You are here: silicon.com > Software > Operating Systems

Operating Systems

Trojan slips through XP's back door

'Phel' takes advantage of 'Help' flaw - geddit?

By Robert Lemos

Published: 30 December 2004 14:40 GMT

Online miscreants have released a Trojan horse that can infect computers running Microsoft's Windows XP, installing programs to remotely control a victim's system.

Symantec warned in an advisory this week that the program - dubbed "Phel", an anagram of "Help" - infects visitors to a maliciously created website through Internet Explorer's Help controls. A bug in the malicious program may prevent it from infecting some computers, the security company said.

The Symantec advisory can be found on the company's website.

The Trojan horse exploits a vulnerability, found in October, in how Internet Explorer and Windows XP Service Pack 2 handle help files called from web pages.

The flaw is unrelated to the recent help-file flaws outed by a Chinese security company last week. In that instance, Microsoft took the Chinese security group to task for disclosing the vulnerability without giving the company a chance to develop a way to fix the problem.

A company spokesperson said: "Microsoft is working to forensically analyse the malicious code in Phel and will work with law enforcement to identify and bring to justice those responsible for this malicious activity."

A patch is not yet available from Microsoft for the October flaw, nor the most recent flaws, but the software giant said its programmers are working on the issue.

"Microsoft is taking this vulnerability very seriously, and an update to correct the vulnerability is currently in development," the spokesperson said. "We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."

Robert Lemos writes for CNET News.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

for IT White Papers Newsletter

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
MS Exchange/Windows XP Technical Support - Birmingham, West Midlands

MS Exchange/Windows XP Technical Support - Birmingham, West Midlands. You will need good knowledge of PC's in general, and ideally MCP accreditation ...

Software Packaging and Windows XP Build technician

We are looking for experienced Windows XP and Desktop build professionals to take responsibility for implementing all changes to the Desktop ...

French Premier role open

A suitable candidate must demonstrate a good working knowledge of current Microsoft desktop operating systems, (Windows XP, Windows Vista, Windows ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: