<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: EICARgen</title>
	<atom:link href="http://blog.didierstevens.com/programs/eicargen/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-45710</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 31 Aug 2011 19:21:29 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-45710</guid>
		<description><![CDATA[@Anonymous Fixed it!]]></description>
		<content:encoded><![CDATA[<p>@Anonymous Fixed it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-45545</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Fri, 26 Aug 2011 09:32:27 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-45545</guid>
		<description><![CDATA[Is it correct that the archive does not contain an executable anymore?]]></description>
		<content:encoded><![CDATA[<p>Is it correct that the archive does not contain an executable anymore?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve54</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-42771</link>
		<dc:creator><![CDATA[steve54]]></dc:creator>
		<pubDate>Fri, 13 May 2011 00:58:47 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-42771</guid>
		<description><![CDATA[This isn&#039;t quite as elegant as yours, but it isn&#039;t (yet. at least) detected as a virus. It&#039;s AutoHotKey, so it can be compiled to an exe that&#039;ll run on any Windows version. 

Just one line:

&lt;code&gt;FileAppend, X5O!P`%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-
ANTIVIRUS-TEST-FILE!$H+H*, eicar.com&lt;/code&gt;

Isn&#039;t AHK nice? :)]]></description>
		<content:encoded><![CDATA[<p>This isn&#8217;t quite as elegant as yours, but it isn&#8217;t (yet. at least) detected as a virus. It&#8217;s AutoHotKey, so it can be compiled to an exe that&#8217;ll run on any Windows version. </p>
<p>Just one line:</p>
<p><code>FileAppend, X5O!P`%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-<br />
ANTIVIRUS-TEST-FILE!$H+H*, eicar.com</code></p>
<p>Isn&#8217;t AHK nice? <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Romeo29</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-40441</link>
		<dc:creator><![CDATA[Romeo29]]></dc:creator>
		<pubDate>Wed, 03 Nov 2010 14:27:31 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-40441</guid>
		<description><![CDATA[I created a similar program in C, but AVG always caught it. First I thought that AVG is detecting the EICAR code string inside the EXE. So I used simple ROT13 and later XOR encryption to hide the string. But AVG always detects it! Actually AVG checks behavior of the program and finds out that it is dropping EICAR test virus and flags it as Eicar.dropper. No use!

Maybe if you can make some regular Windows program put the code in the target EICAR virus file in steps, then you can survive. BTW, EICARGen is caught both by AVG and avast!.]]></description>
		<content:encoded><![CDATA[<p>I created a similar program in C, but AVG always caught it. First I thought that AVG is detecting the EICAR code string inside the EXE. So I used simple ROT13 and later XOR encryption to hide the string. But AVG always detects it! Actually AVG checks behavior of the program and finds out that it is dropping EICAR test virus and flags it as Eicar.dropper. No use!</p>
<p>Maybe if you can make some regular Windows program put the code in the target EICAR virus file in steps, then you can survive. BTW, EICARGen is caught both by AVG and avast!.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-38580</link>
		<dc:creator><![CDATA[Jack]]></dc:creator>
		<pubDate>Wed, 19 May 2010 15:04:31 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-38580</guid>
		<description><![CDATA[dang, Rising AV didn&#039;t say a thing........
hmmmmm has always been exceptional at finding stuff]]></description>
		<content:encoded><![CDATA[<p>dang, Rising AV didn&#8217;t say a thing&#8230;&#8230;..<br />
hmmmmm has always been exceptional at finding stuff</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickpost: New EICARgen Version &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-36727</link>
		<dc:creator><![CDATA[Quickpost: New EICARgen Version &#171; Didier Stevens]]></dc:creator>
		<pubDate>Fri, 04 Dec 2009 14:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-36727</guid>
		<description><![CDATA[[...] Filed under: My Software, Quickpost &#8212; Didier Stevens @ 14:58   I never expected to release a new version of EICARgen, but I&#8217;m forced to: EICARgen.exe generates just too many false [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Filed under: My Software, Quickpost &#8212; Didier Stevens @ 14:58   I never expected to release a new version of EICARgen, but I&#8217;m forced to: EICARgen.exe generates just too many false [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-35974</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 22 Oct 2009 15:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-35974</guid>
		<description><![CDATA[Interesting, thanks for the heads-up.]]></description>
		<content:encoded><![CDATA[<p>Interesting, thanks for the heads-up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-35973</link>
		<dc:creator><![CDATA[Jan]]></dc:creator>
		<pubDate>Thu, 22 Oct 2009 13:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-35973</guid>
		<description><![CDATA[Microsoft Security Essentials found the &quot;Trojan:Win32/Meredrop&quot; in EICARgen.exe when extacting the zip-file.
Even before I could test the EICAR Anti-Virus test file, at least MSE is doing it&#039;s job.]]></description>
		<content:encoded><![CDATA[<p>Microsoft Security Essentials found the &#8220;Trojan:Win32/Meredrop&#8221; in EICARgen.exe when extacting the zip-file.<br />
Even before I could test the EICAR Anti-Virus test file, at least MSE is doing it&#8217;s job.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: D0R</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-33671</link>
		<dc:creator><![CDATA[D0R]]></dc:creator>
		<pubDate>Thu, 06 Nov 2008 13:58:24 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-33671</guid>
		<description><![CDATA[Probably AVAST recognized your program as a virus generator and classified it as malware. 
Now wait until Google ranks this very URL with the alert &quot;This site may damage your computer&quot;. :)]]></description>
		<content:encoded><![CDATA[<p>Probably AVAST recognized your program as a virus generator and classified it as malware.<br />
Now wait until Google ranks this very URL with the alert &#8220;This site may damage your computer&#8221;. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/programs/eicargen/#comment-33514</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 25 Sep 2008 13:11:28 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/programs/eicargen/#comment-33514</guid>
		<description><![CDATA[Great!]]></description>
		<content:encoded><![CDATA[<p>Great!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

