desktoptech 0 Posted September 17, 2013 Share Posted September 17, 2013 (edited) I have a user who is having items quarantined since the 10th by the startup scanner. I'm not sure if this is a legitimate threat or not and what steps to take. The first was that morning and Remote Administrator shows this Operating memory » C:\Program Files\Common Files\microsoft shared\OFFICE14\MSPTLS.DLL Threat a variant of Win32/Urlbot.NAG trojan Action cleaned by deleting (after the next restart) - quarantined This file no longer shows up as being quarantine, but every day since she has this file being quarantined: Operating memory » C:\Program Files\Microsoft Office\Office14\OMSMAIN.DLL Threat a variant of Win32/Urlbot.NAG trojan Action cleaned by deleting (after the next restart) - quarantined Thanks. Edited September 17, 2013 by desktoptech Link to comment Share on other sites More sharing options...
Administrators Marcos 5,243 Posted September 18, 2013 Administrators Share Posted September 18, 2013 Win32/Urlbot.NAG is a detection from 2011. I'll drop you a pm with further instructions. Link to comment Share on other sites More sharing options...
eeset 0 Posted September 26, 2013 Share Posted September 26, 2013 Marcos can you send me further instruction too? We're having a problem with this in our office. thanks Link to comment Share on other sites More sharing options...
siljaline 57 Posted September 26, 2013 Share Posted September 26, 2013 From 2010 hxxp://www.virusradar.com/en/Win32_Urlbot.NAG/description hxxp://www.virusradar.com/en/update/info/4815 Link to comment Share on other sites More sharing options...
Recommended Posts