An EICAR alert means your antivirus caught a harmless test file, not a virus. It's a 68-character line of text that every antivirus is built to detect, so people can check their protection works without touching real malware.

Key points
  • EICAR is not malware. It can't infect, copy itself or damage anything. It's a line of text that antivirus programs agree to flag on purpose.
  • The alert usually means someone, or some program, was testing that your antivirus works. Often that someone is your IT team, or a tool you installed.
  • The detection name is what matters. If it says EICAR, the file matched the test string. Any other detection on the same machine is a separate question.
  • You can confirm it in a minute: the real test file is exactly 68 bytes with a known fingerprint.
  • If you run a website and see EICAR in your upload logs, someone was probably checking whether your uploads get scanned.

What EICAR actually is

EICAR is short for the European Institute for Computer Antivirus Research. In the 1990s it published a tiny test file so people could check their antivirus without handling a real virus. Here's the whole thing:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

That's it. Sixty-eight characters. Every antivirus vendor treats it as if it were dangerous, and that's the only reason your computer raised an alarm. If you're curious how that matching works, we explain it in how antivirus scanning works.

There's one fun detail. The string is also a valid program for old DOS computers. Run it there and it prints its own name, then stops. It does nothing else, on any system, ever.

Why it turned up on your computer

People rarely download EICAR by accident, so something put it there. These are the usual reasons:

  • Your IT team is testing. Companies drop EICAR on laptops, file shares and email to prove their protection is switched on.
  • Software you installed brought it along. Plenty of developer tools, mail servers and security libraries ship EICAR in their test folders. Install one and your antivirus spots it.
  • You visited a testing page. Sites that check your browser's download protection serve EICAR on purpose.
  • Someone sent it to you. A colleague checking the mail filter, or a prank. Harmless either way.

The file path in the alert usually gives it away. A path inside a folder like node_modules, test or a program you just installed almost always means the second reason.

What the alert is called

Each antivirus uses its own name, but they all mention EICAR somewhere. Here's what you'll see in the common ones:

Where you saw itDetection nameWhat it tells you
Microsoft DefenderVirus:DOS/EICAR_Test_FileThe test file, nothing else
ClamAVWin.Test.EICAR_HDB-1The test file, nothing else
Most other antivirusA name containing "EICAR" or "Test-File"The test file, nothing else
Scan.nowEICAR antivirus test fileWhether it's the test file itself or the string hidden inside something bigger

And here's the full result our own file scanner gives for the test file. Like every antivirus, it flags EICAR on purpose, and then tells you it's harmless:

What Scan.now reports for eicar.com

Test file detected · This is the EICAR antivirus test file, and it is harmless.

EICAR is a 68-byte test string that every scanner flags on purpose, so people can check their protection works. Like every scanner, we mark it as malicious by design. It cannot spread or damage anything. Delete it when you have finished testing, and if you did not expect it, check where it came from.

Verdict: malicious (risk 100/100) · Plain text, 68 bytes

  • info EICAR antivirus test file: This is the EICAR antivirus test file. It is harmless by design; every scanner must detect it.
  • low Executable program file: .com files execute when opened.

SHA-256: 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f

This box is generated by running Scan.now's own file scanner on eicar.com: the same verdict and findings you get when you upload the file.

How to check what the file really is

You don't have to take the alert on trust. It takes about a minute to check:

  1. Read the detection name. If it names EICAR, the file matched the test string. If you see a different name as well, deal with that one on its own.
  2. Look at where the file lives. The alert shows the path. A test or install folder explains most cases on its own.
  3. Check the size. The genuine file is 68 bytes. Some copies carry a few spaces or a line break after it, but never more than 128 bytes in all.
  4. Compare the fingerprint. The SHA-256 hash of the plain file is 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f. A match means the file is exactly the test string.
  5. Get a second opinion. If you still have a copy that wasn't quarantined, upload it to our free file scanner. It never runs the file. It tells you whether this is the EICAR test file, shows its SHA-256 so you can compare, and flags anything else it finds.
Don't restore a quarantined file just to check it. If your antivirus already named it EICAR and you know where it came from, you have your answer. Let it stay in quarantine or delete it.

When it's worth a second look

An EICAR alert on its own is nothing to worry about. A couple of situations deserve a bit more attention, though:

  • The string is buried inside a bigger file. The real test file is tiny. A large document or program that also contains the EICAR string is unusual. It might be a test, or someone trying to confuse a scanner. Look at it the way you would any file you're not sure about.
  • There are other detections too. EICAR is harmless, but it doesn't vouch for anything else on the machine. A second alert with a real malware name needs its own look.
  • It showed up in your website's uploads. If you run a site with an upload form and find EICAR in your logs, someone was most likely testing whether you scan uploads. That's common and often harmless, but it's also how attackers probe for a weak spot. It's a good prompt to make sure uploads really are checked.

Test your own antivirus

Want to see an EICAR alert on purpose? Download one of the files below and watch what your antivirus does. The plain file checks it's switched on. The zips check it looks inside archives, which is where plenty of scanners quietly give up.

Download the EICAR test files

These are the four official test files. They're completely harmless. If your browser or antivirus blocks the download or deletes the file, that's your protection doing its job.

FileWhat it testsDownload
eicar.comThat your antivirus is running and matching signatures.Download
eicar.com.txtThat it checks what a file contains, not just its extension.Download
eicar_com.zipThat it opens zip archives and looks inside.Download
eicarcom2.zipThat it looks inside a zip within a zip, where scanners often give up.Download

Every download holds only the official 68-byte EICAR test string; the two zips simply wrap it. Nothing else is included.

Frequently asked questions

Can EICAR harm my computer?

No. It can't spread, can't change files and can't send anything anywhere. The only thing it does is get noticed.

Should I delete it?

You can, and it's the tidy choice. If a program installed it as part of its test files, deleting it won't break anything you use day to day.

My antivirus didn't catch it. Is that bad?

Possibly. First make sure the file is exact, because a copy saved in a word processor often gets changed and stops matching. Our guide to testing your antivirus with EICAR walks through doing it properly.

Does catching EICAR mean my antivirus will catch real malware?

It proves the scanner is running and its signature list loaded. It doesn't test the smarter parts, like how a scanner spots brand-new threats. The difference is covered in signature vs heuristic detection.

TL;DR

An EICAR detection is your antivirus catching a harmless test file that exists so people can check their protection. It's almost always from an IT test, a tool you installed or a testing page. Check the name, the path and the 68-byte size, and you'll know for sure. Only take a closer look if the string is hidden inside a bigger file or other detections turned up alongside it.