• I actually need a copy of a virus, or at least a simulated one.

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » I actually need a copy of a virus, or at least a simulated one.

    Author
    Topic
    #476292

    Strange request.

    I teach a Managing Malware class to mature adults, and need a virus to demo how to remove a virus.

    these folks are generally clueless and overlook simple stuff like AV subscriptions expiring, versions going out of date, etc and can really be detoured via social engineering.

    I want impress on them that keeping viruses out of their system is not difficult if they are smart about it, and if it does happen, the virus can usually be fairly easy to remove. Dont want anything that will really mess up a machine, and preferrably is a qualified virus i.e. worm, trojan, etc, and not ad/spyware.

    Really need something very timid, non-evasive, easy to remove, and it doesnt travel over an internal network. Keep in mind that the machine Im teaching on is booted off a locked down image, every time, so what I install will go away at the next boot.

    I used to have a sample floppy that was a demo for a no-name av tool that launched a simulated set of screens that a user might see if they ran into a self-executing virus, but that was years ago, and honestly, I dont remember what company it was for, if they are even around.

    Any suggestions?

    Viewing 3 reply threads
    Author
    Replies
    • #1277480

      Not a strange request at all! Take a look at this and see if it meets your needs:
      http://www.eicar.org/anti_virus_test_file.htm

    • #1277504

      That works to identify a potential virus file, but does anyone have a demo of what a virus could look like, i.e what it displays on the screen, etc.

      Edit: I think it was this one: http://windowssecrets.com/forums/showthread//137554-How-IE-9-SmartScreen-filters-help-counter-social-engineering-attacks

    • #1277509

      The other day someone posted a link to an article that had a screencast showing what happens when you click on a “Fake AV” warning. Would that be useful?

      • #1277510

        better than nothing, but what i really was looking for was either a demo of a virus (which would probably be an advertisement for a real AV product), or an easily removed real virus – something that actually did something, like make all the letters in a WP doc fall to the bottom occasionally, or popup a message saying “you are infected” etc.

        I want them to be afraid enough to make sure that their personal system AV products are honest, reliable, and up to date. I can preach all I want, but a demo is a real example of what can happen, if they dont protect themselves. Many of these folks dont necessarily believe that all this virus mumbo-jumbo is that big of a deal, and just getting them into the class is a huge step forward in their education.

        I did find an entry in the Windows Secrets newsletter about how the author (Fred Langa) got infected and then intentionally followed the instructions to load LizaMoon on his system, and what it did, but no screen shots. His article is at http://http://windowssecrets.com/2011/04/07/01-LizaMoon-infection-a-blow-by-blow-account

        • #1277530

          I want them to be afraid enough to make sure that their personal system AV products are honest, reliable, and up to date. I can preach all I want, but a demo is a real example of what can happen, if they dont protect themselves. Many of these folks dont necessarily believe that all this virus mumbo-jumbo is that big of a deal, and just getting them into the class is a huge step forward in their education.

          Oh yeah! Kind of like the “blood and guts” movies they used to show us in driver’s ed when I was in high school. If you can’t find any good demos or screen shots, have them read posts in the lounge. Most of us here have seen first hand what these things can do to a PC.

        • #1277541

          http://http://windowssecrets.com/2011/04/07/01-LizaMoon-infection-a-blow-by-blow-account%5B/url%5D

          Perhaps the above link in Post #5 needs to be fixed?

          This link to Fred Langa’s article has screen shots……..
          LizaMoon infection: a blow-by-blow account

          HTH

    • #1277604

      Kaspersky also have make believe virus to test its system, you might check there support files

    Viewing 3 reply threads
    Reply To: I actually need a copy of a virus, or at least a simulated one.

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: