nordertextil.de: a ClickFix loader site for Windows, and what to do if you pasted its PowerShell command

nordertextil.de is a German web address that URLhaus lists for four malware downloads tagged ClickFix, Loader, exe and powershell, and our browser could not find the domain when we tested it. If you pasted a command from it into the Windows Run box or PowerShell, treat the PC as compromised: change your passwords from another device, then scan it offline.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a script or program from nordertextil.de, or a command pasted from its page into Run or PowerShell usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove nordertextil.de (ClickFix, Loader, powershell) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of four URLhaus entries for nordertextil.de added on 25 September 2026: the paths room, t/pcmd2, enter and t/dokument281, each tagged ClickFix, DEU, exe, Loader and powershell and all offline
The four URLhaus entries for nordertextil.de that we read on 10 October 2026. Our own browser could not resolve the domain, so this table of reports, not a screenshot of the site, is the main evidence.

Nordertextil.de (ClickFix, Loader, powershell): summary

TypeA malware download address for Windows PCs: URLhaus lists four addresses tagged ClickFix, Loader, exe and powershell
RiskHigh if you pasted its command or opened its files: a loader can bring in a stealer or a remote access tool
SymptomsOften none. A strange line in the Run history, a window that flashed and closed, or an unknown scheduled task are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, run an offline Microsoft Defender scan, then reinstall Windows if in doubt
Our check (10 October 2026)One visit: the domain did not resolve, no page. A quiet or missing site clears nothing; the danger rating comes from URLhaus
Running since / first seenFirst malware URLs reported 25 September 2026; domain registration not known to us
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
PlatformWindows, by the tags powershell and exe
Detection namesNo Microsoft detection name is known for the files on this server, because we did not open them and we did not check them against Microsoft's list. The URLhaus tags are ClickFix, DEU, exe, Loader and powershell
NameNordertextil.de
Evidence4 write-ups by security sites; details still limited
First seen25 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for nordertextil.de, one browser visit of our own, the Microsoft Security Blog, Microsoft Learn, Microsoft Support and Arctic Wolf Labs. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What nordertextil.de is, and what we know about it

We know nordertextil.de only through four malware addresses that a URLhaus reporter added on 25 September 2026. We never saw the page that visitors see, so this guide says plainly which parts are reports and which parts are our own checks.

  1. 1

    What URLhaus lists

    Four addresses on nordertextil.de, all added on 25 September 2026 at about 06:23 UTC by the reporter RoKoBo: /room, /t/pcmd2, /enter and /t/dokument281. Each carries the same five tags, ClickFix, DEU, exe, Loader and powershell. All four are marked malware_download and all four were offline when we read them.

  2. 2

    What the tags mean

    ClickFix is a trick in which a fake page makes you copy a command and run it yourself. powershell is the Windows scripting tool that such a command starts. exe says a Windows program is involved, and Loader says the program's job is to bring in further malware. DEU is a country label, and we do not know exactly what the reporter meant by it.

  3. 3

    What we could not confirm

    We did not download any file and we never saw the page that tells visitors what to paste. So we do not know the lure, which loader family it is, or what it installs next. The labels are the reporter's, not our own findings.

  4. 4

    What this means for you

    If you only saw the name in a log, a link or a warning, that alone did not infect you. The risk is for people who pasted a command from the site into Run, Windows Terminal or PowerShell, or who opened a file from it.

Kind of threat
A malware download address for Windows PCs, tagged ClickFix and Loader
Delivery trick
ClickFix: a fake page asks you to copy a command and paste it into Run or PowerShell
Domain registration
Not known to us. The registry for .de domains has no RDAP service in our lookup, so we have no creation date or registrar
URLhaus entries
4 file addresses, all added on 25 September 2026, all offline when we read them
Platform
Windows, by the powershell and exe tags

What nordertextil.de (ClickFix, Loader, powershell) does on an infected PC

What we checked on 10 October 2026, and what we could not

We tried to open https://nordertextil.de/ once, from Lithuania, in an automated Chromium browser set to English. The browser could not find the domain. That tells you nothing good about the site, and it clears nothing.

Our site test, 10 October 2026

  • The domain did not resolveThe browser reported ERR_NAME_NOT_RESOLVED. In plain words, the name nordertextil.de gave no address on this one visit. We did not get a web page, a certificate or a single byte from the site.
  • Why that is not a clean resultA name that does not resolve can mean that the owner or the registrar switched it off, that the record was removed, or that a lookup failed. We cannot tell which from one visit. The same files may also be offered on other names.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
  • URLhaus listingFour malware addresses on this domain, all marked offline when we read the database.
  • Downloads and the page itselfWe did not download the files and we did not reach any page that shows a command. We cannot tell you what the loader installs.

Dangerous: treat it as a malware site The site test was one visit that found no domain, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. Do not open files from this name, and do not run anything it gives you.

What happened to nordertextil.de, from the first report to our test

The public record is short. We have no registration data, so the history starts with the first report. The dates come from the URLhaus database and from our own test.

  1. 25 September 2026

    Four files are reported in three seconds

    At about 06:23 UTC the reporter RoKoBo adds four addresses to URLhaus: /t/dokument281 first, then /room, /t/pcmd2 and /enter two seconds later. This is the first time URLhaus sees the host in our copy of the data.

  2. 10 October 2026

    Our test finds no address for the name

    Our single visit fails with a name resolution error. When we read the database all four addresses are marked offline.

Fifteen days passed between the reports and our test. A domain that stopped answering in that window may have been cleaned up, or switched off by whoever runs it. A name that no longer answers does not remove the risk for a PC that already ran the command.

A German name that sounds like a textile business can be an operator's own domain or a real small firm whose website was hacked and used to host the files. We found no page for a business of this name, and we do not say which case this is. If you own the domain, see the answer in the FAQ.

How the ClickFix trick works on Windows

ClickFix does not use a security hole. It makes you do the infecting yourself, so the warnings of your browser and your antivirus often never get a say. We did not see nordertextil.de's page; this is how Microsoft describes the trick.

Four steps of the ClickFix trick on Windows: a fake check page, a hidden copy to the clipboard, pasting into the Run box, and a loader running in PowerShell
How ClickFix works on Windows in four steps, following Microsoft's description. We did not see nordertextil.de's own page.
  1. 1

    You land on a page with a check

    Microsoft says victims reach a fake CAPTCHA, a human verification or an error page through phishing email, malicious ads or compromised sites. The lures often copy Cloudflare Turnstile, Google reCAPTCHA or Discord.

  2. 2

    The page copies a command for you

    Clicking the button silently puts a command on your clipboard through the browser. The page then tells you to paste it into the Run box, Windows Terminal or PowerShell.

  3. 3

    You open Run and paste

    The steps ask you to press the Windows key + R, press Ctrl + V and press Enter. Microsoft says attackers like the Run box because many users do not know what it does.

  4. 4

    A loader is fetched and run

    The command usually starts PowerShell, mshta or curl and downloads a first stage. The tags Loader, exe and powershell on these addresses fit that pattern, but we did not see what this loader does.

  5. 5

    Nothing seems to happen

    A window that flashes and closes, or a CAPTCHA that never finishes, is the whole experience for many victims. Microsoft says payloads are often loaded into memory through built in tools such as powershell.exe, msbuild.exe and regasm.exe.

Because a person starts the command, many automated defences treat it as normal. Microsoft notes that successful Run commands are recorded in the registry key RunMRU, which is why that key matters later in this guide.

The four addresses: what each suggests, and what we do not know

Paths and tags are weak evidence. We list what each address could be and mark which statements are only a reading of the name.

