Monday, February 16, 2009

How to Check your Antivirus Protection

Many a time we wonder if our antivirus is providing realtime protection to our computer.

To test your installation, copy the following line
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

open Notepad and paste this line.


Now try saving this file as EICAR.COM


The file size will be 68 or 70 bytes. As soon as you click save, your antivirus should catch this file as virus and deleve/quarantine it or atleast warn you about it. It it does, that means your antivirus is providing you with realtime protection.


If it does not. Then scan the directory in which you have saved this file.
Your antivirus if catches it, then it means your antivirus is working, though it may not be providing realtime protection in all conditions.
If your antivirus does not catch this file, then UNINSTALL that piece of garbage called antivirus,and get your money back from the vendor.

The antivirus industry, through the European Institute for Computer Antivirus Research, has adopted this standard to facilitate this need. Note that this file is NOT A VIRUS. Delete the file when you have finished testing your installation to avoid alarming unsuspecting users.

NOTES - The file is simply a text file of either 68 or 70 bytes that is a legitimate executable file called a COM file that can run by Microsoft operating systems and some work-alikes, including OS/2. When executed, will print "EICAR-STANDARD-ANTIVIRUS-TEST-FILE!" and stop. The test string was specifically engineered to consist of ASCII human-readable characters, easily created using a standard computer keyboard. It makes use of self-modifying code to work around technical issues that this constraint makes on the execution of the test string.

No comments: