The Mac Observer

 
   
 
Help:  I think my mac has a virus, worm or Trojan Horse?
Posted: 24 January 2010 01:23 AM [ Ignore ]
stars_1
Total Posts:  3
Joined  2010-01-24

For the past week or so, people from my mailing list in Eudora have received a series of crude spam emails from my address containing links to porn sites. A couple of them have sent me copies of the messages.  Very embarrassing!  I’m not sure how to deal with this and I would appreciate any suggestions.  The cheaper the solution, the better.

I have the original macbook pro, core duo running 10.5.6 and I use Eudora 6.2 as my email client.

Thank you for any help you can offer,

Christopher

[ Edited: 24 January 2010 02:04 AM by christoxo ]
Profile
 
 
Posted: 24 January 2010 07:39 AM [ Ignore ] [ # 1 ]
stars_1
Total Posts:  37
Joined  2009-09-04

The first thing I would do is change your email password.  What service are you using?

Profile
 
 
Posted: 24 January 2010 07:55 AM [ Ignore ] [ # 2 ]
Administrator
Avatar
Total Posts:  3610
Joined  2004-07-07

Very unlikely that you are the originator. Depending on how you sent large group messages (ie are all the recipients in the To: field or in the BCC: field), any one of your addressees could be the cause. The From: field in most spam messages are not legitimate, meaning they didn’t really originate from that address.

 Signature 

Mac switchers see my profile for switching help…

Profile
 
 
Posted: 24 January 2010 04:18 PM [ Ignore ] [ # 3 ]
stars_1
Total Posts:  3
Joined  2010-01-24

Thanks brokentry and intruder!

I am using yahoo popmail and downloading all mail into Eudora.  I will try changing my yahoo password tonight when i get home. 

When I forward to my list, I always use BCC.  The spam recipient addresses are culled, I think, from my Eudora address list.  I wonder if there is a chance that the addresses could have somehow been culled from my yahoo mail page?  Some are very old and out of date.  In fact, I think they are all old addresses some of which are still valid.

Christopher

Profile
 
 
Posted: 25 January 2010 02:09 AM [ Ignore ] [ # 4 ]
Moderator
Total Posts:  5834
Joined  2001-06-11

I have to agree, I doubt it’s anything related to the computer itself. It is definitely a good idea to change your password, though, if messages are coming from you to other people in your address book.

 Signature 

Mac mini: 2GHz Core 2 Duo, 8GB RAM, GeForce 9400M
iPhone 4S: 32GB, white
iPad 2: WiFi, 16GB, black

Profile
 
 
Posted: 25 January 2010 11:25 AM [ Ignore ] [ # 5 ]
stars_5
Avatar
Total Posts:  2296
Joined  2003-12-30

I’ve seen this fairly often. Usually someone you sent a message to gets infected and the virus digs through incoming e-mail for addresses to use in the to and from fields. I’ve actually received a message like this that I supposedly sent to myself.

Changing your e-mail password isn’t a bad idea. Actually you should change it periodically anyway. I also have two e-mail addresses (.Mac lets you create these spoof addresses). I have one for correspondence with close friends and family and a second that I use as ID for on line things, TMO, and such. I can always throw away the spoof address if it gets compromised.

 Signature 

It’s amazing how many people teach their children that if they work hard they can change the world while at the same time don’t believe that Oswald acted alone

Profile
 
 
Posted: 25 January 2010 11:30 AM [ Ignore ] [ # 6 ]
Moderator
Total Posts:  5834
Joined  2001-06-11

Good point, you’re absolutely right that it could be someone else who has either or both of them in their address book, and who has an infected PC which is sending spam.

 Signature 

Mac mini: 2GHz Core 2 Duo, 8GB RAM, GeForce 9400M
iPhone 4S: 32GB, white
iPad 2: WiFi, 16GB, black

Profile
 
 
Posted: 25 January 2010 11:46 AM [ Ignore ] [ # 7 ]
stars_5
Avatar
Total Posts:  1082
Joined  2007-02-07

Ask some of the recipients to send you the long header from one of the emails. Take a look at it and see if there is a clue to the originator

Post it here and we can all look it, or send it to me via private message if you want. Delete yours and the recpients email addresses from the long header, I just need to see the route it took.

[ Edited: 25 January 2010 12:15 PM by Lee Dronick ]
 Signature 

“Works of art, in my opinion, are the only objects in the material universe to possess internal order, and that is why, though I don’t believe that only art matters, I do believe in Art for Art’s sake.” E. M. Forster

Profile
 
 
Posted: 25 January 2010 01:14 PM [ Ignore ] [ # 8 ]
stars_1
Total Posts:  3
Joined  2010-01-24
Sir Harry Flashman - 25 January 2010 11:46 AM

Ask some of the recipients to send you the long header from one of the emails. Take a look at it and see if there is a clue to the originator

Post it here and we can all look it, or send it to me via private message if you want. Delete yours and the recpients email addresses from the long header, I just need to see the route it took.


Thanks to all who have replied.  Sir Harry, I will ask recipients of the the porn spam to send me a full header which I will post here when I have it. Don’t know if people have retained any of the messages or not.  So, it might take a few days to get one,

Christopher

Profile
 
 
Posted: 25 January 2010 09:10 PM [ Ignore ] [ # 9 ]
Administrator
Avatar
Total Posts:  3610
Joined  2004-07-07

Yahoo may well be the weak link here.

 Signature 

Mac switchers see my profile for switching help…

Profile
 
 
   
 
 

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal