johnsonsvalves.cam: a Windows XWorm malware site that hides code in a PNG, and what to do if a script from it ran
johnsonsvalves.cam is a website that URLhaus lists for malware downloads:
- a PowerShell script and a PNG picture
- both tagged xworm
- the picture also tagged stego
The site no longer answers when we look it up. If you ran a script or a pasted command from it on Windows, treat the PC as compromised: change your passwords from another device, then scan it offline.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a script or file from johnsonsvalves.cam, or a command that fetched an image from it usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove johnsonsvalves.cam (XWorm, stego PNG) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Johnsonsvalves.cam (XWorm, stego PNG): summary
| Type | A malware download address for Windows: URLhaus lists a PowerShell script and a stego PNG, both tagged xworm |
|---|---|
| Risk | High if a script from it ran: passwords, sessions, crypto and PC control may have been exposed |
| Symptoms | Often none. Unknown files in C:\Users\Public, a scheduled task you did not make, or a script you ran are the signs |
| How to get rid of it | Disconnect, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt |
| Our check (10 October 2026) | One lookup: the name did not resolve, no page. A quiet or dead site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 26 May 2026; first malware URLs reported 30 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows, by the ps1 tag; no source says other systems are affected |
|---|---|
| Detection names | No Microsoft detection name is known for the files on this server, because we did not open them and found no Microsoft page that names this campaign. The URLhaus tags are xworm, stego, powershell, ps1 and ascii. Run a Microsoft Defender Offline scan and read the name in Protection history |
| Name | Johnsonsvalves.cam |
| Domain registered | 26 May 2026 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 30 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for johnsonsvalves.cam, RDAP, one browser test of our own, AhnLab ASEC and ANY.RUN write-ups of XWorm campaigns that use pictures, and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's page and were not tried on a live infection.
What johnsonsvalves.cam is, and what we know about it
johnsonsvalves.cam is a web address, not a program on your PC. It is a domain that the abuse.ch project URLhaus lists as a place where malware was served, and two of its three entries carry the tag xworm. No public write-up of this one domain exists that we could find, so this page rests on what URLhaus shows, what we saw ourselves and what researchers have published about XWorm delivered through pictures.
- 1
What URLhaus lists
Three file addresses on johnsonsvalves.cam, all added on 30 September 2026 by the abuse.ch reporter account. At 10:02 UTC came http://johnsonsvalves[.]cam/HF1W1Z5K with the tags ascii, powershell, ps1 and xworm, and https://johnsonsvalves[.]cam/img_215919.png with the tags stego and xworm. At 15:04 UTC came http://johnsonsvalves[.]cam/luFiVL08 with no tags. All three carry the threat type malware_download and were offline when we read them.
- 2
What the tags mean
ps1 and powershell say that the first file is a PowerShell script. ascii says it is plain text, not a compiled program. xworm names the malware family: XWorm is a remote access tool, a program that lets another person control a PC. stego says that the PNG picture hides data inside it. Together they describe a script that fetches a picture and pulls a program out of it.
- 3
What we could not confirm
We did not download any of the files and we never saw a page that tells visitors what to do. So we do not know how a victim reached the script, what exactly the picture holds, or what the third file is. The tags are the reporter's labels, not our finding.
- 4
What this means for you
If you only saw the name in a log, a link or a warning, you are not infected by that alone. The risk is for people who opened a script file that reached out to this address, pasted a command that did, or ran a file that came from it.
- Kind of threat
- A malware download address; two entries are tagged xworm, one of them a PNG tagged stego
- Malware family
- XWorm, a remote access tool for Windows (reporter's tag, not confirmed by us)
- Domain registered
- 26 May 2026, expires 26 May 2027, registrar NameCheap, Inc.; record last changed 30 September 2026 (RDAP, read 10 October 2026)
- URLhaus entries
- 3 file addresses, all added on 30 September 2026; all 3 offline when we read them
- Platform
- Windows, by the ps1 tag. No source says which other systems are hit
What johnsonsvalves.cam (XWorm, stego PNG) does on an infected PC
What we checked on 10 October 2026, and what we could not
We tried to open https://johnsonsvalves.cam/ once, from Lithuania, in an automated Chromium browser set to English. The browser reported that the name could not be found, so no page loaded. That tells you nothing good about the site and it clears nothing.
Our site test, 10 October 2026
- The name did not resolveOur browser reported ERR_NAME_NOT_RESOLVED. That means the domain name gave no address to connect to. URLhaus also lists all three files as offline, which fits a server that has been taken down or switched off.
- Why that is not a clean resultA name that does not resolve can mean the operators removed the records, the hosting provider acted, or the attackers moved to another domain. It does not mean the files you may already have run are gone. Operators of this kind of site often rotate domains, so the same script may now point somewhere else.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
- URLhaus listingThree malware addresses on this domain. The script HF1W1Z5K and the picture img_215919.png were both tagged xworm. All three were offline when we read the database.
- Downloads and the page itselfWe did not download the files and we did not reach any page. We cannot tell you what the script or the picture contains.
Dangerous: treat it as a malware site The site test was one lookup that failed, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. A dead address does not heal a PC that already ran what it served.
What happened to johnsonsvalves.cam, from registration to our test
The history is short: the domain is under five months old and all three malware addresses were reported on one day. The dates come from RDAP and from the URLhaus database.
26 May 2026
The domain is registered
RDAP shows johnsonsvalves.cam registered on 26 May 2026 through the registrar NameCheap, Inc., valid until 26 May 2027. The name sounds like a valve maker; nothing we found shows a real business behind it.
30 September 2026
A script and a picture are reported
At about 10:02 UTC URLhaus receives two entries from abuse.ch: the script HF1W1Z5K, tagged ascii, powershell, ps1 and xworm, and the picture img_215919.png, tagged stego and xworm. This is the first time URLhaus sees the host.

The three URLhaus entries for johnsonsvalves.cam as we read them on 10 October 2026. Addresses are defanged. 30 September 2026
A third file and a record change
At 15:04 UTC a third file, luFiVL08, is added with no tags. The same day RDAP shows the registration record changed. We do not know what was changed or why.
10 October 2026
Our test finds no address
Our browser visit to https://johnsonsvalves.cam/ ends in ERR_NAME_NOT_RESOLVED, and URLhaus shows all three files offline.
We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.
How malware can hide in a picture, and what XWorm is
We did not see what johnsonsvalves.cam's picture holds. This is how security researchers describe the same method in other XWorm campaigns, so you can recognise the pattern.

- 1
A script file starts the chain
AhnLab's analysis says a phishing email delivers a VBScript or JavaScript file. The first script inserts a PowerShell script that holds Base64 text mixed with filler characters, removes the filler, decodes the rest and runs it.
- 2
PowerShell fetches a picture
That PowerShell downloads a JPG image from an outside server. The image opens as a normal picture, so a person who looked at it would see nothing wrong.
- 3
The program is read out of the picture data
AhnLab describes two versions. In the older one, Base64 text sat between two markers at the end of the image. In the newer one, the script finds a bitmap signature at the end of the JPG and reads the red, green and blue values of its pixels to rebuild a .NET loader.
- 4
The loader starts XWorm
The rebuilt loader runs and starts the final malware. ANY.RUN describes another chain in which the files named Vile.png and Mands.png in C:\Users\PUBLIC are not pictures at all but encrypted data, which a two-stage PowerShell loader decrypts and loads straight into memory.
The point of the trick is that no ordinary installer file ever lands on the disk, and a PNG or JPG looks harmless to a quick filter. It does not mean the picture on your screen is dangerous to view. The danger is the script that reads the picture and runs what it finds.
XWorm itself is a remote access tool. That is a program that connects out to a server run by the attacker and then takes orders, which is why this page tells you to disconnect the PC before anything else. We did not analyse a sample, and we found no first-hand analysis of the johnsonsvalves.cam files, so we do not list its commands or settings here.
The three files: what each name suggests, and what we do not know
File names are weak evidence. We list what each one could be and mark which statements are only a reading of the name and tags.
| File on johnsonsvalves.cam | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /HF1W1Z5K | Offline, tagged ascii, powershell, ps1 and xworm, added 30 September 2026 | A plain text PowerShell script with no file ending. It is probably the first stage that fetches the picture and starts the chain |
| /img_215919.png | Offline, tagged stego and xworm, added 30 September 2026 | A PNG that carries hidden data. It is probably the container from which the XWorm program is rebuilt. Not confirmed |
| /luFiVL08 | Offline, no tags, added 30 September 2026 | Another file with a random name and no ending. It may be a second script or a staging file of the same chain. Not confirmed |
Random eight-character names with no file ending are typical of servers that serve a different file to each request path, but that is a habit, not proof. We did not fetch the files, so we cannot say how the three belong together.
