Does anyone know much about "Exploit.HTML.MHTRedir-8"?
Billy <[email protected]>
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
Hi all! We have a WinNT4 server that is running DNS for our WAN. Lately, it seems that our users who are browsing are being redirected elsewhere. A preliminary check of the system using Norton AV 2003 (fully-updated, of course) revealed no infections, but a scan with ClamAV (20050725, also fully-updated) reported the presence of "Exploit.HTML.MHTRedir-8" infection in our DNS server's pagefile.sys. A Google search about "Exploit.HTML.MHTRedir-8" showed only 4 links, none of which said anything much about the infection, except that it was first reported on July 26, 2005. It must indeed be a new virus/trojan. Does anyone else have more useful info about "Exploit.HTML.MHTRedir-8"? As in what it really does? Thanks in advance!