cablewireltd.site: a Windows VIP Keylogger host serving Crypted.ps1 PowerShell files, and what to do if one ran
cablewireltd.site is a web address that URLhaus lists nine times in September 2026 for malware files: seven PowerShell scripts named Crypted.ps1 and two JavaScript loaders, three of them tagged VIPKeylogger, a password and keystroke stealer for Windows.
The domain was registered on 21 September and is now on server hold, so it no longer answers. If you only saw the name in a log, nothing is proven. If a script on your PC fetched these files, change your passwords from another device first, then check and clean or reset Windows.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with a script file or a PowerShell command that fetched files from cablewireltd.site.
Do it yourself · free Remove cablewireltd.site (VIP Keylogger, PowerShell stages) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Cablewireltd.site (VIP Keylogger, PowerShell stages): summary
| Type | A malware host: URLhaus lists seven Crypted.ps1 PowerShell files and two JavaScript loaders, three tagged VIPKeylogger, an information stealer for Windows |
|---|---|
| Risk | High if a script on your PC fetched its files: passwords, cookies, cards, Wi-Fi keys and keystrokes may be taken. Low if you only saw the name |
| Symptoms | Often none. Browsers closing by themselves, a UserInitMprLogonScript value in HKCU\Environment, or account alerts are the signs in the reports |
| How to get rid of it | Change passwords and sign out sessions from another device, check the logon script and startup entries, run Microsoft Defender Offline, reset Windows if unsure |
| Our check (10 October 2026) | The name did not resolve (ENOTFOUND) and RDAP shows server hold. An offline host clears nothing; the rating comes from URLhaus |
| Running since / first seen | Domain registered 21 September 2026; files reported on 23 and 24 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No Microsoft detection name is known for these files, because we did not open them. Defender may show names that contain VIPKeylogger, Snake or PowerShell |
| Name | Cablewireltd.site |
| Domain registered | 21 September 2026 |
| Evidence | 9 write-ups by security sites; details still limited |
| First seen | 23 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against the URLhaus data for cablewireltd.site held in our database, the RDAP record, one plain request from our server (the name did not resolve), and published analyses by Splunk and Seqrite, plus Microsoft's pages on Defender Offline and recovery.
We did not download the files and infected no PC; the removal steps follow Microsoft's pages and the researchers' findings and were not tried on a live infection.
What cablewireltd.site is, and what we know about it
cablewireltd.site is not a program on your PC. It is a web address where, according to the abuse.ch project URLhaus, nine malware files were hosted in September 2026: seven PowerShell scripts all called Crypted.ps1 and two JavaScript files with long random names. Three of the PowerShell files are tagged VIPKeylogger, a password and keystroke stealer for Windows. We found no public write-up of this one address, so this page sets out what URLhaus lists, what our server saw, and what researchers have published about VIP Keylogger and its loaders.
- 1
What URLhaus lists
Nine file addresses on cablewireltd.site, each inside its own folder. The folders carry names such as masabik23, mrprince, prince23, masfrnd and frndmass244. Seven hold a file named Crypted.ps1; one folder, ppriincefil21, holds two .js files. All nine were added between 23 and 24 September 2026, all carry the label malware_download and the reporter is abuse_ch.
- 2
What the tags mean
ps1 and powershell mean the file is a PowerShell script, a plain text program that Windows can run. js means JavaScript, which Windows can run outside a browser when a person opens the file. ascii means the content is readable text. opendir means the folder could be listed by anyone who asked, which is how so many files were found at once. VIPKeylogger is the name of the malware family the reporter linked to three files.
- 3
What we could not confirm
We did not download any of the files, so we cannot say which VIP Keylogger build they lead to, where it sends stolen data, or whether the six files without the family tag do the same thing. We also do not know which email or download made a victim's PC ask for these files.
- 4
What this means for you
If you only saw the name in a firewall log, a DNS log or a browser warning, that alone is not an infection. The risk is for a Windows PC where a script was opened and went to fetch one of these files. A normal visitor has no reason to request a file called Crypted.ps1.
