Hello @popescu
As far as I know they are not detected because WSA knows there harmless but I will ping our Threat Experts @DanP and @TylerM
You should go here: https://www.eicar.org/
Well I got two detection when unzipping them!
HTH,
Hello @popescu
As far as I know they are not detected because WSA knows there harmless but I will ping our Threat Experts @DanP and @TylerM
You should go here: https://www.eicar.org/
Well I got two detection when unzipping them!
HTH,
As you can see , when unzip they are detected , so the theory about “they are not detected because WSA knows there harmless” does not hold water.
They should be detected upon download, before being stored on the PC, not after they are stored and purposely scanned.
“You should go here: https://www.eicar.org/”
This is not a detection, this is a “reaction” implemented in each and every antivirus.
As you can see, downloading Eicar from a different location doe not trigger any reaction on Webroot.
.
Look at the same subjects over the years: https://community.webroot.com/search?q=Eicar
Blog: https://www.webroot.com/blog/2018/09/05/eicar-common-false-positive-world/
Wed 2022-02-16 08:53:47.0664 Blocked website: https://meineipadresse.de/testvirus/eicar.zip (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 08:54:59.0931 Blocked website: https://secure.eicar.org/eicar_com.zip (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 08:55:25.0464 Blocked website: https://secure.eicar.org/eicar.com (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 08:59:22.0316 Blocked website: https://meineipadresse.de/testvirus/eicar.com (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 09:00:01.0858 Blocked website: https://secure.eicar.org/eicar.com.txt (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 09:00:45.0368 Infection detected: E:\Users\Daniel\Downloads\eicar.com\eicar.com \SHA256: 275A021BBFB6489E54D471899F7DB9D1663FC695EC2FE2A2C4538AABF651FD0F] 2MD5: 44D88612FEA8A8F36DE82E1278ABB02F] 83/00080200] AW32.Eicar.Testvirus.Gen]
Wed 2022-02-16 09:00:45.0369 Infection found in realtime: E:\Users\Daniel\Downloads\eicar.com\eicar.com aUniqueID: 1B025A27, MD5: 44D88612FEA8A8F36DE82E1278ABB02F, Size: 68 bytes] A524800/00000003] yW32.Eicar.Testvirus.Gen]
Wed 2022-02-16 09:01:47.0801 Blocked website: https://meineipadresse.de/testvirus/eicar.zip (Rep: 10/Cat: 56/Det: BC)
Wed 2022-02-16 09:03:08.0106 Infection detected: E:\Users\Daniel\Downloads\eicar2\eicar\eicar.com nSHA256: 275A021BBFB6489E54D471899F7DB9D1663FC695EC2FE2A2C4538AABF651FD0F] CMD5: 44D88612FEA8A8F36DE82E1278ABB02F] 83/00080200] DW32.Eicar.Testvirus.Gen]
Wed 2022-02-16 09:03:08.0106 Infection found in realtime: E:\Users\Daniel\Downloads\eicar2\eicar\eicar.com DUniqueID: 1B025A27, MD5: 44D88612FEA8A8F36DE82E1278ABB02F, Size: 68 bytes] D524800/00000003] iW32.Eicar.Testvirus.Gen]