Source: our copy of the URLhaus data, read 10 October 2026. The right hand column is our own reading.
Address on nordertextil.deWhat URLhaus saysWhat it may be (our reading)
/enterOffline. Tags: ClickFix, DEU, exe, Loader, powershell. Added 25 September 2026The name reads like a page or a script entry point. We do not know whether it returns a page, a script or a program
/roomOffline. Same five tags. Added 25 September 2026Also a short page like name. It may be a lure page or a file the command fetches
/t/pcmd2Offline. Same five tags. Added 25 September 2026A path under /t/ whose last part could mean a PowerShell command, version 2. This is a guess from the name only
/t/dokument281Offline. Same five tags. Added 25 September 2026, two seconds before the othersDokument is German for document. It may be a lure that pretends to open a document, which would fit the DEU tag. Not confirmed

All four carry the same tags and were added within about two seconds. That suggests one reporter looked at one chain. It does not tell us how many people received it, and URLhaus shows no victim count.

What nordertextil.de (ClickFix, Loader, powershell) can steal or download

What a ClickFix loader on Windows can bring in

We do not know what the loader on this server installs. Here is what Microsoft and Arctic Wolf publish about ClickFix chains of the same kind, as a guide to what may be at stake.

Final payloads that Microsoft names for ClickFix

  • Lumma Stealer, which Microsoft calls the most prolific final payload
  • Remote access tools such as Xworm, AsyncRAT, NetSupport and SectopRAT
  • Loaders such as Latrodectus and MintsLoader
  • Rootkits, including a modified r77
Sources: Microsoft Security Blog on ClickFix and Arctic Wolf Labs on a ClickFix PowerShell loader (16 July 2026), both read 10 October 2026.
PointWhat it means for youSource
A loader brings in moreA loader on its own often steals little. Its job is to download the next program, which may be a stealer or a remote access tool. You cannot tell the next stage from the firstMicrosoft Security Blog
It can run in memoryArctic Wolf describes a July 2026 command that built the words irm and iex from pieces, ran the downloaded text in memory and later fetched an exe. A scan of files may then find nothingArctic Wolf Labs
Execution trackingThe same loader tried to report its status to a second address, a sign that someone watches for successArctic Wolf Labs
PersistenceNeither source we read describes how this kind of loader restarts. We do not know if this one doesMicrosoft and Arctic Wolf

What this can cost you

Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where the command was pasted and run, or a file from the site was opened.

  • High

    Account takeover

    If the loader brought in a stealer, saved logins and browser sessions can be used to enter your email, social and work accounts. Changing a password alone may not end a stolen session.

  • High

    Crypto theft

    Wallet files and wallet apps are a main target of the stealers that ClickFix delivers. Stolen crypto cannot be reversed, so move funds from a clean device first.

  • High

    Someone else controlling the PC

    Microsoft lists remote access tools among the payloads. With one of them running, a person can use the PC, see the screen and read files.

  • Medium

    A hidden program that starts again

    Some chains add a scheduled task, a Startup entry or a registry Run key. Until it is gone the PC keeps contacting the attackers.

  • Medium

    Work accounts and company data

    On a work PC the passwords and sessions in the browser reach company systems. Tell your IT or security team at once; they can block the accounts.

  • Low

    Nothing, if you only saw the name

    A name in a warning, a firewall log or a blocked link is not an infection.

What you may notice, and what you may not

Many victims notice nothing. The signs below follow from how these chains work; the first two are the best evidence you have.

Sources: Microsoft Security Blog for the Run history and the in memory payloads; the rest follows from how the chain works.
SignWhat it means
A line in the Run history that you did not writeWindows records what was typed in Run. A line with powershell, iex, irm, mshta, curl or a web address is the command that was pasted
A window that flashed and closedA black or blue window that vanished right after you pressed Enter is how many victims remember it
A page that never finished its checkA CAPTCHA that asked you to press keys and then did nothing
A task or Startup file you did not makeTask Scheduler entries with random names and files in the Startup folder are common places for a loader to restart
Defender alerts around that timeWindows Security may show a detection in Protection history, or it may show nothing if the code ran in memory
Accounts you did not touchLogins from new places, password reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote
Nothing at allLoaders are built to run quietly and pass the work to the next stage

How to check the PC for nordertextil.de (ClickFix, Loader, powershell)

How people end up on a page like this

We do not know how visitors reached nordertextil.de. These are the routes that Microsoft names for ClickFix pages in general.

  1. 1

    A phishing email with a link

    An email about a document, an invoice or an order sends you to a page that must be checked before you can read it. The path /t/dokument281 fits that picture, but this is only our reading.

  2. 2

    A malicious ad

    Microsoft lists malvertising as a route. An ad on a search page sends you to a fake check.

  3. 3

    A hacked website

    Microsoft lists compromised sites. A real small business site can show a fake CAPTCHA after criminals change its pages, and the owner may not know.

  4. 4

    A fake Windows or browser fix

    A page claims that your browser is broken or a font is missing and offers a fix that you paste into Run.

Check your Windows PC before you delete anything

Start with the question that matters: did you paste a command from a website into Run, Windows Terminal or PowerShell, or open a file from nordertextil.de? If yes, follow the numbered plan on this page, because a clean looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and network cables if you can.

Order of actions after pressing Enter on a pasted command: disconnect, secure accounts from another device, run an offline scan, then reinstall Windows if in doubt
The order of actions after pasting the command: accounts and crypto first, from another device; the PC last.
  1. 1

    Read the Run box history

    Open Registry Editor (press the Windows key, type regedit, press Enter) and go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is a line typed into Run. Look at it, do not run it, and do not delete it yet. Write down or photograph any line with powershell, iex, irm, mshta, curl or a web address.

  2. 2

    Look for a scheduled task you did not make

    Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet; note the name.

  3. 3

    Look in the Startup folder

    Press Windows key + R, type shell:startup and press Enter. A file that you did not put there is worth noting.

  4. 4

    Check Windows Security

    Open Windows Security, choose Virus & threat protection, then Protection history. On Windows 10 the app is under Settings, Update & Security, Windows Security. Look for detections dated around the time you pasted the command.

  5. 5

    Remember what a clean check means

    Clearing RunMRU removes evidence of the command, not the malware. In memory payloads may leave nothing in these places. A clean check lowers the doubt; it does not remove it.

How to remove nordertextil.de (ClickFix, Loader, powershell)

How to remove nordertextil.de

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to nordertextil.de or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever nordertextil.de installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows: Microsoft Defender Offline

An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.

  1. 1

    Prepare

    Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You must be signed in as a local administrator, and the Windows Recovery Environment must be enabled. To check, open a Command Prompt as administrator and run reagentc /info; if it says Disabled, run reagentc /enable. Microsoft says that with it disabled the scan does not run and shows no error.

  2. 2

    Suspend BitLocker if it is on

    If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.

  3. 3

    Start the scan

    Open Windows Security, choose Virus & threat protection, then Scan options. Select Microsoft Defender Offline scan and then Scan now. Accept the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends.

  4. 4

    Read the result

    Open Windows Security, then Virus & threat protection, then Protection history. Microsoft says the scan does not apply to ARM versions of Windows, and that Microsoft Defender Antivirus must be the main antivirus to receive its updates.

  5. 5

    Do not stop there

    A scan that finds nothing does not prove the PC is clean if a remote access tool was running. If you pasted a command and it ran, the safest end of the plan is to back up documents and reinstall Windows.

If you use a Mac, an iPhone or an Android phone

The powershell and exe tags point at Windows. We found nothing that says the four addresses work on anything else.

Your deviceWhat we knowWhat to do
MacA PowerShell command does not run on macOS. ClickFix also exists for Macs, where it uses Terminal, but we do not know what this page shows a Mac visitorIf you pasted something into Terminal, treat it as a separate case and see our Mac guides, not the Windows steps
iPhone or iPadThe trick needs a place to paste a command, which phones do not haveNothing to remove. If you typed passwords on a page, change them
AndroidNo source mentions itNothing to remove for this chain; change passwords if you entered any

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

Do these in this order and from a device that did not run the command. A phone or another computer is enough.

  1. 1

    Change passwords from a clean device

    Start with the email account that resets all others, then banks, then work and social accounts. Use a new password for each. Do not reuse a password that the PC knew.

  2. 2

    Sign out other sessions and revoke keys

    In each important account, choose the option to sign out everywhere. Revoke access tokens, remote desktop and SSH keys that were on the PC and make new ones.

  3. 3

    Move crypto first if a wallet was on the PC

    From a clean device, create a new wallet with a new seed phrase and move the funds. Do this before the other steps if you hold crypto.

  4. 4

    Turn on two factor sign in

    Use an authenticator app or a hardware key, not only a text message.

  5. 5

    Back up documents and reinstall Windows if in doubt

    Copy only documents and photos to an external disk, not programs. On Windows 11 open Settings, System, Recovery and choose Reset this PC, then Remove everything. On Windows 10 open Settings, Update & Security, Recovery. Restore documents only. We did not test these steps on an infected PC.

  6. 6

    Watch your accounts

    For some weeks read the sign in alerts of your email, bank and exchange accounts, and report any charge you did not make.

Keep a Windows PC out of this kind of trap

The rule that would have stopped this site is one line: a website never needs you to paste something into Run or PowerShell.

Do

  • Treat a request to press Windows key + R and paste a command as an attack. Close the tab.
  • Keep Windows, your browser and Microsoft Defender up to date, and leave cloud protection on.
  • On a work PC ask IT whether the Run box can be switched off by policy; Microsoft lists this as a protection.
  • Keep a backup of documents on a disk that you unplug.
  • Use an authenticator app for your important accounts.

Don't

  • Do not copy and paste a command to pass a check, to fix a page or to open a document.
  • Do not follow a page that tells you which keys to press to verify that you are human.
  • Do not run files from sites that promise free versions of paid software.
  • Do not turn off Defender or Windows Security because a page tells you to.
  • Do not rely on a quiet scan to say that you are safe.

Questions about nordertextil.de (ClickFix, Loader, powershell)

What is nordertextil.de?

nordertextil.de is a web address that the URLhaus database lists for Windows malware downloads. A reporter added four addresses on 25 September 2026, all tagged ClickFix, DEU, exe, Loader and powershell.

When we tried to open the domain on 10 October 2026 our browser could not find it, so we never saw the page that visitors see. We have no registration data for it, because the lookup for .de names gave us none.

We do not know who runs it, whether it is a real business whose site was hacked, or how many people received the files. What we can say is that the reports describe a chain that starts with a command pasted into Run or PowerShell.

Is nordertextil.de a virus?

No, a website is not a virus, but the files it handed out may be malware. URLhaus lists four addresses on nordertextil.de as malware downloads, tagged as a loader and as PowerShell. Visiting a page does not usually run those files.

The danger comes when you paste a command from the page into Run or PowerShell, or open a file it gave you. We did not download the files, so we cannot say what they do.

Our rating of dangerous rests on the URLhaus reports, because our own visit failed. Do not open anything from this name, and do not read the failed visit as proof that it is harmless.

What does ClickFix mean?

ClickFix is a trick in which a web page convinces you to copy a command and run it yourself. On Windows the page tells you to press the Windows key and R, paste with Ctrl and V, and press Enter.

Microsoft says the lures are fake CAPTCHAs, human checks or error pages, reached through phishing email, ads or hacked sites. Because you start the command, no download warning appears and no security hole is needed.

The rule that protects you is simple: a real website check never asks you to open Run or PowerShell and paste something. If a page asks, close it. If you already pasted, follow the steps on this page.

I pasted the command. What do I do first?

Disconnect the PC from the network, then use another device for everything that follows. Do not type a password on the PC. If you hold crypto, move it first from a clean device to a new wallet, since stolen coins cannot be returned.

Then change your email password, then banks, then other accounts, and choose the option to sign out all sessions. After that, run a Microsoft Defender Offline scan from Windows Security, copy only your documents to an external disk, and reinstall Windows if you want to be sure.

