ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
backdoor.haiyangweng NOT detecting or removing
toddmyd


Joined: 19 May 2009
Posts: 0
Reply with quote
This trojan is present in one of our windows 2003 servers, we know the exact file and location however up to date ClamWin is not detecting this virus.

Downloading to a client windows Vista running Symantec detects this immediately.

What do we do to have ClamWin work correctly here? How do we manually remove this or use ClamWin for removal?
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
Please see this article:
https://www.clamwin.com/content/view/40/27/
View user's profileSend private message
toddmyd


Joined: 19 May 2009
Posts: 0
Reply with quote
Thanks for the reply. The file has been analysed and recognised by Virustotal.com, only there is no further help. Simply a table that displays the common name of this trojan horse per anti-virus company/software.

ClamWin is up to date on the server but does not find this infection/trojan horse.

What to do from here?
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If ClamWin does not detect the trojan in the file, the signature for the trojan is not in ClamWin's database. Clam Antivirus provides the signature database and scanning engine that ClamWin uses. You will need to upload this file to Clam Antivirus starting at https://www.clamav.net/sendvirus/ on the web. This is the same location in the article to which Alch referred you. When you get to the actual virus submission form, be sure to fill out the form. Clam Antivirus will prepare a signature for the trojan in a day or so.

If the trojan file is not a system file, you can manually delete it from the server and replace it from backup. If it is a system file, you may need to restore that file from your Windows system package.

Regards,
View user's profileSend private message
toddmyd


Joined: 19 May 2009
Posts: 0
Reply with quote
Thanks for the information,

Yesterday we uploaded the trojan file to ClamAV and are awaiting a response or ClamWin update.

We'll see how that goes and I'll report from there.
View user's profileSend private message
backdoor.haiyangweng NOT detecting or removing
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic