1
   

[resolved]HTML.MHTML.Redir.exploit trojan

 
 
gozmo
 
Reply Wed 16 Jun, 2004 11:00 pm
My virus checker is reporting the presence of above whenever I visit A2K.
I am not happy and intend avoiding the site in future.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 7,298 • Replies: 9
No top replies

 
Craven de Kere
 
  1  
Reply Wed 16 Jun, 2004 11:17 pm
gozmo,

You are the second Aussie to say that. This is making me wonder. I have not seen a thing.

Whatever it is, I need to get to the bottom of it.

Are you using the Kasperky A-V program? The other report was for that one too and I need to start nailing down the factors involved.

I've shut off the only advertising network that has been added within the last month (ads are the only off site code, and the Oz factor might mean it's because of defaults).

I can't find any meaningful information on the reported text either.
0 Replies
 
gozmo
 
  1  
Reply Thu 17 Jun, 2004 01:34 am
I am using E-Z Trust. It happened again.
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 17 Jun, 2004 01:38 am
What ads are you seeing when it does this? Please do that a few times (as long as it's being flagged nothing can happen, and if you have used windows patches since april the exploit is addressed on your system).

I'm beginning to think it's not necessarily coming from any of the ads though. Only two reports when we get millions of hits might indicate a problem specific to your computer (though if it is only here maybe not).

I will PM you an email address and I'd like to get the contents of your cache in case the culprit is there.

I've contacted every major ad network, when they wake up I expect them to start hunting for it in earnest.
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 17 Jun, 2004 01:53 am
A few more things that can help me:

Please visit this page: http://www.able2know.com/disclaimer.php

Let me know what happens, that is a page that I do not think contains any remote html (except for one, and that would nail it immediately).

Another question: is it every time or just some times?
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 17 Jun, 2004 03:08 am
I'd like to thank gozmo for providing me with information by email that I would not have otherwise been able to get.

Any more leads are very very very welcome. I wanna nail these guys' balls to a wall. The exploit is a low-level one that doesn't manage to cause any harm even on some tests with unprotected puters but the nerve of the asses really pisses me off.
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 17 Jun, 2004 03:12 am
I gotta go to bed, gotta be up in a wee bit and i didn't sleep last night.

Gozmo, please send me anything else you have to report (including whether it is now resolved or not).
0 Replies
 
gozmo
 
  1  
Reply Sun 20 Jun, 2004 05:11 am
Thanks Craven. The problem is not recurring.
0 Replies
 
Canary51
 
  1  
Reply Mon 5 Jul, 2004 04:18 pm
i have the same problem as this user...mhtml.redir
Craven de Kere wrote:
A few more things that can help me:

Please visit this page: http://www.able2know.com/disclaimer.php

Let me know what happens, that is a page that I do not think contains any remote html (except for one, and that would nail it immediately).

Another question: is it every time or just some times?


I have read the chain here and done this visit to the above site with no problem. However EZ antivirus keeps popping up with this mhtml thing relentlessly. i mean 10-12 windows at a time and over and over.
Do you have a solution>?
I am using ad aware and hi jack this and they are looking at my logs.
Thanks for any help Smile
0 Replies
 
Craven de Kere
 
  1  
Reply Mon 5 Jul, 2004 06:45 pm
Canary51,

Go get help on the computer forum. This thread is about THIS SITE and not others.
0 Replies
 
 

Related Topics

How to use the new able2know - Discussion by Craven de Kere
New A2K feature requests. - Discussion by DrewDad
I'm the developer - Discussion by Nick Ashley
JIM NABORS WAS GOY? - Question by farmerman
A2K censors tags? - Discussion by hingehead
New A2K Bugs - Discussion by sozobe
New A2K annoyances - Discussion by sozobe
The a2k world is changing 3: about voting - Discussion by Craven de Kere
LOST & MISPLACED A2K people. - Discussion by msolga
Welcome to the 'New' My Posts - Discussion by Nick Ashley
The "I get folksonomy" club - Discussion by Robert Gentel
 
  1. Forums
  2. » [resolved]HTML.MHTML.Redir.exploit trojan
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 06/26/2024 at 09:08:56