johnsonsvalves.cam: a Windows XWorm malware site that hides code in a PNG, and what to do if a script from it ran

johnsonsvalves.cam is a website that URLhaus lists for malware downloads:

  • a PowerShell script and a PNG picture
  • both tagged xworm
  • the picture also tagged stego

The site no longer answers when we look it up. If you ran a script or a pasted command from it on Windows, treat the PC as compromised: change your passwords from another device, then scan it offline.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a script or file from johnsonsvalves.cam, or a command that fetched an image from it usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove johnsonsvalves.cam (XWorm, stego PNG) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of three URLhaus entries for johnsonsvalves.cam: a PowerShell script and a PNG image tagged xworm, and one untagged file, all offline on 30 September 2026
The three URLhaus entries for johnsonsvalves.cam that we read on 10 October 2026, with the addresses defanged. Our own browser test could not even find the site, so this table of reports is the main evidence.

Johnsonsvalves.cam (XWorm, stego PNG): summary

TypeA malware download address for Windows: URLhaus lists a PowerShell script and a stego PNG, both tagged xworm
RiskHigh if a script from it ran: passwords, sessions, crypto and PC control may have been exposed
SymptomsOften none. Unknown files in C:\Users\Public, a scheduled task you did not make, or a script you ran are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt
Our check (10 October 2026)One lookup: the name did not resolve, no page. A quiet or dead site clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 26 May 2026; first malware URLs reported 30 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows, by the ps1 tag; no source says other systems are affected
Detection namesNo Microsoft detection name is known for the files on this server, because we did not open them and found no Microsoft page that names this campaign. The URLhaus tags are xworm, stego, powershell, ps1 and ascii. Run a Microsoft Defender Offline scan and read the name in Protection history
NameJohnsonsvalves.cam
Domain registered26 May 2026
Evidence3 write-ups by security sites; details still limited
First seen30 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for johnsonsvalves.cam, RDAP, one browser test of our own, AhnLab ASEC and ANY.RUN write-ups of XWorm campaigns that use pictures, and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's page and were not tried on a live infection.

What johnsonsvalves.cam is, and what we know about it

johnsonsvalves.cam is a web address, not a program on your PC. It is a domain that the abuse.ch project URLhaus lists as a place where malware was served, and two of its three entries carry the tag xworm. No public write-up of this one domain exists that we could find, so this page rests on what URLhaus shows, what we saw ourselves and what researchers have published about XWorm delivered through pictures.

  1. 1

    What URLhaus lists

    Three file addresses on johnsonsvalves.cam, all added on 30 September 2026 by the abuse.ch reporter account. At 10:02 UTC came http://johnsonsvalves[.]cam/HF1W1Z5K with the tags ascii, powershell, ps1 and xworm, and https://johnsonsvalves[.]cam/img_215919.png with the tags stego and xworm. At 15:04 UTC came http://johnsonsvalves[.]cam/luFiVL08 with no tags. All three carry the threat type malware_download and were offline when we read them.

  2. 2

    What the tags mean

    ps1 and powershell say that the first file is a PowerShell script. ascii says it is plain text, not a compiled program. xworm names the malware family: XWorm is a remote access tool, a program that lets another person control a PC. stego says that the PNG picture hides data inside it. Together they describe a script that fetches a picture and pulls a program out of it.

  3. 3

    What we could not confirm

    We did not download any of the files and we never saw a page that tells visitors what to do. So we do not know how a victim reached the script, what exactly the picture holds, or what the third file is. The tags are the reporter's labels, not our finding.

  4. 4

    What this means for you

    If you only saw the name in a log, a link or a warning, you are not infected by that alone. The risk is for people who opened a script file that reached out to this address, pasted a command that did, or ran a file that came from it.

Kind of threat
A malware download address; two entries are tagged xworm, one of them a PNG tagged stego
Malware family
XWorm, a remote access tool for Windows (reporter's tag, not confirmed by us)
Domain registered
26 May 2026, expires 26 May 2027, registrar NameCheap, Inc.; record last changed 30 September 2026 (RDAP, read 10 October 2026)
URLhaus entries
3 file addresses, all added on 30 September 2026; all 3 offline when we read them
Platform
Windows, by the ps1 tag. No source says which other systems are hit

What johnsonsvalves.cam (XWorm, stego PNG) does on an infected PC

What we checked on 10 October 2026, and what we could not

We tried to open https://johnsonsvalves.cam/ once, from Lithuania, in an automated Chromium browser set to English. The browser reported that the name could not be found, so no page loaded. That tells you nothing good about the site and it clears nothing.

Our site test, 10 October 2026

  • The name did not resolveOur browser reported ERR_NAME_NOT_RESOLVED. That means the domain name gave no address to connect to. URLhaus also lists all three files as offline, which fits a server that has been taken down or switched off.
  • Why that is not a clean resultA name that does not resolve can mean the operators removed the records, the hosting provider acted, or the attackers moved to another domain. It does not mean the files you may already have run are gone. Operators of this kind of site often rotate domains, so the same script may now point somewhere else.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
  • URLhaus listingThree malware addresses on this domain. The script HF1W1Z5K and the picture img_215919.png were both tagged xworm. All three were offline when we read the database.
  • Downloads and the page itselfWe did not download the files and we did not reach any page. We cannot tell you what the script or the picture contains.

Dangerous: treat it as a malware site The site test was one lookup that failed, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. A dead address does not heal a PC that already ran what it served.

What happened to johnsonsvalves.cam, from registration to our test

The history is short: the domain is under five months old and all three malware addresses were reported on one day. The dates come from RDAP and from the URLhaus database.

  1. 26 May 2026

    The domain is registered

    RDAP shows johnsonsvalves.cam registered on 26 May 2026 through the registrar NameCheap, Inc., valid until 26 May 2027. The name sounds like a valve maker; nothing we found shows a real business behind it.

  2. 30 September 2026

    A script and a picture are reported

    At about 10:02 UTC URLhaus receives two entries from abuse.ch: the script HF1W1Z5K, tagged ascii, powershell, ps1 and xworm, and the picture img_215919.png, tagged stego and xworm. This is the first time URLhaus sees the host.

    Table of the three URLhaus entries for johnsonsvalves.cam with dates, status and tags
    The three URLhaus entries for johnsonsvalves.cam as we read them on 10 October 2026. Addresses are defanged.
  3. 30 September 2026

    A third file and a record change

    At 15:04 UTC a third file, luFiVL08, is added with no tags. The same day RDAP shows the registration record changed. We do not know what was changed or why.

  4. 10 October 2026

    Our test finds no address

    Our browser visit to https://johnsonsvalves.cam/ ends in ERR_NAME_NOT_RESOLVED, and URLhaus shows all three files offline.

We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.

How malware can hide in a picture, and what XWorm is

We did not see what johnsonsvalves.cam's picture holds. This is how security researchers describe the same method in other XWorm campaigns, so you can recognise the pattern.

Four steps of an image-hiding malware chain: a script starts, PowerShell fetches a picture, code is read out of the picture data, and XWorm runs from memory
The general method in four steps. We did not download the johnsonsvalves.cam picture, so this is not a description of that file.
  1. 1

    A script file starts the chain

    AhnLab's analysis says a phishing email delivers a VBScript or JavaScript file. The first script inserts a PowerShell script that holds Base64 text mixed with filler characters, removes the filler, decodes the rest and runs it.

  2. 2

    PowerShell fetches a picture

    That PowerShell downloads a JPG image from an outside server. The image opens as a normal picture, so a person who looked at it would see nothing wrong.

  3. 3

    The program is read out of the picture data

    AhnLab describes two versions. In the older one, Base64 text sat between two markers at the end of the image. In the newer one, the script finds a bitmap signature at the end of the JPG and reads the red, green and blue values of its pixels to rebuild a .NET loader.

  4. 4

    The loader starts XWorm

    The rebuilt loader runs and starts the final malware. ANY.RUN describes another chain in which the files named Vile.png and Mands.png in C:\Users\PUBLIC are not pictures at all but encrypted data, which a two-stage PowerShell loader decrypts and loads straight into memory.

The point of the trick is that no ordinary installer file ever lands on the disk, and a PNG or JPG looks harmless to a quick filter. It does not mean the picture on your screen is dangerous to view. The danger is the script that reads the picture and runs what it finds.

XWorm itself is a remote access tool. That is a program that connects out to a server run by the attacker and then takes orders, which is why this page tells you to disconnect the PC before anything else. We did not analyse a sample, and we found no first-hand analysis of the johnsonsvalves.cam files, so we do not list its commands or settings here.

The three files: what each name suggests, and what we do not know

File names are weak evidence. We list what each one could be and mark which statements are only a reading of the name and tags.

Source: the URLhaus database, read 10 October 2026. The third column is our interpretation of the names and tags, not a finding.
File on johnsonsvalves.camWhat URLhaus saysWhat it may be (our reading)
/HF1W1Z5KOffline, tagged ascii, powershell, ps1 and xworm, added 30 September 2026A plain text PowerShell script with no file ending. It is probably the first stage that fetches the picture and starts the chain
/img_215919.pngOffline, tagged stego and xworm, added 30 September 2026A PNG that carries hidden data. It is probably the container from which the XWorm program is rebuilt. Not confirmed
/luFiVL08Offline, no tags, added 30 September 2026Another file with a random name and no ending. It may be a second script or a staging file of the same chain. Not confirmed

Random eight-character names with no file ending are typical of servers that serve a different file to each request path, but that is a habit, not proof. We did not fetch the files, so we cannot say how the three belong together.

What johnsonsvalves.cam (XWorm, stego PNG) can steal or download

What a remote access tool like XWorm can mean for you

We did not open the files and found no analysis of them, so we cannot list what this copy does. The table below is the general meaning of a remote access tool, not a claim about this site's file.

Names and tags from the reports and the research we read

  • xworm (URLhaus tag on two files)
  • stego (URLhaus tag on the PNG)
  • powershell and ps1 (URLhaus tags on the script)
  • A .NET loader rebuilt from picture data (AhnLab)
  • Encrypted data in files named like pictures (ANY.RUN)
  • Files placed in C:\Users\PUBLIC (ANY.RUN)
Sources: AhnLab ASEC and ANY.RUN, read 10 October 2026. Both describe other campaigns that use XWorm. Neither covers johnsonsvalves.cam.
KindWhat it can do to youSource
Remote access toolLets another person reach the PC from outside. What that person can then do depends on the tool and its settings; typical abuse is watching, copying and installing more softwareOur reading of the xworm tag; not confirmed for this site
LoaderStarts the final program from memory, so the first script may not be the last thing on the PCAhnLab and ANY.RUN on similar chains
Scheduled taskIn the ANY.RUN chain a scheduled task keeps the loader running after a restartANY.RUN report on a different campaign
Files in C:\Users\PUBLICStaging files with picture endings that are really encrypted dataANY.RUN report on a different campaign

What this can cost you

Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where a script from the site ran or a file from it was opened.

  • High

    Someone else controlling the PC

    If XWorm ran, a person may be able to reach the PC from outside. Disconnect it from the network first, before you change any password on it.

  • High

    Passwords and sessions typed or saved on the PC

    A remote tool can see what you type and what your browser holds. Change passwords from another device and sign out of your accounts everywhere, because a new password alone may not end a stolen session.

  • High

    Crypto theft

    Wallet files and recovery phrases on an infected PC should be treated as exposed. Stolen crypto cannot be reversed, so move funds to a new wallet made on a clean device before you do anything else on the PC.

  • Medium

    A hidden program that starts again

    ANY.RUN describes a scheduled task that re-runs the loader. Until that is found and removed, the PC may keep contacting the attackers after a restart.

  • Medium

    Work accounts and company data

    On a work PC the saved logins reach company systems. Tell your IT or security team at once; they can block the accounts.

