ikovrsps.com: a server handing out Java game files and an EXE tagged stealer and CoinMiner, and what to do if you ran them

ikovrsps.com is a web address that URLhaus lists three times in two days for game style files (Ikov.jar, Mina.jar and gamefiles/image.exe), all tagged stealer and runelite, two also tagged CoinMiner. If you only saw the name in a log or a warning, nothing is proven.

If you downloaded and ran one of these files, treat the Windows PC as compromised: change your passwords from another device, then scan with Microsoft Defender Offline and clean or reset Windows.

Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a file called Ikov.jar, Mina.jar or image.exe that came from ikovrsps.com usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove ikovrsps.com (stealer and CoinMiner files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of three URLhaus entries for ikovrsps.com: Ikov.jar, Mina.jar and image.exe, tagged stealer, runelite, runelure, two also CoinMiner
The three URLhaus entries for ikovrsps.com that we hold, added on 6 and 7 October 2026. We made no browser test; our check was one plain request from our server, so this table of reports is the main evidence.

Ikovrsps.com (stealer and CoinMiner files): summary

TypeA malware server: URLhaus tags its three files stealer and runelite, and two of them CoinMiner
RiskHigh if you ran one of the files: logins, tokens, wallet data and processor time may be taken. Low if you only saw the name
SymptomsOften none. A hot, slow PC with high processor use and an unknown javaw.exe are the signs the tags suggest
How to get rid of itChange passwords and sign out all sessions from another device, run Microsoft Defender Offline, delete the files, and reset Windows if you are not sure
Our check (11 October 2026)One plain request from our server: a 307 redirect to another host. That clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 22 January 2026; first file reported 6 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows for image.exe; the jar files run wherever Java does, but the stealers vendors describe target Windows
Detection namesNo Microsoft detection name is known for these files because we did not open them. Other vendors name similar Java stealers Trojan.Java.Fractureiser.* (Bitdefender) and Java/DiscordSteal.gen (Intego)
NameIkovrsps.com
Domain registered22 January 2026
Evidence3 write-ups by security sites; details still limited
First seen6 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked11 October 2026

Facts checked on 11 October 2026 against the URLhaus data for ikovrsps.com held in our database, RDAP, one plain request from our server, and published reports by Check Point Research, Bitdefender, Intego, the OSRS Wiki and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What ikovrsps.com is, and what we know about it

ikovrsps.com is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served. The three files are named like parts of a game download, and the tags mention runelite, which is the name of a well known add on client for the game Old School RuneScape. We found no public write up of this address, so this page uses what URLhaus shows, what our server saw, and vendor reports on similar Java stealers.

  1. 1

    What URLhaus lists

    Three file addresses on ikovrsps.com: /Ikov.jar, /Mina.jar and /gamefiles/image.exe. Ikov.jar was added on 6 October 2026 at about 16:19 UTC, Mina.jar and image.exe on 7 October at about 04:41 UTC. All three carry the threat label malware_download and the same reporter, rc4. When we read our copy of the data, only image.exe was marked online; the two jar files were marked offline.

  2. 2

    What the tags mean

    stealer means the file is said to steal data such as passwords. CoinMiner (on the two jar files) means it is said to use your processor to mine cryptocurrency for someone else. runelite names the game client the files imitate or hide behind. runelure is a tag we cannot explain: we found no vendor page that defines it, so we do not claim to know whether it is a family name or a label the reporter made up.

  3. 3

    What we could not confirm

    We did not download any of the three files, so we cannot tell you what they do, what they connect to, or which Microsoft detection name they carry. URLhaus shows tags, not proof. We also do not know how a victim is sent to this address; the first step is not visible from the server side.

  4. 4

    What this means for you

    If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a Windows PC where someone downloaded and ran Ikov.jar, Mina.jar or image.exe, or where a program fetched them. Our reading of the file names is that they target players of a game server called Ikov; that is a guess from the names, not a finding.

