Symantec Web Gateway is not detecting the eicar test file

book

Article ID: 158727

calendar_today

Updated On:

Products

Web Gateway

Issue/Introduction

When the eicar test virus is downloaded, it is not detected by the Symantec Web Gateway (SWG).

 

In the case of the eicar test, the file was detected as a file in motion but the file itself was not downloaded.

Cause

Internet Explorer uses a smartscreen filter.

The smartscreen filter detects suspect URLs and files and blocks the access or download of the file.

When this is done the Web Gateway does not see the file and therefore cannot block it.


 

Resolution

You may disable the smartscreen filter as described in the following Microsoft FAQ:

http://windows.microsoft.com/en-us/windows7/smartscreen-filter-frequently-asked-questions-ie9