nordertextil.de: a ClickFix loader site for Windows, and what to do if you pasted its PowerShell command
nordertextil.de is a German web address that URLhaus lists for four malware downloads tagged ClickFix, Loader, exe and powershell, and our browser could not find the domain when we tested it. If you pasted a command from it into the Windows Run box or PowerShell, treat the PC as compromised: change your passwords from another device, then scan it offline.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a script or program from nordertextil.de, or a command pasted from its page into Run or PowerShell usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove nordertextil.de (ClickFix, Loader, powershell) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Nordertextil.de (ClickFix, Loader, powershell): summary
| Type | A malware download address for Windows PCs: URLhaus lists four addresses tagged ClickFix, Loader, exe and powershell |
|---|---|
| Risk | High if you pasted its command or opened its files: a loader can bring in a stealer or a remote access tool |
| Symptoms | Often none. A strange line in the Run history, a window that flashed and closed, or an unknown scheduled task are the signs |
| How to get rid of it | Disconnect, change passwords from another device, move crypto, run an offline Microsoft Defender scan, then reinstall Windows if in doubt |
| Our check (10 October 2026) | One visit: the domain did not resolve, no page. A quiet or missing site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | First malware URLs reported 25 September 2026; domain registration not known to us |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Platform | Windows, by the tags powershell and exe |
|---|---|
| Detection names | No Microsoft detection name is known for the files on this server, because we did not open them and we did not check them against Microsoft's list. The URLhaus tags are ClickFix, DEU, exe, Loader and powershell |
| Name | Nordertextil.de |
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 25 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for nordertextil.de, one browser visit of our own, the Microsoft Security Blog, Microsoft Learn, Microsoft Support and Arctic Wolf Labs. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What nordertextil.de is, and what we know about it
We know nordertextil.de only through four malware addresses that a URLhaus reporter added on 25 September 2026. We never saw the page that visitors see, so this guide says plainly which parts are reports and which parts are our own checks.
- 1
What URLhaus lists
Four addresses on nordertextil.de, all added on 25 September 2026 at about 06:23 UTC by the reporter RoKoBo: /room, /t/pcmd2, /enter and /t/dokument281. Each carries the same five tags, ClickFix, DEU, exe, Loader and powershell. All four are marked malware_download and all four were offline when we read them.
- 2
What the tags mean
ClickFix is a trick in which a fake page makes you copy a command and run it yourself. powershell is the Windows scripting tool that such a command starts. exe says a Windows program is involved, and Loader says the program's job is to bring in further malware. DEU is a country label, and we do not know exactly what the reporter meant by it.
- 3
What we could not confirm
We did not download any file and we never saw the page that tells visitors what to paste. So we do not know the lure, which loader family it is, or what it installs next. The labels are the reporter's, not our own findings.
- 4
What this means for you
If you only saw the name in a log, a link or a warning, that alone did not infect you. The risk is for people who pasted a command from the site into Run, Windows Terminal or PowerShell, or who opened a file from it.
- Kind of threat
- A malware download address for Windows PCs, tagged ClickFix and Loader
- Delivery trick
- ClickFix: a fake page asks you to copy a command and paste it into Run or PowerShell
- Domain registration
- Not known to us. The registry for .de domains has no RDAP service in our lookup, so we have no creation date or registrar
- URLhaus entries
- 4 file addresses, all added on 25 September 2026, all offline when we read them
- Platform
- Windows, by the powershell and exe tags
What nordertextil.de (ClickFix, Loader, powershell) does on an infected PC
What we checked on 10 October 2026, and what we could not
We tried to open https://nordertextil.de/ once, from Lithuania, in an automated Chromium browser set to English. The browser could not find the domain. That tells you nothing good about the site, and it clears nothing.
Our site test, 10 October 2026
- The domain did not resolveThe browser reported ERR_NAME_NOT_RESOLVED. In plain words, the name nordertextil.de gave no address on this one visit. We did not get a web page, a certificate or a single byte from the site.
- Why that is not a clean resultA name that does not resolve can mean that the owner or the registrar switched it off, that the record was removed, or that a lookup failed. We cannot tell which from one visit. The same files may also be offered on other names.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
- URLhaus listingFour malware addresses on this domain, all marked offline when we read the database.
