reinigung-kosanke.de: a hacked WordPress site that served Formbook PowerShell scripts, and what to do
reinigung-kosanke.de is a German cleaning business website that URLhaus lists for four PowerShell (.ps1) malware downloads tagged Formbook, and it answered our test with a 503 error. If you ran a script from it, treat your Windows PC as compromised: change passwords from another device and scan offline. If you own the site, it was almost certainly broken into and needs cleaning.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a PowerShell script (.ps1) from reinigung-kosanke.de, or a command that fetched one keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1): summary
| Type | A malware download address for Windows on a hacked WordPress site: four PowerShell scripts tagged Formbook |
|---|---|
| Risk | High if you ran one of its scripts: passwords may have been taken. Low if you only saw the name |
| Symptoms | Often none. A PowerShell window that flashed and closed, an unknown scheduled task or a script in Startup are the signs |
| How to get rid of it | Disconnect, change passwords from another device, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt. Site owners: replace wp-admin and wp-includes and close the way in |
| Our check (9 October 2026) | One visit: a 503 Service Temporarily Unavailable page. A broken or quiet site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | First malware URL reported 29 September 2026. No registration date: no RDAP data for .de |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Platform | Windows, by the ps1 tag; no source says other systems are affected |
|---|---|
| Detection names | Microsoft Defender Antivirus names the Formbook family Trojan:Win32/Formbook and TrojanSpy:Win32/FormBook (Microsoft Security Intelligence); we did not check these four files against them |
| Name | Reinigung-kosanke.de |
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 29 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for reinigung-kosanke.de, one browser visit of our own on 9 October, Microsoft Security Intelligence, Forcepoint X-Labs, the WordPress.org guide to hacked sites and Microsoft Learn (the offline scan steps were read on 9 October).
We did not download the files and we infected no PC; the removal steps follow those pages and were not tried on a live infection.
What reinigung-kosanke.de is, and what we know about it
reinigung-kosanke.de is a web address, not a program on your PC. The abuse.ch project URLhaus lists four files on it as malware downloads, all tagged Formbook. The folder they sit in belongs to WordPress itself, which points to a normal business site that someone broke into. No public write-up of this one domain exists that we could find, so this page rests on what URLhaus shows, what we saw ourselves and what Microsoft, Forcepoint and WordPress.org have published.
- 1
What URLhaus lists
Four file addresses on reinigung-kosanke.de, all added on 29 September 2026 by the reporter abuse_ch between 06:33 and 12:42 UTC. Each is a PowerShell script whose name ends in CRYPTED_STUB.ps1, and each carries the tags ascii, Formbook, powershell and ps1. All four have the threat type malware_download and were offline when we read them.
- 2
Why the folder matters
The files sit under /wp-includes/theme-compat/ followed by three folders with random names. wp-includes is a core WordPress folder that normally holds only files shipped by WordPress. A script with a random path inside it was put there by someone who had write access to the server. That is our reading, not a statement from the site owner.
- 3
What the tags mean
ps1 is the ending of a PowerShell script. Formbook is the name of a malware family that Microsoft detects as Trojan:Win32/Formbook and TrojanSpy:Win32/FormBook. The tag is the reporter's label. We did not download the scripts, so it is not our finding.
- 4
What we could not confirm
We do not know how visitors were sent to these files, who received them, what the scripts do step by step, or how the site was broken into. We also do not know whether the owner has cleaned it since.
- Kind of threat
- A malware download address on a hacked WordPress site; four PowerShell scripts tagged Formbook
- Where the files sit
- /wp-includes/theme-compat/ in random subfolders, file names ending in CRYPTED_STUB.ps1
- Domain registration
- Not available: our lookup has no RDAP server for the .de ending, so we give no registration date
- URLhaus entries
- 4 file addresses, all added on 29 September 2026; all offline when we read them
- Platform
- Windows, by the ps1 tag and by Microsoft's detection names. No source says other systems are hit
What reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1) does on an infected PC
What we checked on 9 October 2026, and what we could not
We opened https://reinigung-kosanke.de/ once, from Lithuania, in an automated Chromium browser set to English. The server answered with a 503 error page. That is a broken or switched-off site, not a clean one.

Our site test, 9 October 2026
- The site answered with an errorThe page title was 503 Service Temporarily Unavailable. The text says the server cannot serve the request because of maintenance or capacity problems. That text is a standard host error page.
- Why that is not a clean resultA 503 can mean the owner or the host switched the site off after a warning, that the server is overloaded, or that it blocks our kind of visitor. We cannot tell which from one visit. A site that shows nothing is not cleared.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
- URLhaus listingFour malware addresses on this domain, added on 29 September 2026. All four were offline when we read the database.
- Downloads and the page itselfWe did not download the scripts and we did not reach any page that links to them. We cannot tell you what they do.
Dangerous: treat it as a malware site Our visit was one visit that ended in an error page, so it proves nothing either way. The danger rating comes from the four URLhaus reports. Do not open files from this address, and do not run anything it gives you.
What happened to reinigung-kosanke.de, in dates
The history we can document is one day long. The dates come from the URLhaus database and from our own test.
29 September 2026, 06:33 and 06:34 UTC
Two scripts are reported
URLhaus adds two addresses ending in MCRYPTED_STUB.ps1 and OJCRYPTED_STUB.ps1, both in the same wp-includes/theme-compat subfolder, with the tags ascii, Formbook, powershell and ps1. This is the first time URLhaus sees the host.
29 September 2026, 07:41 UTC
A third script is added
A file ending in 22CRYPTED_STUB.ps1 is listed with the same tags and the same folder.
29 September 2026, 12:42 UTC
A fourth script is added
The file ending in myCRYPTED_STUB.ps1 is the last entry. All four are marked offline by the time we read them, which means the files were no longer served at the time of the checks.

How the parts fit together, and what stays unknown: the hacked server, the scripts, the Formbook tag and the PC that would be hit. 9 October 2026
Our test gets a 503 page
Our browser visit to https://reinigung-kosanke.de/ ends on a Service Temporarily Unavailable page. We do not know whether the site is switched off for cleaning or broken.
We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.
What Formbook is, and what a campaign with it can look like
Microsoft lists two detection names for Formbook and rates both as severe. Forcepoint has described one campaign in detail. That campaign is not this site, and the steps below show what is possible, not what happened here.
| What | What a source says | Source |
|---|---|---|
| Microsoft's names | Trojan:Win32/Formbook (updated January 2019) and TrojanSpy:Win32/FormBook (updated September 2018), both with the alert level severe | Microsoft Security Intelligence |
| How a chain started in one campaign | A Word document protected with a tool called Horus Protector dropped a VBS file and made a scheduled task that ran it every minute | Forcepoint X-Labs |
| How the payload ran | A hex-encoded PowerShell command loaded a program from the registry straight into memory | Forcepoint X-Labs |
| Defender check | The script asked WMI whether Windows Defender was present and changed its course by the answer | Forcepoint X-Labs |
| Where it hid | A second DLL rebuilt the Formbook payload from registry values and ran it inside a real Windows program, RegAsm.exe, through process hollowing | Forcepoint X-Labs |
The point for you is that a PowerShell stage can leave very little on disk. A normal scan of files may find nothing even when the memory-only part ran, which is why the plan below ends with an offline scan and, after a real run, a reinstall.
The four files: what each name suggests, and what we do not know
File names are weak evidence. We list what URLhaus shows and mark which statements are only a reading of the name.
| File ending (full folder path shortened) | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /wp-includes/theme-compat/qmxythi/.../MCRYPTED_STUB.ps1 | Offline, tags ascii, Formbook, powershell, ps1, added 29 September 2026 at 06:33 UTC | A PowerShell script. The word STUB suggests a small first stage that fetches or unpacks something else. Not confirmed |
| /wp-includes/theme-compat/qmxythi/.../OJCRYPTED_STUB.ps1 | Offline, same tags, added at 06:34 UTC | Another copy with a different prefix. The prefixes look like per-target labels, which we cannot confirm |
| /wp-includes/theme-compat/qmxythi/.../22CRYPTED_STUB.ps1 | Offline, same tags, added at 07:41 UTC | A third copy of the same kind |
| /wp-includes/theme-compat/qmxythi/.../myCRYPTED_STUB.ps1 | Offline, same tags, added at 12:42 UTC | A fourth copy of the same kind |
The tag ascii and the word CRYPTED in the name say the script text is probably obfuscated, but that is a reading of the label, not something we checked. We fetched none of the files, so we name no behaviour beyond what the tags say.
What reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1) can steal or download
What this can cost you
Reading the site name or seeing a warning costs nothing. The risks below apply to a Windows PC where one of these scripts, or a command that fetched it, was run.
- High
Stolen logins
Microsoft files Formbook under TrojanSpy, its label for programs that spy on the user. Treat every password typed or saved on that PC as seen by someone else.
- High
A hidden program that starts again
In the campaign Forcepoint describes, a scheduled task ran a script every minute. Until such a task is gone, the PC keeps starting the chain.
- Medium
Work accounts and company data
On a work PC the saved passwords reach company systems. Tell your IT team at once so they can block the accounts.
- Medium
Damage to the hacked site's own customers
If you ever sent your details to the cleaning company through its site, someone with control of the server may have seen them. We have no evidence of this; it is a possibility to weigh.
- Low
Nothing, if you only saw the name
A name in a warning, a firewall log or a blocked link is not an infection.
What you may notice, and what you may not
Most victims of a spying program notice nothing. The signs below follow from the chain Forcepoint describes and from how PowerShell leaves traces.
| Sign | What it means |
|---|---|
| A PowerShell window that flashed and closed | A script ran and finished at once. This is how many stages look |
| A scheduled task you did not make | Forcepoint's campaign used a task that ran a dropped file every minute |
| A .vbs or .ps1 file in your user folders or Startup | The usual place for a starter file; check shell:startup as shown below |
| Windows Security reporting a Formbook name | Protection history may show Trojan:Win32/Formbook or TrojanSpy:Win32/FormBook |
| Sign-ins or password resets you did not start | A sign that a login was taken. This is our reading, not a quote |
| Nothing at all | Spying programs are built to run quietly |
How to check the PC for reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1)
How people could end up running one of these scripts
We do not know how visitors reached these files, and no source says. The routes below are common ways a script on a hacked website reaches a PC; they are a list of possibilities.
- 1
A link in a phishing email
The email links straight to a file on a real, trusted business site, which passes a quick look at the address. The file is a script or a document that fetches one.
- 2
A document that fetches the script
A Word or other document runs a macro or a hidden command that downloads the .ps1 and starts it. This is the pattern in the Forcepoint campaign, which began with a Word document.
- 3
A pasted command
A page asks you to paste a line into the Windows Run box or PowerShell. The line downloads the script from the hacked site. Never paste a command from a web page.
- 4
A message from someone you know
A hacked account sends the link to its contacts, which is why you may trust it.
Check your Windows PC before you delete anything
Start with one question: did you run a .ps1 file, or paste a command, that came from reinigung-kosanke.de? If yes, follow the plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, stop using the PC for banking, email or work, and disconnect it from Wi-Fi and the network cable if you can.
- 1
Check Windows Security
Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for a Formbook name or any detection dated around the time you ran the file.
- 2
Look for a scheduled task you did not make
Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Note the name; do not delete anything yet.
- 3
Look in the Startup folder
Press Windows key + R, type
shell:startupand press Enter. A .vbs, .cmd or .ps1 file you did not put there is suspect. Note it. - 4
Read the Run box history
If you pasted a command, open Registry Editor and go to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is a line typed into Run. Read it, do not run it, and write down any line that names this site or contains powershell. - 5
Remember what a clean check means
A payload loaded into memory can leave nothing in these places, as the Forcepoint chain shows. A clean check lowers the doubt; it does not remove it.
How to remove reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1)
How to remove reinigung-kosanke.de
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like reinigung-kosanke.de add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after reinigung-kosanke.de, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of reinigung-kosanke.de that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Reinigung-kosanke.de can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. It needs an administrator account and Windows Recovery Environment turned on. To check, open a Command Prompt as administrator and run
reagentc /info; if it says Disabled, runreagentc /enable. - 2
Suspend BitLocker if it is on
If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the scan.
- 3
Start the scan
Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now. Agree to the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends.
- 4
Read the result
Open Windows Security > Virus & threat protection > Protection history. Microsoft says the scan only works on x64 Windows 10 and 11, not on ARM, and that it needs Microsoft Defender Antivirus as the main antivirus.
- 5
Do not stop there
A scan that finds nothing does not prove the PC is clean if the script ran and loaded its payload into memory. If you ran one of these scripts, the safest end of the plan is to back up documents and reinstall Windows.
If you own or manage reinigung-kosanke.de or another hacked WordPress site
Files that visitors cannot normally upload, sitting in wp-includes, mean someone had write access to the server. The WordPress.org guide to hacked sites gives the order below. A clean-up that skips the way in will be undone.

- 1
Take a copy and write down what you see
WordPress.org advises a snapshot of the site as it is, even infected, before the clean-up, and a note of what you saw and when. Here the notes start with the four .ps1 files in wp-includes/theme-compat.
- 2
Tell your host and lock access
Ask the host whether other sites on the account are hit and what they log. Change every access point: SFTP, WP-Admin, the host's control panel and the database user, and do it for all users. Replace the secret keys in wp-config.php so every logged-in session ends.
- 3
Scan your own computer first
WordPress.org says attackers often start from trojans on the site owner's own machine that sniff FTP and WP-Admin logins. Run a full scan on the PC you use for the site, with a second scanner if you can.
- 4
Replace wp-admin and wp-includes
Download the same WordPress version you run and copy the /wp-admin and /wp-includes folders over by SFTP. Do not use the reinstall button in WP-Admin: it only overwrites existing files, and hacks add new ones. Delete the whole theme-compat folder first and look for any file in it that is not in the official release.
- 5
Go through wp-content, .htaccess and users
Check plugins, themes and uploads for files you do not recognise, especially PHP files in uploads. WordPress.org names .htaccess as the file most often changed, and index.php, header.php, footer.php and functions.php as high-value targets. Open Users in the dashboard and remove any administrator you did not add.
- 6
Update, change passwords again, ask the community
When the site is clean, update WordPress, themes and plugins, and change the passwords again, including the database user. The WordPress.org Hacked and Malware forums can help if you are stuck.
- 7
Find the way in
Look at which plugin or login was the entry point, and remove anything unused. Register the site with Google Search Console and Bing Webmaster Tools, as WordPress.org suggests, so you see blocklist warnings early.
If you use a Mac, an iPhone or an Android phone
The ps1 tag and Microsoft's Win32 detection names point at Windows. We found nothing that says the four files run on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | A PowerShell script is not made for macOS | Nothing to remove for these files. If you typed a password on the site, change it |
| iPhone or iPad | No source mentions it | Nothing to remove. Change any password you typed on the site |
| Android | No source mentions it | Nothing to remove for these scripts; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then the PC.
- 1
Change passwords from a clean device
Use a phone or another computer. Start with your email, then banking, then work and social accounts. Change your Microsoft account password at account.microsoft.com.
- 2
Sign out other sessions
In each important account use the option to sign out everywhere, so an old session ends along with the old password.
- 3
Turn on two-factor sign-in
Use an authenticator app or a security key where the account allows it.
- 4
Back up documents and reinstall Windows if in doubt
Copy only documents and photos to an external drive, not programs. In Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, choose to reset the PC and remove everything.
- 5
Watch your accounts
For some weeks look at your bank and email for activity you did not start, and tell your bank at once if you see any.
Keep a Windows PC out of this kind of trap
A trusted address is not a safe file. This site probably belongs to an honest business, and its files were still dangerous.
Do
- Keep Windows, your browser and Windows Security up to date and turned on.
- Open attachments and downloads only when you expected them, even from a known site or a known sender.
- Check the file ending before you open a download: .ps1, .vbs, .js and .cmd are scripts, not documents.
- Keep a backup of documents on a disk you unplug.
- Use an authenticator app for your important accounts.
Don't
- Do not paste a command from a web page into Run, Terminal or PowerShell.
- Do not enable macros in a document because the document says so.
- Do not assume a business website is safe because it looks normal.
- Do not rely on a quiet scan to say that you are safe.
Questions about reinigung-kosanke.de (Formbook, CRYPTED_STUB.ps1)
What is reinigung-kosanke.de?
