fahrzeugvergabe.de: a German FileFix page that made visitors paste a PowerShell command, and what to do if you did
fahrzeugvergabe.de is a German web address that URLhaus lists three times on 3 October 2026 for malware delivery, tagged ClickFix, FileFix, Loader and powershell. Those tags describe a page that makes you paste a command into File Explorer or the Run box yourself, which then downloads a program onto Windows.
The name no longer resolves today. If you only opened the page, nothing is proven. If you pasted something and pressed Enter, treat the PC as infected: change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a PowerShell command you pasted into File Explorer or the Run box because the fahrzeugvergabe.de page asked you to usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove fahrzeugvergabe.de (ClickFix and FileFix loader page) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Fahrzeugvergabe.de (ClickFix and FileFix loader page): summary
| Type | A ClickFix and FileFix page: it makes you paste a PowerShell command into Windows, which fetches a loader (URLhaus tags ClickFix, FileFix, Loader, powershell, exe, DEU) |
|---|---|
| Risk | High if you pasted the text and pressed Enter: passwords, sessions, crypto and work keys may be taken. Low if you only opened the page or saw the name |
| Symptoms | Usually none. A flash of a PowerShell window, a strange line in the Run box or File Explorer address history, or a Defender ClickFix alert |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, check RunMRU, TypedPaths, Startup and tasks, and reset Windows if you are not sure |
| Our check (8 October 2026) | One plain request from our server: the name did not resolve (ENOTFOUND). A dead site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Registration date not known (no RDAP record); first and only reports on 3 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Platform | Windows. The reports name PowerShell and an exe file; nothing points to Mac or phones |
|---|---|
| Detection names | Microsoft uses Trojan:Win32/ClickFix and Behavior:Win32/ClickFix for the paste trick. The name of the loader from this site is not known |
| Name | Fahrzeugvergabe.de |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 3 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data for fahrzeugvergabe.de held in our database, an RDAP lookup that returned no record, one plain request from our server that failed with ENOTFOUND, and published material from Microsoft, mr.d0x, Bridewell, Acronis, Elastic and the University of Muenster.
We never saw the page or the file and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What fahrzeugvergabe.de is, and what we know about it
fahrzeugvergabe.de is not a program on your PC. It is a German web address that the abuse.ch project URLhaus lists three times for malware delivery, with the tags ClickFix and FileFix. Those two names describe a trick, not a virus: a web page talks you into pasting a command into Windows yourself. We found no public write-up of this one address, so what follows is what URLhaus shows, what our server saw, and what Microsoft and security researchers have published about the trick.
- 1
What URLhaus lists
Three addresses on the site: the home page, a page called unterlagen.html and an address ending in /api/cm-token. All three were added on 3 October 2026 within four seconds of each other, at about 09:10 UTC, by the reporter YoshmanSJ. All three carry the threat label malware_download, and all three are now marked offline.
- 2
What the tags mean
ClickFix and FileFix are the names of the paste trick. Loader means the command fetches a program whose job is to bring in more malware. powershell names the Windows tool the command runs in, exe says a Windows program file was involved, and DEU marks the report as German. The tags come from the reporter; URLhaus shows them, it does not prove them.
- 3
What the names suggest
Fahrzeugvergabe means vehicle allocation or vehicle award in German, and Unterlagen means documents. Our reading is that the page posed as a German service handing out documents about a vehicle, a tender or a fleet contract, and asked the visitor to open those documents through File Explorer. No report we read describes the page itself, so treat this as our reading of the names, not as a fact.
- 4
What this means for you
Opening the page alone did not infect anyone, as far as every source on ClickFix and FileFix says. The harm starts when a visitor follows the instructions: copies a text, opens File Explorer or the Run box, pastes and presses Enter. If you did that, read the check and cleaning sections below. If you only saw the name in a log or a warning, nothing is proven.
