"unrepairable virus detected" says MAILER DAEMON....victim of spoofing?

Arg. A few months ago my friend's email was put onto a blocklist, because it was detected that his mac was vulnerable to hackers. We went to a website where we requested his IP be removed from this blocklist, and everything started working as normal again. Well, today he received an email stating that an email (which he never sent) is being returned to him because the mailer daemon has detected an "unrepairable virus".....is this cause for major concern?!
Could he in fact have a virus? He uses an iMac 20"/1.8 Ghz (running on Panther) and purchased in March '05....could this make him more vulnerable than those of us running on Tiger with newer machines?
Is there any way to stop hackers from using his email address?
Will his IP eventually get block listed again?
Or is the mailer daemon email ITSELF A SPOOF?
aaaaaaaaaahhhhhhhhh
iMac G5 Intel Core 2 Duo 2.16 Ghz   Mac OS X (10.4.8)   *peace can happen*
iMac G5 Intel Core 2 Duo 2.16 Ghz   Mac OS X (10.4.8)  
Powermac G4 733 MHz, 512 MB   Mac OS X (10.3.9)  

Stanley,
Since wireless networking involves broadcasting traffic that can be intercepted by any appropriately tuned receiver within radio line of sight, I stand by my statement.
Second, you are creating a single point-of-failure for your network's security. Given the huge number of known router vulnerabilities, using the BSD-standard firewall ipfw, for which Apple has so kindly provided a user-friendly and easily-understood GUI, makes for a solid second layer of defense.
Making regular data backups and properly configuring your router are both VERY GOOD IDEAS(TM), but, even taken together, they are not "all the average person needs" with respect to computer security.
Computer security is a process. You have named two good practices in that process, but there is no single "magic" bullet that makes computers secure, not even for the average person.
-Wayne

Similar Messages

  • Keep getting mailer-daemon in email

    I have an iPhone 4s and use my email on there but just in last couple of days i have had over a 1000 emails saying mailer-daemon they are still coming in to my phone now as i write this message. How can i stop this please? I have changed my password and that not done anything as i still getting these emails. My fear is that it could affect the softwere on my phone or more. what can i do? can anybody help please?

    Contact the email provider and find out what is going on.

  • Virus Detected in inbound e-mail

    I have been getting alerts on mac os server pertaining to the mail:
    Virus detected in inbound email
    A virus was detected in an inbound email. The message containing the virus was not delivered to the intended recipient and has been moved to:
    /Library/Server/Mail/Data/scanner/quarantine
    It is recommended that you delete all messages in this directory. Messages left in the above location for longer than 72 hours will be automatically deleted.
    However when I go look in that folder it is empty (I know it deletes in 72 hours but I look immediately).  I get no info on who it was intended for, what was really done with it, if it was a mistake or anything.  Am i missing something?
    Thanks

    I found this post on Google, sorry to dig up an old thread but I'd just like to say you can inspect them this way:
    sudo su
    cd /Library/Server/Mail/Data/scanner/quarantine
    ls
    If the files are gz format like they are on my server you can:
    zless <bad file name here>.gz
    Then use your up and down keys to see the HTML content or anything else. In my case it was actually a legitimate message being marked as spam, not a virus at all!

  • I have received text messages from mailer-daemon. Do not use my 4S for email. Is it a virus?

    I have received 2 text message from 'mailer-daemon'  I do not use my 4S for email. Is it a virus?

    No

  • Mail server rejected message: spam or virus detected (#5.3.0)

    Hi everybody,
    for the first time ever I got this funny message:
    mail server rejected message: spam or virus detected (#5.3.0)
    This happens now with e-mails containing a pdf which I a) have already sent before and b) created on the mac. Checked with another pdf just for testing - same effect. Any other documents work fine - just those pdfs don't work anymore.
    Any ideas?
    Thanks in advance,
    Bettina

    Bettina,
    There is the possibility of the MS Office and Word being infected (but not the Mac overall) with what are called micro-viri, and are cross-platform. Many AV filters will catch those. I am providing a link where some of us discussed this MS Office infection:
    http://discussions.apple.com/thread.jspa?messageID=2782109&#2782109
    Let us know what you find? See also:
    http://outlandishjosh.com/wp/index.php?p=861
    which you will see in that topic linked above.
    I have not confirmed the path you chose to create the PDF will transmit this virus, but this must be checked out, and is probably the source of the message you are getting.
    Ernie

  • I have iphone4, I keep getting mailer daemon notices, I didn't email these people. Did I get hacked, or is it a virus? I changed my email password but it is still happening. If its a virus, what do I do?

    I have the iphone4, I keep getting mailer daemon messages, returning emails that won't go through that I didn't send. I change my email password incase I was hacked, but I'm still getting failed emails that I didn't send. Is it a virus? What do I do?

    This is what the mailer daemon looks like:
    Sorry, we were unable to deliver your message to the following address.
    <[email protected]>:
    Message expired for domain evaluateusa.com. Remote host said: 451 Can't connect to evaluateusa.com - psmtp [RCPT_TO]
    --- Below this line is a copy of the message.
    Received: from [98.139.52.195] by nm28.bullet.mail.ac4.yahoo.com with NNFMP; 19 Jan 2012 20:27:27 -0000
    Received: from [98.139.52.178] by tm8.bullet.mail.ac4.yahoo.com with NNFMP; 19 Jan 2012 20:27:27 -0000
    Received: from [127.0.0.1] by omp1061.mail.ac4.yahoo.com with NNFMP; 19 Jan 2012 20:27:27 -0000
    X-Yahoo-Newman-Property: ymail-3
    X-Yahoo-Newman-Id: [email protected]
    Received: (qmail 68123 invoked by uid 60001); 19 Jan 2012 20:27:26 -0000
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1327004846; bh=R5BkyvFcy4/U47AahH4TrjFSBe8QVwHdIXBd0DNPF00=; h=X-YMail-OSG:Received:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Co ntent-Type; b=XWiKOCxM/R+eOa+hBeisSIWk3DKTypVATt5xi0ojZQmZSLeUsejF7v7/vGJ5tJSziy6EMLjwp/MvJ Idc/XFW/za7um6xdI0+64zeauU2FUUV+y124SaWfWntrlBxkLkB5K6m7490BDR365tTaFPK44DSosvbI 93KmjncWZq5w94=
    DomainKey-Signature:a=rsa-sha1; q=dns; c=nofws;
     s=s1024; d=yahoo.com;
     h=X-YMail-OSG:Received:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Co ntent-Type;
     b=U+JK5UiWiR+Pr/F4Z6nUK90715kNFCovrFQdSe4mMkwmg5XHX2+4nI4yffoNyyG1hB/T/ydUaR2pc KvOPyzNlAgII14vLTO4VRR+65duR6Z5ACtEHoMj7jtnM8hbFQjbRs5kAIOF1iUlFwcnHPzP6vF3+XE/d /yE0/L0pPON7hk=;
    X-YMail-OSG: BJt_s.cVM1mbf4z50ODBQnThWXcLFLwDlMofzG1gll2d6Cp
    Ga_uy3DeVzKncjCcdq5jHnfhnRoL3dN1PGrWGTVf2jv2W9.mcllUym3Ko_hH
    BEr4.HhBhQIUI0bbPgTlXAVEQhx5CGy8OMRCZJysmsMMOV8ou0VTEZAsJ9BU
    DsCmjcDgiCuIv9JYbQSJFufFml1sVRnLUHRmGKrrGuJGbjwyA_wTMlSQTUXP
    xTddw2mCS3wzH1YIQw7xF8gryLEPkxx..TXO6Az_oWvOwYCTddhPIpfLVgA9
    FSS4ayCZOOdjPOVE8bDdS5DsEAhjUB3dFOVcx0WLBgP8XyMtSZaICB4xAECM
    D_sNs1CaMyXklCmLQyDhxCK01QsxjpwJhP4n3.SiPlYqCXcil945TkmN1SXj
    sXNkp43woFdYXMGmytbd8XjC5cemHU95ZJEnZD8nOcgSC003eBtZkGBrJcLP
    HglVM4uG877_iXQb_il4J6c.dwOgFS7ZYalQogxZTxD0VVYky3p2NQ16CaGv
    qyhMGtivFkQboHHBhsEYx11ybrxeu0sIekO7ZrYnKrGQL679ibsQ_gKYAN2R
    E
    Received: from [147.46.164.250] by web38501.mail.mud.yahoo.com via HTTP; Thu, 19 Jan 2012 12:27:26 PST
    X-Mailer: YahooMailWebService/0.8.115.331698
    Message-ID: <[email protected]>
    Date: Thu, 19 Jan 2012 12:27:26 -0800 (PST)
    From: Anna Southworth <[email protected]>
    Subject: Yo
    To: [email protected], [email protected],
     [email protected], [email protected],
     [email protected]
    MIME-Version: 1.0
    Content-Type: text/plain; charset=us-ascii
    This is for you:)  http://gradit.com/febrary.html

