Hello, I got this detection

Hello everyone, I got this detection and would like to know what else to do?

C:\Users\(removed for privacy)1~1\AppData\Local\Temp\etmpBAECD872-6BFE-BC4A-B48D-97A5D7E190ED

Trojan.Upatre.Crypted.2

Comments

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod
    edited July 20

    That file is in the temporary folder. You can simply delete it by following the steps below.

    Open the Run command and execute the following commands one by one:

    temp – delete all the files in the folder.

    %temp% – delete all the files in the folder.

    prefetch – delete all the files in the folder.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    Hi I cant seem to delete this folder specifically. It says I need special permissions.

    Ive went ahead and deleted some but not all got deleted

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    That is fine. Some folders do not get deleted because they are used by system applications. There is a way to delete them by going into safe mode. If you want to, you can follow the steps below; otherwise, it's not necessary. You’re good as it is.

    1) Restart your PC in safe mode. You can follow this guide: https://support.microsoft.com/en-us/windows/start-your-pc-in-safe-mode-in-windows-92c27cff-db89-8644-1ce4-b3e5e56fe234

    2) Open the Run command and execute the following commands one by one:

    temp – delete all the files in the folder.

    %temp% – delete all the files in the folder.

    prefetch – delete all the files in the folder.

    3) Restart your PC in normal mode by unselecting the option to run the system in Safe Mode, then click 'Apply.'

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    Well after doing this I got a BSOD

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod
    edited July 23

    So, you proceeded with the deletion of temp files in Safe Mode. This should not cause the BSOD error. Can you share a screenshot of the BSOD screen or tell me the stop code displayed at the bottom of the BSOD screen?

    @Alexandru_BD, what do you think? Deleting temp files should not cause a BSOD error. I have never seen that happen—have you?

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    I didn't do it in safe mode and honestly its the only way to access my files. After the deletion I had restarted my laptop manually (which is ten years old btw).

    I get a Critical_Process_Died error.

    I plan on saving some files that are downright important to mostly sentimental for me via a USB drive. Please tell me is that a good idea to do right now? I can only do that action through Safe Mode

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    Here is the corrected text:

    1. Boot in Safe Mode.
    2. Open Command Prompt as an administrator by right-clicking and selecting "Run as administrator." Then type sfc /scannow and press Enter. Let it finish.
    3. In the same Command Prompt window, type DISM /Online /Cleanup-Image /RestoreHealth
    4. If DISM fails or you still get a BSOD error after restarting your PC, you will need a bootable Windows USB or flash drive. If all is set, insert the USB/flash drive into a USB port and boot in Safe Mode again. Open Command Prompt and type DISM /Online /Cleanup-Image /RestoreHealth /Source:E:\Sources\Install.wim/LimitAccess, replacing letter "E" with the drive letter of your USB or flash drive.
    5. Resetting Windows: This reinstalls Windows while giving you options to keep or remove your personal files. Here's how you can reset Windows: https://support.microsoft.com/en-us/windows/give-your-pc-a-fresh-start-0ef73740-b927-549b-b7c9-e6f2b48d275e

    Note: If you do not have a bootable Windows USB or flash drive, you can skip to point 5 directly. If the issue still persists, let us know.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month
    edited July 23

    Before I did those actions between the date of the posting and my first response and actions, my laptop was operating just fine turning off and on ok. Then I deleted those temp files and bam here I am. I've scanned my laptop between those dates in all the ways possible that Bit defender offers and other third party means.

    Mainly from what the Malwarebytes support mods offer plus Microsoft's own Antivirus standalone MSRT Tool. They all come clean.

    Edit: sorry this response was before you posted. the last one.

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod
    edited July 23

    Deleting temporary files should not cause a Blue Screen of Death (BSOD) error, as these files are meant to be temporary and not critical to system operations.

    Check out the links below related to the same:

    https://www.bitdefender.com/consumer/support/answer/2136/

    https://www.avg.com/en/signal/top-three-ways-to-clean-temporary-files-from-your-computer#:~:text=your%20laptop%20freezing.-,Is%20it%20safe%20to%20delete%20temp%20files%3F,Local%5CTemp%20without%20many%20worries.

    https://www.howtogeek.com/743633/how-to-delete-temporary-files-on-windows-10/

    Nevertheless, try the steps stated in the previous comments to see if they help.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    Acc

    Chatted with Microsoft support before talking with you they told me that my only option was to do What step 5 says. Gonna go and buy a USB stick, backup those files then gonna try that method.

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    You do not need a USB for that. You can simply reset and click 'Do not remove anything'; none of your data will be removed. But still, on the safer side, you can backup files on a USB.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    @Flexx

    Ok thanks for the confirmation. While in safe mode will can malware move to the USB while I'm backing up my desired files?

    I'm kinda paranoid ATM over all this

  • Scott
    Scott Defender of the month mod
    edited July 23

    When you get Windows up and running, and a AV, Bitdefender reinstalled, you can scan the USB drive for malware before moving files back onto Windows.

    All Bitdefender Home Product User Guides: https://www.bitdefender.com/consumer/support/user-guides/

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    When in Safe Mode, Windows operates with limited services and drivers, making it more difficult for malware to function or spread. However, it's not impossible.

    Some types of malware can still potentially move to a USB drive while in Safe Mode, especially if they are:

    Rootkits: These can hide malware, making it harder to detect.

    File infectors: These can infect files on the USB drive.

    Boot sector malware: This can infect the USB drive's boot sector.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    What are some good tools for these when I get my laptop running?

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    As @Scott said in above comment, you can simply scan the USB with Bitdefender once your PC is running.

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)

  • King of the cats
    King of the cats Defender of the month

    I've tried these steps up to step 3. Sfc/scan now command says I no integrity violations.

    "Dism/online cleanup etc" came up with an Error 87 stating "online/cleanup-image/restore-health option is unknown"

  • King of the cats
    King of the cats Defender of the month
    edited July 24

    Should I continue with step 5 then?

    Hold up I just had to write correctly with spaces.

  • King of the cats
    King of the cats Defender of the month

    Ok those steps aren't working I'm gonna have to do a full reset

  • King of the cats
    King of the cats Defender of the month

    Well an Update. I did pretty much what you told me to do. I followed the instructions and this is what happened.

    "I've tried these steps up to step 3. Sfc/scan now command says I no integrity violations."

    Did DISM step, mispelled it a bit but typed it correct. It did its job I suppose.

    Then I did a reinstall but choosing to keep my files, but since I have a second drive I chose to have my main drive be reinstalled.

    Reinstalled any apps Bitdefender and other personal choice.

  • Flexx
    Flexx DEFENDER OF THE YEAR 2023 / DEFENDER OF THE MONTH ✭✭✭✭✭ mod

    Is your issue resolved, or are you still facing the problem?

    Regards

    Life happens, Coffee helps!

    Show your Attitude, when you reach that Altitude!

    Bitdefender Ultimate Security Plus (user)