- Kind of threat
- A FileFix and ClickFix page: a fake document or check page that makes you paste a PowerShell command into Windows, which then fetches a loader
- Reported addresses
- hxxps://fahrzeugvergabe[.]de/, hxxps://fahrzeugvergabe[.]de/unterlagen.html and hxxps://fahrzeugvergabe[.]de/api/cm-token
- URLhaus entries
- 3, all added on 3 October 2026 at about 09:10 UTC by YoshmanSJ; all 3 offline when we read our copy on 8 October 2026
- Registration
- Not known. Our RDAP lookup on 8 October 2026 returned no record for the name, so we cannot give a creation date or registrar
- Our test
- A plain request from our server on 8 October 2026 failed: the name did not resolve in DNS (ENOTFOUND)
- Platform
- Windows. The tags name PowerShell and an exe file. The same trick exists for Mac, but nothing in these reports points to a Mac version
What fahrzeugvergabe.de (ClickFix and FileFix loader page) does on an infected PC
What we checked on 8 October 2026, and what we could not
We sent one plain request to fahrzeugvergabe.de from our server on 8 October 2026. It did not reach any server: the lookup of the name failed with getaddrinfo ENOTFOUND, which means DNS no longer points the name anywhere. A site that is gone today tells you nothing about what it did on 3 October.
Our check, 8 October 2026
- The name does not resolveOur request ended with ENOTFOUND. The name has no working address in DNS right now. This can mean the domain was suspended, deleted or simply switched off by its operator.
- Why that is not a clean resultPages of this kind live for days or hours. An operator can switch the name back on, or move the same page to a new name. A dead address is not a sign that the people behind it stopped.
- Registration dataOur RDAP lookup returned no record. We cannot say when the name was registered or by whom.
- URLhaus listingThree addresses tagged ClickFix, FileFix, Loader, powershell, exe and DEU, all added on 3 October 2026, all offline now.
- The page and the filesWe never saw the page, the command or the program it fetched. We cannot say which malware family the loader carried.
Dangerous: treat it as a malware page The rating comes from the three URLhaus reports and their tags, not from our request, which could not reach anything. If the name comes back, do not open it and do not follow any instruction it gives.
What happened to fahrzeugvergabe.de, from the reports to our check
The whole story we can see fits into five days. The dates come from the URLhaus data we hold and from our own request; the times are UTC.
Before 3 October 2026
Registration, date not known
Our RDAP lookup gave no record, so we cannot say when fahrzeugvergabe.de was registered or who the registrar is. The .de registry, DENIC, publishes very little about private holders.
3 October 2026, 09:10:11 UTC
The document page is reported
URLhaus adds hxxps://fahrzeugvergabe[.]de/unterlagen.html with the tags ClickFix, DEU, exe, FileFix, Loader and powershell. Unterlagen is German for documents.
3 October 2026, 09:10:12 UTC
The home page is reported
One second later the home page itself is added with the same six tags and the threat label malware_download.
3 October 2026, 09:10:14 UTC
The api/cm-token address is reported
Two seconds after that, hxxps://fahrzeugvergabe[.]de/api/cm-token is added with the same tags. Its role is not explained in the report. Our reading is that the page called this address to get the next piece of the attack, but we did not see it.

The three URLhaus entries for fahrzeugvergabe.de, read on 8 October 2026. There is no screenshot of the site: by the time we checked, the name no longer resolved. 8 October 2026
Our check
All three entries are marked offline. Our plain request fails because the name does not resolve in DNS.
What the pattern suggests, and what it does not: three addresses reported in four seconds looks like one person recording one attack chain, page, document page and the address the page talks to. That is our reading of the times, not something the report says.
How FileFix and ClickFix work
ClickFix and FileFix do not break into Windows. They make you run the attacker's command yourself, so Windows sees an ordinary user action. We did not see the page on fahrzeugvergabe.de; this is how Microsoft, the researcher mr.d0x, Bridewell and Acronis describe the technique.

- 1
ClickFix: a fake check or a fake error
Microsoft's Threat Intelligence team (21 August 2025) describes pages that show a fake CAPTCHA, a fake Cloudflare check or a fake browser crash. The page tells you to press the Windows key and R, then Ctrl and V, then Enter. The page has already put a command on your clipboard, so the Run box starts PowerShell or mshta with the attacker's code.
- 2
FileFix: a fake shared file
The researcher mr.d0x published FileFix on 23 June 2025. The page says a file was shared with you and tells you to copy its path, open File Explorer, press Ctrl and L to select the address bar, paste and press Enter. The copied text is really a PowerShell command followed by a # sign and a harmless looking path, so the box shows only the path.
- 3
Why the browser opens File Explorer
The page uses an ordinary file upload button. When you click it, Windows opens its own file window, and the address bar of that window can run commands. mr.d0x notes that a program started this way loses the Mark of the Web, the label Windows puts on downloaded files to warn you.
- 4
What the command does
In the cases Bridewell and Acronis describe, the pasted command starts PowerShell without a visible window, downloads the next stage and runs it. Acronis (16 September 2025) found a FileFix page posing as a Meta security notice in 16 languages, German among them, that pulled code out of JPG pictures and ended with the StealC password stealer.
- 5
What arrives at the end
Microsoft lists Lumma Stealer, Xworm, AsyncRAT, NetSupport, SectopRAT, Latrodectus, DarkGate and others as payloads of ClickFix campaigns. Bridewell names MintsLoader, StealC and the Interlock remote access tool for FileFix. Which one fahrzeugvergabe.de delivered is not known.
The German University of Muenster warned its own staff about the same trick on 7 May 2026. It lists the key presses to watch for: Windows and R, Windows and X followed by I for the Terminal, Ctrl and V, copying a verification code into a new window, or copying a browser address as a check. It says that real CAPTCHAs never ask for any of this.
What a ClickFix or FileFix loader usually brings
The tag Loader says the first program was a door opener. What came through that door on 3 October is not in the report, so the table shows what the sources found in other campaigns of the same kind.
| Question | What the sources say | Source |
|---|---|---|
| What is a loader? | A small program whose job is to download and start the real malware, often after checking that it is not in a test machine | Bridewell; Acronis |
| Which families came through ClickFix? | Lumma Stealer, Xworm, AsyncRAT, NetSupport, SectopRAT, Latrodectus, MintsLoader, DarkGate, Lampion, ScreenConnect and a modified r77 rootkit | Microsoft Security Blog, 21 August 2025 |
| Which came through FileFix? | MintsLoader, GhostWeaver, StealC and the Interlock RAT, which is tied to Interlock ransomware | Bridewell |
| What did the one in the wild steal? | StealC took browser passwords and data, crypto wallets, Telegram, Discord and other chat apps, VPN settings and Azure and AWS keys | Acronis TRU, 16 September 2025 |
| Did any target Germany? | Acronis lists Germany among the countries of the FileFix campaign it studied. The Muenster warning shows the trick reaching German users in 2026 | Acronis; University of Muenster |
| Which one did this site deliver? | Not known. URLhaus shows only the tags; we never saw the file | Not available |
What fahrzeugvergabe.de (ClickFix and FileFix loader page) can steal or download
What can be taken if you ran the command
Because the final program is not known, this list is what the families above are known to take. Each item is named by at least one source; no single report lists all of them.
Reported as possible
- Saved browser passwords
- Browser cookies and logged in sessions
- Crypto wallet files and extensions
- Telegram and Discord data
- VPN settings
- Cloud keys for Azure and AWS
- Keystrokes and screen
- Remote control of the PC
- More malware, up to ransomware
| Data | Detail | Source |
|---|---|---|
| Logins | Passwords and data from many browsers | Acronis (StealC) |
| Sessions | Session cookies that let someone use your accounts without the password | University of Muenster |
| Money | Wallets such as Exodus, Electrum, Ledger Live, Atomic and Binance | Acronis (StealC) |
| Work access | Azure and AWS keys, VPN profiles | Acronis (StealC) |
| The PC itself | Remote access tools such as AsyncRAT, NetSupport and the Interlock RAT | Microsoft; Bridewell |
What this can cost you
Seeing the name costs nothing. Opening the page and closing it costs nothing as far as the sources say. The risks below apply to a Windows PC where someone pasted the text and pressed Enter.
- High
Email, bank and work accounts
Stealers take saved passwords and session cookies. A stolen session can open your mailbox without a password and without a two step code.
- High
Crypto
Wallet files and browser wallet data are on every stealer list we read. Crypto that has been moved cannot be called back.
- High
Your employer's network
A page about vehicle documents reads like a business lure. Interlock, named by Bridewell, is tied to ransomware against companies. If this was a work PC, tell your IT team at once.
- Medium
Someone using the PC later
If the loader brought a remote access tool, the attacker can return at any time and watch what you do.
- Low
Nothing, if you only saw the name
A name in a block list, a DNS log or a browser warning is not an infection.
What you may notice, and what you may not
The command runs hidden and the stealers work in seconds, so most people notice nothing. These are the traces that are left.
| Sign | What it means |
|---|---|
| A PowerShell window that flashed and closed | The command may have run. Many versions hide the window completely |
| A command in the Run box history | Microsoft names the RunMRU registry key as the place where Run box entries are kept |
| A command in the File Explorer address history | Elastic's detection rule looks at the TypedPaths registry key, which normally holds only folder paths |
| A Defender alert named Trojan:Win32/ClickFix or Behavior:Win32/ClickFix | Microsoft uses these names for the paste trick itself |
| Logins or messages you did not make | Sign in alerts from new places, password reset emails, posts sent from your accounts |
| Nothing at all | The usual case |
How to check the PC for fahrzeugvergabe.de (ClickFix and FileFix loader page)
How a person ends up on a page like this
Nobody types fahrzeugvergabe.de by chance. The name and the German tag point to a lure aimed at German speaking people or companies. We do not know how the link was sent; these are the routes the sources name for ClickFix and FileFix pages.
- 1
An email with a link to documents
Microsoft describes phishing emails with links or HTML attachments that lead to a ClickFix page. A message about a vehicle, a tender or a contract with a link to the documents fits that pattern; that part is our reading.
- 2
A search result or an advert
The University of Muenster lists manipulated search results and adverts among the ways in. Microsoft also describes pages that open from free streaming sites.
- 3
A hacked legitimate site
Microsoft and Bridewell describe real websites that were broken into and made to show the fake check. The visitor trusts the site and follows the steps.
- 4
A fake notice from a big brand
Acronis describes a FileFix page that posed as a Meta security notice warning that a Facebook account would be closed, asking the visitor to open a shared PDF through File Explorer.
Check your PC before you delete anything
The one question that matters: did you, or someone using this PC, paste a text into File Explorer, the Run box or the Terminal because a web page asked you to? If no, you are not infected by this site. If yes or not sure, do the checks below. None of them deletes anything.
Stop using the PC for banking, email, work or crypto until you are done. The University of Muenster tells its staff to disconnect the device from the network right away; do that if you can.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. A stealer needs the connection to send what it took, and a remote access tool needs it to be used.
- 2
Look at the Run box history
Microsoft names the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Open Registry Editor (press Start, type regedit) and go there. An entry that starts PowerShell, mshta or cmd with a long text you did not type yourself is the trace of ClickFix. Write it down; do not delete it yet.
- 3
Look at the File Explorer address history
Elastic's FileFix rule watches the TypedPaths key under Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths in your user hive. It normally holds folder paths. A line that starts with powershell or another command, often followed by a # and a document path, is the trace of FileFix.
- 4
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for Trojan:Win32/ClickFix, Behavior:Win32/ClickFix or anything blocked around 3 October 2026 or the day you visited. Microsoft's ClickFix entry says Defender removes threats it detects, and tells you to update definitions and run a full scan.
- 5
Look at Startup apps and Task Scheduler
Open Settings > Apps > Startup and look for names you did not install. Then press Start, type Task Scheduler and look in Task Scheduler Library for tasks with random names that run PowerShell or a program from a user folder. Loaders often add one of these to come back after a restart.
- 6
Look at Installed apps
In Settings > Apps > Installed apps, look for remote support tools you did not install, such as ScreenConnect or NetSupport. Microsoft lists both among ClickFix payloads.
