desktoptech 0 Posted September 17, 2013 Posted September 17, 2013 (edited) I have a user who is having items quarantined since the 10th by the startup scanner. I'm not sure if this is a legitimate threat or not and what steps to take. The first was that morning and Remote Administrator shows this Operating memory » C:\Program Files\Common Files\microsoft shared\OFFICE14\MSPTLS.DLL Threat a variant of Win32/Urlbot.NAG trojan Action cleaned by deleting (after the next restart) - quarantined This file no longer shows up as being quarantine, but every day since she has this file being quarantined: Operating memory » C:\Program Files\Microsoft Office\Office14\OMSMAIN.DLL Threat a variant of Win32/Urlbot.NAG trojan Action cleaned by deleting (after the next restart) - quarantined Thanks. Edited September 17, 2013 by desktoptech
Administrators Marcos 5,466 Posted September 18, 2013 Administrators Posted September 18, 2013 Win32/Urlbot.NAG is a detection from 2011. I'll drop you a pm with further instructions.
eeset 0 Posted September 26, 2013 Posted September 26, 2013 Marcos can you send me further instruction too? We're having a problem with this in our office. thanks
siljaline 57 Posted September 26, 2013 Posted September 26, 2013 From 2010 hxxp://www.virusradar.com/en/Win32_Urlbot.NAG/description hxxp://www.virusradar.com/en/update/info/4815
Recommended Posts