- Downloads and the page itselfWe did not download the files and we did not reach any page that shows a command. We cannot tell you what the loader installs.
Dangerous: treat it as a malware site The site test was one visit that found no domain, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. Do not open files from this name, and do not run anything it gives you.
What happened to nordertextil.de, from the first report to our test
The public record is short. We have no registration data, so the history starts with the first report. The dates come from the URLhaus database and from our own test.
25 September 2026
Four files are reported in three seconds
At about 06:23 UTC the reporter RoKoBo adds four addresses to URLhaus: /t/dokument281 first, then /room, /t/pcmd2 and /enter two seconds later. This is the first time URLhaus sees the host in our copy of the data.
10 October 2026
Our test finds no address for the name
Our single visit fails with a name resolution error. When we read the database all four addresses are marked offline.
Fifteen days passed between the reports and our test. A domain that stopped answering in that window may have been cleaned up, or switched off by whoever runs it. A name that no longer answers does not remove the risk for a PC that already ran the command.
A German name that sounds like a textile business can be an operator's own domain or a real small firm whose website was hacked and used to host the files. We found no page for a business of this name, and we do not say which case this is. If you own the domain, see the answer in the FAQ.
How the ClickFix trick works on Windows
ClickFix does not use a security hole. It makes you do the infecting yourself, so the warnings of your browser and your antivirus often never get a say. We did not see nordertextil.de's page; this is how Microsoft describes the trick.

- 1
You land on a page with a check
Microsoft says victims reach a fake CAPTCHA, a human verification or an error page through phishing email, malicious ads or compromised sites. The lures often copy Cloudflare Turnstile, Google reCAPTCHA or Discord.
- 2
The page copies a command for you
Clicking the button silently puts a command on your clipboard through the browser. The page then tells you to paste it into the Run box, Windows Terminal or PowerShell.
- 3
You open Run and paste
The steps ask you to press the Windows key + R, press Ctrl + V and press Enter. Microsoft says attackers like the Run box because many users do not know what it does.
- 4
A loader is fetched and run
The command usually starts PowerShell, mshta or curl and downloads a first stage. The tags Loader, exe and powershell on these addresses fit that pattern, but we did not see what this loader does.
- 5
Nothing seems to happen
A window that flashes and closes, or a CAPTCHA that never finishes, is the whole experience for many victims. Microsoft says payloads are often loaded into memory through built in tools such as powershell.exe, msbuild.exe and regasm.exe.
Because a person starts the command, many automated defences treat it as normal. Microsoft notes that successful Run commands are recorded in the registry key RunMRU, which is why that key matters later in this guide.
The four addresses: what each suggests, and what we do not know
Paths and tags are weak evidence. We list what each address could be and mark which statements are only a reading of the name.
| Address on nordertextil.de | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /enter | Offline. Tags: ClickFix, DEU, exe, Loader, powershell. Added 25 September 2026 | The name reads like a page or a script entry point. We do not know whether it returns a page, a script or a program |
| /room | Offline. Same five tags. Added 25 September 2026 | Also a short page like name. It may be a lure page or a file the command fetches |
| /t/pcmd2 | Offline. Same five tags. Added 25 September 2026 | A path under /t/ whose last part could mean a PowerShell command, version 2. This is a guess from the name only |
| /t/dokument281 | Offline. Same five tags. Added 25 September 2026, two seconds before the others | Dokument is German for document. It may be a lure that pretends to open a document, which would fit the DEU tag. Not confirmed |
All four carry the same tags and were added within about two seconds. That suggests one reporter looked at one chain. It does not tell us how many people received it, and URLhaus shows no victim count.
What nordertextil.de (ClickFix, Loader, powershell) can steal or download
What a ClickFix loader on Windows can bring in
We do not know what the loader on this server installs. Here is what Microsoft and Arctic Wolf publish about ClickFix chains of the same kind, as a guide to what may be at stake.