This order matters, because a loader can bring in a stealer within minutes and the data that left is the real loss.

What is a loader?

A loader is a small program whose job is to download and start other malware. The tag Loader on these addresses tells us the reporter saw it behave that way, but it does not tell us which family it is or what it installs next.

Microsoft names loaders such as Latrodectus and MintsLoader among the things that ClickFix delivers, next to stealers like Lumma and remote access tools like AsyncRAT.

For you this means the first file may do little harm on its own while the second does the damage. You cannot judge a PC by the first stage alone, so treat a pasted command as a full infection.

Will Microsoft Defender stop this?

We cannot promise that. Microsoft says ClickFix payloads are often loaded into memory through built in tools such as powershell.exe, msbuild.exe and regasm.exe, and that many automated defences see a command you start yourself as normal. Defender may still detect a known file, and Microsoft recommends turning on cloud protection, network protection and attack surface reduction rules.

We did not test these files against Defender. If you pasted the command, do not rely on the lack of an alert. Check Protection history, run the offline scan, and still change your passwords from another device.

The site does not load. Am I safe?

A site that does not load makes new infections from that name less likely, but it does not help a PC that already ran the command. When we tested on 10 October 2026 the domain did not resolve, and all four URLhaus entries were offline.

That may mean the owner or a registrar switched it off, or that we hit a lookup failure. The same campaign can move to other domains, and a page can show a different thing to each visitor.

If you ran the command before the site went down, the loader has already done its work and the steps for passwords, crypto and the scan still apply. If you did not, the name alone has not infected you.

I own nordertextil.de. What should I do?

Treat the website as hacked until you prove otherwise. Take the site offline or put it behind a maintenance page, ask your hosting provider for the access and error logs, and look for files and pages that you did not create, especially the paths /enter, /room and /t/.

Change every password for the hosting panel, the content system, FTP and the database, and update the software and plugins. Restore from a clean backup if you have one. Then ask your host to help you request a re check.

If you hold customer data, ask a lawyer or your data protection contact whether a breach report is due. We cannot tell from outside whether your site was hacked or the name was registered by someone else.

Can I just delete the files and be done?

No. Deleting a file removes a program but does not bring back anything that the program already sent away. A loader may have already brought in a second program that is stored elsewhere or only in memory, and Arctic Wolf describes a loader that never wrote its first stage to disk.

A scheduled task or a Startup entry can start the malware again. Deleting files you find is fine as a first look, but the safe way to end a compromise is to change every password from another device, move crypto, run the offline scan, and reinstall Windows if there is any doubt about what ran.

Will Fortect remove nordertextil.de?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For nordertextil.de, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Android Charging Boost

Android Charging Boost blue lock screen is an intrusive problem for Android users triggered by PUPs and malware Android Charging Boost is an unwanted lock screen that emerges on AndroidMalwareHigh riskLinas Kiguolis ·

Remove Ghost Push virus

Ghost Push virus - a dangerous cyber attack that gains root access of Android devices Ghost Push virus is malware designed to infiltrate Android OS tablets and phones exclusively. ItMalwareHigh riskAlice Woods ·

Remove tryclix.com: a Mac ClickFix site listed for the MacSync stealer, and what to do if you pasted its command

tryclix.com is a website that URLhaus lists for Mac malware downloads tagged ClickFix and MacSync, and our browser could not find the domain at all when we tested it. If you pasted a command from it into Terminal on...TRHigh riskUgnius Kiguolis ·

Remove swatting.wiki: a Mirai botnet download address for routers and cameras, and what to do if a device of yours may be infected

swatting.wiki is a web address that URLhaus lists for 14 malware downloads, every one tagged mirai, a botnet that takes over routers, cameras and other small network devices. The name no longer resolves when we look...TRHigh riskUgnius Kiguolis ·

Questions and experiences: nordertextil.de (ClickFix, Loader, powershell)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,449 members already hereReading, writing, commenting and voting. 0 verified · 174 joined this year