Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

D0ct0rteeth

macrumors 65816
Original poster
Mar 11, 2002
1,239
7
Franklin, TN
I just received well over 100 emails in the last hour. In my actual inbox, not in my junk folder.

All are very similar and have one of three subjects along the lines of "Re: Details" and have "please see attached message" as the body.

I recognize about a third of the peoples addresses, while another third of the address' are from companies I deal with.. but not people I know.

The final third are just random address'

Any help? Please?

-Doc
 

D0ct0rteeth

macrumors 65816
Original poster
Mar 11, 2002
1,239
7
Franklin, TN
I cant even see the attachments. It just says "see attachment for details".. but there is no attachment.

I assume3 someone else is affected and I am just in their address book?

(16 more emails while typing this :))

-Doc
 

D0ct0rteeth

macrumors 65816
Original poster
Mar 11, 2002
1,239
7
Franklin, TN
Thats the little bastard. :)

Most of my clients run pc's.. but I am safe. We only use macs.

I was just in their address book like I hoped.

Thanks for the link Chad.

-Doc
 

Daveman Deluxe

macrumors 68000
Jun 17, 2003
1,555
1
Corvallis, Oregon
Evidently, this virus will look through temporary Internet files and get whatever email addresses it can from then, then send the email with the attachment. I've gotten a couple dozen today.

It makes sense, when you consider I'm the only one in the office who's gotten these, and I'm also the only one in the office whose email is on our company's main page (I'm the webmaster, so my email is on EVERY page).
 

Chad4Mac

macrumors 6502
Apr 20, 2002
299
0
Los Angeles
Before we upgraded our network (Cisco PIX, Win 2003 Server, Symantec Corporate), I would open my emails only though my Mac, fearing that if I used Outlook, a virus would slip by and down my trading system. It really was the only way I was safe. But now that we upgraded, I tend to leave the Mac excusively to personal stuff -- no work emails and such.

I wonder how long it would take for somene to write something serious for OS X. If you think about it, now that there is credit card info stored within the OS -- through .Mac and now iTunes -- there might be a little more incentive to write some something that can retreive it.

Just a thought...

Chad4Mac
 

cnladd

macrumors regular
Feb 6, 2003
127
0
Northridge, CA
Originally posted by Chad4Mac
If you think about it, now that there is credit card info stored within the OS -- through .Mac and now iTunes -- there might be a little more incentive to write some something that can retreive it.

There's no credit card information stored within the OS due to those services. They operate the way Amazon.com or most other online retailers operate: they store your credit card information on their own site and you log in with a user name and password. Automatic logins happen using cookies, again like Amazon.com or other retailers.

Both iTunes and .Mac are entirely web-based and both make extensive use of cookies.

The only credit card info stored on your system will be in any personal records that you keep on your Mac (say, in Quicken, for example.)
 

cnladd

macrumors regular
Feb 6, 2003
127
0
Northridge, CA
Re: Do I Have A Mac eMail Virus??

Originally posted by D0ct0rteeth
I just received well over 100 emails in the last hour. In my actual inbox, not in my junk folder.

All are very similar and have one of three subjects along the lines of "Re: Details" and have "please see attached message" as the body.

I recognize about a third of the peoples addresses, while another third of the address' are from companies I deal with.. but not people I know.

The final third are just random address'

Any help? Please?

-Doc

No, you don't have a Mac e-mail virus -- to date, none exist for the Mac (and it would be hard to create one.)

What you're experiencing is the result of PC users who have an e-mail virus.

An email virus spreads by sending an e-mail out to everyone in your address book with an attachment that either gets executed automatically or that the user opens (and activates) themselves.

Being on a Mac means that you're pretty much immune from spreading the virus (unless you forward those e-mails on yourself, they won't automatically be spread as they would on a PC.) Unfortunately, you're at the mercy of your PC-using friends who have you in their address books -- when they get the virus, it responds by propagating out to all their contacts, including you.

Just don't forward those messages on. :)
 

TEG

macrumors 604
Jan 21, 2002
6,621
169
Langley, Washington
Yes its a Virus, actually there are two going around... But thankfully it only affects windows.

More:
-----
New virus alert: W32/Sobig.F-mm

Warning: dangerous new variant of “Sobig” family spreading

On 18th August 2003, MessageLabs the email security company intercepted several copies of a mass-mailing virus which were identified as W32/Sobig.F-mm. The initial copies all originated from the United States.

Name: W32/Sobig.F-mm
Number of copies intercepted so far: 1,124 (increasing rapidly)
Time & Date first Captured: 18 Aug 2003 21:04 GMT
Origin of first intercepted copy: United States
Most active country: United States (95%), Denmark (3%), Norway (1%)

Characteristics
Initial analysis would suggest that Sobig.F is a mass-emailing virus that is spreading very vigorously. Sobig.F appears to be polymorphic in nature and the email from: address is also spoofed and may not indicate the true identity of the sender. In earlier versions of the Sobig family, the file extension has sometimes been truncated. MessageLabs have not yet observed this with the Sobig.F strain.

