How can I get rid of this...and what is it? Exploit-MhtRedir.gen

Dani AI

Generated

Quick clarification and a focused cleanup plan (following ’s direction to continue cleanup in the related thread). The detection name “Exploit‑MhtRedir.gen” points to specially crafted MHTML/HTML redirect content that exploits the MHTML URL‑processing vulnerability (CVE‑2004‑0380 / Microsoft MS04‑013). That exploit can make a browser treat remote content as local and allow attacker code to run. (learn.microsoft.com)

How this was used in the wild: compromised IIS sites or injected pages redirected visitors to exploit pages that served an exploit (often packaged in .chm/.mht redirects) and then dropped additional payloads. Historically those payloads included keystroke loggers and other backdoors, so the redirects were the delivery mechanism. (infoworld.com)

Practical, reliable steps to recover (do these in order):

  • Isolate the machine from networks immediately (pull network cable / disable Wi‑Fi).
  • Patch: ensure Windows/IE/Outlook Express are fully updated (install MS04‑013 historically; today install all current OS updates). (learn.microsoft.com)
  • Scan and remove: run up‑to‑date on‑demand tools (Microsoft’s Malicious Software Removal Tool / Safety Scanner) and a reputable AV full scan. If in‑OS tools fail, create bootable rescue media (example: Kaspersky Rescue Disk) and scan offline. (support.microsoft.com)
  • If antivirus reports threats inside System Restore / _RESTORE, purge those restore points (turn System Restore off, reboot, then re‑enable) because restore stores can keep infected copies.
  • After cleanup: change all passwords from a clean device, monitor accounts, and consider a clean OS reinstall if sensitive data or root‑level compromise is suspected. (en.wikipedia.org)

Preventive notes: keep browsers and Windows updated, disable unnecessary ActiveX/active scripting for untrusted sites and avoid visiting unknown links. If unsure about removal or evidence of data theft, preserve logs and get professional incident response help. (cisa.gov)

Hi Linchey050 and welcome to DaniWeb :)

This is a Trojan and can be cleaned up in conjuntion with your other thread (); please follow the suggestions there to prevent duplicating efforts.

This thread is being closed.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.