Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

virus attack

My E mail appears to have been corrupted by some form of trojan or other viral software. It replicates my e mail address and sends out an e mail eith an attachment advertisement. Sophos does not appear to pick up this virus, any suggestions??

Regards

Dennis

:1010572


This thread was automatically locked due to age.
  • Do you have evidence that your email client is sending out the attachments, or is it just that others are receiving malware purportedly from you?

    "From" headers are commonly forged in spam messages, and it could just be that some piece of malware has your address on its list, and is forging it from you.

    However, the other common thing that's found is people using webmail who either use a simple-to-guess password, or re-use their username and password across sites.  In these cases, the attack system just attempts to log into your email account, harvest your address book, and then either use your account to send email to your address book contacts,  or do the same thing via a botnet.

    As far as I know, there are no in-the-wild Mac pieces of malicious software that attempt to spew malware from your local computer via your local email client.  This is obviously subject to change, and there ARE a number of malicious remote access packages that could be used to accomplish this task, even though it isn't their primary objective.  We tend to do a pretty good job at detecting these, however.

    :1010578
  • Thanks for your reply, this has happened before and I suspect I re-introduced the virus by rebuilding back from an external hard drive that must have stored the original message.

    The initial attack though when I ran the virus scan picked up the malware or trojan and enabled me to delete/repair this has not happened on the last two scans?

    regards

    Dennis

    :1010586
  • It sounds like it's cleaned from your main drive but is still detecting the archived copies, which it can't delete without damaging your archive.  Does this sound reasonable from your scan logs and experience?

    :1010612