How to test your anti-virus tool

So you have an anti-virus tool. Does it work? Here's a basic test.

So you have an anti-virus tool. How can you test that it works?

This is a good ques­tion and it is wise to famil­iar­ize your­self with how your anti-virus soft­ware behaves when it detects a virus, before it really hap­pens. One quick way to do this is to use the "EICAR" Anti-Virus Test File. This is a test file that will cause no dam­age to your sys­tem and still allow you to test if anti-virus tool is awake.

Here are some steps:

  1. Open a text edi­tor (e.g. Notepad)
  2. Enter the fol­low­ing text in it:
    X5O!P%@AP[4PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
  3. Save the file as "EICAR.COM" on your desktop.
  4. Open DOS and try to exe­cute this .COM file (or sim­ply double-click the file on Desktop)

If your anti-virus soft­ware is work­ing prop­erly, it will warn you that a virus has been detected when you attempt to run the .COM file.

To be double-sure, zip this file, and then try double-clicking on the ZIP file to see if your AV tool rec­og­nized viruses inside ZIP files. You can also send this file to your­self as an attach­ment, just to ver­ify if your AV tool has com­mand of email cleanliness.

20 comments
  1. Emmanuel says: Jan 15, 20048:41 pm

    This is neat stuff, didn't know there was a file for this pur­pose! Can you now tell me how I can test my credit card val­i­da­tion script with­out try­ing out my own num­ber? :P

  2. Cheryl:) says: May 22, 20041:01 pm

    How cool! It worked!! (Panda antivirus came through!) Thanks for the info! Cheryl:)

  3. don says: May 30, 20042:45 pm

    worked like acharm.…this site is amazing

  4. Don Mynack says: Jul 01, 20041:01 pm

    Uh, I tried it and noth­ing hap­pened. I use Nor­ton AV. What do I do now?

  5. sniptools says: Jul 11, 200412:18 pm

    Don, I guess it's time to ditch Nor­ton AV and get a free but still quite decent tool like AVG. Microsoft now rec­og­nizes AVG in it's recent SP2 update to Win­dows, so it's a very respectable one. http://www.grisoft.com

    HTH! Shanx

  6. Shahid Ali says: Jul 25, 20046:20 pm

    Hi!

    I tried what U said. It's amaz­ing. I couldn't beleive,Norton could do this. Nor­ton detected the 'infected file' and deleted it. And it could also scan thru the zipped file. Also, I tried send­ing the infected file to myself as an e-mail attach­ment. To my sur­prise, the file couldn't be attached in Yahoo. It said that the file was infected and it couldn't be attached.

  7. Mary says: Aug 01, 20045:34 am

    I couldn't even try zip­ping it ("virus found!"), nev­er­mind see­ing if a zip would be scanned!

    My virus scan­ner is AVG 6 (free) so if you don't have a virus scan­ner, or a good one, try it out. :)
    http://free.grisoft.com/freeweb.php/doc/2/

  8. Ariel says: Jan 10, 20056:12 am

    I was unable to zip or attach with­out my virus soft­ware throw­ing up a warn­ing. Am using Avast 4.5 Home Edi­tion, incom­pa­ra­ble free­ware with steel door secu­rity, broad cov­er­age, fre­quent updates, and easy inter­face. Go to http://www.avast.com

  9. Rav says: Feb 22, 20054:03 am

    Ok, but how do I know my scan­ner will detect the most recent threats? Sure it picks up a know pat­tern but will it pick up the lat­est attack strat­egy though up by some­one? Does any­one know where I can get a buch of infected files with the most recent viruses (real and active or just the sig­na­tures). Google doesn't seem to be help­ing me today :(

  10. sniptools says: Feb 22, 20054:05 pm

    Rav, for that you should prob­a­bly use some good anti-virus tool (check out http://www.grisoft.com for instance) and leave the auto-update on. Then the tool will check peri­od­i­cally for updates to virus def­i­n­i­tions and down­load them auto­mat­i­cally. Almost all decent anti-virus com­pa­nies offer this fea­ture these days.

  11. Rav says: Feb 24, 20051:02 pm

    I do have AVG installed, Trend Micro before that. How do I know AVG will work when the time comes? Or any other one for that mat­ter. Just becuase it detects some stan­dard file cre­ated a few years ago does NOT mean it will pro­tect me from some­thing more recent. Are their any other stan­dard tests that were devel­oped say with in the last 6 months? I am not ask­ing for a guar­an­tee. When a new virus threat comes out it would be nice if a good samar­i­tan would put out a pseudo infected file so we can see if the lates virus gets cuaght and iden­ti­fied by our scan­ners. Just a thought, some­thing for the com­mu­nity to think about.

  12. BHARTHI says: Apr 21, 20054:21 pm

    how to delete and stop that " osa.exe" file in startup ? cd rom drive eject­ing prob­lem. this prob­lem is not a hard­ware prob­lem. i thing this is virus prob­lem. now i need the help what type of virus is hear that system?

  13. sniptools says: Apr 22, 20059:01 am

    Bharathi, that's the Microsoft Office startup util­ity. If you don't mind some unex­pected results with your MS Office func­tion­al­ity, there are a cou­ple of ways of get­ting rid of it:

    (1) You can down­load a util­ity called "Hijack This"  — don't let the name scare you, it is a very reli­able and yet FREE tool. Run it and it'll show you all the software/utilities that are loaded when your sys­tem starts up. Dis­able OSA.EXE or any oth­ers you don't need.

    (2) Or, just down­load Spy Sweeper, it also allows you to add and remove startup options. It's not free but it's a fan­tas­tic anti-worm tool in general.

  14. Jon says: Jun 12, 20051:50 pm

    Thats the coolest and eas­i­est test I have ever done. AVG in my opin­ion and sev­eral oth­ers believe it is the best. Thanks for the test and I hope that who ever made that can put more tests to see if AVG proves that it is bet­ter than Norton

  15. Brian D'silva says: Jun 14, 200510:59 pm

    My Virus tools is not detect­ing this EICAR.COM file .Plz sug­gect me .

  16. Iain Shortreed says: Oct 10, 200510:44 am

    The sec­ond i saved to my desk­top i got a popup saying:

    Real-time Scan
    Trend Micro PC-cillin Inter­net Secu­rity has detected a virus, spy­ware appli­ca­tion, or other Inter­net threat, and per­formed the action specified.

    Infected file: C:\Documents and Settings\Administrator\Desktop\EICAR.COM
    Virus name: Eicar_test_file
    User name: Admin­is­tra­tor
    Scan action result: Unable to clean infected file. The file was quarantined.


    Yay :D

  17. liam says: Dec 11, 20055:16 am

    it really worked well the moment i tryed to exe­cute it avg popped up say­ing virus detected. that is really cool thanks.

  18. Bob says: Apr 04, 200712:34 pm

    This really made me feel safer with my virus soft­ware (Avira AntiVir http://www.free-av.com/ ). It actu­ally detected right when I saved it (not even let­ting the pro­gram run; just knew that it was bad). It's free, but it bugs you to upgrade to pre­mium. I'd rec­om­mend it. Still blown away by how quick it was though…

  19. vinod says: Nov 29, 20073:24 pm

    it's awe­some.….……
    it's work­ing
    but i'm using NOD32 av .….……
    Is it good av?

  20. vinod says: Nov 29, 20073:25 pm

    it's awe­some. It's work­ing
    but i'm using NOD32 av .Is it good av?

Submit comment