• On The Insider: Bruno Film Edited Due to Jackson's Death

December 29, 2004 11:13 AM PST

Trojan horse threatens latest Windows XP

  • 6 comments
Online miscreants have released a Trojan horse that can infect computers running Microsoft's Windows XP, installing programs to remotely control a victim's system.

The program--dubbed "Phel," an anagram of "Help"--infects visitors to a maliciously-created Web site through Internet Explorer's Help controls, Symantec warned in an advisory this week. A bug in the malicious program may prevent it from infecting some computers, the security company said.

The Trojan horse exploits a vulnerability, found in October, in how Internet Explorer and Windows XP Service Pack 2 handle help files called from Web pages.

The flaw is unrelated to the recent help-file flaws outed by a Chinese security company last week. In that instance, Microsoft took the Chinese security group to task for disclosing the vulnerability without giving the company a chance to develop a way to fix the problem.

"Microsoft is working to forensically analyze the malicious code in Phel and will work with law enforcement to identify and bring to justice those responsible for this malicious activity," a company spokesperson said.

A patch is not yet available from Microsoft for the October flaw, nor the most recent flaws, but the software giant said its programmers are working on the issue.

"Microsoft is taking this vulnerability very seriously, and an update to correct the vulnerability is currently in development," the spokesperson said. "We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."

Microsoft has had significant problems securing its Web browser in 2004. As a result, the freely available open-source browser Firefox has gained market share. Security experts have recommended that computer users consider other browsers and some schools have told their students to use a non-Microsoft browser.

The Symantec advisory can be found on the company's Web site.

See more CNET content tagged:
spokesperson, flaw, vulnerability, trojan horse, Microsoft Windows XP Service Pack

Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
Maybe...
by DeathMagnet December 29, 2004 9:26 PM PST
Microsoft should be spending more time looking at their own code to prevent these type of vulnerabilities instead of trying to 'look' like the good guy by chasing the culprit down.
Reply to this comment
chasing the culprit down
by Al Johnsons June 3, 2007 3:47 PM PDT
http://www.analogstereo.com/dodge_dakota_owners_manual.htm
OH MY GOD!!!
by olePigeon December 30, 2004 7:16 PM PST
... I'll continue using my Mac. ;)
Reply to this comment
Preach it Pidgeon!
by January 3, 2005 8:53 AM PST
=D Honestly. Why put up with the hassle? Our macs can do everything a PC can, and more. So why not get a ncier computer with a better interface that's not so full of security holes.
View reply
(6 Comments)
  • prev
  • 1
  • next

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (1.63%) 0.25 15.59
Microsoft (-0.22%) -0.05 22.39
Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right