  • Virus detected in inbound email

    We have just upgraded to OSX Server 3.0.3 and am now getting alerts saying "Virus detected in inbound email".
    Go to /Library/Server/Mail/Data/scanner/quarantine 
    When I go to the folder, I don't have permission to get into it even though I am logged into the server as the administrator?
    I need to see if these are coming from customer or not.
    Any ideas on how to inspect them much appreciated.
    Thanks
    Carl

    I found this post on Google, sorry to dig up an old thread but I'd just like to say you can inspect them this way:
    sudo su
    cd /Library/Server/Mail/Data/scanner/quarantine
    ls
    If the files are gz format like they are on my server you can:
    zless <bad file name here>.gz
    Then use your up and down keys to see the HTML content or anything else. In my case it was actually a legitimate message being marked as spam, not a virus at all!

  • Sendmail---Mailer Daemon query

    If this is the correct forum i am posting in please read further otherwise you may redirect me to correct link.
    I want to control Sendmails Mailer-Daemon messages.
    When a user sends mail to a list maintained using aliases
    and one or more accounts specified in alias file are not existing.....instead of sending a bounced message from
    Mailer-Daemon to Sender....can i direct this bounced mail
    to system administrartor...so that he can remove those names from alias file....
    For example....
    I send a mail to list [email protected] where "list" is an alias file at listserver.com with accounts:
    account1
    account2....and so on till accountN
    Suppose one or more accounts are not existing now but
    these have not been removed from "list"....Obviously i will get MAiler-Daemon for that....So instead of me receiving these bounced mails...can i redirect them to system
    administrator...
    Thanks in advance...

    Our sendmail expert says to read
    http://www.sendmail.org/faq/section3.html#3.15
    More appropriate places for sendmail support would be
    http://sendmail.org , http://supportforum.sun.com/network ,
    http://sun.com/bigadmin , or http://opensolaris.org/os/community/networking .

  • Sendmail---Mailer Daemon

    If this is the correct forum i am posting in please read further otherwise you may redirect me to correct link.
    I want to control Sendmails Mailer-Daemon messages.
    When a user sends mail to a list maintained using aliases
    and one or more accounts specified in alias file are not existing.....instead of sending a bounced message from
    Mailer-Daemon to Sender....can i direct this bounced mail
    to system administrartor...so that he can remove those names from alias file....
    For example....
    I send a mail to list [email protected] where "list" is an alias file at listserver.com with accounts:
    account1
    account2....and so on till accountN
    Suppose one or more accounts are not existing now but
    these have not been removed from "list"....Obviously i will get MAiler-Daemon for that....So instead of me receiving these bounced mails...can i redirect them to system
    administrator...
    Thanks in advance...

    Our sendmail expert says to read
    http://www.sendmail.org/faq/section3.html#3.15
    More appropriate places for sendmail support would be
    http://sendmail.org , http://supportforum.sun.com/network ,
    http://sun.com/bigadmin , or http://opensolaris.org/os/community/networking .

  • Mailer-daemon

    Hello,  I have been receiving dozens of "mailer-daemon" failures emailed to me saying that my email did not reach the recipient.  I have sent none of these emails.  I am also being notified by people on my email list that they are receiving ( some people have received dozens ! ) an out-of-office reply from me .... Once again, I am not sending any of these out.  I am also finding that my Mac Mail is freezing-up a bit when I scroll through the emails or type something. My Mac Mail is linked to my Yahoo account.  I cleared all my history from my CHROME Browser from the beginning of time & nothing has helped. My email is a "yahoo.ca" address.  I phoned Yahoo, but of course was on hold for 20 mins and then got disconnected.  I also talked with Mac Support & they said this issue did not sound like a Mac issue.  **  Why is my Mac Mail freezing-up if it's not Mac-related ?!   All I can say is HELP !!!    Thanks very much ....  N

    First of all, tell sorbs to go stick their $50 where it hurts. Their extortion technique is distasteful, to say the least.
    As for the issue itself, it has nothing to do with you filtering incoming mail to your spam/junk mailbox. It has everything to do with mail you send out.
    If you have your system set to send mail directly you need to be aware that many ISPs will block these emails if you're on a dynamic IP address. This happens mostly because legitimate mail servers don't usually sit on dynamic IP addresses, a lot of spam comes from dynamic mail servers, and it's harder to track down spammers if they come from dynamic IP addresses.
    So what's happening is that Sue's ISP is blocking your mail because you're trying to send it directly to their mail server from a dynamic IP address.
    The simplest solution is to configure your mail server to relay your mail through your ISP. In this setup you send your message to your local mail server when then sends it to your ISP (who accept it because you're on their network). Your ISP then sends the message to Sue's ISP who now accept it because it comes from a known mail server (your ISP's) on a static IP address.
    Assuming you're using the built-in postfix mail server and you haven't don't any significant customization of its configuration, edit the file /etc/postfix/main.cf and look for a line 'relayhost'.
    Change this line so that it contains the name of your ISP's mail server, like:
    relayhost = mail.yourisp.com
    Save the file and issue the command: postfix reload to load the new configuration. Now postfix will send outgoing mail through your ISP and you won't get blocked by dynamic IP blacklists like sorbs.