Kind of threat
A server that hands out two Java archives and one Windows program, tagged stealer; the two jar files are also tagged CoinMiner
Where the files are
hxxps://ikovrsps[.]com/Ikov.jar, hxxps://ikovrsps[.]com/Mina.jar and hxxps://ikovrsps[.]com/gamefiles/image.exe
Domain registered
22 January 2026, registrar Ultahost, Inc., status active (RDAP, read 7 October 2026)
URLhaus entries
3 file addresses, added 6 and 7 October 2026; 1 online (image.exe) and 2 offline in our copy of the data
Delivery
Not known. Game files that people download by hand or through a launcher are the likely route, which is our reading of the names
Platform
Windows for image.exe. A .jar file runs on any system with Java, so Mac and Linux users who ran a jar are also in question; the stealer part that the tags describe has only been documented for Windows

What ikovrsps.com (stealer and CoinMiner files) does on an infected PC

What we checked on 11 October 2026, and what we could not

We made one plain request to https://ikovrsps.com/ from our server, with no browser and no clicks. The server answered with a redirect to a different address. That clears nothing: a plain request is exactly what a cloaking server can answer differently from a real visitor.

Our server request, 11 October 2026

  • The home page redirects awayThe answer was HTTP 307 Temporary Redirect from a LiteSpeed web server, pointing to hxxps://recaptcha[.]cloud/ with the server's address, our address and the host name added as parameters. recaptcha.cloud is not Google's reCAPTCHA domain. We did not follow the redirect, so we do not know what that page shows. A gate that sends visitors to a page styled as a check is a pattern vendors describe, but we did not see it here.
  • Why that is not a clean resultA server that serves malware files can answer a plain request with an unrelated page and still hand the files to a visitor who asks for the exact file address. A quiet or odd home page is not a sign of safety.
  • Notification requestNot seen in this one request. There was no page body to see, only the redirect.
  • URLhaus listingThree file addresses tagged stealer and runelite, two also CoinMiner; one still online in our copy of the data.
  • Downloads and the files themselvesWe did not download any file. We cannot tell you what Ikov.jar, Mina.jar or image.exe contain.

Dangerous: treat it as a malware server Our test was one plain request, so it proves nothing either way. The danger rating comes from the three URLhaus reports and their tags, not from our request. Do not download or run files from this address.

What happened to ikovrsps.com, from registration to our check

The domain is under nine months old and every report is from the last week. The dates come from RDAP and from the URLhaus data we hold; times are UTC.

  1. 22 January 2026

    The domain is registered

    RDAP shows ikovrsps.com registered on 22 January 2026 through Ultahost, Inc. The record was active when we read it on 7 October 2026.

  2. 6 October 2026

    Ikov.jar is reported

    At about 16:19 UTC abuse.ch contributor rc4 adds https://ikovrsps.com/Ikov.jar with the tags CoinMiner, runelite, runelure and stealer. The file is marked offline in our copy.

  3. 7 October 2026

    Mina.jar and image.exe are reported

    At about 04:41 UTC the same reporter adds Mina.jar (tags CoinMiner, runelite, runelure, stealer, offline) and gamefiles/image.exe (tags runelite, runelure, stealer, online). Two entries within two seconds suggest the files were found together.

    Table of the three URLhaus entries for ikovrsps.com with dates, file names, online status and tags
    All three URLhaus entries for ikovrsps.com. The jar files are offline, the exe was still online in our copy.
  4. 11 October 2026

    Our plain request

    The home page answers with a 307 redirect to a different host. We do not know whether the files are still served.

Timeline from domain registration on 22 January 2026 to the three reports on 6 and 7 October and our request on 11 October
Registration, reports and our request on one line. Dates from RDAP and URLhaus.

What the pattern suggests, and what it does not: a domain that waits nine months and then serves three files within a day looks like a server prepared for a campaign. That is our reading of the dates; no report says it.

How a Java game file can carry a stealer

We did not open Ikov.jar or Mina.jar. Security vendors have, however, published detailed analyses of Java archives that hide stealers behind game mods, and the mechanism is the same kind. Read the points below as how such files work in general, not as proof of what these two do.

