Virus 8399.emlx

I have a virus that continues to appear but gets detected by ClamXav. The identified virus is 8399.emlx and it is found in my

/Users/(Mydirectory)/Library/Mail/IMAP-(My email)@imap.gmail.com/[Gmail]/All Mail.imapmbox/Messages/8399.emlx:


After it is found it reappears and the only function I am performing is Web browsng with no downloads. Anyone have any experience or knowledge of the virus?

MacBook Pro, Mac OS X (10.6.8)

Posted on Jan 9, 2012 8:35 PM

Reply
Question marked as Top-ranking reply

Posted on Jan 9, 2012 10:58 PM

macfrombrampton wrote:


I have a virus that continues to appear but gets detected by ClamXav. The identified virus is 8399.emlx and it is found in my

/Users/(Mydirectory)/Library/Mail/IMAP-(My email)@imap.gmail.com/[Gmail]/All Mail.imapmbox/Messages/8399.emlx:

Actually, that's the name of the e-mail message file that may be infected. It's not a virus nor is it the infection name.

After it is found it reappears and the only function I am performing is Web browsng with no downloads. Anyone have any experience or knowledge of the virus?

You don't say how you are trying to get rid of it, but there is only one way to safely process an infected e-mail and that is from within the e-mail client (Apple Mail in your case). Otherwise you will most certainly corrupt the mailbox index (which can usually be fixed by rebuilding the mailbox), could cause you to lose additional e-mails and as you found, sometimes does not delete the file from the server, so it comes to your computer again the next time you check for new mail.


You can either navigate to the location shown above or the next time ClamXav finds it, Right-click / Control-click on the file or infection name and select "Reveal In Finder" from the contextual pop-up menu. Once the file appears in the "Messages" window, double-click on 8399.emlx and read the message. If you agree that it is an infected message that you don't need, make note of the date and subject of the e-mail (you will need this in the step below) then use the Mail delete button to trash it, then if you have elected to move deleted message to the trash, be sure to empty the trash mailbox. If it appears to be a false alarm and is an e-mail you want to retain, write down the number so that you can ignore it during future scans.


With gmail accounts, there is sometimes an additional step to permanently delete the message. Log into your gmail account in webmail using your favorite browser. Go to the "All Mail" mailbox, search for that message using the subject and date copied above. Use the webmail delete button and again make sure to empty the trash if there's anything there.


And in the future I would encourage you to visit the ClamXav Forum where you will find the answer to most situations and usually a faster response if you don't find it.

58 replies
Question marked as Top-ranking reply

Jan 9, 2012 10:58 PM in response to macfrombrampton

macfrombrampton wrote:


I have a virus that continues to appear but gets detected by ClamXav. The identified virus is 8399.emlx and it is found in my

/Users/(Mydirectory)/Library/Mail/IMAP-(My email)@imap.gmail.com/[Gmail]/All Mail.imapmbox/Messages/8399.emlx:

Actually, that's the name of the e-mail message file that may be infected. It's not a virus nor is it the infection name.

After it is found it reappears and the only function I am performing is Web browsng with no downloads. Anyone have any experience or knowledge of the virus?

You don't say how you are trying to get rid of it, but there is only one way to safely process an infected e-mail and that is from within the e-mail client (Apple Mail in your case). Otherwise you will most certainly corrupt the mailbox index (which can usually be fixed by rebuilding the mailbox), could cause you to lose additional e-mails and as you found, sometimes does not delete the file from the server, so it comes to your computer again the next time you check for new mail.


You can either navigate to the location shown above or the next time ClamXav finds it, Right-click / Control-click on the file or infection name and select "Reveal In Finder" from the contextual pop-up menu. Once the file appears in the "Messages" window, double-click on 8399.emlx and read the message. If you agree that it is an infected message that you don't need, make note of the date and subject of the e-mail (you will need this in the step below) then use the Mail delete button to trash it, then if you have elected to move deleted message to the trash, be sure to empty the trash mailbox. If it appears to be a false alarm and is an e-mail you want to retain, write down the number so that you can ignore it during future scans.


With gmail accounts, there is sometimes an additional step to permanently delete the message. Log into your gmail account in webmail using your favorite browser. Go to the "All Mail" mailbox, search for that message using the subject and date copied above. Use the webmail delete button and again make sure to empty the trash if there's anything there.


And in the future I would encourage you to visit the ClamXav Forum where you will find the answer to most situations and usually a faster response if you don't find it.

Jan 9, 2012 10:47 PM in response to macfrombrampton

In ClamXav, choose Help > ClamXav Help, or go to


<http://www.clamxav.com/documentation.php#infected>


and read Dealing with Infected Files. Heed the warning about deleting or putting in quarantine e-mail messages. So use Reveal in Finder to show the respective file, double-click on it to open it in Mail, and delete it. Then make sure to delete the message from server, otherwise it will show up again.