- Kind of threat
- A malware host serving PowerShell and JavaScript stages; three files tagged VIPKeylogger, an information stealer for Windows
- Where the files were
- hxxps://cablewireltd[.]site/<folder>/Crypted.ps1 and two .js files in /ppriincefil21/
- Domain registered
- 21 September 2026 through Spaceship, Inc.; the registry status now shows server hold (RDAP, read 10 October 2026)
- URLhaus entries
- 9 file addresses added on 23 and 24 September 2026; all 9 offline when we read our copy of the data
- Delivery trick
- Script stages that fetch further code; VIP Keylogger chains hide the last parts in image files. The first step on a victim's PC is not known
- Platform
- Windows. PowerShell stages and the .NET stealer are Windows software. Nothing we read says Mac, iPhone or Android are affected
What cablewireltd.site (VIP Keylogger, PowerShell stages) does on an infected PC
What we checked on 10 October 2026, and what we could not
Our server asked for cablewireltd.site once on 10 October 2026 with a plain request. The name did not resolve at all: the answer was getaddrinfo ENOTFOUND, which means no DNS server gave an address for it. That fits the registry status server hold, which takes a domain out of the DNS. It clears nothing about the files that were served in September.
Our check, 10 October 2026
- The name did not resolvegetaddrinfo ENOTFOUND cablewireltd.site. There was no server to talk to, so no page, no file and no redirect could be seen.
- Server hold on the domainRDAP lists the status server hold, together with client transfer prohibited and client update prohibited. Server hold is set at registry level and usually follows an abuse report. It does not tell us who set it or why.
- Why an offline host is not a clean resultThe operators can move the same files to a new name within hours. A script already on a PC may also try other addresses. A dead name today says nothing about a PC that fetched a file in September.
- URLhaus listingNine malware_download entries, seven PowerShell files and two JavaScript files, three tagged VIPKeylogger; all offline in our copy of the data.
- The files themselvesWe did not download or open any file. What each one contained is not confirmed by us.
Dangerous: treat it as a malware host The name no longer answers, so our check could not see anything. The rating comes from the nine URLhaus reports and their tags, and from what researchers publish about VIP Keylogger. If anything on your PC contacted this address, follow the steps below.
What happened to cablewireltd.site, from registration to our check
The whole life of this address fits into three days of activity and a quick shutdown. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
21 September 2026
The domain is registered
RDAP shows cablewireltd.site registered on 21 September 2026 at about 12:18 UTC through Spaceship, Inc. The name sounds like a cable and wire company, a common way to make a malware host look like a business.
23 September 2026, morning
Five files are reported
At about 08:09 and 08:10 UTC abuse.ch adds Crypted.ps1 in the folders masabik23, mrprince and masfrnd, and two long .js files in ppriincefil21. The file in masabik23 is tagged VIPKeylogger. All five carry the opendir tag, so the folders were open to browse.
23 September 2026, afternoon
Three more PowerShell files
At about 13:59 UTC Crypted.ps1 is added in prince23, masabik232 and massfrnd232. The one in masabik232 is tagged VIPKeylogger. The new folder names are the old ones with a number added, which looks like fresh batches.
24 September 2026
The last file
At about 13:41 UTC Crypted.ps1 in frndmass244 is added, again tagged VIPKeylogger. No later report exists in our data.

The nine URLhaus entries for cablewireltd.site as we read them on 10 October 2026. Seven files share the name Crypted.ps1; only the folder changes. 10 October 2026
Our check
All nine entries are marked offline. The domain shows server hold in RDAP and our server cannot resolve the name.
Our reading of the pattern, not a statement from any report: folder names such as prince, mrprince, ppriincefil21 and masabik look like labels for different customers or campaigns of the same operator, each given its own copy of the stage. That is common when a loader is sold or shared, but we cannot prove it here.
