Switcher Hangout The place for switchers to discuss their new machines, and how to work with OS X. General support can be had here for newbie stuff, like "How do I restart my new iMac?" :)

Medhealthx trojan on my Mac?


Post Reply New Thread Subscribe

 
Thread Tools
walkingal

 
Member Since: Jul 04, 2008
Posts: 3
walkingal is on a distinguished road

walkingal is offline
I love my Mac. After reading many threads on this site, I decided not install anti virus software on my computer and I've been happy with that decision.

This morning my mother told me that my computer had somehow sent a suspicious email to her and many others with a link to hgd4.medhealthx.com/
My mother was smart enough not to click on the link. So I looked online, deleted many old contacts from my email list (hotmail) in case this happened again and installed CalmXav, which found nothing. Sure enough tonight my hotmail account sent another link--this time to soq7.medhealthx.com/

Hopefully my contacts will not click on the links, but I would like to remove whatever is on my computer that is causing this problem. I do not run Windows on my Mac. I don't do a lot of downloading and I have no idea what I might have clicked on myself that allowed the trojan on my computer--I would have said I was very cautious regarding what I download.

Please be gentle with your replies--I am not a computer expert.

Thanks. Donna
Mac OS X Version 10.5.8
QUOTE Thanks
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, Pennsylvania
Posts: 25,917
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15" MBP, Core i7/2GHz, 8GB RAM, 256GB Crucial M4 SSD

cwa107 is offline
The good news is, you probably don't have a virus. What you're likely experiencing is a phenomenon known as "sender address spoofing".

Do you see these emails actually sitting in your Sent Items folder in Hotmail?

Liquid and computers don't mix. It might seem simple, but we see an incredible amount of people post here about spills. Keep drinks and other liquids away from your expensive electronics!
QUOTE Thanks
walkingal

 
Member Since: Jul 04, 2008
Posts: 3
walkingal is on a distinguished road

walkingal is offline
Yes, they are in my sent folder. I got many delivery failure notices. I'm glad of that.
QUOTE Thanks
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, Pennsylvania
Posts: 25,917
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15" MBP, Core i7/2GHz, 8GB RAM, 256GB Crucial M4 SSD

cwa107 is offline
Quote:
Originally Posted by walkingal View Post
Yes, they are in my sent folder. I got many delivery failure notices. I'm glad of that.
Change your account password immediately. Make sure it is strong (mix of upper and lower case letters, include numbers and at least one special character like !@#$%^*(, etc).

Liquid and computers don't mix. It might seem simple, but we see an incredible amount of people post here about spills. Keep drinks and other liquids away from your expensive electronics!
QUOTE Thanks
walkingal

 
Member Since: Jul 04, 2008
Posts: 3
walkingal is on a distinguished road

walkingal is offline
Okay. I did that. Thank you.
QUOTE Thanks
DarkestRitual

 
Member Since: Apr 09, 2009
Location: Ithaca NY
Posts: 2,073
DarkestRitual is just really niceDarkestRitual is just really niceDarkestRitual is just really niceDarkestRitual is just really nice
Mac Specs: 13 inch alMacBook 2GHz C2D 4G DDR3, 1.25GHz G4 eMac

DarkestRitual is offline
Yea, if they're in your sent folder, somebody definitely highjacked your account, not just spoofed it. Gotta keep ridiculously strong passwords in today's day and age. I usually use 14-16 characters, randomized. If you can remember a phone number, you can remember one good password.
QUOTE Thanks
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, Pennsylvania
Posts: 25,917
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15" MBP, Core i7/2GHz, 8GB RAM, 256GB Crucial M4 SSD

cwa107 is offline
Quote:
Originally Posted by DarkestRitual View Post
Yea, if they're in your sent folder, somebody definitely highjacked your account, not just spoofed it. Gotta keep ridiculously strong passwords in today's day and age. I usually use 14-16 characters, randomized. If you can remember a phone number, you can remember one good password.
Especially with Hotmail, which has traditionally been a haven for spammers, scammers and other riff-raff.

Liquid and computers don't mix. It might seem simple, but we see an incredible amount of people post here about spills. Keep drinks and other liquids away from your expensive electronics!
QUOTE Thanks
MYmacROX

 
MYmacROX's Avatar
 
Member Since: Mar 17, 2009
Posts: 3,329
MYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of light
Mac Specs: 2008 15" MBP ML, 2012 21.5" iMac ML

MYmacROX is offline
Quote:
Originally Posted by cwa107 View Post
Especially with Hotmail, which has traditionally been a haven for spammers, scammers and other riff-raff.
I can vouch for that. Happened a few months ago to my Hotmail account and my wife's. We implemented tougher passwords and haven't had trouble since.

16GB iPhone 5, 64GB Wi-Fi only iPad 1st Gen.

