Page 1 of 3 123 LastLast
Results 1 to 16 of 35

Thread: Test your AV

  1. #1
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber

    Test your AV

    This is a poll of sorts, not to find out what AV people are using, but how it performs with detection of a test virus.

    The idea behind this is to have the ability to verify your AV is working correctly without having a risk of infecting a machine.


    All you need to do is visit http://www.eicar.org/anti_virus_test_file.htm and at the bottom you will see a table of download links for a HARMLESS TEST VIRUS SIGNATURE.

    1. Select to save the .COM file first and make a reply to this post with what AV (and version) you are running and when & how it prompted you about the presence of the virus.

    2. Then repeat the test by saving the .ZIP file to verify archives are examined correctly too.


    Do not attempt to run the executable or manually open the ZIP file - the files have been written to disk (or even better, intercepted before being committed to disk) so should be checked automatically without user intervention.

    Please also comment if you have write caching enabled on your drive (check in Computer Management/Device Manager/Disk Drive - properties - Policies tab).
    I suspect that write caching may prevent some AV products of detecting infected files immediately, and has to check the data when it is committed to disk - leading to a delay in reporting and possibly erroneous reporting if the file has already been moved/deleted.

    This is a purely on-access test - we are not relying on a manual or scheduled system scan or an attempt to work with an infected local file.

    The ideal response is for the AV product to alert immediately and prevent the file being written to the disk, and for an event to be written to one of the system event logs.


    Here is my result:

    AV: AVG Free 7.0.344 w/virus base 267.10.24/101 (2005-09-13 20:45:00)

    .COM save results:
    Detected automatically YES/NO: YES
    At point: ~6 minutes after the file was saved to the disk
    Action: "Virus detected" message popped up, offering the actions; keep, info, heal, delete, move to vault

    .ZIP save results:
    Detected automatically YES/NO: NO (waited 7 minutes)
    Detected when file was opened: NO
    Detected when infected file was extracted to the disk: YES, after about ~20 seconds the copy in WinRAR's temporary folder was reported as infected - the copy which was already deleted
    Manually detected when scanned: YES

    Write caching is enabled on my hard disk.

    There was no entry written to the Windows event logs (Application, Security or System) to indicate a virus had been detected.


    I think I'll check out other AV solutions in light of this...
    Last edited by Paul Adams; 14-09-2005 at 01:20 PM.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  2. #2
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    AV: Computer Associates' eTrust 7.1.192 (InoculateIT engine 23.70.36)

    .COM save results:
    Detected automatically YES/NO: YES
    At point: ~5 seconds after the file was saved to the disk
    Action: Silently moved (configured action)

    .ZIP save results:
    Detected automatically YES/NO: NO
    Detected when file was opened: YES
    Action: Pop-up message informed the archive contained an infected file and had been removed.

    Write caching is enabled on my hard disk.

    There was no entry written to the Windows event logs (Application, Security or System) to indicate a virus had been detected.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  3. #3
    Spodes Henchman unrealrocks's Avatar
    Join Date
    Aug 2003
    Location
    Nottingham UK
    Posts
    2,390
    Thanks
    3
    Thanked
    2 times in 2 posts
    AV: Norton 7.5.6.14

    .COM save results:
    Detected automatically YES/NO: YES
    At point: Before it'd even let Opera give the option to save to disk ~2secs after clicking the link.
    Action: "Virus detected" message popped up, offering the actions; Delete

    .ZIP save results:
    Detected automatically YES/NO: NO (waited 7 minutes)
    Detected when file was opened: NO
    Detected when infected file was extracted to the disk: YES, after ~2secs.
    Manually detected when scanned: N/A (didn't have a chance to manually scan before it caught it automatically.

