Testing for alternate data stream scanning

Testing for alternate data stream scanning

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Testing for alternate data stream scanning Julian 11-25-2005
Posted by Julian on November 25, 2005, 5:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Would the following command file (mk_eicar_ads.cmd):

echo
X5O!P%%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* >
test.txt:eicar.com

(all one line!)

be a valid test to see if an anti-virus detects writing to an alternate
data stream? How many anti-virus products would alert on this?
--
Julian

Posted by David H. Lipman on November 25, 2005, 9:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Would the following command file (mk_eicar_ads.cmd):
|
| echo
| X5O!P%%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* >
| test.txt:eicar.com
|
| (all one line!)
|
| be a valid test to see if an anti-virus detects writing to an alternate
| data stream? How many anti-virus products would alert on this?

All AV software *should* work with the EICAR.

http://www.eicar.org/anti_virus_test_file.htm


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Julian on November 25, 2005, 10:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman wrote:
>
> | Would the following command file (mk_eicar_ads.cmd):
> |
> | echo
> | X5O!P%%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* >
> | test.txt:eicar.com
> |
> | (all one line!)
> |
> | be a valid test to see if an anti-virus detects writing to an alternate
> | data stream? How many anti-virus products would alert on this?
>
> All AV software *should* work with the EICAR.
>
> http://www.eicar.org/anti_virus_test_file.htm
>
>

Yes, but will they detect it in an alternate data stream? Or are
alternative data streams not considered a valid location for the Eicar file?

--
Julian

Posted by Adam Piggott on November 25, 2005, 10:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Julian wrote:
> Would the following command file (mk_eicar_ads.cmd):
>
> echo
> X5O!P%%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* >
> test.txt:eicar.com
>
> (all one line!)
>
> be a valid test to see if an anti-virus detects writing to an alternate
> data stream? How many anti-virus products would alert on this?

Close! The string you need is:

X5O!P%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

I see you'ved added an extra caret at (P^) but the extra percent !P%% is
unnecessary.

To test this, once written, you need to type:

more < test.txt:eicar.com > eicar.com

NAV 2002 notices this when using more, but not when writing the string.
- --
Adam Piggott, Proprietor, Proactive Services (Computing).
http://www.proactiveservices.co.uk/

Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (MingW32)

iD8DBQFDhyrw7uRVdtPsXDkRAgKMAJ9zjrXotYgQQdqOBlQhRXHYQPiUtwCglcjs
pTGvIYD6t5dRWYkHfJuWQcc=
=81S1
-----END PGP SIGNATURE-----

Posted by Julian on November 25, 2005, 10:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Adam Piggott wrote:
>
> Close! The string you need is:
>
> X5O!P%@AP[4\PZX54(P^^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
>
> I see you'ved added an extra caret at (P^) but the extra percent !P%% is
> unnecessary.

I don't think it is unnecessary, because I tested it first by echoing to
a regular eicar.com and then checking the result in notepad, and with
only one percent, there was no percent in the output file. I needed two,
to get the one that is supposed to be there.
>
> To test this, once written, you need to type:
>
> more < test.txt:eicar.com > eicar.com
>
> NAV 2002 notices this when using more, but not when writing the string.

That's presumably because at that point it's saving it to a regular .com
file. I was interested in whether any anti-virus would detect the Eicar
file when it is being written to an ADS, or while it is hidden there,
during an on-demand scan.

--
Julian

Similar ThreadsPosted
TESTING October 15, 2008, 4:43 pm
av comparatives testing February 16, 2006, 9:46 pm
Testing your antivirus June 17, 2006, 12:26 pm
All Data Gone October 20, 2006, 9:14 pm
Data Disappearance September 20, 2005, 1:08 pm
Japanese anti-malware testing site November 20, 2006, 7:42 pm
AV testing practices questioned, 14 August 2007 August 16, 2007, 6:32 pm
AVG - Placement of Data Folder February 12, 2006, 12:32 pm
AVG Internal Virus Data Base June 1, 2005, 6:13 pm
Trend Micro IMSA 5000 Version 7.0 Usability Testing December 12, 2006, 1:48 pm

The site map in XML format XML site map

Contact Us | Privacy Policy