  • Low

    Nothing, if you only saw the name

    A name in a warning, a firewall log or a blocked link is not an infection.

What you may notice, and what you may not

Many victims notice nothing. The signs below follow from how these chains are built; the first three are the best evidence you have.

Sources: ANY.RUN and AhnLab ASEC on similar XWorm chains, read 10 October 2026.
SignWhat it means
A script file or a pasted command you ran that mentions a picture or an address ending in .camThis is the start of the chain. Note the file name or the line before you do anything else
Files with a .png ending in C:\Users\PUBLIC that do not open as picturesANY.RUN found data containers named like pictures in this folder in a different XWorm campaign. A real picture opens; a container does not
A scheduled task or a Startup entry you did not makeANY.RUN describes a scheduled task that re-runs the loader at each logon in a similar chain
A window that flashed and closedA PowerShell or Command Prompt window that runs a one-line download and exits
Accounts you did not touchLogins from new places, password-reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote
Nothing at allRemote tools are built to stay quiet

How to check the PC for johnsonsvalves.cam (XWorm, stego PNG)

How people end up running a script like this

We do not know how visitors reached johnsonsvalves.cam, and no source says. AhnLab names one route for the image method in general: an email that carries a script file.

  1. 1

    An email with a script attachment

    AhnLab says the chain begins with a phishing email that delivers a VBScript or JavaScript file. The file may be named like an order, an invoice or a document.

  2. 2

    A script or archive from a web page

    ANY.RUN describes a JavaScript file named like a purchase order that came by email and web pages. Opening it runs it; Windows does not treat a .js file as a document.

  3. 3

    A command you are told to paste

    Some pages ask you to copy a command into the Windows Run box or PowerShell to pass a check. The ps1 tag fits that way of starting a script, but no source tells us this site did so. We did not see its page.

  4. 4

    A file that claims to be an update or a free program

    Cracked software and fake updates are common carriers for remote tools. This is general knowledge, not something we saw on this domain.

Check your Windows PC before you delete anything

Start with the question that matters: did you open a script file or paste a command that fetched something from johnsonsvalves.cam, or run a file that came from it? If yes, follow the numbered plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and network cables if you can.

Order of actions after a malicious script ran: disconnect, change passwords from another device, sign out and move crypto, run an offline scan, then reinstall Windows if in doubt
The order of actions after a script ran: accounts and crypto first, from another device; the PC last.
  1. 1

    Look in C:\Users\Public

    Open File Explorer and go to C:\Users\Public. ANY.RUN found staging files there in an XWorm chain: a batch file, and two files ending in .png that were not pictures. Look for files you did not put there. If a .png will not open in Photos, note its name and do not delete it yet.

  2. 2

    Look for a scheduled task you did not make

    Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet; note the name.

  3. 3

    Look in the Startup folder

    Press Windows key + R, type shell:startup and press Enter. A file you did not put there is a reason for doubt. Note it.

  4. 4

    Read the Run box history if you pasted a command

    Open Registry Editor (press the Windows key, type regedit, press Enter) and go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is a line typed into Run. Look at it, do not run it, and write down any line that contains powershell, a web address or johnsonsvalves.

  5. 5

    Check Windows Security

    Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for detections dated around the time the script ran.

  6. 6

    Remember what a clean check means

    The chain is built to run from memory, so it may leave little on the disk. A clean check lowers the doubt; it does not remove it.

How to remove johnsonsvalves.cam (XWorm, stego PNG)

How to remove johnsonsvalves.cam

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like johnsonsvalves.cam add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after johnsonsvalves.cam, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of johnsonsvalves.cam that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Johnsonsvalves.cam can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows: Microsoft Defender Offline

An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.

  1. 1

    Prepare

    Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You must be signed in as a local administrator and Windows Recovery Environment must be on. To check, open a Command Prompt as administrator and run reagentc /info; if it says Disabled, run reagentc /enable. Microsoft notes that if it is off, the scan simply does not run and shows no error.

  2. 2

    Suspend BitLocker if it is on

    If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.

