Thread: BeBook Spam
View Single Post
Old 11-05-2010, 05:34 AM   #4
FrancisT
Member
FrancisT is on a distinguished road
 
FrancisT's Avatar
 
Posts: 23
Karma: 65
Join Date: Mar 2008
Device: Cybook, Toshiba NB100
If anyone has tried to run the .exe then please be aware that the statement by BeBook - http://mybebook.com/forum/viewtopic....st=0&sk=t&sd=a - that it didn't do much is optimistic. I checked the ip address (64.62.181.43) that jackecruise.fileave.com
resolves to in our database - http://threatstop.com/checkip.php is the
public version. It shows up as a ZeuS C&C host which suggests to me that
the comment quoted below is false.
Your PC might have been effected by a virus, which sends random
e-mails to your e-mail contacts, but only when using Outlook. This
only contains a random text message, and a copy of the file. Na data
can and will be retrieved from both sender or receiver.


If anyone were stupid enough to run that exe they have probably been
infected by the ZeuS trojan which steals banking passwords and the like

Run some ZeuS specific check/removal tools ASAP if in doubt.
FrancisT is offline   Reply With Quote