IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Any way to tell it not to scan the mail files?
(The Inbox lost its contents because Symantec quarantined the whole file.)

It may be a bit problematic as Thunderbird doesn't seem to use extensions for the main files. Alternatively, turn off the on-access scanner for now. Restore the inbox from quarantine. You may have to reindex.

Delete the suspected message by hand and compact the Inbox.

Symantec's AV products have always had difficulties scanning ZIP files. That may be what the other error messages are about.
New ^^^^ GREAT ADVICE! ^^^^
New Probably.
Yeah, like so many other programs, Thunderbird keeps mailboxes as a single file. One of the things I really liked about PMMail was that it kept each message separate. It made it much easier to fix when something went wrong.

I found the Quarantined Inbox mailbox (265kB). I really shouldn't let it get that big....

I tried the standard instructions about booting in SafeMode, running SBS&D and SAV, etc., but nothing fixed the Trojan problem. On rebooting I turned off "File System AutoProtect" and got the Inbox file out of Quarantine. I started up Thunderbird and deleted what I think are the problematic files, and compacted the mailboxes.

FSAP is back on, but I haven't run a new scan just yet. I'll start that in a few minutes.

I think there's a setting in Thunderbird about incoming AV scanning - I'll check after I do another scan. I'll probably keep incoming scanning on, and just be careful about keeping the size down. Although I get very little mail, I don't want to risk infecting other machines.

Thanks!

Cheers,
Scott.
New So why aren't you using PMMail then?
It's available for Windows. I use it every day - mostly on OS/2, but also on Windows, and I have several clients who have used it on Windows since the days when eMail infections became rampant.

The thing I like best about PMMail is the ease and clarity with which you can maintain completely separate email accounts. I run one instance of PMMail for support and it has accounts for 17 client mailboxes. I run another instance for my own 13 mailboxes (at several hosting services).

New I needed Kerberos authentication.
I made the transition from PMMail to Eudora and then to Thunderbird for work. IIRC, PMMail wouldn't work with Kerberos. A few years after I moved from PMMail to Eudora, Eudora stopped being updated, so I went to Thunderbird. It also seems to be in danger of being orphaned, but it's working well at home and work so far.

If I started using IMAP it probably wouldn't be an issue, but I'm still mostly on POP and I haven't felt the need to investigate it more.

Evolution may be great, but since I've never used an integrated calendar/mail product like Outlook I haven't felt the need to try it out.

Cheers,
Scott.
New Got it fixed.
After turning off FSAP and moving the Inbox out of Quarantine, I was able to delete the 5 problematic e-mail files and compact the mailboxes.

I then did a full scan of C: and SAV found 2 infected files. I was able to delete them, turn FSAP back on, and everything seems Ok now.

Thanks all.

Cheers,
Scott.
New One more thing - a Thunderbird setting tweak.
There's a setting in Thunderbird that lets SAV (or other AV) grab only the infected message rather than the whole Inbox file.

Tools->Options->Security->Anti-Virus tab:

Check "Allow antivirus clients to quarantine individual incoming messages".

I'm still getting trojan attempts, and SAV still takes forever when it finds one, but at least it's not grabbing the whole Inbox now.

Cheers,
Scott.
     Well that's annoying. Lost my Inbox... - (Another Scott) - (26)
         Symantic? - (Andrew Grygus) - (2)
             Yeah... - (Another Scott) - (1)
                 Part of my toolkit is . . . - (Andrew Grygus)
         Dude.... - (folkert) - (1)
             I'm trying. - (Another Scott)
         Any way to tell it not to scan the mail files? - (scoenye) - (6)
             ^^^^ GREAT ADVICE! ^^^^ -NT - (folkert)
             Probably. - (Another Scott) - (4)
                 So why aren't you using PMMail then? - (Andrew Grygus) - (1)
                     I needed Kerberos authentication. - (Another Scott)
                 Got it fixed. - (Another Scott) - (1)
                     One more thing - a Thunderbird setting tweak. - (Another Scott)
         Get rid of Symantec - (pwhysall) - (13)
             I'd love to, but how are they better? - (Another Scott) - (12)
                 Re: I'd love to, but how are they better? - (pwhysall) - (11)
                     :-) Thanks. Gotta find something for Win2k though... :-( - (Another Scott) - (10)
                         Re: :-) Thanks. Gotta find something for Win2k though... - (Andrew Grygus) - (3)
                             Thanks. I'll try it again. -NT - (Another Scott)
                             Take a look at Avast as well - (scoenye) - (1)
                                 Thanks for the info. I appreciate it. -NT - (Another Scott)
                         Time to wave farewell to W2K, I think. -NT - (pwhysall) - (5)
                             If it ain't broke... - (Another Scott)
                             Where would you suggest next? - (static) - (2)
                                 Based on recent experience, I'd say Linux Mint. - (pwhysall) - (1)
                                     From what I've seen at Helios... - (folkert)
                             Here it's the only Windows machine always running. - (Andrew Grygus)

That’s a great, great story. Therefore, it’s too good to be true.
142 ms