xbox02
xbox02

Xbox web hoax installs Trojan horse

Malicious code masquerades as Xbox emulator

James Middleton

Internet users caught up in the hype of the recent Xbox launch may be falling for a web hoax that installs a Trojan horse on their machine.

The success of the malicious code may be boosted by the fact that the Trojan masquerades as an Xbox emulator for the PC.

Advertisement

Of course, there is no such thing, but the launch hype of the new console, mixed with a little bit of internet trickery, seems to have created a sizeable hotbed of web users who really think they are downloading an Xbox emulator.

Such things aren't unheard of; there are a multitude of other console emulators available on the web allowing you to play anything from N64 games to PlayStation discs.

But users downloading the Xbox emulator, which arrives as a file called 'EMU_xbox.exe', are really installing a Trojan on their PC.

When executed, the program quits out with an error message after dropping a back door program called NetBUIE.exe on the victim's machine.

Once installed, the Trojan connects up to a number of remote servers, suggesting that it may be racking up dollars for its creators by scamming a number of pay-per-click services.

But analysis also revealed that the program makes attempts to connect to four Microsoft-run servers, for reasons yet unknown, although one of these connects to Microsoft's free Bcentral.com counter service and reveals a worrying four million or so hits from the Trojan.

According to another link on the fake emulator's website before it was pulled earlier today, over 30,000 visitors have been to the site. That's 30,000 potential victims of the Trojan.

By way of a disguise, NetBUIE.exe looks similar to Netbeui (NetBios Enhanced User Interface) which is a networking protocol commonly used on Windows networks.

Right clicking on the executable and selecting properties even brings up a Microsoft copyright notice, adding a legitimate feel to the file.

Earlier today the main web page that hosted the program was taken down by free host Angelfire for violation of its terms of service.

But the program may yet crop up on other websites in the same guise, and antivirus firms do not appear to be on the case yet.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Website touts Xbox mod chip

Got a copied or unsigned game? No problem, says modder

Scorpion takes sting out of Xbox hoax

Not harmful, says emulator creator

Kazaa Lite is 'spyware free' says creator

Hacked version of file sharing software

BugWatch: Magic Lantern - not magic and not very bright

FBI Trojan horse lacks the Hogwart touch

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation