Цей вебсайт матиме обмежену функціональність, доки ми проводимо його обслуговування для поліпшення роботи. Якщо прочитана стаття не розв'язала вашу проблему і ви хочете поставити питання, наша спільнота підтримки з радістю допоможе вам на @FirefoxSupport у Twitter та /r/firefox на Reddit.

Шукати в статтях підтримки

Остерігайтеся нападів зловмисників. Mozilla ніколи не просить вас зателефонувати, надіслати номер телефону у повідомленні або поділитися з кимось особистими даними. Будь ласка, повідомте про підозрілі дії за допомогою меню “Повідомити про зловживання”

Докладніше

Ця тема перенесена в архів. Якщо вам потрібна допомога, запитайте.

How to localize and delete the attachment from Inbox folder file?

  • 2 відповіді
  • 1 має цю проблему
  • 5 переглядів
  • Остання відповідь від ptyborow

more options

Hello,

My name is Piotr Tyborowski and I'm the Technical Support Engineer in Doctor Web. I have got such suport request - one of our customers has problem with viruses in Thunderbird's Inbox folder - our antivirus scanner has found two Trojans in one file located in Inbox file and moved the whole Inbox file to quarantine. We know that these files are located here:

>>C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part is ZIP archive C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\KeyDLL.dll - infected with Trojan.KeyLogger.6153 C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\KeyDLL.dll - infected >>>C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - packed by UPX C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - infected with Trojan.Click.27588 C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - infected C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part - infected archive

I'm not very familiar with Thunderbird, so my question is - is is possible to get to this 12145.part file and to delete it permanetly, even with the message which cointains it inside?

Thank you in advance and Best Regards,

Piotr Tyborowski Doctor Web

Hello, My name is Piotr Tyborowski and I'm the Technical Support Engineer in Doctor Web. I have got such suport request - one of our customers has problem with viruses in Thunderbird's Inbox folder - our antivirus scanner has found two Trojans in one file located in Inbox file and moved the whole Inbox file to quarantine. We know that these files are located here: >>C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part is ZIP archive C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\KeyDLL.dll - infected with Trojan.KeyLogger.6153 C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\KeyDLL.dll - infected >>>C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - packed by UPX C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - infected with Trojan.Click.27588 C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part\svhosts.exe - infected C:\Users\Renatrix\AppData\Roaming\Thunderbird\Profiles\4dhjzo2v.default\Mail\Local Folders\Inbox.sbd\Konto WP\12145.part - infected archive I'm not very familiar with Thunderbird, so my question is - is is possible to get to this 12145.part file and to delete it permanetly, even with the message which cointains it inside? Thank you in advance and Best Regards, Piotr Tyborowski Doctor Web

Обране рішення

Piotr,

If it is practical, the absolutely safest approach is to delete the entire profile folder 4dhjzo2v.default while TB is shut down.

If the person is using IMAP, or POP with the option of leaving emails on the server, there should not be a loss of emails (except in local folders).

If there are significant emails in local folders, and they are not infected, they could be exported to a storage medium and later inported to the new profile. There is an add-on to TB which allows import and export of emails in various formats.

The instructions on how to download and install it can be found at http://barryduggan.info/exportMail.php

Читати цю відповідь у контексті 👍 1

Усі відповіді (2)

more options

Вибране рішення

Piotr,

If it is practical, the absolutely safest approach is to delete the entire profile folder 4dhjzo2v.default while TB is shut down.

If the person is using IMAP, or POP with the option of leaving emails on the server, there should not be a loss of emails (except in local folders).

If there are significant emails in local folders, and they are not infected, they could be exported to a storage medium and later inported to the new profile. There is an add-on to TB which allows import and export of emails in various formats.

The instructions on how to download and install it can be found at http://barryduggan.info/exportMail.php

more options

Hello,

Thank you for answer. The problem is already solved - fortunately the user was able to localize this infected e-mail. She has deleted it, purged TB cache and temp files and after that the anti-virus scanner stopped finding any threats in the system.

Anyway, thank you for your help.

Best Regards,

Piotr Tyborowski Doctor Web