What VIP Keylogger is
VIP Keylogger is a stealer written in .NET for Windows. Seqrite describes it as similar to Snake Keylogger, almost down to the variable names. Splunk's Threat Research Team studied more than 200 of its script loaders captured between March and April 2026 and published the results on 13 May 2026.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | A .NET keylogger and stealer that records keystrokes and takes saved logins, cookies, card data and more | Seqrite; Splunk |
| How does it arrive? | Phishing emails posing as bank payment notices, purchase orders and shipping updates, with a script or document attached | Splunk; Seqrite |
| Which loaders? | .vbs, .js and .bat files that start PowerShell; Seqrite also describes an RTF document that fetches a VBScript | Splunk; Seqrite |
| Where is the code hidden? | In picture files. Splunk found two .png files with encoded data between markers; Seqrite found a picture with text between <<BASE64_START>> and <<BASE64_END>> | Splunk; Seqrite |
| Where does it run? | Inside a genuine Windows program. Splunk names aspnet_compiler.exe; Seqrite describes process hollowing into dxdiag.exe | Splunk; Seqrite |
| How does it stay? | Splunk saw the .bat loader write its path to the UserInitMprLogonScript value so it runs at every sign in | Splunk |
| Where does data go? | Telegram bots and the operators' own servers in Splunk's samples; an HTTP server in Seqrite's | Splunk; Seqrite |
| Which build is on this host? | Not known. URLhaus gives only the tag; we did not open the files | Not available |
How a Crypted.ps1 file fits into the infection chain
A file named Crypted.ps1 is a middle step. It does nothing unless something already on the PC downloads it and runs it. The two .js files on the same host are the kind of first step that does that. This is how the researchers describe the chain; we did not see it run from this host.

- 1
A person opens an attachment
Splunk's samples start with a .vbs, .js or .bat file sent as if it were an order or a payment notice. Seqrite's start with an RTF document named like an order inquiry. Double clicking the file is the step that starts everything.
- 2
The script calls PowerShell
Splunk found the .js loaders heavily obfuscated, pulling a PowerShell stager that is unpacked with base64 and AES. In the .vbs path, the PowerShell code is written into a user environment variable called INTERNAL_DB_CACHE, run, and deleted.
- 3
The PowerShell stage downloads pictures
Splunk's stager downloaded two .png files. The script looks for the markers IN- and -in1, swaps every # for A, reverses the text and decodes it. The result is not a picture at all but the next program.
- 4
The stealer is loaded into a trusted program
Splunk saw VIP Keylogger injected into aspnet_compiler.exe, a normal .NET tool. Seqrite saw a loader start dxdiag.exe and swap its contents. In Task Manager the stealer then wears a Microsoft name.
- 5
The data leaves, and the file may vanish
The stealer sends what it found to a Telegram bot or a server. Both reports describe it deleting itself afterwards. Splunk saw a hidden command prompt use choice.exe for a three second pause before the file is removed.
The nine files: what each name suggests, and what we do not know
File names and tags are weak evidence. The third column below is our reading and is marked as such.
| File on cablewireltd.site | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /masabik23/Crypted.ps1 | Offline; ascii, opendir, powershell, ps1, VIPKeylogger; 23 Sep | A PowerShell stage the reporter linked to VIP Keylogger |
| /masabik232/Crypted.ps1 | Offline; ascii, powershell, ps1, VIPKeylogger; 23 Sep | A newer copy for the same folder name with a number added; the only file without opendir |
| /frndmass244/Crypted.ps1 | Offline; opendir, powershell, VIPKeylogger; 24 Sep | The last file reported, again tied to VIP Keylogger |
| /mrprince/, /prince23/, /masfrnd/, /massfrnd232/ Crypted.ps1 | Offline; ascii, opendir, powershell, ps1; 23 Sep | Four more stages with the same name. Probably the same kind of script; the content is unknown |
| /ppriincefil21/ two long .js files | Offline; ascii, js, opendir; 23 Sep | JavaScript loaders of the kind Splunk describes, which a person opens and which then fetch a PowerShell stage. Not confirmed |
What cablewireltd.site (VIP Keylogger, PowerShell stages) can steal or download
What VIP Keylogger takes from a Windows PC
Unlike a remote access trojan, a stealer does not wait for a person to sit at your PC. It collects and sends in one go, often within a minute of starting. Everything below is named in the Splunk or Seqrite analysis.
Named in the reports
- Every key you type
- Saved browser passwords
- Browser cookies
- Saved credit card details
- Autofill entries
- Browsing and download history
- Outlook, Thunderbird and Foxmail logins
- Discord tokens
- Telegram data
- Wi-Fi passwords
- Clipboard text
- Screenshots
- Your location and IP address
| Data | Detail | Source |
|---|---|---|
| Browsers | Logins, cookies, cards, autofill, top sites and downloads from Chrome, Edge, Firefox, Opera, Brave, Yandex, Vivaldi and many lesser known Chromium and Firefox based browsers | Seqrite; Splunk |
| Email and chat | Outlook passwords read from the registry, plus Thunderbird, Foxmail, PostBox, Pidgin and Discord | Splunk; Seqrite |
| Wi-Fi | Saved network passwords read in plain text with netsh wlan show profile ... key=clear | Splunk |
| Crypto | The clipboard is watched for wallet addresses (Bitcoin, Ethereum, Monero, Litecoin and others) and a copied address is swapped for the attacker's | Splunk |
| Screen | Screenshots saved as Screenshot.png in Documents\VIPRecovery before sending | Splunk |
| Location | Host name, IP address, country and coordinates from public IP check services | Splunk; Seqrite |
What this can cost you
Seeing the name costs nothing. The risks below apply to a Windows PC where a script from this host ran and the stealer started.