As to the malware itself, it's not going to affect your Mac in any way. But, by finding and deleting it, you made sure you wouldn't pass it on to a Windows-using friend or acquaintance, who might very well have been affected. You've done your good deed for the day. You can now go to sleep with a clear conscience.

Jan 13, 2012 9:20 PM in response to macfrombrampton

macfrombrampton wrote:


This is a Virus as it has appeared in the same spot after more than 10 deletions and i noticed other posts.

Listen to me. There are no Mac viruses, period, and a phishing email is not a virus. That message is still on Google's gmail server and gets downloaded to your hard drive every time you check for new mail.


As I said last night, Google reportedly has a fix for that, so it perhaps it will now go away.


If you want it to be gone for good then you I strongly recommend you log onto Google gmail using your browser, not Mail and delete the message there, but to find it you must know the subject and date it was sent out. If you haven't opened it up to find that information then you may be stuck with it forever.

Jan 25, 2012 8:21 AM in response to suefrommountainview

This is not a virus. Sounds like you fell victim to a phishing scam - someone else sent that e-mail, which redirected you to a fake site that captured your login information. So now hackers have access to your e-mail account, and who knows what they might have done. You need to change your e-mail account password ASAP if you can, and if you can't you need to contact your e-mail provider and ask for help.

Apr 25, 2012 12:17 PM in response to macfrombrampton

By allowing ClamXav to delete e-mail messages, you are corrupting your mailboxes and possibly allowing the message to come right back in from the IMAP mail server (which it has not been removed from, since it was not properly deleted). You should stop doing that, rebuild all your mailboxes, and in the future delete those e-mail messages manually. They cannot hurt you unless you click the link(s) in them and then provide personal information at the spoofed site you end up on.

Apr 25, 2012 3:42 PM in response to macfrombrampton

In my sixteen or seventeen years of regular participation in these forums, starting about 1994/5, I've never encountered anyone as resolutely determined not to benefit from the help he has asked for as you are, macfrombrampton.


ClamXav, like many other troubleshooting and diagnostic tools, uses heuristics — experience-based "rules of thumb" — to flag some potential threats to your security. One of those rules of thumb is "flag any email message containing a link to a web site that pretends to be somewhere it's not," because experience indicates that an intentionally misleading site is often designed to fool visitors into supplying personal information about themselves that can then be criminally misused. A great many such email messages are filtered out as SPAM by most ISPs or by the user's own email client software, but there are so many of them sent that a few get through to you, and those few messages are what ClamXav is flagging. The messages themselves are harnless — they have no payload that installs itself or performs any action on your computer. The only way any harm can come to you from them is if you 1) click the links they contain, and 2) supply the information you are asked for by the sites those links take you to.


In other words, those email messages are merely SPAM inviting you to put your security in jeopardy. If you're disinclined to do that, all you need to do is delete the email messages in the manner provided by your email client application. You don't need to use ClamXav to delete them, and as Thomas has warned you, deleting them in any manner other than the one provided by your email client is apt to corrupt the database that your email client maintains. Doing that is exactly analogous to using the Finder to delete pictures from an iPhoto Library or music from an iTunes Library — two other things one should never do, because the result will be a corrupt library database that refuses to open at all or exhibits anomalous behavior when it does open. The proper way to delete pictures from an iPhoto Library is to do it within the iPhoto application, and similarly, the proper way to delete email messages from a Mail database is to do it within Mail.

Apr 25, 2012 10:50 PM in response to eww

eww wrote:


all you need to do is delete the email messages in the manner provided by your email client application. You don't need to use ClamXav to delete them, and as Thomas has warned you, deleting them in any manner other than the one provided by your email client is apt to corrupt the database that your email client maintains. Doing that is exactly analogous to using the Finder to delete pictures from an iPhoto Library or music from an iTunes Library — two other things one should never do, because the result will be a corrupt library database that refuses to open at all or exhibits anomalous behavior when it does open. The proper way to delete pictures from an iPhoto Library is to do it within the iPhoto application, and similarly, the proper way to delete email messages from a Mail database is to do it within Mail.

You can add TimeMachine/TimeCapsule to that list. For the most part it won't let you mess with individual files in the Finder, but if you insist on moving or deleting something, you almost certainly will correupt it's index and make it a worthless backup. TM/TC files need to be deleted from within TimeMachine.

Jan 16, 2012 1:58 AM in response to macfrombrampton

macfrombrampton wrote:


This is a virus for 2 reasons


1) Clamxav finds this virus even though it has showed up with 3 different file names

2) I removed the file from mail and the Gmail server and it still shows up

OK, I see your point, but since it's only showing up on your Mac because it keeps showing up on the Server (as a new message, if I understand what you are saying) it's not spreading by itself, which is what a virus can do.