Four steps: a player downloads a game file, the Java archive loads, a second stage is fetched, data is sent out
The chain as vendors describe it for Java game malware. The first step for ikovrsps.com is not something we saw.
  1. 1

    A person installs a file that looks like part of a game

    Check Point Research (18 June 2025) describes fake Minecraft mods and cheat tools on GitHub. The Java archive in that campaign did nothing when run with java -jar; it only ran when it sat in the Minecraft mods folder and the game started. That is why a casual scan or a sandbox without the game can see nothing.

  2. 2

    The first stage checks where it runs

    Check Point says the downloader compared system properties with a list of virtualization keywords and ran tasklist to look for analysis and network tools, and quit if it found them. A researcher's test machine therefore often sees a harmless file.

  3. 3

    It fetches the next stage

    In Check Point's case the address of the second stage was stored in a Base64 paste on Pastebin and loaded into memory. Bitdefender (published 8 June 2023, updated 21 May 2025) describes a staged Java chain called Fractureiser with a first stage that creates persistence and a later stage that downloads and updates the final payload.

  4. 4

    It spreads and stays

    Bitdefender found that the malware tried to infect other Java archives on the PC, including ones that are not game mods, and stripped their signature files afterwards. In one variant it installed a Windows service. Any program that runs Java could therefore be carrying it.

  5. 5

    It sends your data out

    Check Point lists Minecraft and Discord tokens, Telegram data, browser logins, wallet data and a screenshot, sent in a zip to a Discord webhook. Intego (29 May 2026) describes a newer polymorphic Java loader whose Windows payload sends Discord tokens and account fields to a Discord webhook.

A cryptocurrency miner, as the CoinMiner tag says, is a different goal: it uses your processor and graphics card, and the first sign is usually a hot, slow PC. Whether Ikov.jar and Mina.jar carry a miner, a stealer or both, we cannot say; URLhaus gives only the tags.

What ikovrsps.com (stealer and CoinMiner files) can steal or download

What a stealer of this kind can take from a Windows PC

The list below is what the sources say comparable Java based stealers take. It is not a list of what these three files take, because we did not open them. Each item is named by at least one source.

Reported for similar Java game malware

  • Game account tokens
  • Discord tokens
  • Microsoft account credentials
  • Saved browser logins and cookies
  • Telegram data
  • Cryptocurrency wallet data
  • Clipboard contents, and wallet addresses swapped for the attacker's
  • VPN and file transfer logins
  • Files from Desktop and Documents
  • A screenshot
  • Processor time for mining
Sources: Check Point Research (18 June 2025), Bitdefender (8 June 2023, updated 21 May 2025) and Intego (29 May 2026), read 11 October 2026.
DataDetailSource
Game and chat tokensMinecraft, launcher, Discord and Telegram data taken and sent as JSON or a zipCheck Point
Browser dataChromium, Edge and Firefox credentials (Check Point); cookies and saved logins from popular browsers (Bitdefender)Check Point; Bitdefender
Microsoft loginA function that retrieves Microsoft account credentialsBitdefender
Clipboard and cryptoWallet data for about a dozen wallets; a clipboard monitor that replaces copied wallet addresses with the attacker'sCheck Point; Bitdefender
Files and screenshotFiles from Desktop, Documents and source folders, and one screenshotCheck Point
Discord accountsTokens and account fields sent to a Discord webhookIntego

What this can cost you

Reading the site or seeing its name costs nothing. The risks below apply to a PC where one of the three files was run.

  • High

    Game, Discord and email accounts

    A stolen token lets someone use an account without the password, and it can survive a password change until the session is signed out. Game accounts with valuable items are a common target.

  • High

    Crypto and banking logins

    Wallet data and saved browser logins are on the lists above. Crypto sent out cannot be recalled, and a clipboard swapper can redirect a payment you make later.

  • Medium

    A slow, hot PC from mining

    The CoinMiner tag points to a miner. It wears out fans, raises the power bill and makes the PC unusable for games.

  • Medium

    More infected files

    Bitdefender found that the malware it studied infected other Java archives. Files you copy to friends can carry it on.

  • Low

    Nothing, if you only saw the name

    A name in a block list, a log or a warning is not an infection.

What you may notice, and what you may not

Stealers are built to be quiet. The signs below come from the sources and from the CoinMiner tag; none is certain, and many victims notice nothing.

SignWhat the reports show
High processor or graphics use with nothing openThe expected sign of a miner, which is our reading of the CoinMiner tag
A java or javaw process you did not startThe Java stages run inside Java. A javaw.exe in Task Manager with no game open is worth a look
A Windows service or program you did not installBitdefender found one variant that installed a service named NekoService; this is one build, not this server's files
Logins from new places, Discord messages you did not sendThis follows from stolen tokens; it is our reading, not a quote
Jar files that changedBitdefender says the malware it studied removed the signature files from jar archives it infected
Nothing at allJava stages that check for analysis tools and run in memory are designed to be quiet

How to check the PC for ikovrsps.com (stealer and CoinMiner files)

How a person ends up with these files

Nobody needs to visit ikovrsps.com for any other reason than to download the files. We cannot say how people are led there. The routes below are the ones vendors found for similar Java game malware.

  1. 1

    A fake or modified game client

    The tag runelite and the folder name gamefiles suggest a client download. The OSRS Wiki says the official RuneLite site is runelite.net and that on 2 March 2022 Jagex and RuneLite added a link to it on the game homepage, particularly to prevent phishing by fake RuneLite websites. Anything else offering a client is not that.

  2. 2

    Mods and cheat tools from a repository or chat

    Check Point found fake mods with fake stars on GitHub. Stars and forks do not show a file is safe.

  3. 3

    Files shared inside a gaming community

    Intego notes that a jar can be passed through shared folders, chat apps and gaming communities. A file sent by a friend whose account was taken over is a common start.

  4. 4

    A private server's own download

    A private game server needs its players to install a client. That makes a download page believable. We did not see this server's page and do not say that the server itself is a fraud; we say that the files URLhaus lists are tagged as malware.

Check your PC before you delete anything

Start with the question that matters: did you or anyone on this PC download or run Ikov.jar, Mina.jar or image.exe, or a game client from a server called Ikov? If you saw the name in a router or DNS log, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and disconnect it from the network if you can.

  1. 1

    Find the files

    Open File Explorer > Downloads and look for Ikov.jar, Mina.jar and image.exe, and for the game folder you installed. Note names and dates; do not open them.

  2. 2

    Look at Installed apps

    Open Settings > Apps > Installed apps and sort by install date. Look for a game client, launcher or Java tool you did not install on purpose.

  3. 3

    Look at Startup apps

    Open Settings > Apps > Startup. A name you do not know, or a Java launcher that starts with Windows, is worth writing down. Do not delete yet.

  4. 4

    Check Task Manager

    Press Ctrl+Shift+Esc, open Processes and sort by CPU. Look for javaw.exe or a program you do not know using a lot of processor while you do nothing. Bitdefender also names a Windows service called NekoService for one build; look in Services only as a hint, since this server's files may differ.

  5. 5

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for anything blocked or quarantined around the time of the download. Microsoft says offline scan results appear there too.

  6. 6

    Check your accounts from another device

    Look at sign in activity for email, Discord, your game account, bank and exchange accounts, and at crypto balances. This is quicker than any file check.

  7. 7

    A scan helps, but it does not clear the PC

    A scan can find known files. Check Point says the Java downloader it studied had no detections when published, and Java loaders are often overlooked. Treat a clean result as one data point. The plan below is our judgement from Microsoft's pages and the vendor write ups, not a tested removal.

How to remove ikovrsps.com (stealer and CoinMiner files)

How to remove ikovrsps.com

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like ikovrsps.com add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after ikovrsps.com, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of ikovrsps.com that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Ikovrsps.com can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The file image.exe is a Windows program. The two .jar files are Java archives, which can run on any system with Java installed.

