Funnel Web
Nov 19 2009, 08:05 AM
A Trick To Check Ur Antivirus Is Working Properly
Open notepad
Copy this code in the text file....
"X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*"
without quotes
then save it with the name fakevirus.exe
If this file got deleted immediately ....that means your antivirus is working 100%
Just to say that mine zapped it straight away
Monty007
Nov 19 2009, 03:37 PM
Interesting but I would suspect that most programs would pick this up.
Junior2007
Nov 19 2009, 08:53 PM
No problem here, Avast snagged it right away.
Andrew
Nov 20 2009, 05:48 PM
BWK
Nov 20 2009, 11:47 PM
ESET NOD32 Antivirus 4 picked it as soon as name was entered.
SFB
Nov 24 2009, 07:08 PM
One should be aware that you might not be allowed access to the file in order to delete it after it has been picked up by the AV.
xblindx
Nov 27 2009, 01:28 PM
Avira caught it instantly.
Bezukhov
Nov 28 2009, 10:52 AM
Thank you, Funnel Web. That was both fun and instructive.
ryan_bigl
Nov 28 2009, 10:59 PM
AVG isn't picking it up and Malwarebytes saw nothing wrong with it -_-
Iobit Security 360 and Windows Defender saw something wrong with it when I scanned it though
Stang777
Nov 28 2009, 11:22 PM
Ryan, I don't know about AVG but Malwarebytes sees the Eicar test file as a waste of time to put it in their detection rules. They only focus on actual threats and the Eicar test files have been around so long that they know it isn't one. It is possible that any program that does not pick it up has also excluded it from their detection rules.
MadDawg
Nov 29 2009, 12:35 AM
AVG picks it up immediately if I create it on the desktop. If I save it to a folder, I have to scan it manually open the folder.
Keith1
Nov 29 2009, 03:19 PM
I saved it in a folder myself. AVG 9.0 and MalwareBytes didn't find it. I think stang777 gave the reason for that.
Interesting though - A-Squared found it. Just tossing this in for informational purposes.
ltdave
Dec 1 2009, 08:44 PM
i saved it in 'my documents' and after closing notepad it was there...
as soon as i scrolled over it, AVG 8.5.436 popped up their 'threat warning' window...
i clicked remove or heal and it was gone...
does that mean MY avg is working?
EDITED:
i just tried it again, saving it to my desktop, and as soon as i minimized the other windows (to allow me to see the desktop) the AVG popped a threat window...
C03_M4NN
Dec 1 2009, 08:49 PM
8.5.426 AVG did not find anything, allowed it to be put on desktop and executed..
Roderunner
Dec 7 2009, 04:03 AM
100% success
Adamsappleone
Dec 8 2009, 10:00 AM
Microsoft Security Essentials picked it up as soon as I clicked save.
Nice test.
Union_Thug
Dec 12 2009, 07:19 PM
Avira (Free) zapped it immediately, even identified it as Eicar's test.
CODE
Exported events:
12/12/2009 19:12 [Guard] Malware found
Virus or unwanted program 'Eicar-Test-Signature [virus]'
detected in file 'C:\Documents and Settings\****\Desktop\fakevirus.exe.
Action performed: Delete file
Edit: Disabled real-time AV---saved test to desktop scanned w/MBAM Quick scan, Right click scan with, even saved it to C/Program files...no detection.
Platypus
Dec 12 2009, 11:02 PM
QUOTE(I @ Dec 13 2009, 11:19 AM)

scanned w/MBAM...no detection.

As mentioned earlier in the topic, it's known that MBAM doesn't respond to the Eicar file, which is designed to confirm operation of signature-based anti-virus scanning, which is not the function of MBAM.
Admin at Malwarebytes advise that MBAM function checking can be done with the Spycar spyware test suite:
http://www.spycar.orgI think it would also be worth pointing out to everyone reading the topic that the eicar test file is useful only to confirm that an anti-virus application is operational. It doesn't give any guide as to its effectiveness as protection against any particular range of actual viruses.
Union_Thug
Dec 12 2009, 11:42 PM
QUOTE(Platypus @ Dec 12 2009, 11:02 PM)

QUOTE(I @ Dec 13 2009, 11:19 AM)

scanned w/MBAM...no detection.