- 7
Check your accounts from another device
Look at the sign in activity of your email, bank, work and exchange accounts and at crypto balances. This is quicker than any file check, and it is where a stealer hurts.
- 8
A scan helps, but it does not clear the PC
A full scan finds known files. No vendor has published an analysis of this site's loader, and we did not infect a PC, so the order of the plan is our judgement from Microsoft's pages, not a tested result.

How to remove fahrzeugvergabe.de (ClickFix and FileFix loader page)
How to remove fahrzeugvergabe.de
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to fahrzeugvergabe.de or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever fahrzeugvergabe.de installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags on every report name PowerShell and an exe file, both Windows only. ClickFix pages for Mac do exist: Microsoft names the Atomic macOS Stealer among ClickFix payloads, and Muenster mentions Terminal variants for macOS and Linux. Nothing in these three reports points to one.
| Your device | What we know | What to do |
|---|---|---|
| Mac | The reports name PowerShell and exe, which do not run on a Mac. Mac ClickFix pages ask you to paste into Terminal instead | If you pasted anything into Terminal because a page asked you to, treat the Mac as infected and change passwords from another device |
| iPhone or iPad | No source describes this trick on iOS; there is no Run box or address bar that runs commands | Nothing to remove. If you typed passwords on the page, change them |
| Android | No source mentions it | Nothing to remove for this threat; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Cleaning the PC does not bring back what a stealer sent away in the first seconds. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Muenster tells staff to change every password stored or used on the device from another, trusted device. Start with email, because it resets everything else, then bank, work, cloud and crypto exchanges.
- 2
Sign out every other session
Stolen session cookies keep working after a password change on some services. In each important account, use the option to sign out of all devices, then turn on two step sign in with an authenticator app or a security key.
- 3
Move crypto first if a wallet was on the PC
StealC looks for wallet files and browser wallets. If a wallet or a recovery phrase was on the PC, create a new wallet on a clean device and move the funds there.
- 4
Tell your employer if it was a work PC
Cloud keys, VPN profiles and work logins are on the stealer lists. Your IT team needs to know the time and the address so it can revoke keys and look for the same command on other PCs.
- 5
Run Microsoft Defender Offline
Microsoft Learn says to open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Offline scan and Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. Results appear in Protection history. If BitLocker is on, suspend it first or the restart may ask for the recovery key.
- 6
Remove what the checks found, with care
Delete a startup entry, task or remote tool only when you can tie it to the time of the paste. If you cannot tell, do not guess: the reset below is the safer answer.
- 7
If you are not sure, reset Windows
Microsoft Support puts it at Settings > System > Recovery > Reset this PC. Reset reinstalls Windows and removes apps and settings; you choose whether to keep or remove personal files. For a PC that ran an unknown loader, Remove everything does not depend on finding every piece. Back up documents first, as Microsoft says.
- 8
Restore only documents by hand
Copy back documents and photos, not programs and not a full system image from after the paste. Install apps again from their makers' own sites.
- 9
Watch your accounts for weeks
Turn on login and card alerts. Stolen data is often used days or weeks later. Report misuse to your bank and, in Germany, to the police; a report helps if money is lost.
Keep a PC out of this kind of trick
Every ClickFix and FileFix attack needs one thing from you: the paste. Nothing else in the chain works without it.
Do
- Close any page that asks you to press Windows and R, Windows and X, or Ctrl and L and then paste something. Muenster says real CAPTCHAs never do this.
- Open shared documents only in the service that shared them, in the browser, never by pasting a path into File Explorer.
- Use Microsoft Edge or another browser with SmartScreen or a similar filter, as Microsoft recommends, and keep Windows and Defender updated.
- In a company, follow Microsoft's advice: remove the Run box by policy where it is not needed, and turn on PowerShell script block logging.
- Use a password manager and two step sign in, so one stolen password or cookie is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not paste anything into Windows because a website, an email or a chat told you to, even if it says it is a check or a fix.
- Do not trust a page because it is in perfect German or carries a known brand.
- Do not keep crypto recovery phrases in a text file or in the browser.
- Do not change your passwords on the PC you suspect.