Are all these messages from the same source? Does it appear to be from an organization you deal with or just junk mail?


The reason I ask is that in my mail I have 20 or so e-mails that have been identified as heuristic.phishing and they are all newsletters from my credit union that contained a link to FaceBook. It was flagged because it didn't come from FaceBook. When I complained that I didn't think FaceBook deserved to be protected as a financial institution and that it would be referenced by hundreds of organizations looking to be "liked" they removed it. I still get a few similar hits, but in every case both the e-mail and the link have checked out and I want to keep them. I just make note of the file names and ignore the hits.

Jan 17, 2012 6:22 PM in response to macfrombrampton

MadMacs0 has already explained to you - repeatedly - that this is not a Mac virus, that it is in fact not a virus at all, and has explained in great detail what it is likely to be. What part of his posts are you having difficulty understanding? He is not just a fanboy repeating the phrase "there are no Mac viruses." He is extremely knowledgeable on the topic of malware on the Mac. I am no slouch on that topic myself - CMCSK has already given you a link to my Mac Malware Guide - but even so I would likely defer to MadMacs0. By repeatedly ignoring the information he has provided you, you are being exceedingly rude, not to mention throwing very good knowledge out the window.


In addition to everything else that has been said about how improperly-removed e-mails can come back, note that these phishing e-mails are often spam, sitting in your junk mailbox, and will repeatedly keep coming back once you are on the spammer's lists. There is nothing whatsoever you can do about that except be careful about links you click in e-mails and not opening attachments from people you don't know.


You do not have a virus!

Jan 26, 2012 5:58 PM in response to macfrombrampton

macfrombrampton wrote:


If it is not malware why is ClamAV identifing the specific file on my Mac?

I did not say it wasn't malware, I said it wasn't a virus and it might not even be malware. As I explained before, the clamav engine identified a link within the message which is on their list of protected financial sites. It then applies 28 tests to see if there is anything suspicious about the link. One test is do the words you see in the link match up with the web site it will take you to. Another is does the From address match the link? If not then the message may not be from who it says it is and could be a phishing attempt. Do you know what phishing is? The engine is guessing that it might be malware, but it could very well be a false alarm.


I also told you that I have several e-mails which the clamav engine marked as a possible "Heuristic.Phishing.email.SpoofedDomain" but they are not. They are newsletters from my Credit Union that contain a link to irs.gov which is a protected link. The e-mail is really from my Credit Union who is telling me that if I need tax help to go to irs.gov to get it. It is a false alarm.


Now it's your turn to answer a question. Who does the message come from and what links are contained in that e-mail?

I am to understand that you think that Clamxav which can be downloaded from Apple store searches your files and displays after the search Heuristic.Phishing.email.SpoofedDomain so that a user can just look up the name?

Yes. The clamav folks do not routinely provide detailed information about any of infections, but in this case they provided a three word definition http://wiki.clamav.net/bin/view/Main/MalwareNamingURL domain mismatch

Apr 26, 2012 6:41 PM in response to macfrombrampton

And you never will be able to locate any, because "Heuristic.Phishing.email.SpoofedDomain" is not the name of a piece of malware. It is the name of a rule used by ClamXav to identify certain email messages containing falsified links. Those email messages are harmless if you don't click on the links in them and supply personal information about yourself.


I have reported this entire thread to the forum hosts as a months-long dead end in which you have wasted the time of every person who has replied to your broken-record posts. With any luck, the whole sorry mess will be gone tomorrow.

Jan 17, 2012 4:24 PM in response to macfrombrampton

macfrombrampton wrote:


This virus appears to be coming from false Google alerts emailed to me. I would like to know from any other Macbook OS snow leopard if they know the function of this virus. If Clamav is able to identify it as "Heuristic.Phishing.email.SpoofedDomain" then there must be a function for this virus.

As many have said, it is not a virus.


  • Heuristic means that they clamav has no proof that this is malware, but by applying 28 different tests they are guessing it could be.
  • Phishing means that it could be an attempt to harvest personal information about you (userID, Password, Creditcard number, etc.) by asking you to enter it into a form that is revealed when you click on a link that takes you to a web page.
  • email is self explanatory
  • SpoofedDomain indicates that there may have been an attempt to disquise a clickable url as some other site (probably Google) when it actually takes you to the bad guys site.


If you would like a second opinion on any of these terms you can find them on WikiPedia, but it's about to be shut down for a day or two, so you need to hurry.


I don't know why it makes a difference as to whether I use a MacBook and Snow Leopard, but I don't currently use either. I do provide uncompensated tech support on the afore mentioned ClamXav Forum, however.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Virus 8399.emlx

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.