  3. 3

    Start the scan

    Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now. Agree to the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends. In PowerShell as administrator, the command Start-MpWDOScan does the same.

  4. 4

    Read the result

    Open Windows Security > Virus & threat protection > Protection history. Microsoft says the offline scan does not apply to Windows on ARM, and that Microsoft Defender Antivirus must be the main antivirus to receive its updates.

  5. 5

    Do not stop there

    A scan that finds nothing does not prove the PC is clean if a remote access tool was running. If a script from this site ran, the safest end of the plan is still to back up documents and reinstall Windows.

If you use a Mac, an iPhone or an Android phone

The ps1 tag points at Windows. We found nothing that says the three files run on anything else.

Your deviceWhat we knowWhat to do
MacA PowerShell script chain written for Windows does not run as it is on macOS. We do not know what a Mac visitor was shownIf you ran something from a site on a Mac, treat it as a separate case and see our Mac guides; do not follow the Windows steps
iPhone or iPadWindows scripts do not run on iOSNothing to remove. If you typed passwords on a page, change them
AndroidNo source mentions itNothing to remove for this script; change passwords if you entered any

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.

  1. 1

    Change passwords from a clean device

    Use a phone or another computer. Start with your email, then banking, then work and social accounts. Passwords typed on the infected PC may be seen by the attackers. Change your Microsoft account password at account.microsoft.com.

  2. 2

    Sign out other sessions and revoke keys

    Cookies were possibly taken, so a new password alone may not end a stolen session. In each important account use the option to sign out everywhere. Revoke API tokens, SSH keys and cloud keys that were on the PC.

  3. 3

    Move crypto first if a wallet was on the PC

    If a recovery phrase may have been exposed, move the funds to a new wallet with a new phrase made on a clean device.

  4. 4

    Turn on two-factor sign-in

    Use an authenticator app or a security key where the account allows it, so that a stolen password or session is not enough at a new sign-in.

  5. 5

    Back up documents and reinstall Windows if in doubt

    Copy only documents and photos to an external drive, not programs. In Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, choose to reset the PC and remove everything.

  6. 6

    Watch your accounts

    For some weeks look at your bank, email and crypto for activity you did not start, and tell your bank at once if you see any.

Keep a Windows PC out of this kind of trap

The rule that stops this chain is short: a script file from an email or a web page is not a document, and you should not run it.

Do

  • Treat a .js, .vbs, .ps1 or .cmd file that arrives by email or download as a program, not a document. Delete it.
  • Treat a request to paste a command into Run or PowerShell from a web page as an attack. Close the tab.
  • Keep Windows and your browser up to date, and keep Windows Security turned on.
  • Keep a backup of documents on a disk you unplug.
  • Use an authenticator app for your important accounts.

Don't

  • Do not open an order, invoice or receipt that is a script file, even if it is named like a purchase order.
  • Do not trust a picture to be safe because it opens as a picture: the danger is in what reads it.
  • Do not run files from sites that promise free versions of paid software.
  • Do not open a file that arrives by link or message and claims to be an update.
  • Do not rely on a quiet scan to say that you are safe.

Questions about johnsonsvalves.cam (XWorm, stego PNG)

What is johnsonsvalves.cam?

johnsonsvalves.cam is a web address that URLhaus, the malware database run by abuse.ch, lists for malware downloads. Three file addresses were added on 30 September 2026. Two of them carry the tag xworm: a PowerShell script and a PNG picture that is also tagged stego.

The domain was registered on 26 May 2026. When we looked it up on 10 October 2026 the name did not resolve, and URLhaus showed all three files offline. We found no public write-up of this domain itself.

Is johnsonsvalves.cam a virus?

A website is not a virus, but this one is listed as a source of malware. URLhaus gives all three of its file addresses the threat type malware_download, and two are tagged xworm, the name of a remote access tool.

We did not download the files, so we cannot say exactly what they do. Treat the domain as dangerous, do not open it, and do not run anything it offers. Reading about it on this page cannot infect you.

What is XWorm?

