Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How can I test that XProtect is working?

For people who have virus scanners, there is the EICAR file that they can use to test that their virus scanner is working.


While XProtect is not a true virus scanner, I would like to know if there is a file like EICAR for the Mac OS that simulates the same thing. How do I know that it's running while I am browsing the web?

Posted on Sep 23, 2013 8:13 PM

Reply
12 replies

Sep 24, 2013 3:27 AM in response to NotANoob

XProtect will detect the EICAR test file. Download the following file:


eicar.com


Try to open it, and when it asks what app you want to open it with, select a text editor. At that point, XProtect should jump in and prevent it from opening:


User uploaded file

Of course, it won't actually damage your computer, since it's just an EICAR test file and not actual malware. However, this does demonstrate accurately what would happen if you downloaded and tried to open a malicious executable file.

May 13, 2015 3:49 PM in response to John Whitehead

John Whitehead wrote:


Should I be worried?


No, looks like that's normal... or, at least, that's happening for me as well in Yosemite. The eicar definition is still present in XProtect, but it looks like Yosemite is not checking that file against the definition... probably because it's not identified as containing executable code, which it doesn't. I don't know whether Apple has simply forgotten about supporting the eicar file or what. I'll report this to the product security team.

Dec 17, 2015 1:55 AM in response to thomas_r.

thomas_r. wrote:


XProtect will detect the EICAR test file. Download the following file:


eicar.com


Try to open it, and when it asks what app you want to open it with, select a text editor. At that point, XProtect should jump in and prevent it from opening:


User uploaded file

Of course, it won't actually damage your computer, since it's just an EICAR test file and not actual malware. However, this does demonstrate accurately what would happen if you downloaded and tried to open a malicious executable file.


As an aside, I tried this on my iMac running Mavericks and my malware checker, Avira, flagged it and snagged it before I could even try to open it!

Feb 26, 2016 5:58 AM in response to Drew Reece

Drew Reece wrote:


tomas_r's first post has a sample file that should trigger XProtect, see what it does for you.


It does not trigger an alert on Yosemite. It would appear that the eicar file is (still) not triggering the alert on open, at least via an editor. Or that XProtect is not working — not that I'm going to go look for a hunk of actual malware that it should (hopefully) detect.

How can I test that XProtect is working?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.