Reminder: Please include your Mac's specs. This will make it much easier for the other members to assist you.
QUOTE Thanks
sving

 
Member Since: Sep 09, 2010
Posts: 2
sving is on a distinguished road

sving is offline
I'm not a Mac user but this is one of the more intelligent discussions I've seen and I thought I'd put my post here.

Last weekend, I got two messages from a colleague's Hotmail that pointed me to *.medhealthx.com sites. This morning, I got a very similar message from my wife's Hotmail account, pointing me to a *.xpharmx.com site.

I've been googling today to try to find what's up. As far as I can tell, all discussions including "medhealthx" are all from the past week or two. On the other hand, that may be because the spam author rolls out new domain names every week since I bet Hotmail spam filters will soon weed out messages containing *.medhealthx.com links. (My filters at work do that now.)

From what I've seen posted around the internet, this medhealthx issue spans Windows and Mac, Gmail and Hotmail. Messages do reside in Sent Items, so it appears this is not spoofing.

I changed my wife's Hotmail password. My fear is that the culprit is keylogging spyware. If that's true, it may happen again.

Regarding the possibility that it is an attack on weak passwords: My wife and colleague both had 6-character alpha passwords. That's not a super-easy level, but also not very strong.

I welcome suggestions about what to try or look for.
QUOTE Thanks
baggss

 
baggss's Avatar
 
Member Since: Oct 10, 2004
Location: Margaritaville
Posts: 10,306
baggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond repute
Mac Specs: 27" 3.4 Ghz i7 iMac-13" C2D Macbook-OSX 18.8.2-64Gb iPad 2-32 Gb iPhone 5-ATV 2-14Tb of Storage

baggss is offline
Quote:
Originally Posted by sving View Post
From what I've seen posted around the internet, this medhealthx issue spans Windows and Mac, Gmail and Hotmail. Messages do reside in Sent Items, so it appears this is not spoofing.
True. The virus isn't ifiltrating the OS, it's hitting the GMail and Hotmail servers vice the individual machines.


QUOTE Thanks
MYmacROX

 
MYmacROX's Avatar
 
Member Since: Mar 17, 2009
Posts: 3,329
MYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of lightMYmacROX is a glorious beacon of light
Mac Specs: 2008 15" MBP ML, 2012 21.5" iMac ML

MYmacROX is offline
Quote:
Originally Posted by sving View Post
I'm not a Mac user but this is one of the more intelligent discussions I've seen and I thought I'd put my post here.

Last weekend, I got two messages from a colleague's Hotmail that pointed me to *.medhealthx.com sites. This morning, I got a very similar message from my wife's Hotmail account, pointing me to a *.xpharmx.com site.

I've been googling today to try to find what's up. As far as I can tell, all discussions including "medhealthx" are all from the past week or two. On the other hand, that may be because the spam author rolls out new domain names every week since I bet Hotmail spam filters will soon weed out messages containing *.medhealthx.com links. (My filters at work do that now.)

From what I've seen posted around the internet, this medhealthx issue spans Windows and Mac, Gmail and Hotmail. Messages do reside in Sent Items, so it appears this is not spoofing.

I changed my wife's Hotmail password. My fear is that the culprit is keylogging spyware. If that's true, it may happen again.

Regarding the possibility that it is an attack on weak passwords: My wife and colleague both had 6-character alpha passwords. That's not a super-easy level, but also not very strong.

I welcome suggestions about what to try or look for.
I had a 7 digit alpha-numeric password on my Hotmail and it was still "hacked". So, changing the password to something unique/random/difficult is your best approach/solution. I haven't had this happen again since I changed mine.

16GB iPhone 5, 64GB Wi-Fi only iPad 1st Gen.

Reminder: Please include your Mac's specs. This will make it much easier for the other members to assist you.
QUOTE Thanks
sving

 
Member Since: Sep 09, 2010
Posts: 2
sving is on a distinguished road

sving is offline
MYmacROX, did your hack involve the symptoms discussed in this thread (spam sent from your account with *.medhealthx.com or another medical website ending with an x), or is yours an unrelated attack?
QUOTE Thanks

Post Reply New Thread Subscribe


« Adobe PDF Viewer | Maps in iphoto...places of interest labels? »
Thread Tools

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread
Thread Starter
Forum
Replies
Last Post
Running Windows on a Mac: A Switcher's Guide cwa107 Running Windows (or anything else) on your Mac 276 04-20-2013 11:28 PM
Who's got the most Macs? narf1899 Schweb's Lounge 139 11-24-2012 10:53 AM
Has The Mac Been Hacked...... MaDDoG Apple Rumors and Reports 5 05-01-2007 07:06 PM

All times are GMT -4. The time now is 03:12 PM.

Powered by vBulletin
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
X

Welcome to Mac-Forums.com

Create your username to jump into the discussion!

New members like you have made this community the ultimate source for your Mac since 2003!


(4 digit year)

Already a member?