搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

Learn More

After allowing remote content for a msg, launching TB get virus warning w/Forticlient, rehappens after Forticlient removal everytime, any help? Thanks Mark

  • 1 个回答
  • 1 人有此问题
  • 4 次查看
  • 最后回复者为 Matt

more options

I've let my Forticlient remove the detected infected file three times. If I don't launch Thunderbird I won't get the message. It started happening right after I selected 'download content for this message', and the remote content was four images contained w/in a canned message about 'Advice from an old man' with advice in captions of each 'seductive' image of women. I deleted the message from inbox, and trash, the last time, then let Fortinet reboot and remove once again. After roboot and removal, launch Thunderbird with same problem. The only difference is that the actual filename of the infected file changes some each time. The first time it was 'invoice_SCAN_28Vvk.js', the second it was 'invoice_copy_SXXKra.ja', and the third it was 'invoice_copy_OJFzQw.js', each time appearing in folder 'c:\users\owner\appdata\roaming\thunderbird\...\' (doesn't show the full address in the warning message from Forticlient, but to the ellipsis). I've also tried to scan for viruses in the 'owner\appdata' directory w/no reported virus. If I don't launch Thunderbird, the file / virus isn't spawned. Thank you for any help. Mark.

I've let my Forticlient remove the detected infected file three times. If I don't launch Thunderbird I won't get the message. It started happening right after I selected 'download content for this message', and the remote content was four images contained w/in a canned message about 'Advice from an old man' with advice in captions of each 'seductive' image of women. I deleted the message from inbox, and trash, the last time, then let Fortinet reboot and remove once again. After roboot and removal, launch Thunderbird with same problem. The only difference is that the actual filename of the infected file changes some each time. The first time it was 'invoice_SCAN_28Vvk.js', the second it was 'invoice_copy_SXXKra.ja', and the third it was 'invoice_copy_OJFzQw.js', each time appearing in folder 'c:\users\owner\appdata\roaming\thunderbird\...\' (doesn't show the full address in the warning message from Forticlient, but to the ellipsis). I've also tried to scan for viruses in the 'owner\appdata' directory w/no reported virus. If I don't launch Thunderbird, the file / virus isn't spawned. Thank you for any help. Mark.

所有回复 (1)

more options

I am not sure what your problem is, but I suggest you compact your folders in Thunderbird as it is only after you do that that your "delete" actually removes the email in question.