The EICAR test

AmberClad

Diamond Member
Jul 23, 2005
4,914
0
0
I'm a little confused about how and why the EICAR test works. It just looks like a plain text ASCII string to me. How exactly does it simulate a virus?
 

AmberClad

Diamond Member
Jul 23, 2005
4,914
0
0
This might just be me, but that hardly seems useful as a test of how good an AV program is at detecting real viruses in the wild. Especially the more dynamic ones that require heuristic algorithms.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: AmberClad
This might just be me, but that hardly seems useful as a test of how good an AV program is at detecting real viruses in the wild.

I'm certain that the EICAR test isn't meant to show how good an AV program is at detecting real viruses in the wild. Tangentially, this thread might interest you, a small test against in-the-wild malware scanned as soon after collection as practical.
 

Zugzwang152

Lifer
Oct 30, 2001
12,134
1
0
It's meant to test antivirus programs' response to a virus without actually infecting the computer.

How are you sure that your antivirus will properly delete/quarantine/alert/whatever when it detects a virus? You can't really be sure without downloading a virus, so use the EICAR test file instead. That way, even if your antivirus program fails to catch it, you won't be infected.
 

AmberClad

Diamond Member
Jul 23, 2005
4,914
0
0
Originally posted by: mechBgon
Tangentially, this thread might interest you, a small test against in-the-wild malware scanned as soon after collection as practical.
Thanks. That series of tests you guys did was a pretty interesting read. Lots of good info :thumbsup:.
 

lusher

Member
Aug 17, 2007
86
0
0
It's just a test to see if your AV is functioning. That's all. It's not meant to test how good it is.

Anyone remember that there was a similar attempt a few years back to create a anti-trojan simulator test file for anti-trojans kind of like Eicar but for anti-trojans.

http://www.misec.net/trojansimulator/ by trojanhunter boys...

This one is slightly different from eicar, in that it actually does something as little as it is...

Some vendors choice to add a detection for it, many others did not.
 

hans007

Lifer
Feb 1, 2000
20,212
17
81
its not going to test a heuristic scanner no. but your basic, real time scanner, or on demand scanner based on defs is a string search engine at some level. im fairly certain all of them at some part is a string search with possible more routines for more complicated virus.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |