Jump to content

Does Eset Detect Eicar Test String?


Go to solution Solved by Marcos,

Recommended Posts

Namely:

Eicar_String.png.d9fdc1ba5ee0c065182102ac8b907e45.png

I added it to a .bat file. Then saved the file and not a peep from Eset real-time protection?

I then ran the .bat file and not a peep from Eset real-time protection?

Edited by itman
Link to comment
Share on other sites

Hello.

Worked as expected here.

Created a file eicar.bat on my desktop, edited the file and just pasted in the EICAR string (shown in your message). As soon as I saved the file, ESET real-time popped up with the expected alert.

Link to comment
Share on other sites

1 hour ago, itman said:

Namely:

Eicar_String.png.d9fdc1ba5ee0c065182102ac8b907e45.png

I added it to a .bat file. Then saved the file and not a peep from Eset real-time protection?

I then ran the .bat file and not a peep from Eset real-time protection?

I'm sure this kind of test is useless. all known antivirus detect this type of threat.
Better saying it is not a threat.

Link to comment
Share on other sites

28 minutes ago, mallard65 said:

Created a file eicar.bat on my desktop, edited the file and just pasted in the EICAR string (shown in your message). As soon as I saved the file, ESET real-time popped up with the expected alert.

Correct.

However if the Eicar test string is placed after some existing code as shown in the below screen shot, Eset doesn't detect it:

Eicar_bat.thumb.png.0e0551acdc8a4b723d3ac4a0f6b07c69.png

 

Edited by itman
Link to comment
Share on other sites

  • Administrators
  • Solution
3 minutes ago, itman said:

Correct.

However if the Eicar test string is placed after some existing code as shown in the below screen shot, Eset doesn't detect it:

Eicar_bat.thumb.png.a417cf94801ad1fc54f11cc1b55e3aca.png

That's correct. Eicar is detected only if it meets its definition:

https://www.eicar.org/?page_id=3950

Any anti-virus product that supports the EICAR test file should detect it in any file providing that the file starts with the following 68 characters, and is exactly 68 bytes long.

The above file is longer and contains additional characters, breaking the definition of eicar.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...