Security firm Symantec is warning users of a newly discovered Trojan horse named Phel -an anagram of the word help -that attacks Windows XP. The Trojan is capable of remotely controlling a user's system even if the latest Windows XP Service Pack, SP2, has been installed.
The Trojan, distributed as an HTML file, attempts to exploit a vulnerability in Internet Explorer's HTML Help Control component in all versions of Windows. The vulnerability was discovered in October.
Microsoft is actively investigating new public reports of a criminal attack, according to a Microsoft spokesperson.
For the exploit to succeed, an attacker would need to entice a user to visit a malicious Web site and then place the Trojan on the user's machine. If the Trojan executes successfully, potentially malicious software could be downloaded and run on the user's system, the spokesperson said.
Microsoft is working to forensically analyse the malicious code in Phel and will work with law enforcement agencies to identify and bring to justice those responsible for the malicious activity, he said.
"Microsoft is taking this vulnerability very seriously, and an update to correct the vulnerability is currently in development," the spokesperson said in an e-mail message. "We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."
Microsoft said customers who think they may have been affected can receive support . Customers outside the US should contact the national law enforcement agency in their country, the spokesperson added.