Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Does this look a virus in my Mac?

I received an email with my daughters name, yet not her email address at cox.net. I forwarded the email to abuse at cox.net and received a reply with these headers, along with a reply from them for two OLD inquiry emails to persons/business I had sent a couple months ago. I have been having problems with my Mac Pro receiving email from Facebook persons who do NOT know my personal email and confirmed they had never sent. Here is the latest header from the Cox reply to the abuse send - supposedly. PLEASE ADVISE WHAT TO DO. My iCloud email has not worked well, either, yet my gmail accounts seem fine. Running Safari 5.1.9. (up to date it claims) and 10.6.8 OS on an 2x2.66 dual-core intel Xeon with 1 GB 667 DDR2 FB-DIMM supposedly up to day. I have reformatted, run Disk Warrior..... nothing seems to help.



From: Cox Customer Safety <abuse@cox.net>

Subject: [6.7.2013 13644033] Re: TEST

Date: June 7, 2013 11:42:01 AM CDT

To: Cox Customer Safety <deloreskirkwood@gmail.com>

Delivered-To: deloreskirkwood@gmail.com

Received: by 10.224.37.8 with SMTP id v8csp102656qad; Fri, 7 Jun 2013 09:42:01 -0700 (PDT)

Received: from eastrmfepo202.cox.net (eastrmfepo202.cox.net. [68.230.241.217]) by mx.google.com with ESMTP id k1si3046675qaz.47.2013.06.07.09.42.01 for <deloreskirkwood@gmail.com>; Fri, 07 Jun 2013 09:42:01 -0700 (PDT)

Received: from eastrmimpo109 ([68.230.241.222]) by eastrmfepo202.cox.net (InterMail vM.8.01.05.09 201-2260-151-124-20120717) with ESMTP id <20130607164201.LESW14810.eastrmfepo202.cox.net@eastrmimpo109> for <deloreskirkwood@gmail.com>; Fri, 7 Jun 2013 12:42:01 -0400

Received: from dukecautil01.mgt.cox.net ([172.18.18.217]) by eastrmimpo109 with cox id lUi11l0094h0NJL01Ui1BY; Fri, 07 Jun 2013 12:42:01 -0400

Received: by dukecautil01.mgt.cox.net (Postfix, from userid 100) id 2510A400011D; Fri, 7 Jun 2013 12:42:01 -0400 (EDT)

X-Received: by 10.224.39.77 with SMTP id f13mr3785704qae.96.1370623321426; Fri, 07 Jun 2013 09:42:01 -0700 (PDT)

Return-Path: <abuse@cox.net>

Received-Spf: pass (google.com: domain of abuse@cox.net designates 68.230.241.217 as permitted sender) client-ip=68.230.241.217;

Authentication-Results: mx.google.com; spf=pass (google.com: domain of abuse@cox.net designates 68.230.241.217 as permitted sender) smtp.mail=abuse@cox.net


Authentication-Results: cox.net; none

Message-Id: <20130607164201GMT.725222303357.cats13644033@dukecautil01.mgt.cox.net>


X-Auto-Response-Suppress: AutoReply

X-Loop: Cox Customer Safety <abuse@cox.net>

Mac Pro, Mac OS X (10.6.8)

Posted on Jun 7, 2013 11:02 AM

Reply
14 replies

Jun 7, 2013 11:26 AM in response to pjdxxxwa

you have heard of 'never open an email' or respond and all the warnings about phishing emails and such.


This member has the best help on the state of malware.


Thomas A Reed


I will tell you your Mac will not run well with that original 1GB RAM though.


How To Install and Remove Memory Mac Pro

https://support.apple.com/kb/HT4433


2x2GB FBDIMM DDR2 667MHz @ $32

http://www.amazon.com/BUFFERED-PC2-5300-FB-DIMM-APPLE-Memory/dp/B002ORUUAC/


This will put some added ***** and performance into your system tool


SSD: Samsung 840 128GB

http://www.amazon.com/Samsung-Series-120GB-internal-MZ-7TD120BW/dp/B009NHAF06/


I think you need to look closer at security settings for Fb and social media (or do you need and want those?)


Jun 7, 2013 11:32 AM in response to pjdxxxwa

What often happens is that someone with whom you or your daughter has corresponded has their Address Book compromised, and a spambot starts sending emails on your behalf. If wacky emails had come through your mail client, there would be copies in the "Sent" folder.


The important email is not the reply from cox, but the email originally sent to you.

Jun 7, 2013 11:47 AM in response to The hatter

My Mac worked find even with Snow Leopard until it changes to iCloud. However, it was minor problems until a few months ago.


I know all the precautions on email. The only reason I opened that one was because I was speaking to my daughter on the phone and she's just said, I will try to send this to you. I saw her name and missed seeing it was not her email addy until too late.


Now I am getting dozens of emails with cox.net return subject lines from more old emails I have sent. Also, these types of email are ALWAYS address to my mac.com address - never to my gmail.address so even that is suspect. That is why I ask about viruses.


My FB account is as tight as it can be with my personal information. It has NEVER been available publically but I wonder if it originated in FB since I sign in using my mac.com email.


Futhrer suggestions?

Jun 7, 2013 12:03 PM in response to pjdxxxwa

worked fine and 1GB RAM in the same breath... your system is starving and unable to perform as it should. I know, I have one, and I know how OS X will starve apps or will use RAM effectively.


