Here we have a website claiming you can “Play Super Mario Online”, complete with looped Youtube video and a large “Start Here” button at the bottom of the page.


As you’re about to see, The Princess is most definitely in another Castle.

Hitting the “Start Here” button downloads a file called “SuperMario.exe”. However, this isn’t so much “It’s a me, Mario” as it is “It’s a me, a bunch of other stuff instead”.

During testing, we saw the following installer prompt:

As you can see, this is an installer for something called “StartNow”, a Toolbar from Zugo. Readers will recall a mention of their toolbars in this writeup, described as a  “Bing-powered search toolbar toolbar with a history of installs performed through exploits and other misleading/deceptive means”. What’s particularly interesting here though is what happens should you hit the “Decline” button – StartNow goes away, but something called “Web Essentials” from Quantrologic is installed silently instead (you can see more about them in a fake codec writeup by Paretologic).

We’re still looking at it, but the “competitor killer” file has a rather interesting name – especially if you remember these antics from 2004/05.  Here’s an example of adverts appearing on Facebook with this installed:

We informed Zugo about this bundle, and they reported to us that they were in the process of identifying and terminating the affiliate responsible. At time of writing, our US based researchers confirm Zugo is still appearing in testing, whereas other regions end up with something altogether different. For example, this one is from the UK – say hello to “FaceTheme”:

Unfortunately, you’ll still end up with a silent Web Essentials install should you hit “Decline”:

We detect SuperMario.exe as Trojan.Win32.Generic!BT, and VirusTotal scores are currently at 9/42.

Christopher Boyd (Thanks to Matthew for finding this one)

Update 1: Matthew performed some additional analysis on the competitor_killer.exe. Here’s a list of the apps it targets (based on strings found in the file) – notice FaceTheme is listed, even though it is appearing in installs alongside Web Essentials above…