Here is the technical commentary for this:
Technical Information (Analysis)
Exploit:HTML/IframeRef.gen is generic detection for specially formed IFrame tags that point to remote Web sites containing malicious content, for example malicious Javascript containing an exploit for a specific vulnerability.
Installation
An IFRAME is a valid HTML element which allows content from a separate page or Web site to be embedded in other Web site pages. In the case of Exploit:HTML/IframeRef.gen, a malicious IFrame is appended at the end of local html files. The rendered IFrame may be only one pixel in length to avoid being spotted by the user.
Exploit:HTML/IframeRef.gen requires that a user view or visit the Web sites or open the HTML page in order for malicious action to occur.