View Full Version : EICAR Test Virus
bryanjoe
October 30th, 2006, 01:51 AM
Currently trialling the site on AVG Free (not sure if this is one the official site)
http://www.rexswain.com/eicar.html
AVG Free managed to Prompt Alert on eicar.com when downloading
No response for the other 2 when downloading.
Alert was prompted when on-demand scan of the 2 files...
Still not so bad.
What is your antivirus software and does it prompt u of virus activity on the 2 zip files?
Tarq57
October 30th, 2006, 05:06 AM
I've clicked on them from here http://www.eicar.org/anti_virus_test_file.htm and Avast home blocked all four in http, (Page wouldn't open..."cannot be displayed" message) but in https, only blocked 1, 3 &4 , and the zipped ones only when open attempted. The txt file (2) displayed in the web page, no bells or whistles went off.
Interesting. I wonder why the difference? Might have to ask at the Avast forum.
C.S.J
October 30th, 2006, 02:17 PM
f-secure 2007 automatically blocks / prevents or removes ALL before it can get on the machine.
ASpace
October 30th, 2006, 02:57 PM
@bryanjoe
Hi . I use NOD. Its internet scanner blocks all files (including the archives) . Anyway , if your AVG doesn't pop-up on the zip files , don't worry , when the ZIP is unpacked , it will :-)
Tarq57
October 30th, 2006, 03:16 PM
Quote from one of the folks at Avast:
"The Web Shield scans only the HTTP traffic of the browser, that's why standard protocol http eicar files are detected. The others four samples of the eicar test, which use the secure HTTPS protocol are not detected during download by the Web Shield, because the Web Shield simply do not scan this traffic. So when you download the four samples on your PC and do a scan with avast!, all of them will be detected "
I can confirm this is the case.
Banshee
October 31st, 2006, 02:29 PM
I clicked on the eicar.com.txt file and f-secure did nothing.a few seconds later a blank new window opened and all I could see was this:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
wasn't f-secure supposed to block this page ?
huntnyc
October 31st, 2006, 02:41 PM
Antivir Security suite denies access when trying to download. I guess it's working then.
Gary
ASpace
October 31st, 2006, 04:31 PM
-{ Quote: "
wasn't f-secure supposed to block this page ?" }-
Yes , but only if F-Secure is set to scan TXT files . Many AVs doesn't scan TXT files by default because TXT doesn't bring malware in them ;)
Inspector Clouseau
October 31st, 2006, 04:45 PM
-{ Quote: "because TXT doesn't bring malware in them ;)" }-
1. Open Notepad
2. Write exactly "Mike has you owned" (without enter and without quotes)
3. Save it
4. Reopen it with Notepad ;D
Banshee
October 31st, 2006, 05:40 PM
-{ Quote: "1. Open Notepad
2. Write exactly "Mike has you owned" (without enter and without quotes)
3. Save it
4. Reopen it with Notepad ;D" }-
Just did. When I opened the txt file all I could see was this:
楍敫栠獡礠畯漠湷摥
?????
ASpace
October 31st, 2006, 06:19 PM
Mike (IC) created a new Halloween virus for Notepad ;D ;D ;D ;D <just kidding , of course>
EraserHW
October 31st, 2006, 06:36 PM
hahaha ;D Mike ownz you ;D this is a nice old trick :)
It was born with "Bush hid the facts", but every string that has <4 letter> <3 letters> <3 letters> <5 letters> works :D It's some unicode parsing bug in notepad :)
Banshee
October 31st, 2006, 08:46 PM
An old trick ? Ok, I am slow.But.Why do I get those "chinese" kind-of-like things?
I really don't get it:wacko:
ggf31416
October 31st, 2006, 09:38 PM
-{ Quote: "Why do I get those "chinese" kind-of-like things?" }-
http://blogs.msdn.com/oldnewthing/archive/2004/03/24/95235.aspx
Banshee
October 31st, 2006, 10:04 PM
Have a look:
lodore
November 1st, 2006, 07:39 AM
-{ Quote: "I clicked on the eicar.com.txt file and f-secure did nothing.a few seconds later a blank new window opened and all I could see was this:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
wasn't f-secure supposed to block this page ?" }-
when you save the file you call it a filename with the .com extension on the end for it to work
lodore
November 1st, 2006, 07:40 AM
-{ Quote: "1. Open Notepad
2. Write exactly "Mike has you owned" (without enter and without quotes)
3. Save it
4. Reopen it with Notepad ;D" }-
great one mike:thumb: lmao
C.S.J
November 1st, 2006, 01:04 PM
-{ Quote: "I clicked on the eicar.com.txt file and f-secure did nothing.a few seconds later a blank new window opened and all I could see was this:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
wasn't f-secure supposed to block this page ?" }-
i have tried this page with f-secure,
it loads up a white page, without that text and in the bottom right corner, it pops up (animated slide) "virus has been removed"
maybe check your f-secure settings
Banshee
November 1st, 2006, 05:58 PM
-{ Quote: "i have tried this page with f-secure,
it loads up a white page, without that text and in the bottom right corner, it pops up (animated slide) "virus has been removed"
maybe check your f-secure settings" }-
Oops I had scan web traffic unticked.Enabled that and that did the trick.Thanks CSJ
C.S.J
November 1st, 2006, 06:07 PM
-{ Quote: "Oops I had scan web traffic unticked.Enabled that and that did the trick.Thanks CSJ" }-
no problem, i would suggest you set it to ask you about everything in the system control for better protection, if you need it ;D
pykko
November 2nd, 2006, 04:14 PM
LOL, Mike! That's super. ;D
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums