Windows 10 Trojan w32/Tiggre!plock locked up temp files

windozUser2021

New Member
Hi,
Sorry I cant seem to find a thread regarding malware.Just needed to get the prob solved as i have work files and software on my laptop,so am posting here intead.thank you
Windows defender picked up the trojan named w32/Tiggre!plock,after i scanned the laptop as it was running extremely slowly.The trojan has now been deleted but i tried to delete the temp files from windows/temp as i often do,but now the files cannot be deleted.it first asks for administrator permission (ignore photos that has the "skip" highlighted,i definitely pressed the allow),i press continue to allow that,but still wont delete the temp files.I am assuming it is due to the trojan,it has locked up my files in the temp files folder.It doesnt seem like the laptop is running slow after the trojans' detection and deletion,but i am wondering what is in the files that it wont allow them to be deleted? The trojan has also backdated these files,as I often delete them. In any case,all i really want is to delete them as i have no idea what they may be trying to do.
SO HOW WOULD I DO THIS?? without re-formatting the laptop? thank you

laptop:
acer
win8.1

Thanks in advance for any help.

Btw,the trojan somehow got onto my laptop after i started allowing java to run,to enable videos in major news sites!!
thanks for any help.thanks
 

Attachments

  • DSC01187--.jpg
    DSC01187--.jpg
    520.8 KB · Views: 81
  • DSC01189--.jpg
    DSC01189--.jpg
    536.1 KB · Views: 90
  • DSC01193--.jpg
    DSC01193--.jpg
    517.1 KB · Views: 94
  • DSC01194--.jpg
    DSC01194--.jpg
    408.9 KB · Views: 79
Temp files are just that temp. They can belong to any process so they may not really be associated with the Trojan. Either they're used by some other process or they don't have permissions allowing you to remove them. You can boot into safe mode and shouldn't have any problem removing temp files.
 
Temp files are just that temp. They can belong to any process so they may not really be associated with the Trojan. Either they're used by some other process or they don't have permissions allowing you to remove them. You can boot into safe mode and shouldn't have any problem removing temp files.
hi,thanks for the info.
I often delete the temp files,and usually only the ones being used cant be deleted like u said.I usually delete them everyday ! or more than once a day.But now some of those files are dated back to several months .... so thats why i think it may be associated with the trojan.But something has occured with the permissions also for those temp files that will not allow deletion even after i have pressed the allow,and after restarts and all browsers closed etc etc.So this must be something new,or the attacker was doing something with them.The dates of those files arent possible,as i delete the temp files all the time.
 
If the process using the files is running as SYSTEM or trusted installer, not even members of the administrators group may have permissions. You have to take ownership of those files and then grant the administrators group permissions in order to delete them. Windows has been that way since Vista (2007). It's part of DACL permissions that Microsoft tends to use.
 
Back
Top