Wednesday, March 08, 2006

First fake eicar test string inside a mobile virus!

My friend Mikko H. Hypponen of F-Secure sent me yesterday the first fake (test string) inside a mobile virus. It seems to be dropped dropped by a new Symbian virus (Appdisabler.I). It won't run and it contains this text: {Series60ProductID}$EICAR-SYMBIAN-ANTIVIRUS-TEST-FILE-2006!
What could be the reason to drop such a file which is even not detected as the real eicar string and which can't be run.... tell me!
Thanks Mikko for bringing this up to the EICAR organisation.