As mentioned earlier in the topic, it's known that MBAM doesn't respond to the Eicar file, which is designed to confirm operation of signature-based anti-virus scanning, which is not the function of MBAM.
Admin at Malwarebytes advise that MBAM function checking can be done with the Spycar spyware test suite:
http://www.spycar.orgI think it would also be worth pointing out that the eicar test file is useful only to confirm that an anti-virus application is operational. It doesn't give any guide as to its effectiveness as protection against any particular range of actual viruses.
Thank you for clearing that up for me. Next time I'll try something new, like ummmm...reading the entire thread, maybe?(Blushes profusely) MBAM is a terrific app which I trust and use twice a week to scan my machine.
Platypus
Dec 13 2009, 01:20 AM
QUOTE(I @ Dec 13 2009, 03:42 PM)

reading the entire thread, maybe? (Blushes...
That can catch any of us out at times...
SameerPrehistorica
Dec 15 2009, 03:52 AM
Avast caught it quickly...
msrrahul
Dec 21 2009, 02:26 PM
kaspersky didnt find it
lady storm
Dec 22 2009, 09:50 PM
Bitdefender total security 2010 picked it up immediately after saving
these did not
spybot search & destroy
spywareblaster
msrrahul
Dec 23 2009, 02:24 AM
hey fellas...i'm using kaspersky antivirus...with license...i created the same file and saved the file with the name specified in this forum...but neither kaspersky found it nor it's being deleted nor cant b moved from desktop to any where....
msrrahul
Dec 23 2009, 02:27 AM
i saved it with different name...XYZ.exe.... still its not deleted....[:-/]
xblindx
Dec 24 2009, 11:51 AM
I switched my AV from Avira to Avast 5 beta 3 today just to change things around. File got detected right when I clicked save
Andy K.
Dec 24 2009, 12:00 PM
McAfee caught it right away. Thanks, pretty cool.
Hawkeye4
Jan 7 2010, 01:09 AM
QUOTE(ryan_bigl @ Nov 28 2009, 10:59 PM)

AVG isn't picking it up and Malwarebytes saw nothing wrong with it -_-
My AVG caught it as soon as I renamed the file from *.txt.
Malleus Maleficarum
Jan 8 2010, 12:59 PM
My anti virus software (symantec) caught it and the info on the "virus" stated that it was a test virus. Ha.
reinmar
Jan 9 2010, 07:12 AM
works 100% :D
when i minimize the notepad it was automatically deleted.
webeyes
Jan 12 2010, 01:52 AM
As soon as I clicked save Microsoft Security Essentials got it, glad it works!
the_patriot09
Jan 12 2010, 05:50 AM
you know, im not an expert but I dont see how this proves any anti virus is 100% effective. in fact i have never seen one 100% effective. and even if it catches this one file, it doesnt mean it will catch every other file. I have taken heavily infected computers and ran 3 different anti virus programs (all up to date) right after the other and each found stuff the one before it did not. that is why I have 3 on my system-AVG, malwarebytes, and Comodo. Not one of them catches them all-but if I rotate them (run one a month, a different one each month) they do a pretty darn good job of keeping my system clean.
xblindx
Jan 12 2010, 05:20 PM
The Eicar test is to help make sure that your real time protection is working. It doesn't determine effectiveness.
geekvolcano
Jan 16 2010, 02:09 PM
Hmm that is a pretty cool trick, never saw that before. Are there any newer strings you can use, since many ati-virus programs simply don't care about that test file anymore?
Funnel Web
Jan 17 2010, 07:41 PM
A lot of people are saying that malwarebytes and comodo etc did not pick it up, but the reason is that malwarebytes antimalware and comodo are not anti virus programs. malwarebytes antimalware is for malware/adware/trojans, and comodo will not pick it up because its a firewall program.
but its good to know that most of the peeps anti virus programs are working 100%
carri
Jan 20 2010, 10:42 AM
Mine worked

(Avira)
It's a good trick and as stated several times in the thread is effective to show if your antivirus programme is working real time, and its a whole other kettle of fish as to proving the reliability of any one particular anti virus programme.
Thanks Funnel Web
Killer_clown
Jan 20 2010, 10:36 PM
(((((( beware ))))))
Downloaded it to my mac.. Mac poked it and left it alone ! LOL go apple!! :D
(( Yes joke ))
Darthy
Jan 24 2010, 10:38 PM
Avira picked it up instantly.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.