Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Infected with trojan.agent.blyi that regenerates

  • Please log in to reply
1 reply to this topic

#1 dusanrc


  • Members
  • 1 posts
  • Local time:06:14 PM

Posted 13 November 2015 - 11:49 AM


My name is Dusan i am new here but i will try to describe the problem the best i can and hope you can help me,


Computer spec:


OS: Microsoft Windows 10 pro

Antivirus: Bitdefender endpoint security tools, Malwarebytes


How it happen:


I coleauge of mine gave me a usb stick that had a problem, i inserted the usb stick and scanned it with my antivirus software, and found some threats and cleaned it, but from that day i realised that something slipped through since i get malware detections daily.


Problem description:


Every day, sometimes few times a day a get notifications from Bitdefender that it has found and deleted a threat and after deleting it reboot is required so it can delete it for sure, the threat found is malware Trojan.Agent.BLYI, it creates folders nad files under the path: C:\Windows\Temp\ that are in form of tmp00000... and it starts to generate them fast, then I temporary fix the problem by scanning the C:\Windows\Temp\ directory but the malware regenerates and tries again after a while.


Tried actions:


Scanned computer fully for spyware, malware and rootkits in normal and safe mode with:


Bitdefender - after deleting from Temp dir. it finds nothing else on the system

Windows defender - finds win32 worm under the Temp dir. but cant resolve it (probably it sees the trojan like a worm)

Malwarebytes - finds nothing


How can i find the core problem and remove the malware ?


If more info is needed i am open for any suggestions,


Thanks in advance,




BC AdBot (Login to Remove)


#2 buddy215


  • Moderator
  • 13,323 posts
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:14 PM

Posted 13 November 2015 - 12:03 PM

Welcome to BC !


I think it best, based on what you report, to start a new topic in the Malware Removal Forum.


Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.


DO NOT bump your new topic. Wait for a response from one of the Team Members.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users