Final payloads that Microsoft names for ClickFix
- Lumma Stealer, which Microsoft calls the most prolific final payload
- Remote access tools such as Xworm, AsyncRAT, NetSupport and SectopRAT
- Loaders such as Latrodectus and MintsLoader
- Rootkits, including a modified r77
| Point | What it means for you | Source |
|---|---|---|
| A loader brings in more | A loader on its own often steals little. Its job is to download the next program, which may be a stealer or a remote access tool. You cannot tell the next stage from the first | Microsoft Security Blog |
| It can run in memory | Arctic Wolf describes a July 2026 command that built the words irm and iex from pieces, ran the downloaded text in memory and later fetched an exe. A scan of files may then find nothing | Arctic Wolf Labs |
| Execution tracking | The same loader tried to report its status to a second address, a sign that someone watches for success | Arctic Wolf Labs |
| Persistence | Neither source we read describes how this kind of loader restarts. We do not know if this one does | Microsoft and Arctic Wolf |
What this can cost you
Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where the command was pasted and run, or a file from the site was opened.
- High
Account takeover
If the loader brought in a stealer, saved logins and browser sessions can be used to enter your email, social and work accounts. Changing a password alone may not end a stolen session.
- High
Crypto theft
Wallet files and wallet apps are a main target of the stealers that ClickFix delivers. Stolen crypto cannot be reversed, so move funds from a clean device first.
- High
Someone else controlling the PC
Microsoft lists remote access tools among the payloads. With one of them running, a person can use the PC, see the screen and read files.
- Medium
A hidden program that starts again
Some chains add a scheduled task, a Startup entry or a registry Run key. Until it is gone the PC keeps contacting the attackers.
- Medium
Work accounts and company data
On a work PC the passwords and sessions in the browser reach company systems. Tell your IT or security team at once; they can block the accounts.
- Low
Nothing, if you only saw the name
A name in a warning, a firewall log or a blocked link is not an infection.
What you may notice, and what you may not
Many victims notice nothing. The signs below follow from how these chains work; the first two are the best evidence you have.
| Sign | What it means |
|---|---|
| A line in the Run history that you did not write | Windows records what was typed in Run. A line with powershell, iex, irm, mshta, curl or a web address is the command that was pasted |
| A window that flashed and closed | A black or blue window that vanished right after you pressed Enter is how many victims remember it |
| A page that never finished its check | A CAPTCHA that asked you to press keys and then did nothing |
| A task or Startup file you did not make | Task Scheduler entries with random names and files in the Startup folder are common places for a loader to restart |
| Defender alerts around that time | Windows Security may show a detection in Protection history, or it may show nothing if the code ran in memory |
| Accounts you did not touch | Logins from new places, password reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote |
| Nothing at all | Loaders are built to run quietly and pass the work to the next stage |
How to check the PC for nordertextil.de (ClickFix, Loader, powershell)
How people end up on a page like this
We do not know how visitors reached nordertextil.de. These are the routes that Microsoft names for ClickFix pages in general.
- 1
A phishing email with a link
An email about a document, an invoice or an order sends you to a page that must be checked before you can read it. The path /t/dokument281 fits that picture, but this is only our reading.
- 2
A malicious ad
Microsoft lists malvertising as a route. An ad on a search page sends you to a fake check.
- 3
A hacked website
Microsoft lists compromised sites. A real small business site can show a fake CAPTCHA after criminals change its pages, and the owner may not know.
- 4
A fake Windows or browser fix
A page claims that your browser is broken or a font is missing and offers a fix that you paste into Run.
Check your Windows PC before you delete anything
Start with the question that matters: did you paste a command from a website into Run, Windows Terminal or PowerShell, or open a file from nordertextil.de? If yes, follow the numbered plan on this page, because a clean looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and network cables if you can.

- 1
Read the Run box history
Open Registry Editor (press the Windows key, type regedit, press Enter) and go to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is a line typed into Run. Look at it, do not run it, and do not delete it yet. Write down or photograph any line with powershell, iex, irm, mshta, curl or a web address. - 2
Look for a scheduled task you did not make
Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet; note the name.
- 3
Look in the Startup folder
Press Windows key + R, type
shell:startupand press Enter. A file that you did not put there is worth noting. - 4
Check Windows Security
Open Windows Security, choose Virus & threat protection, then Protection history. On Windows 10 the app is under Settings, Update & Security, Windows Security. Look for detections dated around the time you pasted the command.
- 5
Remember what a clean check means
Clearing RunMRU removes evidence of the command, not the malware. In memory payloads may leave nothing in these places. A clean check lowers the doubt; it does not remove it.
How to remove nordertextil.de (ClickFix, Loader, powershell)
How to remove nordertextil.de
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to nordertextil.de or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever nordertextil.de installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You must be signed in as a local administrator, and the Windows Recovery Environment must be enabled. To check, open a Command Prompt as administrator and run
reagentc /info; if it says Disabled, runreagentc /enable. Microsoft says that with it disabled the scan does not run and shows no error. - 2
Suspend BitLocker if it is on
If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.
- 3
Start the scan
Open Windows Security, choose Virus & threat protection, then Scan options. Select Microsoft Defender Offline scan and then Scan now. Accept the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends.
- 4
Read the result
Open Windows Security, then Virus & threat protection, then Protection history. Microsoft says the scan does not apply to ARM versions of Windows, and that Microsoft Defender Antivirus must be the main antivirus to receive its updates.
- 5
Do not stop there
A scan that finds nothing does not prove the PC is clean if a remote access tool was running. If you pasted a command and it ran, the safest end of the plan is to back up documents and reinstall Windows.
If you use a Mac, an iPhone or an Android phone
The powershell and exe tags point at Windows. We found nothing that says the four addresses work on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | A PowerShell command does not run on macOS. ClickFix also exists for Macs, where it uses Terminal, but we do not know what this page shows a Mac visitor | If you pasted something into Terminal, treat it as a separate case and see our Mac guides, not the Windows steps |
| iPhone or iPad | The trick needs a place to paste a command, which phones do not have | Nothing to remove. If you typed passwords on a page, change them |
| Android | No source mentions it | Nothing to remove for this chain; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Do these in this order and from a device that did not run the command. A phone or another computer is enough.
- 1
Change passwords from a clean device
Start with the email account that resets all others, then banks, then work and social accounts. Use a new password for each. Do not reuse a password that the PC knew.
- 2
Sign out other sessions and revoke keys
In each important account, choose the option to sign out everywhere. Revoke access tokens, remote desktop and SSH keys that were on the PC and make new ones.
- 3
Move crypto first if a wallet was on the PC
From a clean device, create a new wallet with a new seed phrase and move the funds. Do this before the other steps if you hold crypto.
- 4
Turn on two factor sign in
Use an authenticator app or a hardware key, not only a text message.
- 5
Back up documents and reinstall Windows if in doubt
Copy only documents and photos to an external disk, not programs. On Windows 11 open Settings, System, Recovery and choose Reset this PC, then Remove everything. On Windows 10 open Settings, Update & Security, Recovery. Restore documents only. We did not test these steps on an infected PC.
- 6
Watch your accounts
For some weeks read the sign in alerts of your email, bank and exchange accounts, and report any charge you did not make.
Keep a Windows PC out of this kind of trap
The rule that would have stopped this site is one line: a website never needs you to paste something into Run or PowerShell.
Do
- Treat a request to press Windows key + R and paste a command as an attack. Close the tab.
- Keep Windows, your browser and Microsoft Defender up to date, and leave cloud protection on.
- On a work PC ask IT whether the Run box can be switched off by policy; Microsoft lists this as a protection.
- Keep a backup of documents on a disk that you unplug.
- Use an authenticator app for your important accounts.
Don't
- Do not copy and paste a command to pass a check, to fix a page or to open a document.
- Do not follow a page that tells you which keys to press to verify that you are human.
- Do not run files from sites that promise free versions of paid software.
- Do not turn off Defender or Windows Security because a page tells you to.
- Do not rely on a quiet scan to say that you are safe.
Questions about nordertextil.de (ClickFix, Loader, powershell)
What is nordertextil.de?
nordertextil.de is a web address that the URLhaus database lists for Windows malware downloads. A reporter added four addresses on 25 September 2026, all tagged ClickFix, DEU, exe, Loader and powershell.
When we tried to open the domain on 10 October 2026 our browser could not find it, so we never saw the page that visitors see. We have no registration data for it, because the lookup for .de names gave us none.
We do not know who runs it, whether it is a real business whose site was hacked, or how many people received the files. What we can say is that the reports describe a chain that starts with a command pasted into Run or PowerShell.
Is nordertextil.de a virus?
No, a website is not a virus, but the files it handed out may be malware. URLhaus lists four addresses on nordertextil.de as malware downloads, tagged as a loader and as PowerShell. Visiting a page does not usually run those files.
The danger comes when you paste a command from the page into Run or PowerShell, or open a file it gave you. We did not download the files, so we cannot say what they do.
Our rating of dangerous rests on the URLhaus reports, because our own visit failed. Do not open anything from this name, and do not read the failed visit as proof that it is harmless.
What does ClickFix mean?
ClickFix is a trick in which a web page convinces you to copy a command and run it yourself. On Windows the page tells you to press the Windows key and R, paste with Ctrl and V, and press Enter.
Microsoft says the lures are fake CAPTCHAs, human checks or error pages, reached through phishing email, ads or hacked sites. Because you start the command, no download warning appears and no security hole is needed.
The rule that protects you is simple: a real website check never asks you to open Run or PowerShell and paste something. If a page asks, close it. If you already pasted, follow the steps on this page.
I pasted the command. What do I do first?
Disconnect the PC from the network, then use another device for everything that follows. Do not type a password on the PC. If you hold crypto, move it first from a clean device to a new wallet, since stolen coins cannot be returned.
Then change your email password, then banks, then other accounts, and choose the option to sign out all sessions. After that, run a Microsoft Defender Offline scan from Windows Security, copy only your documents to an external disk, and reinstall Windows if you want to be sure.
This order matters, because a loader can bring in a stealer within minutes and the data that left is the real loss.
What is a loader?
A loader is a small program whose job is to download and start other malware. The tag Loader on these addresses tells us the reporter saw it behave that way, but it does not tell us which family it is or what it installs next.
Microsoft names loaders such as Latrodectus and MintsLoader among the things that ClickFix delivers, next to stealers like Lumma and remote access tools like AsyncRAT.
For you this means the first file may do little harm on its own while the second does the damage. You cannot judge a PC by the first stage alone, so treat a pasted command as a full infection.
Will Microsoft Defender stop this?
We cannot promise that. Microsoft says ClickFix payloads are often loaded into memory through built in tools such as powershell.exe, msbuild.exe and regasm.exe, and that many automated defences see a command you start yourself as normal. Defender may still detect a known file, and Microsoft recommends turning on cloud protection, network protection and attack surface reduction rules.
We did not test these files against Defender. If you pasted the command, do not rely on the lack of an alert. Check Protection history, run the offline scan, and still change your passwords from another device.
The site does not load. Am I safe?
A site that does not load makes new infections from that name less likely, but it does not help a PC that already ran the command. When we tested on 10 October 2026 the domain did not resolve, and all four URLhaus entries were offline.
That may mean the owner or a registrar switched it off, or that we hit a lookup failure. The same campaign can move to other domains, and a page can show a different thing to each visitor.
If you ran the command before the site went down, the loader has already done its work and the steps for passwords, crypto and the scan still apply. If you did not, the name alone has not infected you.
I own nordertextil.de. What should I do?
Treat the website as hacked until you prove otherwise. Take the site offline or put it behind a maintenance page, ask your hosting provider for the access and error logs, and look for files and pages that you did not create, especially the paths /enter, /room and /t/.
Change every password for the hosting panel, the content system, FTP and the database, and update the software and plugins. Restore from a clean backup if you have one. Then ask your host to help you request a re check.
If you hold customer data, ask a lawyer or your data protection contact whether a breach report is due. We cannot tell from outside whether your site was hacked or the name was registered by someone else.
Can I just delete the files and be done?
No. Deleting a file removes a program but does not bring back anything that the program already sent away. A loader may have already brought in a second program that is stored elsewhere or only in memory, and Arctic Wolf describes a loader that never wrote its first stage to disk.
A scheduled task or a Startup entry can start the malware again. Deleting files you find is fine as a first look, but the safe way to end a compromise is to change every password from another device, move crypto, run the offline scan, and reinstall Windows if there is any doubt about what ran.
Will Fortect remove nordertextil.de?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For nordertextil.de, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for nordertextil.de (entries read from our copy of the feed) (read October 10, 2026)
- Microsoft Security Blog: Think before you ClickFix, analyzing the ClickFix social engineering technique (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 10, 2026)
- Arctic Wolf Labs: ClickFix campaign exploits PowerShell loader with identifier obfuscation (read October 10, 2026)
- Microsoft Support: Virus and threat protection in the Windows Security app (read October 10, 2026)