GPEN · Question #187
You have received a file named new.com in your email as an attachment. When you execute this file in your laptop, you get the following message: 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE!' When you open…
The correct answer is B. Do nothing. The EICAR Standard Anti-Virus Test File is a completely harmless, internationally recognized test string used solely to verify antivirus detection - it contains no malicious payload.
Question
You have received a file named new.com in your email as an attachment. When you execute this file in your laptop, you get the following message:
'EICAR-STANDARD-ANTIVIRUS-TEST-FILE!' When you open the file in Notepad, you get the following string:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* What step will you take as a countermeasure against this attack?
Options
- AImmediately shut down your laptop.
- BDo nothing.
- CTraverse to all of your drives, search new.com files, and delete them.
- DClean up your laptop with antivirus.
How the community answered
(23 responses)- A9% (2)
- B70% (16)
- C17% (4)
- D4% (1)
Why each option
The EICAR Standard Anti-Virus Test File is a completely harmless, internationally recognized test string used solely to verify antivirus detection - it contains no malicious payload.
Shutting down the laptop is an unnecessary and disruptive overreaction - the EICAR file contains no executable malicious code and cannot damage the system or spread.
The string X5O!P%@AP[4\PZX54(P^)7CC)7}}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* is the official EICAR test file defined by the European Institute for Computer Antivirus Research specifically to allow safe testing of antivirus software without using real malware. It causes no harm, makes no system changes, and requires no remediation because it is not malicious in any way.
Searching for and deleting all new.com files is unwarranted because the EICAR file is a benign, standardized test artifact and not actual malware that needs to be eradicated.
Running an antivirus cleanup is unnecessary because the EICAR file is intentionally detectable by antivirus programs as a test pattern - any detection is a sign the AV is working correctly, not that the system is infected.
Concept tested: EICAR standard antivirus test file recognition
Source: https://www.eicar.org/download-anti-malware-testfile/
Topics
Community Discussion
No community discussion yet for this question.