Friday, October 15, 2010

How to test your virus scanner for its effectiveness Against Trojan?

For years many of us are using "Eicer" an antivirus test file, to test if the antimalware/antivirus is working correctly. Using the just released "Trojan Simulator" you can now test your Trojan scanner in the same manner, using a harmless demonstration Trojan. This is a risk-free way to see how your security software behaves in a real-world situation.


 


Installation is simple: Simply unzip all files contained in TrojanSimulator.zip to any directory. To start, simply double-click TrojanSimulator.exe.


 


When you run Trojan Simulator, you will be presented with a screen showing some informational text about Trojan Simulator. Clicking the Install button will install the demo trojan on your system. The demo trojan simulates a real trojan server by hiding its main window and writing an autostart entry to the registry.


 


Clicking the Uninstall button removes the autostart entry from the registry and then unloads the demo trojan server from memory. While the demo trojan is running, you get a chance to observe the behavior of any installed security software.


 


When run with the /install parameter, TSServ.exe loads into memory and adds an autostart entry to the registry. An information dialog will pop up notifying that the demo server was successfully installed along with the path to the server and its process ID. Most trojans don't really present a dialog saying they've successfully installed themselves in your system!


  


When run with the /uninstall parameter, TSServ.exe removes its autostart entry and then unloads all copies of itself from memory. If you run TSServ.exe without any parameters, nothing will happen - the program simply starts and exits.


 


"I did download the zip fille and uploaded to the Virus total for scanning with 40 antivirus. Find the results here.


One interesting thing was that out of 43 virus scanning engins, 36 reported the file as malware. Remaining 7 did not report any thing, in that seven KASPERSKY also was one of them.


 


May be kaspersky Does know that thae file is False positive(SAFE FILE) or it may report when you execute the file."


  


Note: Use the software at your own risk.

Download:TrojanStimulator.Zip

No comments:

Post a Comment