Sophos

Online support

Product maintenance

Contact support

Support services

Advisory: vulnerable websites, Troj/Iyus-I and Troj/Iyus-Fam

Some users of Sophos Anti-Virus software have reported detecting Troj/Iyus-I and Troj/Iyus-Fam when browsing some large, well-known, legitimate websites.

The detection reports appear to be connected with websites using the RedSheriff activity monitoring tool. Some versions of this tool are reported to have had a vulnerability that could be exploited by malicious hackers to gain access to computers browsing the websites concerned. The RedSheriff tool has now (2 February 2005) reportedly been upgraded to fix this vulnerability.

Sophos Anti-Virus correctly intercepts any attempts by these Trojans to infect computers.

If you encounter either of these Trojans immediately after browsing a website, please contact the administrator of the website concerned.

If you need more information or guidance, then please contact technical support.