Threat Name Trojan:PowerShell/AmsiBypazz.D!MTB

SVETOSLAV SVETOSLAV 20 Reputation points
2025-11-30T14:03:56.29+00:00

Hello

I need help removing this virus.

Threat Name Trojan:PowerShell/AmsiBypazz.D!MTB

C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

amsi:_\Device\HarddiskVolume5\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

FRST file log

https://onedrive.live.com/?authkey=%21AItSjS10kMUco%2DI&id=512721943D76E138%21118&cid=512721943D76E138

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. _AW_ 64,056 Reputation points Volunteer Moderator
    2025-11-30T14:23:03.57+00:00
    • Download Fixlist.txt and save it in the folder where FRST64English.exe is located.
    • Close any apps with unsaved work.
    • Run FRST64English.exe and click "Fix".
    • The computer will reboot to complete the procedure.

    Please upload Fixlog.txt so I can check if any further action is needed.

    1 person found this answer helpful.

6 additional answers

Sort by: Most helpful
  1. SVETOSLAV SVETOSLAV 20 Reputation points
    2025-11-30T21:23:26.88+00:00

    please check file Fixlog.txtcrash protection history


  2. SVETOSLAV SVETOSLAV 20 Reputation points
    2025-11-30T21:28:37.0833333+00:00

    I can give you access with Ultraviewer.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.