EICAR_Test virus

acme

Level 1
Thread author
Apr 29, 2012
77
Has anybody received a EICAR_Test virus ? Yes, our beloved EICAR has turned into a virus o_O
I got about 10 of these so far. Must be a clone.....



004.JPG





;)
 

Cch123

Level 7
Verified
May 6, 2014
335
Did you purposely download the Eicar test file? If not, then it could be a virus. I know of malware which purposely includes the Eicar test string inside its code to confuse virus scanners and users into thinking that it is harmless.
 

acme

Level 1
Thread author
Apr 29, 2012
77
Did you purposely download the Eicar test file? If not, then it could be a virus. I know of malware which purposely includes the Eicar test string inside its code to confuse virus scanners and users into thinking that it is harmless.

I haven't downloaded EICAR in years. It just pops up anytime :confused: I changed antivirus to see if it does it again, so far it hasn't popped up. Somebody could have piggy backed EICAR and drove it around to create havoc :D





:)
 

Behold Eck

Level 19
Verified
Top Poster
Well-known
Jun 22, 2014
906
Yup, I got the same about a week ago.It was picked up by Unthreat but it was of no concern due to it being in the temp files which were sandboxed anyway.

Not a good ploy for malware to pose as a test virus as most AV`s will pick up on it.Maybe EICAR somehow got out in the wild and now is whirling around as a driveby ?

Had to get rid of Unthreat as it kept reverting to an expired trial version.Shady tactics,to be expected.

Regards Eck:)
 

acme

Level 1
Thread author
Apr 29, 2012
77
Yup, I got the same about a week ago.It was picked up by Unthreat but it was of no concern due to it being in the temp files which were sandboxed anyway.

Not a good ploy for malware to pose as a test virus as most AV`s will pick up on it.Maybe EICAR somehow got out in the wild and now is whirling around as a driveby ?

Had to get rid of Unthreat as it kept reverting to an expired trial version.Shady tactics,to be expected.

Regards Eck:)



I think I found out what happened. I did some digging into how it gets sent out every hour and saw an 'Emsisoft Anti-Malware' address attached to the malware link o_O Below ↓ shows it's gone after I uninstalled Emsisoft . The RED highlighted is the malware caught, then it stops. Don't know how that happened :D


001.JPG
 

Behold Eck

Level 19
Verified
Top Poster
Well-known
Jun 22, 2014
906
Could be some sort self test otherwise it`s going to be a name change to Emsisoft Pro Malware ?:D

Who knows but interesting all the same.:cool:

Regards Eck:)
 

Maximum

Level 1
Verified
Dec 20, 2014
46
Could be some sort self test otherwise it`s going to be a name change to Emsisoft Pro Malware ?:D

Who knows but interesting all the same.:cool:

Regards Eck:)

Interesting indeed.

But EICAR is harmless, so there's nothing to worry about :)
 

Behold Eck

Level 19
Verified
Top Poster
Well-known
Jun 22, 2014
906
No worries at all as they were only temp files that were sandboxed anyway but it`s more where the hell did they come from and that it happened to someone else as well ?o_O

Regards Eck:)
 

Behold Eck

Level 19
Verified
Top Poster
Well-known
Jun 22, 2014
906
It`s back, just after installing Bitdefender free the same detection.o_O

No big deal though.:cool:

Regards Eck:)
 

Attachments

  • BDF detections.txt
    374 bytes · Views: 384

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top