Testing BitDefender

Using

08

BitDefender

 

Chapter 8. Testing BitDefender

You can verify that BitDefender Antivirus component works properly with the help of a special test file, known as EICAR Standard Anti-virus Test file. EICAR stands for the European Institute of Computer Anti-virus Research. This is a dummy file, detected by antivirus products.

There is no reason to worry, because this file is not a real virus. All that EICAR.COM does when executed is to display the text EICAR-STANDARD-ANTIVIRUS-TEST-FILE and exit.

The reason we do not include the file within the package is that we want to avoid generating any false alarms for those who use BitDefender or any other virus scanner. However, the file can be created using any text editor, provided the file is saved in standard MS-DOS ASCII format and is 68 bytes long. It might also be 70 bytes if the editor puts a CR/LF at the end. The file must contain the following single line:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Copy this line and save the file with any name and .COM extension, for example EICAR.COM. You can keep the EICAR.COM in a safe place and test periodically the system protection.

EICAR online resources

You can visit the EICAR website at http://eicar.com/, read the documentation and download the file from one of the locations on the web page http://eicar.com/anti_virus_test_file.htm.

8.1. Scan an executable file

Open a new terminal and enter the directory EICAR.COM file resides. Type the following command.

# bdscan EICAR.COM

47

Page 47
Image 47
Unisar 1.24.1867 manual Testing BitDefender, Scan an executable file, Eicar online resources