Your deviceWhat we knowWhat to do
MacIntego says Java carrier files move freely between systems and that the final stealer it studied was for Windows. We do not know what Ikov.jar does on a MacIf you ran a jar from this address, delete it, change the passwords you used on that Mac and scan it. Do not follow the Windows steps
iPhone or iPadJava archives do not run on iOS. No source describes this threat thereNothing to remove. If you typed passwords on a page from this address, change them
AndroidNot known; the tags and sources describe desktop Java and WindowsNothing to remove for this threat that we know of; change passwords if you entered any

After removal: passwords, accounts and prevention

If you ran one of the files: clean up in the right order

The PC is one half. The other half is everything you typed or stored on it. The order matters: another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, sign out all sessions, run Defender Offline, reset Windows if unsure
The order of actions if one of the files ran. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then Discord, game, Microsoft, bank, work and crypto accounts. Anything typed on the PC after the file ran may be known.

  2. 2

    Sign out all sessions and turn on two step sign in

    Tokens survive a password change. In Discord, Microsoft, Steam and your game account, use the option to sign out of all devices, then turn on two step sign in. Intego advises treating stolen Discord tokens as compromised and reviewing account activity.

  3. 3

    Move crypto first if a wallet was on the PC

    If a seed phrase or wallet file was ever on the PC, assume it is known. Create a new wallet and phrase on a clean device and move the funds.

  4. 4

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on the system drive, suspend it first or the restart may ask for the recovery key. Results are under Protection history. Microsoft notes that the scan does not run if Windows Recovery Environment is disabled.

  5. 5

    Remove the files and check Java archives

    Delete Ikov.jar, Mina.jar, image.exe and the game folder you installed from them. Bitdefender found that its malware infected other jar files, so do not copy jars from that PC to another.

  6. 6

    If you are not sure, reset Windows

    Open Settings > System > Recovery > Reset this PC. Remove everything wipes the PC. Because Java stages can spread into other archives and may sit in memory, the full wipe is the answer that does not depend on finding every piece. Back up documents first.

  7. 7

    Restore only documents by hand

    Copy back documents and photos, not programs, not jar files and not a system image from after the first contact. Install the game client only from its official site.

  8. 8

    Watch your money and your accounts

    Check card statements, exchange logs and game account activity for a few weeks. Turn on alerts. Tell the people you message if your Discord account sent links.

Keep a PC out of this kind of chain

Every write up we read starts with a person running a file that came with a game, a mod or a cheat.

Do

  • Download RuneLite only from runelite.net, the address the OSRS Wiki names as official, or through the game's own homepage link.
  • Treat any game client, mod or cheat tool from a chat message, a video description or a random repository as untrusted, however many stars it has.
  • Keep Windows and Microsoft Defender updated; the offline scan uses the latest definitions.
  • Use a password manager and two step sign in, so one stolen token or password is not enough.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not run image.exe, Ikov.jar or Mina.jar from this address.
  • Do not install a private server's client on the PC you use for banking, email or crypto.
  • Do not change your passwords on the PC you suspect.
  • Do not share jar files from a PC that ran one of these files.
  • Do not rely on a quiet scan to say that you are safe.

Questions about ikovrsps.com (stealer and CoinMiner files)

What is ikovrsps.com?

It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for three files:

  • Ikov.jar
  • Mina.jar
  • gamefiles/image.exe

All are tagged stealer and runelite, and the two jar files are also tagged CoinMiner. They were reported on 6 and 7 October 2026.

It is not a program on your PC. We did not download the files, so what they contain is not confirmed by us.

Is ikovrsps.com safe to open?

No. Do not download or run files from it. Our own check was one plain request from our server, which got a redirect to another host.

That proves nothing, because a server that hands out malware can show a visitor something different from what it gives to a request for an exact file address. The rating comes from the three URLhaus reports and their tags, not from our request.

