The Naked PC Newsletter

Your good neighbor
who's also a computer
consultant!

Monday, 08-Sep-2008 11:07:19 EDT

TNPCers Say:
Yet another fantastic The Naked PC issue with EXCELLENT Windows NT coverage! -- Kenneth H.
117,977+ current readers

Type your email address and click Subscribe!
Subscribe to Our Newsletter
Name: 
E-mail:

Swiss-Tech Key Ring Products

You'll find a jillion uses for these super-cool portable tool kits that fit right on your key chain. Whether it's fixing your eyeglasses, pulling splinters, tightening up the loose screws you run into everyday... Open computer cases with ease, snip wires, all the jobs a small set of pliers would make easy work of, you've got to check out Swiss-Tech tools!


Get Jim and Lee's Book!
T.J. Lee and Lee Hudspeth's Absolute Beginner's Guide to PC Upgrades
Now available at Amazon!



Contact TNPC



Home What is TNPC?
Meet the crew... The TNPC Store TNPC Articles
Send comments Members Only Prior Issues

From TNPC issue #3.24...Lee Hudspeth

Safely Testing Your AntiVirus Package with the EICAR Test File

by Lee Hudspeth
November 30, 2000

Have you ever tested your anti-virus software?

I recently upgraded from Norton AntiVirus 2000 version 6.0 to Norton AntiVirus 2001 version 7.0. While configuring the new version, I remembered having previously tested one or more anti- virus packages using the EICAR anti-virus test file, and set about to remember what it was I did before. ("EICAR" stands for European Institute for Computer Anti-Virus Research.) Sadly, Norton's help file doesn't get you very far on search terms like "test", "probe", or "validate". You have to open up the Readme.txt to find it.

That file states, "To create a harmless text file that will be detected as a virus, which you can use to verify detection of viruses, logging, and alert functioning, visit this site:"
http://www.TheNakedPC.com/t/324/tr.cgi?eicar1

Also, a quick search on the Internet like this:

+"anti-virus" +"test file"

will take you right where you need to go.

As you read the aforementioned Web page, you can learn about the history behind the obvious need for an innocuous anti-virus test file. The really fun part is downloading the four versions of the EICAR test file and scanning them to see how well your anti-virus program performs. Here are descriptions of the four files, and the test results on my production PC. (Test configuration: Windows 98 SE 4.10.2222 A and Norton AntiVirus 2001 version 7.00.51F with auto-protect and email protection features turned on.)

1. Eicar.com -- a legitimate DOS program that actually produces sensible results when you run it; it contains the EICAR test string.

RESULT:  Norton passed.

When I started the download Norton correctly halted the download, produced an alert that the file was infected with "EICAR Test String.68", and recommended that I repair the infected file.

2. Eicar.com.txt -- a copy of EICAR.com with a different filename; according to EICAR, "[provided because] some readers reported problems when downloading the first file, which can be circumvented when using the second version."

RESULT:  Norton passed.

Immediately upon renaming the file to EICAR.com, same results as #1 above.

3. Eicar_com.zip -- contains the test file inside a zip; use to test your anti-virus program's ability to see a virus inside an archive.

RESULT:  Norton passed.

When I scanned the folder containing the archive, Norton correctly reported an infection with "EICAR Test String.68". Clicking the "Virus Info" button reports, "THIS IS NOT A VIRUS. The EICAR Test File is an internationally recognized, non-virus code string included for analysis purposes only. Again, THIS IS NOT A VIRUS."

4. Eicarcom2.zip -- contains the third file (EICAR_com.zip) inside a zip; use to test your anti-virus program's ability to see a virus inside a multi-level archive.

RESULT:  Norton passed.

When I scanned the folder containing the archived archive, Norton behaved correctly just as it did with file #3.

Drop me a line and let me know how your anti-virus program fares against these EICAR test files.

Norton Anti-Virus at Amazon.com:
http://www.TheNakedPC.com/t/324/tr.cgi?amazon1

You can reach Lee Hudspeth at:
mailto:leehudspeth@TheNakedPC.com

Why not subscribe to TNPC Newsletter Now?
You'll be glad you did.
Your Name: 
Your E-mail Address:
Copyright © 2000, PRIME Consulting Group, Inc. and Dan Butler.
All Rights Reserved.
The Naked PC is a trademark of PRIME Consulting Group, Inc.
ISSN: 1522-4422

You may reprint an article from TNPC as long as you show the
entire article and include the authors byline, excerpt and
subscription information as shown:

article_title
by author_name
(This article originally appeared in The Naked PC
newsletter; subscribe at http://www.TheNakedPC.com)

Return to Top


Advertise in TNPC Disclosure JOIN the Horde!
Letters to Editor Privacy policy Search TNPC
TNPC Library
TNPC Forum
Subscriber Services

Why not subscribe to TNPC Newsletter Now?
You'll be glad you did.
Your Name: 
Your E-mail Address:

TNPC Hot Tips:
  • Email out of control? Spam filling your inbox? People trying to steal your identity? Same here - until I applied these tips. You can too in a new multimedia e-book. Tame Your Email.

  • DO YOU MAKE THESE MONEY MISTAKES? Do you know that trying to pay off your high interest rate debts first and/or paying extra on more than one debt is the SLOWEST way to get out of debt? Don't make these same mistakes. Learn more at by clicking here...

Google

In The Current Issue

Read #3.24 here!

Testing Your AntiVirus
   Package with EICAR

Beginner's Guide to
   PC Upgrades

Registry Toolkit
   by Funduc Software

PayPal vs.
   The Freebie Seekers


Java Examples in a Nutshell
David Flanagan
As a teaching tool this book serves well and covers a very impressive range of Java topics; from Java Basics to Graphical User Interfaces to Servlets and much more.

Twinklebulbs lets you string virtual lights on or around your Windows desktop, select various bulb sets (from over 165 sets) and colors for the bulbs, add background holiday music, snowfall screen savers and more.

The British Library has put two Gutenberg bibles online. Flip through these Gutenberg Bibles printed around 1454 AD to 1455 AD. Amazing technology gives you a fantastic view of these pages.

Read TNPC Backissues