What johnsonsvalves.cam (XWorm, stego PNG) can steal or download
What a remote access tool like XWorm can mean for you
We did not open the files and found no analysis of them, so we cannot list what this copy does. The table below is the general meaning of a remote access tool, not a claim about this site's file.
Names and tags from the reports and the research we read
- xworm (URLhaus tag on two files)
- stego (URLhaus tag on the PNG)
- powershell and ps1 (URLhaus tags on the script)
- A .NET loader rebuilt from picture data (AhnLab)
- Encrypted data in files named like pictures (ANY.RUN)
- Files placed in C:\Users\PUBLIC (ANY.RUN)
| Kind | What it can do to you | Source |
|---|---|---|
| Remote access tool | Lets another person reach the PC from outside. What that person can then do depends on the tool and its settings; typical abuse is watching, copying and installing more software | Our reading of the xworm tag; not confirmed for this site |
| Loader | Starts the final program from memory, so the first script may not be the last thing on the PC | AhnLab and ANY.RUN on similar chains |
| Scheduled task | In the ANY.RUN chain a scheduled task keeps the loader running after a restart | ANY.RUN report on a different campaign |
| Files in C:\Users\PUBLIC | Staging files with picture endings that are really encrypted data | ANY.RUN report on a different campaign |
What this can cost you
Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where a script from the site ran or a file from it was opened.
- High
Someone else controlling the PC
If XWorm ran, a person may be able to reach the PC from outside. Disconnect it from the network first, before you change any password on it.
- High
Passwords and sessions typed or saved on the PC
A remote tool can see what you type and what your browser holds. Change passwords from another device and sign out of your accounts everywhere, because a new password alone may not end a stolen session.
- High
Crypto theft
Wallet files and recovery phrases on an infected PC should be treated as exposed. Stolen crypto cannot be reversed, so move funds to a new wallet made on a clean device before you do anything else on the PC.
- Medium
A hidden program that starts again
ANY.RUN describes a scheduled task that re-runs the loader. Until that is found and removed, the PC may keep contacting the attackers after a restart.
- Medium
Work accounts and company data
On a work PC the saved logins reach company systems. Tell your IT or security team at once; they can block the accounts.
- Low
Nothing, if you only saw the name
A name in a warning, a firewall log or a blocked link is not an infection.
What you may notice, and what you may not
Many victims notice nothing. The signs below follow from how these chains are built; the first three are the best evidence you have.
| Sign | What it means |
|---|---|
| A script file or a pasted command you ran that mentions a picture or an address ending in .cam | This is the start of the chain. Note the file name or the line before you do anything else |
| Files with a .png ending in C:\Users\PUBLIC that do not open as pictures | ANY.RUN found data containers named like pictures in this folder in a different XWorm campaign. A real picture opens; a container does not |
| A scheduled task or a Startup entry you did not make | ANY.RUN describes a scheduled task that re-runs the loader at each logon in a similar chain |
| A window that flashed and closed | A PowerShell or Command Prompt window that runs a one-line download and exits |
| Accounts you did not touch | Logins from new places, password-reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote |
| Nothing at all | Remote tools are built to stay quiet |
How to check the PC for johnsonsvalves.cam (XWorm, stego PNG)
How people end up running a script like this
We do not know how visitors reached johnsonsvalves.cam, and no source says. AhnLab names one route for the image method in general: an email that carries a script file.
- 1
An email with a script attachment
AhnLab says the chain begins with a phishing email that delivers a VBScript or JavaScript file. The file may be named like an order, an invoice or a document.
- 2
A script or archive from a web page
ANY.RUN describes a JavaScript file named like a purchase order that came by email and web pages. Opening it runs it; Windows does not treat a .js file as a document.
- 3
A command you are told to paste
Some pages ask you to copy a command into the Windows Run box or PowerShell to pass a check. The ps1 tag fits that way of starting a script, but no source tells us this site did so. We did not see its page.
- 4
A file that claims to be an update or a free program
Cracked software and fake updates are common carriers for remote tools. This is general knowledge, not something we saw on this domain.
Check your Windows PC before you delete anything
Start with the question that matters: did you open a script file or paste a command that fetched something from johnsonsvalves.cam, or run a file that came from it? If yes, follow the numbered plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and network cables if you can.

- 1
Look in C:\Users\Public
Open File Explorer and go to
C:\Users\Public. ANY.RUN found staging files there in an XWorm chain: a batch file, and two files ending in .png that were not pictures. Look for files you did not put there. If a .png will not open in Photos, note its name and do not delete it yet. - 2
Look for a scheduled task you did not make
Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet; note the name.
- 3
Look in the Startup folder
Press Windows key + R, type
shell:startupand press Enter. A file you did not put there is a reason for doubt. Note it. - 4
Read the Run box history if you pasted a command
Open Registry Editor (press the Windows key, type regedit, press Enter) and go to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is a line typed into Run. Look at it, do not run it, and write down any line that contains powershell, a web address or johnsonsvalves. - 5
Check Windows Security
Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for detections dated around the time the script ran.
- 6
Remember what a clean check means
The chain is built to run from memory, so it may leave little on the disk. A clean check lowers the doubt; it does not remove it.
How to remove johnsonsvalves.cam (XWorm, stego PNG)
How to remove johnsonsvalves.cam
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like johnsonsvalves.cam add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after johnsonsvalves.cam, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of johnsonsvalves.cam that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Johnsonsvalves.cam can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You must be signed in as a local administrator and Windows Recovery Environment must be on. To check, open a Command Prompt as administrator and run
reagentc /info; if it says Disabled, runreagentc /enable. Microsoft notes that if it is off, the scan simply does not run and shows no error. - 2
Suspend BitLocker if it is on
If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.
- 3
Start the scan
Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now. Agree to the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends. In PowerShell as administrator, the command
Start-MpWDOScandoes the same. - 4
Read the result
Open Windows Security > Virus & threat protection > Protection history. Microsoft says the offline scan does not apply to Windows on ARM, and that Microsoft Defender Antivirus must be the main antivirus to receive its updates.
- 5
Do not stop there
A scan that finds nothing does not prove the PC is clean if a remote access tool was running. If a script from this site ran, the safest end of the plan is still to back up documents and reinstall Windows.
If you use a Mac, an iPhone or an Android phone
The ps1 tag points at Windows. We found nothing that says the three files run on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | A PowerShell script chain written for Windows does not run as it is on macOS. We do not know what a Mac visitor was shown | If you ran something from a site on a Mac, treat it as a separate case and see our Mac guides; do not follow the Windows steps |
| iPhone or iPad | Windows scripts do not run on iOS | Nothing to remove. If you typed passwords on a page, change them |
| Android | No source mentions it | Nothing to remove for this script; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.
- 1
Change passwords from a clean device
Use a phone or another computer. Start with your email, then banking, then work and social accounts. Passwords typed on the infected PC may be seen by the attackers. Change your Microsoft account password at account.microsoft.com.
- 2
Sign out other sessions and revoke keys
Cookies were possibly taken, so a new password alone may not end a stolen session. In each important account use the option to sign out everywhere. Revoke API tokens, SSH keys and cloud keys that were on the PC.
- 3
Move crypto first if a wallet was on the PC
If a recovery phrase may have been exposed, move the funds to a new wallet with a new phrase made on a clean device.
- 4
Turn on two-factor sign-in
Use an authenticator app or a security key where the account allows it, so that a stolen password or session is not enough at a new sign-in.
- 5
Back up documents and reinstall Windows if in doubt
Copy only documents and photos to an external drive, not programs. In Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, choose to reset the PC and remove everything.
- 6
Watch your accounts
For some weeks look at your bank, email and crypto for activity you did not start, and tell your bank at once if you see any.
Keep a Windows PC out of this kind of trap
The rule that stops this chain is short: a script file from an email or a web page is not a document, and you should not run it.
Do
- Treat a .js, .vbs, .ps1 or .cmd file that arrives by email or download as a program, not a document. Delete it.
- Treat a request to paste a command into Run or PowerShell from a web page as an attack. Close the tab.
- Keep Windows and your browser up to date, and keep Windows Security turned on.
- Keep a backup of documents on a disk you unplug.
- Use an authenticator app for your important accounts.
Don't
- Do not open an order, invoice or receipt that is a script file, even if it is named like a purchase order.
- Do not trust a picture to be safe because it opens as a picture: the danger is in what reads it.
- Do not run files from sites that promise free versions of paid software.
- Do not open a file that arrives by link or message and claims to be an update.
- Do not rely on a quiet scan to say that you are safe.
Questions about johnsonsvalves.cam (XWorm, stego PNG)
What is johnsonsvalves.cam?
johnsonsvalves.cam is a web address that URLhaus, the malware database run by abuse.ch, lists for malware downloads. Three file addresses were added on 30 September 2026. Two of them carry the tag xworm: a PowerShell script and a PNG picture that is also tagged stego.
The domain was registered on 26 May 2026. When we looked it up on 10 October 2026 the name did not resolve, and URLhaus showed all three files offline. We found no public write-up of this domain itself.
Is johnsonsvalves.cam a virus?
A website is not a virus, but this one is listed as a source of malware. URLhaus gives all three of its file addresses the threat type malware_download, and two are tagged xworm, the name of a remote access tool.
We did not download the files, so we cannot say exactly what they do. Treat the domain as dangerous, do not open it, and do not run anything it offers. Reading about it on this page cannot infect you.
What is XWorm?
XWorm is the name researchers give to a remote access tool for Windows. A remote access tool connects from the infected PC to a server run by the attacker and then takes orders, so the attacker can reach the PC from outside.
Microsoft's own reference for this page is its offline scan, not an XWorm write-up, so we do not list what a given copy does. AhnLab and ANY.RUN describe campaigns that deliver XWorm through scripts and picture files.
What does the stego tag on the PNG mean?
Stego is short for steganography, the hiding of data inside another file. Here it means the PNG is probably not just a picture: program code or data is hidden in its pixel or file data, and a script reads it out and runs it.
AhnLab describes this for XWorm using JPG images, and ANY.RUN describes encrypted data kept in files named like pictures. We did not open this PNG, so what it holds is not confirmed.
I ran a script from johnsonsvalves.cam. What do I do now?
Disconnect the PC from the network first, by turning off Wi-Fi and unplugging the cable. Then, from another device, change your email, bank and work passwords, sign out of accounts everywhere and move any crypto to a new wallet.
After that run a Microsoft Defender Offline scan on the PC. If the script ran, the safest end is to back up documents and reinstall Windows, because a remote access tool may leave little trace. Tell your IT team if it is a work PC.
What if I only visited the site and ran nothing?
A visit alone is unlikely to be the problem here, because the dangerous part is a script or file that you run. Do not open anything it gave you. If you downloaded a file and did not open it, delete it.
If you typed a password on a page from this site, change that password from a safe device. We could not see the site's page, so we cannot say what it showed to visitors, and the site no longer answers.
Why does the site not load any more?
On 10 October 2026 our browser reported ERR_NAME_NOT_RESOLVED for johnsonsvalves.cam, which means the name gave no address to connect to, and URLhaus showed all three files offline.
The operators may have removed the records, a provider may have acted, or the attackers may have moved to another domain. A dead address does not clean a PC that already ran what it served, and the same script may now point somewhere else.
Can a picture itself infect me?
Viewing a picture is not the risk. In the chains researchers describe, a script that is already running downloads the picture and reads hidden data out of it, and the script is what starts the malware.
The picture looks normal on screen. The risk is opening a script file or pasting a command, not looking at a PNG, though you should not open files from sources you do not know.
Will a scan with Windows Security remove it?
It may find parts of it, but a quiet scan does not prove the PC is clean. These chains are built to run from memory and may leave little on the disk.
Run Microsoft Defender Offline from Windows Security under Virus and threat protection, Scan options, and read Protection history afterwards. If a script from this site ran, back up documents and reinstall Windows to be sure, and change your passwords from another device first.
Will Fortect remove johnsonsvalves.cam?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For johnsonsvalves.cam, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for johnsonsvalves.cam (entries read from our copy of the feed) (read October 10, 2026)
- RDAP registration record for johnsonsvalves.cam (read October 10, 2026)
- AhnLab ASEC: XwormRAT Being Distributed Using Steganography (read October 10, 2026)
- ANY.RUN: malware trends report with an XWorm JavaScript and PNG loader chain (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 10, 2026)