toddmyd
Joined: 19 May 2009 |
Posts: 0 |
|
|
 |
Posted: Tue May 19, 2009 12:27 am |
|
 |
 |
 |
 |
This trojan is present in one of our windows 2003 servers, we know the exact file and location however up to date ClamWin is not detecting this virus.
Downloading to a client windows Vista running Symantec detects this immediately.
What do we do to have ClamWin work correctly here? How do we manually remove this or use ClamWin for removal?
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Tue May 19, 2009 8:54 am |
|
 |
 |
 |
 |
Please see this article:
https://www.clamwin.com/content/view/40/27/
|
|
toddmyd
Joined: 19 May 2009 |
Posts: 0 |
|
|
 |
Posted: Tue May 19, 2009 9:27 am |
|
 |
 |
 |
 |
Thanks for the reply. The file has been analysed and recognised by Virustotal.com, only there is no further help. Simply a table that displays the common name of this trojan horse per anti-virus company/software.
ClamWin is up to date on the server but does not find this infection/trojan horse.
What to do from here?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue May 19, 2009 1:12 pm |
|
 |
 |
 |
 |
If ClamWin does not detect the trojan in the file, the signature for the trojan is not in ClamWin's database. Clam Antivirus provides the signature database and scanning engine that ClamWin uses. You will need to upload this file to Clam Antivirus starting at https://www.clamav.net/sendvirus/ on the web. This is the same location in the article to which Alch referred you. When you get to the actual virus submission form, be sure to fill out the form. Clam Antivirus will prepare a signature for the trojan in a day or so.
If the trojan file is not a system file, you can manually delete it from the server and replace it from backup. If it is a system file, you may need to restore that file from your Windows system package.
Regards,
|
|
toddmyd
Joined: 19 May 2009 |
Posts: 0 |
|
|
 |
Posted: Tue May 19, 2009 10:38 pm |
|
 |
 |
 |
 |
Thanks for the information,
Yesterday we uploaded the trojan file to ClamAV and are awaiting a response or ClamWin update.
We'll see how that goes and I'll report from there.
|
|