Is Ikov.jar or image.exe a virus?

URLhaus lists both addresses as malware downloads with the tag stealer. We did not open them, so we cannot name the family or say what each does.

Ikov.jar and Mina.jar are Java archives and image.exe is a Windows program. Treat any copy you ran as malware: change your passwords from another device, run a Microsoft Defender Offline scan, and reset Windows if you are not sure.

What do the tags runelite and runelure mean?

runelite is the name of a well known add on client for Old School RuneScape. The OSRS Wiki names runelite.net as the official site. The tag suggests the files imitate or hide behind that client.

We found no vendor page that explains runelure, so we do not claim to know whether it is a family name. Do not treat either tag as proof of what the files do.

I saw ikovrsps.com in my firewall or DNS log. Am I infected?

Not necessarily, and the name alone proves nothing. It does mean that a device on your network asked for it, which a person usually does only to download something.

Find which device it was, look in its Downloads folder for Ikov.jar, Mina.jar and image.exe, and run the checks on this page. Do any account changes from another device.

How do I remove this stealer from Windows?

Change your passwords and sign out all sessions from another device first. Then run a Microsoft Defender Offline scan (Windows Security, Virus and threat protection, Scan options), delete the three files and the game folder they came with, and check Installed apps and Startup apps for entries you did not add.

If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test the steps on an infected PC.

What can a Java game stealer take?

Check Point lists Minecraft and Discord tokens, Telegram data, browser credentials, wallet data, files from Desktop and Documents, and a screenshot for a comparable campaign. Bitdefender adds Microsoft account credentials and a clipboard monitor that swaps wallet addresses.

We do not know which of these Ikov.jar does. Treat every password, token and wallet on the PC as known and change them from another device.

Does ikovrsps.com affect Mac, iPhone or Android?

A jar file runs on any system with Java, so a Mac user who ran Ikov.jar is in question, although the stealers vendors describe target Windows.

Intego says the final payload it studied was a Windows stealer and that Mac users should still scan jar files. iPhone cannot run Java archives. For Android we found no source. If you ran a file, change your passwords from another device.

Is the game server Ikov a scam?

We cannot say. We found no primary source about the game server itself, only that this domain serves files that URLhaus tags as malware. Treat the downloads as unsafe.

If you play on a private server, install clients only on a PC you do not use for banking or crypto, and get RuneLite itself only from runelite.net.

Will Fortect remove ikovrsps.com?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For ikovrsps.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove likedrink.beer: a domain that served 27 Mirai botnet files for routers and other Linux devices, and what to do about it

likedrink.beer is a web address that URLhaus lists 27 times on 4 October 2026 for files named mirai followed by a chip type, such as mirai.arm7 and mirai.mips32. These are builds of the Mirai botnet program for...TRHigh riskUgnius Kiguolis ·

Remove niggersmp.net: a Minecraft cheat client site whose .jar downloads URLhaus tags SilentNet, and what to do if you ran one

niggersmp.net is a website that offers free Minecraft cheat clients, and URLhaus lists four of its .jar downloads (Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar) as malware tagged SilentNet. A...TRHigh riskUgnius Kiguolis ·

Remove Trojan:Win32/Ymacco

Ymacco Trojan is a piece of malware that can open backdoors and expose users to malicious websites Trojan:Win32/Ymacco is a is a highly dangerous cyber infection that aims at injectingTrojansHigh riskJulie Splinters ·

Remove donutclients.st: a Minecraft mod site whose 30 .jar files URLhaus tags as stealers, and what to do if you ran one on Windows

donutclients.st is a website that offers 30 free Minecraft mods for Fabric, and URLhaus lists all 30 of its .jar files (such as Sodium-26.2.jar and meteor-client-26.2.jar) as malware downloads tagged stealer on 7...TRHigh riskUgnius Kiguolis ·

Questions and experiences: ikovrsps.com (stealer and CoinMiner files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,462 members already hereReading, writing, commenting and voting. 0 verified · 187 joined this year