    G4 PowerMac - Tiger 10.4 - 512MB RAM
    MacBook - 2Ghz - 1GB RAM - 120GB HDD

    Rotel RC970BX | DBX DriveRack |2x Rotel RB850
    B&W DM640i | Velodyne 1512

  4. #4
    Member
    Join Date
    Aug 2005
    Posts
    108
    Thanks
    0
    Thanked
    0 times in 0 posts
    • OmarSantiago's system
      • Motherboard:
      • Striker Extreme
      • CPU:
      • Core 2 Duo 6750
      • Memory:
      • 4GB Black Dragon DDR
      • Storage:
      • Raptors
      • Graphics card(s):
      • 8800GTX
      • PSU:
      • PC P&C 750 Quad Silencer
      • Case:
      • Silverstone TJ09
    Running Windows XP Pro SP2 fully patched and updated

    AV: Sophos AV 3.97.0 (Build 0235)
    Total Viruses 109858


    .COM save results:
    Detected automatically YES/NO:YES
    At point: As soon as I selected the item for download
    Action: Warning message:Virus:'EICAR-AV-Test' detected in C:\Documents and Settings\Santiago\Local Settings\Temporary Internet Files\Content.IE5\TQFX1EC2\eicar[1].com

    Access to the infected file is denied

    Email sent with this message and a copy made to Sophos' daily log. Sophos will automatically shred it on the next daily sweep


    .ZIP save results:
    Detected automatically YES/NO: NO
    Detected when file was opened: NO
    Detected when infected file was extracted to the disk: XP sees the file without 3rd party utilities and it didn't flag until I tried to execute the program when it followed the above routine.
    Manually detected when scanned:YES

    Write caching is enabled on my hard disk.

    Windows Application log flagged each detection with the following message:

    XP Virus: 'EICAR-AV-Test' detected in C:\DOCUME~1\Santiago\LOCALS~1\Temp\Temporary Directory 1 for eicar_com.zip\eicar.com
    Access to the infected file is denied


    /Edit: Ran this test on a cloned machine that has write-caching disabled by default: Sophos performed exactly the same.
    Last edited by OmarSantiago; 14-09-2005 at 11:13 AM.

  5. #5
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    McAfee Virusscan Enterprise 8
    Scan Engine : 4400
    Virus Definitions : 4579

    .COM save results:
    Detected automatically YES/NO: YES
    At point: As soon as file was selected for download
    Action: "Virus detected" message popped up , file Moved as Virusscan decided it wasn't cleanable.

    .ZIP save results:
    Detected automatically YES/NO: NO
    Detected when file was opened: NO
    Detected when infected file was extracted to the disk: YES, IMMEDIATLY

    Manually detected when scanned: YES

    Entries were added to the local event log and also elerts generated into E- Policy orchestrator.

    EDIT #2: Gave my AV Admin a kick and told him to enable scannign within Archives. one EPO update later and VS8 picked Eicar up as soon as I attempted to download the zip.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  6. #6
    OC Junkie!
    Join Date
    Jul 2005
    Location
    Scarborough
    Posts
    302
    Thanks
    3
    Thanked
    6 times in 6 posts
    • Wiczy's system
      • Motherboard:
      • ASUS M6H 1203
      • CPU:
      • 4770k @ 4.5
      • Memory:
      • 16GB Corsair Vengeance Pro 2400
      • Storage:
      • Samsung Evo Pro 128 + MX100 256 + C300 64 + Assorted Mechanical Drives
      • Graphics card(s):
      • Gigabyte R9 290X OC WF
      • PSU:
      • XFX 650W XXX Pro
      • Case:
      • old noname
      • Operating System:
      • Win 10 x64 Pro
      • Monitor(s):
      • AOC Q2770 PQU + LG WG2353V
      • Internet:
      • Plusnet Unlimited Fibre 80/20
    NOD32 antivirus system information
    Virus signature database version: 1.1216 (20050913)
    Dated: 13 September 2005
    Virus signature database build: 6101

    Information on other scanner support parts
    Advanced heuristics module version: 1.018 (20050805)
    Advanced heuristics module build: 1088
    Internet filter version: 1.002 (20040708)
    Internet filter build: 1013
    Archive support module version: 1.034 (20050902)
    Archive support module build version: 1132

    Information about installed components
    NOD32 For Windows NT/2000/XP/2003 - Base
    Version: 2.50.25
    NOD32 For Windows NT/2000/XP/2003 - Internet support
    Version: 2.50.25
    NOD32 for Windows NT/2000/XP/2003 - Standard component
    Version: 2.50.25

    .COM results

    Detected immediately on clicking to download - msg " The file contains a threat to your computer "

    .ZIP results

    Detected immediately on clicking to download - msg " The file contains a threat to your computer "

    Write caching is enabled.

