Malware

Eicar test file removal tips

Malware Removal

The Eicar test file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Eicar test file virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Eicar test file?


File Info:

name: 93046005111C2D8C1266.mlw
path: /opt/CAPEv2/storage/binaries/a96eb6fce8874f1bc744095e6b6085efbb4fe2f8cde4a715cb2685fb76908281
crc32: 2F059C41
md5: 93046005111c2d8c1266361c1ffa0131
sha1: e561dae28a684b8c7fcd0a9b3fc1fa20a4607873
sha256: a96eb6fce8874f1bc744095e6b6085efbb4fe2f8cde4a715cb2685fb76908281
sha512: 790bb72c9ad0781e6b8f6d06997e71b015fef0b34488ae0f74fdaddbfda1c2a7d3d1d2b9db118bc34e1a2ae8f03a08706017f22f47c04b8df9855c400e18a6fa
ssdeep: 1536:gJ+DjK/7scfOLDFel9fvH2oGHOBiNgzAqwn1P2Fq6XFjy1aNJIsWSqgcdv0AGtCk:LHi7scf4AfH2oGHOBiNgzAqG1scvPGS6
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16D935C41B5C1D471E5B62D324870DAB14E3EFD315E35AE6B3358027A0F352C29A26EAF
sha3_384: c59a7d0cef050161388d66f906e085824c86e5f35b15afbd31cc7987758a7fb45c718a6ac41ec3c445e03d4c691b8cc8
ep_bytes: e8c5030000e974feffff558bec6a00ff
timestamp: 2021-12-03 20:49:19

Version Info:

0: [No Data]

Eicar test file also known as:

MicroWorld-eScanDropped:EICAR-Test-File
FireEyeDropped:EICAR-Test-File (not a virus)
BitDefenderDropped:EICAR-Test-File (not a virus)
BitDefenderThetaDropped:EICAR-Test-File (not a virus)
ESET-NOD32Eicar test file
APEXMalicious
KasperskyTrojan.Win32.Shelma.ind
RisingTrojan.Generic@ML.93 (RDML:JVtCTtsBHJvhcjogtnDxRw)
Ad-AwareDropped:EICAR-Test-File (not a virus)
EmsisoftDropped:EICAR-Test-File (not a virus) (B)
AviraTR/Shelma.wcbhh
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDropped:EICAR-Test-File (not a virus)
VBA32EICAR-Test-File
ALYacDropped:EICAR-Test-File (not a virus)
MalwarebytesMalware.AI.2572438105
AVGWin32:ShellCode-DD [Trj]
Cybereasonmalicious.5111c2
AvastWin32:ShellCode-DD [Trj]

How to remove Eicar test file?

Eicar test file removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment