xbox02
xbox02

Xbox web hoax installs Trojan horse

Malicious code masquerades as Xbox emulator

James Middleton

Internet users caught up in the hype of the recent Xbox launch may be falling for a web hoax that installs a Trojan horse on their machine.

The success of the malicious code may be boosted by the fact that the Trojan masquerades as an Xbox emulator for the PC.

Advertisement

Of course, there is no such thing, but the launch hype of the new console, mixed with a little bit of internet trickery, seems to have created a sizeable hotbed of web users who really think they are downloading an Xbox emulator.

Such things aren't unheard of; there are a multitude of other console emulators available on the web allowing you to play anything from N64 games to PlayStation discs.

But users downloading the Xbox emulator, which arrives as a file called 'EMU_xbox.exe', are really installing a Trojan on their PC.

When executed, the program quits out with an error message after dropping a back door program called NetBUIE.exe on the victim's machine.

Once installed, the Trojan connects up to a number of remote servers, suggesting that it may be racking up dollars for its creators by scamming a number of pay-per-click services.

But analysis also revealed that the program makes attempts to connect to four Microsoft-run servers, for reasons yet unknown, although one of these connects to Microsoft's free Bcentral.com counter service and reveals a worrying four million or so hits from the Trojan.

According to another link on the fake emulator's website before it was pulled earlier today, over 30,000 visitors have been to the site. That's 30,000 potential victims of the Trojan.

By way of a disguise, NetBUIE.exe looks similar to Netbeui (NetBios Enhanced User Interface) which is a networking protocol commonly used on Windows networks.

Right clicking on the executable and selecting properties even brings up a Microsoft copyright notice, adding a legitimate feel to the file.

Earlier today the main web page that hosted the program was taken down by free host Angelfire for violation of its terms of service.

But the program may yet crop up on other websites in the same guise, and antivirus firms do not appear to be on the case yet.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Website touts Xbox mod chip

Got a copied or unsigned game? No problem, says modder

Scorpion takes sting out of Xbox hoax

Not harmful, says emulator creator

Kazaa Lite is 'spyware free' says creator

Hacked version of file sharing software

BugWatch: Magic Lantern - not magic and not very bright

FBI Trojan horse lacks the Hogwart touch

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

NetGear ReadyNAS NVX

Review: NetGear ReadyNAS NVX

NetGear's four-bay compact network-attached storage gets a serious speed boost

AMD

AMD adds to six-core Opteron line up

New HE processors promise even lower power consumption

Adobe Systems

Adobe launches ColdFusion 9 and ColdFusion Builder

Firm promises enhanced developer productivity

Primary Navigation