    In both cases the files were not written to disk.

  7. #7
    Registered+
    Join Date
    Aug 2005
    Location
    Nottinghamshire
    Posts
    40
    Thanks
    0
    Thanked
    0 times in 0 posts
    AVG Free Version 7.0.344

    .COM save results:
    Detected automatically YES/NO: YES
    At point: As soon as file was selected for download
    Action: "Virus detected" message popped up

    .ZIP save results:
    Detected automatically YES/NO: NO
    Detected when file was opened: NO
    Detected when infected file was extracted to the disk: YES, With choice to Delete or Heal
    File Deleted


    Manually detected when scanned: YES,Virus found EICAR_Test

  8. #8
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    Quote Originally Posted by Wiczy
    NOD32 antivirus system information
    Virus signature database version: 1.1216 (20050913)
    Dated: 13 September 2005
    Virus signature database build: 6101

    Information on other scanner support parts
    Advanced heuristics module version: 1.018 (20050805)
    Advanced heuristics module build: 1088
    Internet filter version: 1.002 (20040708)
    Internet filter build: 1013
    Archive support module version: 1.034 (20050902)
    Archive support module build version: 1132

    Information about installed components
    NOD32 For Windows NT/2000/XP/2003 - Base
    Version: 2.50.25
    NOD32 For Windows NT/2000/XP/2003 - Internet support
    Version: 2.50.25
    NOD32 for Windows NT/2000/XP/2003 - Standard component
    Version: 2.50.25

    .COM results

    Detected immediately on clicking to download - msg " The file contains a threat to your computer "

    .ZIP results

    Detected immediately on clicking to download - msg " The file contains a threat to your computer "

    Write caching is enabled.

    In both cases the files were not written to disk.
    good score for NOD there

    is it a free/ low cost AV product ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  9. #9
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    NOD32 2.5 Trial Version:

    .COM save results:
    Detected automatically YES/NO: YES
    At point: Immediately on clicking the link, before the save/open dialog appeared in both IE and Firefox
    Action in Firefox: "Virus detected" message popped up for temporary copy of the file, no options - dialog box from Firefox still appeared
    Action in IE: "Virus detected" message popped up for temporary copy of the file with the options; Copy to Quarantine, Terminate

    .ZIP save results:
    Detected automatically YES/NO: YES (IE) and NO (Firefox)
    At point: Immediately on clicking the link, before the save/open dialog appeared in IE
    Action in Firefox: None, file saved to disk as normal
    Action in IE: "Virus detected" message popped up for temporary copy of the file with the options; Copy to Quarantine, Terminate

    (Also tested "eicarcom2.zip" in Firefox and IE with the same results - this is a test virus file inside a zip file which is inside another zip file, to test recursive virus scanning.)

    There was no entry written to the Windows event logs (Application, Security or System) to indicate a virus had been detected.

    Edit:
    However, NOD32 does maintain its own logs of threats detected, #files scanned, etc. visible through its own interface.
    Last edited by Paul Adams; 14-09-2005 at 03:39 PM.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  10. #10
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    you almost sound impressed there Paul
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  11. #11
    OC Junkie!
    Join Date
    Jul 2005
    Location
    Scarborough
    Posts
    302
    Thanks
    3
    Thanked
    6 times in 6 posts
    • Wiczy's system
      • Motherboard:
      • ASUS M6H 1203
      • CPU:
      • 4770k @ 4.5
      • Memory:
      • 16GB Corsair Vengeance Pro 2400
      • Storage:
      • Samsung Evo Pro 128 + MX100 256 + C300 64 + Assorted Mechanical Drives
      • Graphics card(s):
      • Gigabyte R9 290X OC WF
      • PSU:
      • XFX 650W XXX Pro
      • Case:
      • old noname
      • Operating System:
      • Win 10 x64 Pro
      • Monitor(s):
      • AOC Q2770 PQU + LG WG2353V
      • Internet:
      • Plusnet Unlimited Fibre 80/20
    Low cost and absolutely superb imho. You don't know its there until you click the wrong link ;p

