG popped a threat window...

C03_M4NN
8.5.426 AVG did not find anything, allowed it to be put on desktop and executed..
Roderunner
100% success thumbup2.gif
Adamsappleone
Microsoft Security Essentials picked it up as soon as I clicked save.

Nice test.
Union_Thug
Avira (Free) zapped it immediately, even identified it as Eicar's test.

CODE
Exported events:

12/12/2009 19:12 [Guard] Malware found
      Virus or unwanted program 'Eicar-Test-Signature [virus]'
      detected in file 'C:\Documents and Settings\****\Desktop\fakevirus.exe.
      Action performed: Delete file


Edit: Disabled real-time AV---saved test to desktop scanned w/MBAM Quick scan, Right click scan with, even saved it to C/Program files...no detection. mad.gif thumbsdownsmileyanim.gif
Platypus
QUOTE(I @ Dec 13 2009, 11:19 AM) *
scanned w/MBAM...no detection. mad.gif thumbsdownsmileyanim.gif

As mentioned earlier in the topic, it's known that MBAM doesn't respond to the Eicar file, which is designed to confirm operation of signature-based anti-virus scanning, which is not the function of MBAM.

Admin at Malwarebytes advise that MBAM function checking can be done with the Spycar spyware test suite:

http://www.spycar.org

I think it would also be worth pointing out to everyone reading the topic that the eicar test file is useful only to confirm that an anti-virus application is operational. It doesn't give any guide as to its effectiveness as protection against any particular range of actual viruses.
Union_Thug
QUOTE(Platypus @ Dec 12 2009, 11:02 PM) *
QUOTE(I @ Dec 13 2009, 11:19 AM) *
scanned w/MBAM...no detection. mad.gif thumbsdownsmileyanim.gif

As mentioned earlier in the topic, it's known that MBAM doesn't respond to the Eicar file, which is designed to confirm operation of signature-based anti-virus scanning, which is not the function of MBAM.

Admin at Malwarebytes advise that MBAM function checking can be done with the Spycar spyware test suite:

http://www.spycar.org

I think it would also be worth pointing out that the eicar test file is useful only to confirm that an anti-virus application is operational. It doesn't give any guide as to its effectiveness as protection against any particular range of actual viruses.


Thank you for clearing that up for me. Next time I'll try something new, like ummmm...reading the entire thread, maybe?(Blushes profusely) MBAM is a terrific app which I trust and use twice a week to scan my machine.
Platypus
QUOTE(I @ Dec 13 2009, 03:42 PM) *
reading the entire thread, maybe? (Blushes...

That can catch any of us out at times... smile.gif
SameerPrehistorica
Avast caught it quickly...
msrrahul
kaspersky didnt find it
lady storm
Bitdefender total security 2010 picked it up immediately after saving

these did not

spybot search & destroy
spywareblaster
msrrahul
hey fellas...i'm using kaspersky antivirus...with license...i created the same file and saved the file with the name specified in this forum...but neither kaspersky found it nor it's being deleted nor cant b moved from desktop to any where....
msrrahul
i saved it with different name...XYZ.exe.... still its not deleted....[:-/]
xblindx
I switched my AV from Avira to Avast 5 beta 3 today just to change things around. File got detected right when I clicked save thumbup2.gif
Andy K.
McAfee caught it right away. Thanks, pretty cool. crazy.gif
Hawkeye4
QUOTE(ryan_bigl @ Nov 28 2009, 10:59 PM) *
AVG isn't picking it up and Malwarebytes saw nothing wrong with it -_-


My AVG caught it as soon as I renamed the file from *.txt. thumbup2.gif
Malleus Maleficarum
My anti virus software (symantec) caught it and the info on the "virus" stated that it was a test virus. Ha.
reinmar
works 100% :D thumbup.gif thumbup.gif

when i minimize the notepad it was automatically deleted.

webeyes
As soon as I clicked save Microsoft Security Essentials got it, glad it works!
the_patriot09
you know, im not an expert but I dont see how this proves any anti virus is 100% effective. in fact i have never seen one 100% effective. and even if it catches this one file, it doesnt mean it will catch every other file. I have taken heavily infected computers and ran 3 different anti virus programs (all up to date) right after the other and each found stuff the one before it did not. that is why I have 3 on my system-AVG, malwarebytes, and Comodo. Not one of them catches them all-but if I rotate them (run one a month, a different one each month) they do a pretty darn good job of keeping my system clean.
xblindx
The Eicar test is to help make sure that your real time protection is working. It doesn't determine effectiveness.
geekvolcano
Hmm that is a pretty cool trick, never saw that before. Are there any newer strings you can use, since many ati-virus programs simply don't care about that test file anymore?
Funnel Web
A lot of people are saying that malwarebytes and comodo etc did not pick it up, but the reason is that malwarebytes antimalware and comodo are not anti virus programs. malwarebytes antimalware is for malware/adware/trojans, and comodo will not pick it up because its a firewall program.

but its good to know that most of the peeps anti virus programs are working 100% smile.gif
carri
Mine worked tongue.gif (Avira)
It's a good trick and as stated several times in the thread is effective to show if your antivirus programme is working real time, and its a whole other kettle of fish as to proving the reliability of any one particular anti virus programme.
Thanks Funnel Web smile.gif
Killer_clown
(((((( beware ))))))


Downloaded it to my mac.. Mac poked it and left it alone ! LOL go apple!! :D

(( Yes joke ))
Darthy
Avira picked it up instantly.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.