The email may also comprise the following characteristics:
Subject: Re: Details
Text:
Please see the attached file for details.

Attachment names may include: your_document.pif, details.pif, your_details.pif, thank_you.pif, movie0045.pif, document_Fall.pif, application.pif, document_9446.pif

In an attempt to bypass local antivirus security, the file size varies on each generation reminiscent of Yaha by appending rubbish to the end of the file, but is on average around 74kb in size. The initial copies are packed using TELock, but there may be other variants in the wild packed using different packers.

From Messagelabs.com
-----
TEG
 

Chad4Mac

macrumors 6502
Apr 20, 2002
299
0
Los Angeles
Originally posted by cnladd
There's no credit card information stored within the OS due to those services. They operate the way Amazon.com or most other online retailers operate: they store your credit card information on their own site and you log in with a user name and password. Automatic logins happen using cookies, again like Amazon.com or other retailers.

Both iTunes and .Mac are entirely web-based and both make extensive use of cookies.

The only credit card info stored on your system will be in any personal records that you keep on your Mac (say, in Quicken, for example.)

I see. Thanks for the clarification :)

So I guess if someone were able to send a "trojan" or something like this, they would have a hard time pulling info from iTunes and .Mac, but would be able to steal info stored on your hard drive, like excel files, etc. Well, that can only be a good thing, especially now that Panther will have protected files under the FileVault app.

I just hope that we'll never have to really worry about a Mac virus in the near future....

Chad4Mac
 

Powerbook G5

macrumors 68040
Jun 23, 2003
3,974
1
St Augustine, FL
My mom is always complaining to me about all these worms and virus after virus popping up lately...I keep telling her, they should have bought that iMac they wanted...but they insisted it would be too difficult to relearn a whole new platform and how Winows XP is supposed to be so much more stable and secure...even with anti-virus software, they've gotten a few just in the past month...
 

beefcake

macrumors 6502
Jun 22, 2003
257
0
Baltimore
Originally posted by Powerbook G5
My mom is always complaining to me about all these worms and virus after virus popping up lately...I keep telling her, they should have bought that iMac they wanted...but they insisted it would be too difficult to relearn a whole new platform and how Winows XP is supposed to be so much more stable and secure...even with anti-virus software, they've gotten a few just in the past month...
My Dell is side-lined and awaiting a format after getting whacked by a viruses and a worm. My Powerbook is looking better and better everyday.
 

Powerbook G5

macrumors 68040
Jun 23, 2003
3,974
1
St Augustine, FL
We have the same problem...our brand new Dell is dead and I just don't feel like doing a clean format and install *again*...man, I've had my PowerBook for over 4 years and only did a clean install once when I upgraded to OS 9...and this Dell is about 6 weeks old and already on its *third* format and reinstall...
 

Horrortaxi

macrumors 68020
Jul 6, 2003
2,240
0
Los Angeles
I've gotten about 50 of those today through the account I use for my website. It's public and it's in a lot of people's address books. The messages are the typical Windows "hey, I know you, you want to read this, if you don't understand just open the attachment, haha boy are you stupid" variety of virus. They're scr and pif files so they couldn't work on a Mac--unless you ran Windows in VPC. I've said it before and I'll say it again, 5% market share is a good thing.
 

beefcake

macrumors 6502
Jun 22, 2003
257
0
Baltimore
I did a fresh format, wiped the hard drive clean and even reconfigured the BIOS- still can't shake the worm. It's getting ridiculous, I wonder if I replace the hardware will the worm still haunt my desk.
 

beefcake

macrumors 6502
Jun 22, 2003
257
0
Baltimore
No email, it was all wiped out in the format. I've been able to look into the problem using my PB, and it seems that I missed a critical Windows update and its biting me in the a**.
 

wanderingnomore

macrumors newbie
Jan 11, 2009
1
0
Mac Email Virus??

I too have a problem involving apparent 'spamming' by someone who is using my email. I logged into my Yahoo email account yesterday and somehow it was used to send the following email message to everyone in my contact list:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Dear friend,
The 2009 is coming and all will be perfect in our life -- Studying,working ,loving & shopping .HereYou can do brilliant business also. I would like to introduce you a very good company which i knew.Their website is http://www.doublewin-trade.com .They can offer you all kinds of electronical products which you need like laptops ,gps ,TV LCD,cell phones,ps3,MP3/4, etc... Please take some time to have a check ,there must be somethings you 'd like to purchase or you can do business with them to ean much money.
Their contact email: doublewin_trade@vip.188.com . MSN: doublewin-trade@hotmail.com
Hope you have a good starting of the new year !
Regards
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Is this a virus, or just someone was able to use my email account to send spam? Either way, how do I stop it or get rid of it? Also, what are the consequences for all the people it was sent to? I am using an iMac.

Thanks
 

r.j.s

Moderator emeritus
Mar 7, 2007
15,026
52
Texas
Is this a virus, or just someone was able to use my email account to send spam? Either way, how do I stop it or get rid of it? Also, what are the consequences for all the people it was sent to?

Thanks

Someone has stolen your password, change it now.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.