  • Anti virus - detect and delete - in Snow leopard

    Hello
    They say Snow Leopard has excellent built in anti-virus software, but I'm not sure. I just taken a job to the printer and his PC virus detection said I had serious virus problems on my Mac.
    This seems likely, and could explain the problems I've been having with OS applications like Fontbook - it's so slow it's useless. And Adobe CS3 is also playing up, I have to force quit programs, they work OK for a while, then the most basic elements of the application fail (like quiting, and cropping in Photoshop).
    I have spoken to Adobe (useless) and I have reinstalled the OS, and CS3.
    How can I check and eliminate a worm or virus from my HD and external backup HD.
    I'd be very grateful for any help.
    John

    I'm with you there. I had been running OS 10.4.11 with absolutely no problems whatsoever. Now I have Snow Leopard and CS3. And, the ONLY reason I upgraded to Snow Leopard was to use the iLife suite, which has some software I need. Now there are problems all over the place. I can't use some of the CS3 plugins that I paid good money for, CS3 has a strange artifact that shows up every time it opens (fortunately the artifact doesn't print), video downloads through Firefox, Chrome or Safari have numerous cache issues, startup is slow, some apps crash randomly, and Word doesn't function properly (don't chastise me on using Word. I have to use it.) I've even installed the proper updates and reinstalled CS3 (like you, I can't afford CS5 yet -- starving artist, you know.)
    I am VERY disappointed in Snow Leopard (not to mention Apple support). Macs used to be the machine to beat when it came to bugs and crashes. Now a Mac is just like any PC -- you never know what's going to happen.

  • Receiving many emails in my inbox that say mail delivery system and I'm not able to send messages now.

    I'm receiving a number of emails that say " mail delivery system", and they are not in my sent items. So I've tried to do the virus scan and nothing is coming up. Now the "real" emails I need to send to clients are not going through because I've used up all my space and or number of emails for one day. Please help!

    what you are seeing is backscatter http://en.wikipedia.org/wiki/Backscatter_%28email%29
    There is nothing anyone can do about it.

  • Sophus anti virus detected troj/upatre-jl and cleanup failed.  how to manually remove?

    My Sophus Anti Virus detected "troj-upatre-jl" and the cleanup failed from quarantine manager. 
    It says manual cleanup is required and I have absolutely no idea how to do that.  Need help!

    Either it detected nothing at all, or it detected Windows malware in an email attachment. The malware will have no effect as long as you don't pass it on to anyone else or run it yourself in Windows.
    Remove the useless, time-wasting Sophos product by following the instructions on this page, and also this one, if applicable. If you have a different version, the procedure may be different.
    Back up all data before making any changes.

  • When I click on an email link in Firefox, I get a message in the far left corner of my screen that says "mail to:email address". Outlook doesn't open up like it does in Internet Explorer. I've set Outlook as my default email in Windows 7.

    When I click on an email link in Firefox, I get a message in the far left corner of my screen that says "mail to:email address". Outlook doesn't automatically open like it does in Internet Explorer. I've made Outlook my default email in Windows 7.
    == This happened ==
    Every time Firefox opened
    == When I upgraded to Windows 7.

    See this:
    [http://support.mozilla.com/en-US/kb/Changing+the+e-mail+program+used+by+Firefox]

  • HT5361 I can't shut down my computer because it says mail is open.  It says to close mail and continue shut down.  Problem is I can't open or close mail now.  Can't shut down my computer at all.  What can I do?

    I can't shut down my computer because it says mail is open.  It says to close mail and continue shut down.  Problem is I can't open or close mail now.  Can't shut down my computer at all.  What can I do?

    If you cannot get mail to quit/force quit, you can always remove power from your Mac.
    NOTE: removing power is a bad idea, and can result in data loss, but sometimes it is the only thing left to do.
    Press and hold the power button for 5 to 10 seconds, and the Mac will power off.
    When you power back on, the Mac should reboot.

Maybe you are looking for