Safari alone can eat up 1GB RAM.


The stuff I linked to will make a differnce and it is 1/20th what it cost in 2007 - the preferred configuration quad channel symmetrical memory, 4 DIMMs, a pair on each Riser, and not two OEM 512MB you have had now for ages.


If either of you correspond with Windows users and there system or they opened an email all kinds of things go on, like harvesting email addresses from Contacts. Bad enough Fb and others also want to know and harvest your contacts. Or using the same email or passwords for multiple accounts.


I don't use iClould, there is a forum and support page, and there have been issues with it.


No, you don't have a virus. And the word can be stict or loosely as to what "virus" means or not, but Thomas is one of the #1 on the subject. Web based java and other things being more of an issue today.


I know how to tune my Mac the same way I tuned sportscar 50 yrs ago. Your mac is not running up to snuff as it is capable and intended. Throw in a pair, put in an SSD, probably the original graphic card too before it fails and do a clean install (unless you just did one).


And you don't need and DW does not address anything happening on your system. A new drive might. And clone your system as needed with CCC and swap which drive you use to boot from will.

Jun 7, 2013 12:14 PM in response to The hatter

I h ear what you are saying, but.....


I don't chat online, I don't play games on FB. All I do there is look at the main wall and forward a post, or perhaps upload a Png of about 400 kg to it.


I don't play games on the computer. I may do an occasional Meme, then put them away in a folder (on my desktop) if it something I am currentlly working on, otherwise most of my work is on a Mac Word document in text format only.


Have been working this way since 2007 - so, I guess I am asking if upgrading from Tiger to 10.6.8 is using all this RAM? I have tried Firefox, also, and initially the problem began with it.


I just do not see how lack of RAM is shooting me all these bogus emails.

Jun 7, 2013 1:18 PM in response to Grant Bennet-Alder

My problem at the moment is receiving emails at the mac.com address from people (allegedly) who I know, but have not sent them.

I spoke to an engineer from Cox.net who returned my phone call, saying the system was shooting my incoming mail to their abuse department - and I have since noticed that some of the emails returned to me from their reply has someones name I know, yet MY email address (gmail) behind THEIR name.

I can onlly conclude that there is something (now) in my MacPro (that may have originated from Facebook) that is now privy to the email I send and receive through MobileMe where all my mail goes.


Suggestions on what to do to reverse this? I have changed my gmail p/w - and hesitate to put the new p/w in the MobileMe Mail. I am NOT hooked up iCloud - never was - only the mail.


Should I just shut down MobileMe? Get a malware/virus finder? I am trying to refrain from upgrading at this time, I plan to purchase a new Mac when I get back to WA state in October.

Jun 7, 2013 1:18 PM in response to pjdxxxwa

2GB and app "A" uses a small part of memory, upgrade to 4GB and it can breath better and use more RAM than it did before (same OS). And yes every new OS, every new app like Safari 6 vs 3 or 4, uses more or is designed to and runs better.


The minimum for SL I thought even was 2GB with 4GB recommended (the number of "my computer is slower now" thread on SL and even Leo and then Lion) are rather legendary. A new OS will always make better use of and run better with more RAM.


I like to call the default 1 or even 2GB as starvation and anemic.


And it could indirectly as your system has had to pageout blocks or memory to disk and then read back into RAM affecting proper functioning in ALL apps (and the OS needs 250MB probably to function and manage everyone, if not more).

Jun 7, 2013 1:26 PM in response to The hatter

Hatter, this last paragraph. Are you saying that lack of RAM could be causing bogus emails from people (not in my address book) but are listed as the sender?


Some of the emails are off line people on Fabebook that I do not talk to outside of web post. I don't have their email address, they don't know mine because it has always been private - me only.


Confirm please. I will be back later, I have to go to an appt. right now.

Jun 7, 2013 1:31 PM in response to pjdxxxwa

no relation between bogus and bogged down system


you may want a new system - I would wait until more is known of fate of Mac Pro line etc - but yours woujld FEEL like and run like - no not like - better then it ever did - with RAM, SSD, and graphic card (and some backup drives and new data drives) and get another year or two out of this one, and run Lion (better support going forward).



The only reason for 10.6.8 is to run older software and avoid having to buy new versions that no longer rely on Rosetta.

Jun 7, 2013 1:32 PM in response to pjdxxxwa

All you can tell for sure is that someone has your email Address.


The likelihood that YOUR Mac is infected is quite small.


It is far more likley that someone else's computer, to whom you wrote ONCE has your email in their Address Book, their Addresss book was "Stolen" and now yet another computer is spewing out emails [supposedly] sent by you. To be YOUR email, it would have to have YOUR IP Address as the original Sender.

Jun 7, 2013 3:30 PM in response to Grant Bennet-Alder

Thanks for backing up my suspicion that something in awry in Facebook, because there is no one I wrote to who could have known of the couple facebook emails I received because those people are not in my address book, FB does not show my email to anyone oher than myself, and my mac.com email (since FB assigned theirs) has not been iin the informatoin section - other to what FB has on sign up several years ago.


I will open a new FB acct - take the old one down and put a yahoo.com address in - one I have NEVER used and see what happens from there. Plan to change every password I have also, to see if that helps or not.

Does this look a virus in my Mac?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.