It is a website, apparently of a German cleaning business, that URLhaus lists for handing out malware. Four PowerShell files on it were added on 29 September 2026, all tagged Formbook and ps1, and all offline when we read them. They sit in the wp-includes folder of a WordPress install, which suggests the site was broken into.
On 9 October 2026 our test visit got a 503 error page, so we cannot say what the site shows today. If you only saw the name in a warning or a log, you are not infected by that. If you ran a script from it, use the cleaning steps on this page.
Is reinigung-kosanke.de a virus?
A website is not a virus, but this one is listed as a source of malware. URLhaus gives all four file addresses the threat type malware_download and tags them Formbook. Formbook is a malware family that Microsoft detects as Trojan:Win32/Formbook and TrojanSpy:Win32/FormBook.
We did not download the files, so we cannot say exactly what they do. Treat the domain as dangerous, do not open files from it, and do not run anything it offers. Reading about it on this page cannot infect you.
Was the cleaning company hacked, or is it criminal?
We cannot prove either, but the evidence points to a hacked site. The files are in /wp-includes/theme-compat/, a core WordPress folder, inside random subfolders. Honest owners do not usually put scripts there, and an attacker with write access does.
We found nothing that links a real business to the malware. If you are the owner, assume your site was broken into and follow the owner steps on this page, starting with a copy of the site and new passwords for every access point.
I ran a .ps1 file from reinigung-kosanke.de. What do I do now?
Disconnect the PC from the network first, by turning off Wi-Fi and unplugging the cable. Then, from another device, change your email, bank and work passwords and sign out of accounts everywhere. After that run a Microsoft Defender Offline scan on the PC.
If the script ran, the safest end is to back up documents and reinstall Windows, because a payload that runs in memory may leave little trace. Tell your IT team if it is a work PC.
What if I only visited the site and opened nothing?
Visiting a page does not usually infect a PC by itself, and these files are scripts that must be run. If you did not open a downloaded file and did not paste a command, you should be fine.
Close the tab and, as a precaution, run a normal scan in Windows Security. Do not go back to the site. If you typed a password into a form on it, change that password, in case someone with control of the server saw it.
What is Formbook?
Formbook is the name of a malware family. Microsoft detects it as Trojan:Win32/Formbook and TrojanSpy:Win32/FormBook and rates both as severe. The Spy in the second name is Microsoft's label for programs that watch the user.
Forcepoint has described one Formbook campaign that began with a Word document, used PowerShell and the registry to load the payload into memory, and ran it inside the Windows program RegAsm.exe. That campaign is not this site. For what it does to your PC, assume your saved logins can be taken.
Will a scan with Windows Security remove it?
Microsoft Defender can detect many scripts and the payloads they fetch, and you should run it. But we cannot promise it finds every file from this site, because we did not open them and we do not know what they install. A payload loaded into memory may leave little on disk.
The stronger step is the Microsoft Defender Offline scan, which runs before Windows starts. If a script really ran, reinstalling Windows is the surest cleaning. We know of no removal tool that we have tested against these files.
How do I find and remove the files on a WordPress site?
Make a copy of the site first, then replace the /wp-admin and /wp-includes folders with fresh copies of the same WordPress version, by SFTP and not with the reinstall button in the dashboard. Delete the theme-compat folder before you copy, so no extra file stays.
Then check wp-content, the .htaccess file, uploads for PHP files and the Users list for administrators you did not add. Change all passwords, including the database user, replace the secret keys in wp-config.php and update everything.
Why did our test of reinigung-kosanke.de show a 503 error?
Our browser got a page titled 503 Service Temporarily Unavailable on 9 October 2026. The page text blames maintenance or capacity problems, which is a standard host message.
The owner or host may have switched the site off after a warning, the server may be overloaded, or the site may block visitors from some countries or tools. One visit proves nothing, and a site that shows an error is not cleared. URLhaus showed all four files offline when we read it.
Will Fortect remove reinigung-kosanke.de?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For reinigung-kosanke.de, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for reinigung-kosanke.de (entries read from our copy of the feed) (read October 10, 2026)
- Microsoft Security Intelligence: Formbook detection names (read October 10, 2026)
- Forcepoint X-Labs: FormBook malware distributed via Horus Protector using Word docs (read October 10, 2026)
- WordPress.org Documentation: FAQ My site was hacked (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 9, 2026)