My fiancees' computer is running Mac OS X 10.4.6 (I think)..her MSN e-mail is sending e-mails to her contact list with links to Canadian Drug websites. I've run clamxav numerous times and cant seem to get rid of it. Any help on where to find this pain in the rear and eradicate it would be of immense help (in the form of stress relief). Thanks!

Dani AI

Generated

Brief, practical follow-up based on this thread: building on ' point about remote access, here is a compact checklist and some targeted checks to confirm where outgoing spam originated, harden the account, and perform a focused Mac cleanup.

Immediate account checks:

  • Reset the e-mail password to a new, unique passphrase and enable two-factor authentication where available. Use a password manager so the new password is not reused elsewhere.
  • From the webmail interface, sign out all sessions or revoke active sessions/app passwords, then remove any unknown recovery addresses or phone numbers.
  • Look for and delete any forwarding rules, auto-replies, or delegates in account settings.
  • Inspect a few of the sent messages' full headers (view message source or "show original") and read the earliest "Received" line to find the originating IP; that tells whether the mail was sent from a remote host or the provider's web servers.

Focused Mac checks and cleanup:

  • Open Keychain Access and remove any saved credentials for the affected account.
  • Audit browser extensions and stored passwords; remove unknown extensions and clear saved site passwords relating to the account.
  • Check login items and common launch locations for persistent agents: ~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemons. Also review any crontab entries. Do not delete items unless their purpose is understood; copy suspicious files to a safe folder first.
  • Run an up-to-date macOS malware scan (safe mode if possible) and remove confirmed threats.

If messages continue after all of the above, escalate to the mail provider (report the compromise and provide header evidence), notify contacts not to click links, and consider replacing the address as a last resort. Most incidents like this are credential compromise or a malicious forwarding rule rather than a deep Mac infection; the steps above will diagnose which and reduce the chance of recurrence.

Recommended Answers

All 5 Replies

Hello,

Can her email account be accessed on the internet?
Is it Webmail?

If she can, change the password, someone my have the password for this account.
HINT: have a look at the time email was sent, if the computer which she's on is not switched on that would suggest that someone is using the account on another computer.

- Let us know how it goes

Thanks for your reply. It is MSN email, web based of course. The emails go out at various times but mostly around 0400 or 0500 AM eastern time and the machine is always on.

Hello,

Best option is to change the password for the email service; Check again for malware. If this happens regularly shut down the machine before the emails are usually sent, if emails are still sent then someone is probably accessing the account on another machine.

- Let us know how it goes.

It does seem they were sent from another location. She (girlfriend) spoke to another IT guy who explained a whole different scenario that could be resolved by getting a new e-mail address - I've never seen this info any place on the web which I find puzzling to say the least. So far so good for the weekend and she hasn't taken action other than changing her password. I'll keep you updated.

Well no news is good news. Nothing sent as far as I can tell since the pw change. Issue solved for now!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.