XWorm is the name researchers give to a remote access tool for Windows. A remote access tool connects from the infected PC to a server run by the attacker and then takes orders, so the attacker can reach the PC from outside.

Microsoft's own reference for this page is its offline scan, not an XWorm write-up, so we do not list what a given copy does. AhnLab and ANY.RUN describe campaigns that deliver XWorm through scripts and picture files.

What does the stego tag on the PNG mean?

Stego is short for steganography, the hiding of data inside another file. Here it means the PNG is probably not just a picture: program code or data is hidden in its pixel or file data, and a script reads it out and runs it.

AhnLab describes this for XWorm using JPG images, and ANY.RUN describes encrypted data kept in files named like pictures. We did not open this PNG, so what it holds is not confirmed.

I ran a script from johnsonsvalves.cam. What do I do now?

Disconnect the PC from the network first, by turning off Wi-Fi and unplugging the cable. Then, from another device, change your email, bank and work passwords, sign out of accounts everywhere and move any crypto to a new wallet.

After that run a Microsoft Defender Offline scan on the PC. If the script ran, the safest end is to back up documents and reinstall Windows, because a remote access tool may leave little trace. Tell your IT team if it is a work PC.

What if I only visited the site and ran nothing?

A visit alone is unlikely to be the problem here, because the dangerous part is a script or file that you run. Do not open anything it gave you. If you downloaded a file and did not open it, delete it.

If you typed a password on a page from this site, change that password from a safe device. We could not see the site's page, so we cannot say what it showed to visitors, and the site no longer answers.

Why does the site not load any more?

On 10 October 2026 our browser reported ERR_NAME_NOT_RESOLVED for johnsonsvalves.cam, which means the name gave no address to connect to, and URLhaus showed all three files offline.

The operators may have removed the records, a provider may have acted, or the attackers may have moved to another domain. A dead address does not clean a PC that already ran what it served, and the same script may now point somewhere else.

Can a picture itself infect me?

Viewing a picture is not the risk. In the chains researchers describe, a script that is already running downloads the picture and reads hidden data out of it, and the script is what starts the malware.

The picture looks normal on screen. The risk is opening a script file or pasting a command, not looking at a PNG, though you should not open files from sources you do not know.

Will a scan with Windows Security remove it?

It may find parts of it, but a quiet scan does not prove the PC is clean. These chains are built to run from memory and may leave little on the disk.

Run Microsoft Defender Offline from Windows Security under Virus and threat protection, Scan options, and read Protection history afterwards. If a script from this site ran, back up documents and reinstall Windows to be sure, and change your passwords from another device first.

Will Fortect remove johnsonsvalves.cam?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For johnsonsvalves.cam, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove evacompltd.site: a Windows VIP Keylogger malware site (script files and PowerShell) and what to do if one ran

evacompltd.site is a website that URLhaus lists for malware downloads: The site no longer answers when we look it up. If you opened a script file that came from it on Windows, treat the PC as compromised: change your...TRHigh riskUgnius Kiguolis ·

Remove stanarcservice.com: a Windows ClickFix malware site (s.ps1) and what to do if you pasted its command

stanarcservice.com is a website that URLhaus lists for malware downloads, one of them a PowerShell script (s.ps1) tagged ClickFix, and it refused our test connection. If you pasted a command from it into the Windows...TRHigh riskUgnius Kiguolis ·

Remove meteorrejects.net: a Minecraft cheat-addon site that URLhaus lists for SilentNet stealer files

meteorrejects.net is a polished website for a Minecraft addon called Meteor Rejects, and URLhaus lists three of its .jar files as malware tagged SilentNet and stealer. If you installed one of these files, treat the...TRHigh riskUgnius Kiguolis ·

Remove "Windows activation Error code:0x56102" Support scam virus

Windows activation Error code:0x56102: it‘s just another tech support scam Among recent support scams, Windows activation Error code:0x56102 virus is an interesting sample. Though it is based on a realMalwareHigh riskJulie Splinters ·

Questions and experiences: johnsonsvalves.cam (XWorm, stego PNG)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year