System information
Validating application settings 65
You can download the test "virus" from the EICAR organization’s official website
at: http://www.eicar.org/anti_virus_test_file.htm.
Note
Before you download the file, you must disable the computer’s anti-virus
protection, because otherwise the application would identify and process the file
anti_virus_test_file.htm as an infected object transferred via the HTTP protocol.
Do not forget to enable the anti-virus protection immediately after you download
the test "virus".
The application identifies the files downloaded from the EICAR site as an
infected object containing a virus that cannot be disinfected and performs the
actions specified for such an object.
You can also modify the standard test “virus” to verify the application’s operation
against other types of files. To modify the “virus”, change the content of the
standard “virus” by adding one of the prefixes to it (see table below). To create
the modified “virus” files, you can use any text or hypertext editor, for example
Microsoft Notepad, UltraEdit32, etc.
Warning!
You can test the correctness of the application’s operation using the modified
EICAR "virus" only if your anti-virus bases were last updated on or after October
24, 2003 (October, 2003 cumulative updates).
In the table below, the first column contains the prefixes that must be added at
the start of the standard “virus” text. The second column lists the possible status
values that the application can assign to the object, based on the results of the
scan. The third column indicates how the application processes objects with the
specified status. Please note that the actual actions performed on the objects are
determined by the application's settings.
After you have added the prefix to the test "virus", save the new file under a
different name, for example: eicar_dele.com. Assign similar names to all the
modified "viruses".