- High
Your accounts
Saved passwords and live session cookies let someone sign in as you, sometimes without needing the password again. Email is the most dangerous loss, because it resets everything else.
- High
Money and crypto
Saved cards can be used online. Splunk describes the clipboard swap: you paste a wallet address and the stealer has quietly put its own there. Crypto sent that way cannot be reversed.
- High
Work mail
These campaigns target businesses with order and invoice lures. Stolen Outlook logins are used for invoice fraud against your customers and suppliers.
- Medium
Your home or office network
Wi-Fi passwords leave the building with the rest of the data. Anyone near your premises could then join the network.
- Medium
Discord and Telegram
Tokens and session data let someone post as you and send the same lure to your contacts.
- Low
Nothing, if you only saw the name
A name in a block list, a log or a warning is not an infection.
What you may notice, and what you may not
A stealer is built to finish its work before anyone notices. Most people learn of it from their accounts, not from the PC.
| Sign | What the reports show |
|---|---|
| Browsers closed by themselves | Splunk says the stealer kills running browser processes before it reads their files. A browser that suddenly closed after you opened an attachment is a strong hint |
| A folder called VIPRecovery in Documents | Splunk found screenshots saved there before sending. It may be gone if the stealer cleaned up |
| A pasted wallet address that does not match | The clipboard swap changes what you paste. Compare the first and last characters every time |
| aspnet_compiler.exe or dxdiag.exe running for no reason | Both are real Windows programs. One running with network use while you did nothing related is worth a look |
| A logon script in the registry | The value UserInitMprLogonScript under HKEY_CURRENT_USER\Environment holds a path to a script. Most home PCs have no such value |
| Account alerts | Sign in from a new place, password reset emails, Discord or Telegram messages you did not send |
| Nothing at all | The stealer may delete itself after sending. A clean looking PC does not mean nothing was taken |
How to check the PC for cablewireltd.site (VIP Keylogger, PowerShell stages)
How a person ends up fetching files from this host
Nobody types cablewireltd.site into a browser. The request comes from a script. We do not know which email or download pointed to this host; the routes below are the ones the researchers found for VIP Keylogger.
- 1
A business email with an attachment
Splunk lists bank payment notifications, procurement orders and logistics updates as the lures. The attachment is a script file, sometimes inside an archive, with a name that reads like a document.
- 2
An Office or RTF document
Seqrite describes an email from a supposed buyer with an RTF file named as an order inquiry. Opening it made the PC download a VBScript, which led to PowerShell and a picture hiding the loader.
- 3
Cracked software
Seqrite's conclusion adds software cracks as a route. A crack that runs a script in the background can start the same chain.
Check your PC before you delete anything
Start with one question: did you open an unexpected attachment, a .js, .vbs or .bat file, or a cracked program around 23 and 24 September 2026, or did a log show a device asking for cablewireltd.site? If yes or not sure, do the checks below. None of them deletes anything.
While you check, do not use the PC for email, banking, work or crypto. A stealer may already have taken what it wanted, but a logon script can run it again at the next sign in.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable on the PC in question. The stealer needs the connection to send data.
- 2
Find which device asked for the address
If you came from a router page, a DNS log or a security alert, note the device and the time. Only that device is in question.
- 3
Look for the logon script value
Press Windows key + R, type regedit and open HKEY_CURRENT_USER\Environment. Look for a value named UserInitMprLogonScript and for any unusually long value such as INTERNAL_DB_CACHE. Splunk names both. Write down what the logon script points to; do not delete yet.
- 4
Look in the user folders
Open %appdata%\Microsoft\Windows\Libraries in File Explorer and look for script files that are not library files. Splunk found the .bat path dropping a hidden file there. Also look in Documents for a VIPRecovery folder.