- Do not take a quiet scan or a dead website as proof that you are safe.
Questions about fahrzeugvergabe.de (ClickFix and FileFix loader page)
What is fahrzeugvergabe.de?
It is a German web address that URLhaus, the malware tracking project run by abuse.ch, lists for three addresses reported on 3 October 2026:
- the home page
- unterlagen.html
- api/cm-token
All carry the tags ClickFix, FileFix, Loader, powershell, exe and DEU. It is not a program on your PC. The name no longer resolves, and we never saw the page itself.
Is fahrzeugvergabe.de safe?
No. Treat it as a malware page. Our request on 8 October 2026 could not reach it because the name no longer resolves, but that proves nothing: such pages are switched off and on and moved to new names. The rating comes from the three URLhaus reports and their tags.
What is FileFix?
FileFix is a version of the ClickFix trick published by the researcher mr.d0x in June 2025. A page says a file was shared with you and asks you to copy its path, open File Explorer, press Ctrl and L, paste and press Enter.
The copied text is really a PowerShell command hidden in front of a # sign and a fake path, so pressing Enter runs it.
What is ClickFix?
ClickFix is the name Microsoft and others use for pages that show a fake CAPTCHA, a fake check or a fake error and tell you to press Windows and R, then Ctrl and V, then Enter.
The page has put a command on your clipboard, so you start the malware yourself. Microsoft says these campaigns reach thousands of devices every day.
I only opened the page. Am I infected?
As far as every source we read says, no. ClickFix and FileFix need you to paste and run the command.
If you closed the page without pasting anything into Windows, there is nothing to remove for this threat. If you typed a password into the page, change it from another device.
I pasted the text and pressed Enter. What now?
Disconnect the PC from the network. From another device, change your email, bank, work and crypto passwords, sign out all other sessions and turn on two step sign in.
Then run Microsoft Defender Offline, check the RunMRU and TypedPaths history, Startup apps and Task Scheduler, and reset Windows with Remove everything if you are not sure. Tell your IT team if it was a work PC.
How do I find out what I pasted?
Microsoft names the RunMRU registry key under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer for the Run box history, and Elastic's FileFix rule watches the TypedPaths key in the same place for the File Explorer address bar. A line that starts PowerShell, mshta or cmd with a long text is the trace. Do not run it again.
What malware did fahrzeugvergabe.de deliver?
Not known. URLhaus says Loader and exe but no family name, and we never saw the file.
Other ClickFix and FileFix campaigns delivered Lumma Stealer, StealC, AsyncRAT, NetSupport, MintsLoader and the Interlock RAT, according to Microsoft, Acronis and Bridewell, so plan as if a password stealer ran. Change passwords from another device first.
Does fahrzeugvergabe.de affect Mac, iPhone or Android?
Nothing in the reports says so: they name PowerShell and an exe file, which are Windows only. Mac versions of ClickFix exist and ask you to paste into Terminal; if you did that on a Mac, treat it as infected. On an iPhone or Android phone there is nothing to remove; change any password you typed into the page.
Will Fortect remove fahrzeugvergabe.de?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For fahrzeugvergabe.de, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Microsoft Security Blog: Think before you Click(Fix), analyzing the ClickFix social engineering technique (21 August 2025, updated 19 August 2026) (read October 8, 2026)
- Microsoft Security Intelligence: Trojan:Win32/ClickFix (published 8 May 2025) (read October 8, 2026)
- mr.d0x: FileFix, a ClickFix alternative (23 June 2025) (read October 8, 2026)
- Bridewell: FileFix, the evolved ClickFix (read October 8, 2026)
- Acronis TRU: FileFix in the wild, new FileFix campaign goes beyond POC and leverages steganography (16 September 2025) (read October 8, 2026)
- Elastic Security: Potential FileFix Command via Windows Explorer Address Bar (detection rule, TypedPaths) (read October 8, 2026)
- Universitaet Muenster, Stabsstelle Informationssicherheit: Warnung vor Angriffen mit gefaelschten Captchas (ClickFix) (7 May 2026) (read October 8, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 8, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 8, 2026)