Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Infected File

Status
Not open for further replies.

jwilder

IS-IT--Management
Mar 21, 2001
66
US
On my exchange server, Antivirus caught a virus PWSteal.Trojan, it is in a file called NewGina.DLL. The file can't be cleaned because it's in use. Any ideas? Jason Wilder
IT/CAD Manager
 
You will probably need to go to DOS and delete it. Then run an AV scan, that should fix it. You may have to boot from a floppy disk if it stays in memory, then run an AV scan. That should fix your problem.

Good luck,

Mark ;-)
 
Be carefull the newgina.dll virus is pretty complex. There are several directories you'll need to check as well as editing the registry.

We had this virus, when I applied an IIS patch my server crashed when rebooted. I had do a parrallel NT installation to clean the virus.

Refer to MS article: Q294728

J
 
The parallel install may not have been necessary. I'll see if I can find it again and post it, but I found good documentation on removing the virus from the system, mostly manual, but by editing the registry and removing files. I was fine. I also found a patch that helps prevent it from happening again.

I believe I found another thread in this group with the link. Jason Wilder
IT/CAD Manager
"When I go, I want to go in my sleep like Grandpa. Not screaming in terror like his passengers."
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top