- 5
Check Startup apps and Task Scheduler
In Settings > Apps > Startup look for names you did not install. Then press Start, type Task Scheduler and look in Task Scheduler Library for tasks that run PowerShell, wscript or a script from a user folder. Seqrite's loader had options for a startup task and a startup registry entry.
- 6
Look at running programs
Open Task Manager and look for aspnet_compiler.exe or dxdiag.exe running when you did not start them. Right click and choose Open file location to see where they run from. Their presence alone proves nothing.
- 7
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for anything found or blocked around the time you opened the file, especially names with VIPKeylogger, Snake or PowerShell in them.
- 8
Check your accounts from another device
Look at the recent sign in activity of your email, bank, work, Discord and Telegram accounts. This tells you faster than any file check whether data was used.
How to remove cablewireltd.site (VIP Keylogger, PowerShell stages)
How to remove cablewireltd.site
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to cablewireltd.site or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever cablewireltd.site installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows with Microsoft Defender Offline
Microsoft Defender Offline starts from a trusted environment outside the normal Windows, so malware running inside Windows cannot hide from it as easily. It is built into Windows 10 version 1607 and later and into Windows 11 on x64 PCs.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You need a local administrator account, and the Windows Recovery Environment must be on: in an administrator Command Prompt,
reagentc /infoshows the state andreagentc /enableswitches it on. With it off, Microsoft says, nothing happens and no error shows. - 2
Suspend BitLocker if it is on
Microsoft warns that with BitLocker on the system drive, the restart into the scan may ask for the recovery key. Suspend protection first, or have the key ready.
- 3
Start the scan
Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Confirm the prompts. Windows signs you out, scans and boots back normally. In an administrator PowerShell window,
Start-MpWDOScandoes the same. - 4
Read the result
After the restart open Windows Security > Virus & threat protection > Protection history. Microsoft notes the offline scan is not available on ARM versions of Windows and only updates when Microsoft Defender Antivirus is your main antivirus.
- 5
A clean scan is not the end
A stealer may have run once, sent its data and deleted itself. No scan can undo that. The account steps below matter more than the scan result.
If you use a Mac, an iPhone or an Android phone
The files on cablewireltd.site are PowerShell and Windows script stages, and VIP Keylogger is a .NET program for Windows. Nothing we read says it affects other systems.
| Your device | What we know | What to do |
|---|---|---|
| Mac | A .ps1 or .js file opened on a Mac does not start this chain; every loader in the reports uses Windows tools | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source describes VIP Keylogger on iOS | Nothing to remove. Change passwords that were saved on an infected Windows PC |
| Android | No source mentions it | Nothing to remove for this threat. Sign out sessions that were open on the Windows PC |
After removal: passwords, accounts and prevention
After the PC: protect what was taken
With a stealer, the accounts are the real damage. Do these steps from a phone or another clean computer, in this order, before you trust the PC again.

- 1
Change email passwords first
Your email account resets every other account, so it comes first. Use a new password you have never used before, then change bank, work, cloud storage and shop accounts.
- 2
Sign out every session
Stolen cookies keep a login alive even after a password change. In each important account, use the option to sign out of all devices or end other sessions. In Discord, change the password, which also resets the token.
- 3
Turn on two step sign in
Use an authenticator app or a security key wherever it is offered, so a password alone is not enough next time.
- 4
Call your bank about saved cards
If cards were saved in a browser on the PC, ask the bank to block and reissue them. Watch statements for a few weeks.
- 5
Move crypto to a new wallet
If a wallet or seed phrase was on the PC, create a new wallet on a clean device and move the funds. Check recent transfers for a swapped address.
- 6
Change the Wi-Fi password
Splunk describes the stealer reading saved Wi-Fi passwords. Change the router's Wi-Fi password and reconnect your devices.
- 7
If unsure, reset Windows
Microsoft's recovery options include Reset this PC, reached in Windows 11 from Settings > System > Recovery and from Troubleshoot > Reset this PC in the recovery environment. Keep my files removes apps and settings; for a PC that ran a stealer, Remove everything is the choice that does not depend on finding every piece. Back up documents first; Microsoft calls the reset its most disruptive option.
- 8
Restore only documents
Copy back documents and photos by hand, not programs or scripts. Install programs again from their makers' own sites.
- 9
Warn the people you work with
If work mail was on the PC, tell your colleagues and regular customers. Stolen mailboxes are used to send fake invoices that look real.
Keep a PC out of this kind of chain
Every VIP Keylogger chain the researchers describe needs one action from a person: opening a file. That is where it is easiest to stop.
Do
- Show file name extensions in File Explorer (View > Show > File name extensions in Windows 11) so an invoice.pdf.js is visible for what it is.
- Treat an order, payment notice or shipping update with an attachment you did not expect as an attack until you confirm it by phone.
- Keep Windows and Microsoft Defender updated.
- Use a password manager instead of saving passwords in the browser.
- Turn on two step sign in for email, bank and work accounts.
- Keep a backup of documents on a drive you unplug.
Don't
- Do not double click .js, .vbs, .bat or .ps1 files that arrive by email or in a download.
- Do not run cracked programs or key generators.
- Do not change your passwords on the PC you suspect.
- Do not paste a wallet address without checking it afterwards.
- Do not take a quiet scan as proof that nothing was taken.
Questions about cablewireltd.site (VIP Keylogger, PowerShell stages)
What is cablewireltd.site?
It is a web address that URLhaus, the malware tracking project of abuse.ch, lists for nine malware files reported on 23 and 24 September 2026: seven PowerShell scripts named Crypted.ps1 and two JavaScript files.
Three are tagged VIPKeylogger. The domain was registered on 21 September 2026 and is now on server hold. It is not a program on your PC and not a site anyone is meant to visit.
Is cablewireltd.site safe?
No. It served malware files, and the fact that it is offline now does not change that. Our server could not resolve the name on 10 October 2026, and RDAP shows the status server hold, which usually follows an abuse report. Do not run any script that refers to it, and do not try to reach it.
What is Crypted.ps1?
It is the name used for seven PowerShell scripts on this host. PowerShell is a scripting tool built into Windows.
A file like this is a middle stage of an infection: a script the victim opened downloads it, and it then fetches and starts the next part. We did not open these files, so the exact content is not confirmed by us.
What is VIP Keylogger?
It is a .NET stealer for Windows that Seqrite describes as similar to Snake Keylogger. Splunk studied more than 200 of its loaders in 2026. It records keystrokes and takes saved browser passwords, cookies, cards and autofill data, email and Discord logins, Wi-Fi passwords, clipboard text and screenshots, then sends them to a Telegram bot or a server.
I saw cablewireltd.site in my firewall or DNS log. Am I infected?
Not necessarily. The name alone proves nothing. It does mean a device on your network asked for it, and people do not usually do that by hand.
Find the device, disconnect it, and do the checks on this page:
- the UserInitMprLogonScript value
- startup entries
- Protection history
- a Microsoft Defender Offline scan
Change passwords from another device.
How do I remove VIP Keylogger from Windows?
First change passwords and sign out sessions from another device. Then check HKEY_CURRENT_USER\Environment for a UserInitMprLogonScript value, look at Startup apps and Task Scheduler, and run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options. If you are not sure the PC is clean, use Reset this PC with Remove everything and restore only documents.
My browser closed by itself after I opened an attachment. Is that a sign?
It can be. Splunk reports that VIP Keylogger kills running browser processes before it reads their password and cookie files. A browser closing right after you opened an unexpected attachment is a strong reason to disconnect the PC and follow the steps on this page.
On its own, a browser closing is common and proves nothing; together with an unexpected script file it is worth acting on.
Does cablewireltd.site affect Mac, iPhone or Android?
We found nothing that says so. The files are PowerShell and Windows script stages and VIP Keylogger is a Windows .NET program.
On a Mac, iPhone or Android there is nothing to remove for this threat. Change any password that was saved on an infected Windows PC, from whichever device you trust.
Will resetting Windows protect my accounts?
No. A reset removes the stealer and its logon script from the PC, but it cannot bring back what was already sent. Saved passwords, cookies and cards stay in the attackers' hands until you change the passwords, sign out all sessions, block the cards and turn on two step sign in, from a clean device.
Will Fortect remove cablewireltd.site?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For cablewireltd.site, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for cablewireltd.site (entries read from our copy of the feed) (read October 10, 2026)
- Splunk Threat Research Team: Behind the Code, the Layered Defense-Evasion of VIP Keylogger (13 May 2026) (read October 10, 2026)
- Seqrite: VIPKeyLogger, Unveiling a Multistage Keylogger and Stealer (white paper) (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 10, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 10, 2026)