  12. #12
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    Quote Originally Posted by Moby-Dick
    you almost sound impressed there Paul
    Hehe, yeah - a little concerned as to why NOD32 picks up the virus through one browser but not another though... and it's a shame neither AVG or NOD32 log anything in the Windows event logs.
    Now if I could just figure out a way get a command-line update to work then I've got a new silent AV install for my unattended system build DVD
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  13. #13
    OC Junkie!
    Join Date
    Jul 2005
    Location
    Scarborough
    Posts
    302
    Thanks
    3
    Thanked
    6 times in 6 posts
    • Wiczy's system
      • Motherboard:
      • ASUS M6H 1203
      • CPU:
      • 4770k @ 4.5
      • Memory:
      • 16GB Corsair Vengeance Pro 2400
      • Storage:
      • Samsung Evo Pro 128 + MX100 256 + C300 64 + Assorted Mechanical Drives
      • Graphics card(s):
      • Gigabyte R9 290X OC WF
      • PSU:
      • XFX 650W XXX Pro
      • Case:
      • old noname
      • Operating System:
      • Win 10 x64 Pro
      • Monitor(s):
      • AOC Q2770 PQU + LG WG2353V
      • Internet:
      • Plusnet Unlimited Fibre 80/20
    The 'zip in a zip' was detected in firefox with my version of NOD32

  14. #14
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    Quote Originally Posted by Paul Adams
    Hehe, yeah - a little concerned as to why NOD32 picks up the virus through one browser but not another though... and it's a shame neither AVG or NOD32 log anything in the Windows event logs.
    Now if I could just figure out a way get a command-line update to work then I've got a new silent AV install for my unattended system build DVD

    I'm sure the full version of AVG will either write an event or send an email.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  15. #15
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    Quote Originally Posted by Wiczy
    The 'zip in a zip' was detected in firefox with my version of NOD32
    Not sure why it behaves differently on my machine... at first I thought the default action might be to blame (I had it set to always save ZIPs to disk), but restoring it to prompt for an action (and picking either open or save) doesn't make NOD32 pick up the virus in Firefox...
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  16. #16
    OC Junkie!
    Join Date
    Jul 2005
    Location
    Scarborough
    Posts
    302
    Thanks
    3
    Thanked
    6 times in 6 posts
    • Wiczy's system
      • Motherboard:
      • ASUS M6H 1203
      • CPU:
      • 4770k @ 4.5
      • Memory:
      • 16GB Corsair Vengeance Pro 2400
      • Storage:
      • Samsung Evo Pro 128 + MX100 256 + C300 64 + Assorted Mechanical Drives
      • Graphics card(s):
      • Gigabyte R9 290X OC WF
      • PSU:
      • XFX 650W XXX Pro
      • Case:
      • old noname
      • Operating System:
      • Win 10 x64 Pro
      • Monitor(s):
      • AOC Q2770 PQU + LG WG2353V
      • Internet:
      • Plusnet Unlimited Fibre 80/20
    I have no idea...as you can see from the .JPG it was detected just fine over here.

    Odd.

Page 1 of 3 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Pakistan carries out new missile test
    By Bunjiweb in forum General Discussion
    Replies: 21
    Last Post: 20-08-2006, 09:38 AM
  2. Morality Test.
    By Moby-Dick in forum General Discussion
    Replies: 7
    Last Post: 12-09-2005, 11:31 PM
  3. Replies: 1
    Last Post: 12-06-2005, 09:16 PM
  4. Best way to test RAM stabilities?
    By chriswood_7 in forum PC Hardware and Components
    Replies: 9
    Last Post: 12-02-2005, 05:26 PM
  5. Please test your RAID 0 with this....
    By Wam7 in forum PC Hardware and Components
    Replies: 10
    Last Post: 08-04-2004, 09:54 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •