royalcuts.co.uk: a barber shop site that served fake Chrome installers and CoinMiner files, and what to do
royalcuts.co.uk presents a UK barber shop, but URLhaus lists five Windows program downloads on it, named like Chrome installers, two tagged CoinMiner. All five were offline on 10 October 2026. If you opened one, treat your Windows PC as infected, scan it offline and change passwords from another device. If you own the site, it was most likely broken into.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If an .exe file from royalcuts.co.uk, such as ChromeSetup.exe, Chrome.exe or Setup.exe keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove royalcuts.co.uk (CoinMiner, ChromeSetup.exe) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Royalcuts.co.uk (CoinMiner, ChromeSetup.exe): summary
| Type | A malware download address for Windows on a barber shop website: five .exe files named like Chrome installers, two tagged CoinMiner |
|---|---|
| Risk | High if you opened one of the files: a hidden miner and possibly more. Low if you only saw the name |
| Symptoms | A loud fan and high CPU while idle, a slower PC, a new startup entry or task, or a CoinMiner alert in Windows Security |
| How to get rid of it | Disconnect, uninstall unknown programs, switch off startup entries, run a full scan and Microsoft Defender Offline, change passwords from another device, reset Windows if in doubt |
| Our check (10 October 2026) | One plain request: status 200 and the barber shop title. A normal answer clears nothing; the rating comes from URLhaus |
| Running since / first seen | First malware URL reported 21 September 2026, last on 24 September 2026. No registration date: no RDAP data returned |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Platform | Windows, by the .exe ending; no source says other systems are affected |
|---|---|
| Detection names | Microsoft Defender Antivirus names the miner family Trojan:Win32/CoinMiner (Microsoft Security Intelligence); we did not check these five files against it |
| Name | Royalcuts.co.uk |
| Evidence | 5 write-ups by security sites; details still limited |
| First seen | 21 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for royalcuts.co.uk, one plain request from our server, Microsoft Security Intelligence, Bitdefender, the WordPress.org guide to hacked sites and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow those pages and were not tried on a live infection.
What royalcuts.co.uk is, and what we know about it
royalcuts.co.uk is a web address, not a program on your PC. Its home page presents a barber shop in the UK, but the abuse.ch project URLhaus lists five Windows program files on it as malware downloads. Two are tagged CoinMiner, and three carry names that copy Google Chrome installers.
If you only saw the name in a warning, a firewall log or a blocked link, nothing was installed on your PC by that. If you downloaded and opened one of the .exe files, treat the Windows PC as infected and follow the plan on this page. If you own the site, it was most likely broken into, and the section for owners shows the order of the clean-up.
- 1
What URLhaus lists
Five file addresses at the root of royalcuts.co.uk. Four were added on 21 September 2026 within ten seconds of each other, at 13:01 UTC. The fifth, google.exe, was added on 24 September 2026 at 13:37 UTC. One reporter, adrian__luca, submitted all five.
- 2
What the names say
ChromeSetup.exe is the real name of Google's Chrome installer for Windows, and Chrome.exe is the name of the browser program itself. google.exe, Setup.exe and 3.exe are generic. Copying a famous name is the oldest trick for making a download look safe.
- 3
What the tags say
Chrome.exe and 3.exe carry the tag CoinMiner, which marks a program that mines cryptocurrency with your computer. The other three have no tag, so we cannot say which family they belong to. All five have the threat type malware_download.
- 4
Where things stand now
URLhaus marked all five files offline when we read the data on 10 October 2026. The home page still answered our plain request with the barber shop title. An offline file is gone from that address, but a PC that already ran it is not cleaned by that.
- Kind of threat
- A malware download address on what looks like a small business website; five Windows .exe files, two tagged CoinMiner
- File names
- ChromeSetup.exe, Chrome.exe, google.exe, Setup.exe, 3.exe, all at the site root
- First and last report
- 21 September 2026 and 24 September 2026
- Domain registration
- Not available: our lookup returned no RDAP data for this .co.uk name, so we give no registration date
- Systems at risk
- Windows only, by the .exe ending; no source says Mac or phones are affected
What royalcuts.co.uk (CoinMiner, ChromeSetup.exe) does on an infected PC
What we checked on 10 October 2026, and what we could not
Our server sent one plain request to https://royalcuts.co.uk/ on 10 October 2026. There was no browser, no clicks and no screenshot. The server, which identifies itself as nginx, answered with status 200 and the page title Royal Cuts, Best Barber Shop in UK, Professional Haircut and Grooming Services. A normal-looking answer clears nothing.
Our check, 10 October 2026
- The site answers normallyStatus 200 with a barber shop title and no redirect. That is what a hacked business site usually looks like: the owner's pages stay in place and the bad files sit next to them.
- Why that is not a clean resultA plain request sees only the first answer of the home page. It does not run scripts, it does not see what other visitors may be shown, and it cannot tell whether more files were added after the reports.
- Notification requestOur check found no mention of the browser notification feature in the page. This proves little, because no browser ran the page.
- URLhaus listingFive malware download addresses on this domain, reported between 21 and 24 September 2026. All five were offline when we read the data.
- The files themselvesWe did not download the five files and did not run them. We cannot tell you exactly what each one does beyond the tags.
Dangerous: do not download anything from it The rating comes from the five URLhaus reports, not from our check. Do not open any file from this address, and do not trust a Chrome download that does not come from google.com.
What happened to royalcuts.co.uk, in dates
The history we can document is four days long. The dates come from our copy of the URLhaus data and from our own request.

21 September 2026, 13:01 UTC
Four files are reported in one minute
Setup.exe, ChromeSetup.exe, 3.exe and Chrome.exe are added to URLhaus between 13:01:14 and 13:01:24. 3.exe and Chrome.exe get the tag CoinMiner. A batch like this suggests the reporter found the files together, for example in one sample or one folder listing.
24 September 2026, 13:37 UTC
A fifth file appears
google.exe is added by the same reporter, three days later and without a tag. A new file after the first reports suggests that whoever placed them still had access to the server on that day. That is our reading, not a fact from a source.
By 10 October 2026
All five are offline
URLhaus shows every file as offline. Either the files were deleted, or the server stopped handing them out. We do not know who removed them.
10 October 2026
Our plain request
The home page answers with status 200 and the barber shop title. We give no registration date because our lookup returned no RDAP data for the name.
We did not read the URLhaus website pages themselves, because they ask for a browser check. The entries above come from the same data in our own copy of the feed, which the server gave us with this job.
What a CoinMiner is, and how fake Chrome installers have spread miners
Microsoft describes CoinMiner as a trojan that uses your PC to mine cryptocurrency for someone else. Bitdefender has reported a campaign in which hacked websites showed fake Chrome update messages that delivered a Monero miner. That campaign is not proven to be this site; it shows how such a trap works.

| What | What a source says | Source |
|---|---|---|
| Microsoft's name | Trojan:Win32/CoinMiner, a trojan that uses the PC to mine coins and sends the results to a server the attacker controls | Microsoft Security Intelligence |
| How it hides | The miner may run under a legitimate process name; Microsoft lists file names such as svchost.exe, minerd.exe, cg.exe and amd_gpu.exe | Microsoft Security Intelligence |
| How it arrives | It can be bundled with other software such as cracks and key generators, and often drops supporting library files | Microsoft Security Intelligence |
| The symptom Microsoft names | The PC runs slower than usual | Microsoft Security Intelligence |
| A fake Chrome campaign | Hacked sites, mainly in Japan, South Korea and Spain, said Chrome's automatic update had failed and offered a manual update package. The download was a Monero miner | Bitdefender, April 2023 |
| Why the trick works | The fake message created no urgency, which may have made it more convincing; Chrome never needs a manual update download | Bitdefender, April 2023 |
A miner does not usually lock your files or show a ransom note. Its cost is quieter: electricity, heat, a fan that never stops, a slower PC and wear on the processor or graphics card. The bigger worry is the three untagged files. A program that calls itself Setup.exe can install anything, so a miner may not be the only thing on a PC that ran one.
The five files: what each name suggests, and what we do not know
The names are all we have for three of the files. The table says what each name copies and what is known about it.
| File | What the name copies | What is known |
|---|---|---|
| ChromeSetup.exe | Google's real Chrome installer for Windows | No tag. The real installer only comes from google.com/chrome |
| Chrome.exe | The Chrome browser program itself | Tagged CoinMiner by the reporter |
| google.exe | A generic Google name | No tag. Added three days after the others |
| Setup.exe | Any program's installer | No tag. Could install anything |
| 3.exe | Nothing; a numbered file | Tagged CoinMiner by the reporter |
If you have one of these names in your Downloads folder, check where it came from before you open it. Right-click the file, choose Properties and look at the Digital Signatures tab. A real Chrome installer is signed by Google LLC. A file with no signature, or a signature from another name, is not Chrome. Do not run it to find out.
What royalcuts.co.uk (CoinMiner, ChromeSetup.exe) can steal or download
What this can cost you
Reading the site name or seeing a block warning costs nothing. The risks below apply to a Windows PC where one of the five files was downloaded and opened.
- High
A hidden program that uses your hardware
A miner runs the processor or graphics card hard for hours. That means a slower PC, more heat, a louder fan, a higher power bill and, on a laptop, a battery that drains fast.
- High
Something more than a miner
Three files have no tag. An installer from an attacker can add other programs, such as a password stealer or a remote access tool. Until you know otherwise, treat saved passwords on that PC as exposed.
- Medium
A miner that comes back
Miners often add a startup entry or a scheduled task so they start again after a restart. Deleting the file you downloaded does not remove those.
- Medium
Work PCs and shared networks
On a work PC, tell your IT team at once. A miner on one machine can be a sign that others on the network were reached the same way.
- Low
Nothing, if you only saw the name
A name in a warning, a firewall log or a blocked download is not an infection.
What you may notice, and what you may not
Miners are built to stay unseen, but they cannot hide the work they do. The signs below follow from Microsoft's description of CoinMiner and from how miners use a PC.
| Sign | What it means |
|---|---|
| A loud fan or a hot PC while you do nothing | Something is using the processor or graphics card in the background |
| High CPU or GPU use in Task Manager | Sort by CPU; a process near the top with a name you do not know, or a second svchost.exe with odd use, deserves a look |
| The PC is slower than usual | The symptom Microsoft names for CoinMiner |
| Use drops the moment you open Task Manager | Some miners pause when a monitoring tool opens; our reading of how they hide |
| A new entry in Startup apps or Task Scheduler | How a miner starts again after a restart |
| Windows Security names a CoinMiner | Protection history may show Trojan:Win32/CoinMiner or a similar name |
| Nothing at all | Some miners only run when the PC is idle or locked |
How to check the PC for royalcuts.co.uk (CoinMiner, ChromeSetup.exe)
How people could end up running one of these files
We do not know how visitors reached these five files, and no source says. The routes below are common ways a download on a hacked business site reaches a PC, based on the names and on the Bitdefender report.
- 1
A fake update message on a website
A page you visit says Chrome failed to update and offers an update package. The download link points to a file such as ChromeSetup.exe on a site like this one. Real Chrome updates happen inside the browser.
- 2
A link in an email or a chat message
The link goes straight to an .exe on a real UK business domain, which passes a quick look. The message may promise a missing browser component or a document viewer.
- 3
A search result or an ad for Chrome
Someone looking for a Chrome download clicks a result that is not google.com. The file has the right name and the wrong source.
- 4
A file dropped by another program
A first piece of malware can download the next one from a hacked server. In that case you never clicked these addresses, and the first program is the real problem.
Check your Windows PC before you delete anything
Start with one question: did you open an .exe file that came from royalcuts.co.uk? If yes, follow the whole plan, because a quiet check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, stop using the PC for banking, email and work, and disconnect it from Wi-Fi and the network cable if you can.
- 1
Look at Task Manager
Press Ctrl + Shift + Esc, open the Processes tab and sort by CPU. Right-click any unknown process with high use and choose Open file location. Note the folder; a program in AppData or Temp with a system name is suspect.
- 2
Check Windows Security
Open Windows Security > Virus & threat protection > Protection history. Look for a CoinMiner name or any detection dated around the time you opened the file. On Windows 10 the app is also reached from Settings > Update & Security > Windows Security.
- 3
Look at Startup apps
Open Settings > Apps > Startup on Windows 11. On Windows 10 use the Startup tab in Task Manager. Note any entry you do not recognise.
- 4
Look in Task Scheduler
Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Note it; do not delete it yet.
- 5
Look at Installed apps
Open Settings > Apps > Installed apps and sort by install date. Anything installed on the day you opened the file that you did not choose is suspect.
How to remove royalcuts.co.uk (CoinMiner, ChromeSetup.exe)
How to remove royalcuts.co.uk
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to royalcuts.co.uk or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever royalcuts.co.uk installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Remove it: the order that works
Follow the steps in this order. A miner can come back from a startup entry or a task, so the offline scan comes after you have seen what is there, and a reset is the end of the plan when doubt remains.

- 1
Uninstall what you did not choose
In Settings > Apps > Installed apps, select the three dots next to an unknown program and choose Uninstall. On Windows 10 use Settings > Apps > Apps & features. Then delete the downloaded .exe from your Downloads folder and empty the Recycle Bin.
- 2
Switch off what starts with Windows
In Settings > Apps > Startup, switch off the entries you noted. In Task Scheduler, right-click a task you noted and choose Disable. Disable first; delete after the scan agrees.
- 3
Run a full scan
Open Windows Security > Virus & threat protection > Scan options, choose Full scan and select Scan now. Microsoft's page for CoinMiner advises a full scan because it may find other hidden malware. Make sure Cloud-delivered protection is on under Virus & threat protection settings.
- 4
Change passwords from another device
Use a phone or a different computer. Change your email password first, then banking, then the rest, and turn on two-step sign-in. Do this because the untagged files could have taken more than processor time.
Scan from outside Windows: Microsoft Defender Offline
An offline scan starts before the normal Windows loads, so a program that hides inside Windows has a harder time hiding from it. Microsoft says it targets malware that tries to bypass the Windows shell.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You need an administrator account and the Windows Recovery Environment turned on. To check, open Command Prompt as administrator and run
reagentc /info; if it says Disabled, runreagentc /enable. - 2
Suspend BitLocker if it is on
If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the scan.
- 3
Start the scan
Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now, then Scan, then Yes. Windows signs you out, runs the scan and starts again when it ends.
- 4
Read the result
Open Windows Security > Virus & threat protection > Protection history. Microsoft says the offline scan works on x64 Windows 11 and on Windows 10, not on ARM Windows, and that Microsoft Defender Antivirus must be the main antivirus.
- 5
Reset if doubt remains
If something was found and you are not sure everything went, back up your documents to an external disk and open Settings > System > Recovery > Reset this PC. Choose Remove everything after a real infection; do not restore old programs from the backup.
If you own or manage royalcuts.co.uk or another hacked site
Program files at the root of a barber shop website mean someone had write access to the server. We do not know which system the site runs on. The WordPress.org guide to hacked sites gives an order that fits most sites, and a clean-up that skips the way in will be undone.

- 1
Write down what you saw and take a copy
WordPress.org advises a note of what you saw and when, and a snapshot of the site even while infected, before the clean-up. Here the notes start with the five .exe names and the dates 21 and 24 September 2026.
- 2
Tell your host and lock every door
Ask the host whether other sites on the account are hit and what their logs show for those dates. Change every access point for every user: SFTP or FTP, the hosting control panel, the database and the site admin. On WordPress, replace the secret keys in wp-config.php so every logged-in session ends.
- 3
Scan your own computer first
WordPress.org says attacks often start on the site owner's own machine, with trojans that capture FTP and admin logins. Run a full scan on every computer used to manage the site, with a second scanner if you can.
- 4
Delete the files and look for more
Remove the five .exe files and any other program file in the web root or uploads. Check .htaccess, which WordPress.org names as the file most often changed, and index.php, header.php, footer.php and functions.php. Remove any admin user you did not add.
- 5
Replace core files from a clean copy
On WordPress, download the same version you run and copy /wp-admin and /wp-includes over by SFTP. Do not use the reinstall button in the dashboard; WordPress.org says it only overwrites existing files, and hacks add new ones.
- 6
Update, change passwords again and watch
When the site is clean, update the system, themes and plugins, and change all passwords again. Register the site with Google Search Console and Bing Webmaster Tools, as WordPress.org suggests, to see blocklist warnings early. Ask URLhaus to review the entries once the files are gone.
If you use a Mac, an iPhone or an Android phone
The five files are Windows programs by their .exe ending. We found nothing that says they run on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | An .exe file does not run on macOS | Nothing to remove for these files. Delete the download |
| iPhone or iPad | No source mentions it | Nothing to remove. Do not send the file to a Windows PC |
| Android | An .exe does not install on Android | Nothing to remove for these files; delete the download |
After removal: passwords, accounts and prevention
A known business address is not a safe source of programs. This site probably belongs to an honest barber shop, and the files on it were still dangerous.
Do
- Download Chrome only from google.com/chrome, and let it update itself under Settings > About Chrome.
- Check the digital signature of an installer before you run it: right-click, Properties, Digital Signatures.
- Keep Windows, your browser and Windows Security up to date, with real-time and cloud-delivered protection on.
- Watch Task Manager when the fan runs loud for no reason.
- Use an authenticator app for email and banking.
Don't
- Do not install a browser update offered by a web page.
- Do not trust a program because its name is ChromeSetup.exe or Setup.exe.
- Do not download programs from a site whose business has nothing to do with software.
- Do not rely on a quiet scan after you ran an unknown installer.
Questions about royalcuts.co.uk (CoinMiner, ChromeSetup.exe)
What is royalcuts.co.uk?
It is a website that presents a barber shop in the UK, and URLhaus lists it for handing out malware. Five Windows program files on it were reported between 21 and 24 September 2026, two of them tagged CoinMiner, and all five were offline when we read the data on 10 October 2026.
The home page still answered our plain request with the barber shop title. If you only saw the name in a warning, you are not infected by that.
Is royalcuts.co.uk a virus?
A website is not a virus, but this one is listed as a source of malware. URLhaus gives all five file addresses the threat type malware_download.
Two files are tagged CoinMiner, a kind of trojan that Microsoft detects as Trojan:Win32/CoinMiner. We did not download the files, so we cannot say exactly what the three untagged ones do. Do not open any file from this address.
Was the barber shop hacked, or is the site criminal?
We cannot prove either, but a hack is the likelier reading. A barber shop has no reason to host Chrome installers, the home page looks like a normal business site, and a fifth file appeared three days after the first four.
That pattern fits someone who had access to the server without the owner knowing. Treat this as our reading, not a finding.
I downloaded ChromeSetup.exe from this site. Am I infected?
Downloading alone does not run a program, but opening it does. If you only downloaded it, delete it and empty the Recycle Bin. If you opened it and approved the Windows prompt, follow the plan on this page:
- check Task Manager
- Startup apps and Task Scheduler
- uninstall unknown programs
- run a full scan and an offline scan
- change passwords from another device
How do I know if a miner is running on my PC?
Open Task Manager with Ctrl, Shift and Esc and sort the Processes tab by CPU. A process with a name you do not know, or a system name such as svchost.exe in an odd folder, using a lot of CPU while you do nothing is a warning sign.
A fan that runs loud while the PC is idle and a slower PC point the same way. Windows Security may also list Trojan:Win32/CoinMiner in Protection history.
Can a CoinMiner steal my passwords?
A miner's job is to use your hardware, not to read your data, according to Microsoft's description. The risk here is that three of the five files have no tag, so we do not know what they install. Change your important passwords from another device if you ran any of them, starting with email.
How do I get a real Chrome installer?
Download Chrome only from google.com/chrome. Before you run the installer, right-click it, choose Properties and open the Digital Signatures tab: the real file is signed by Google LLC.
Once installed, Chrome updates itself; you can check under Settings and About Chrome. Bitdefender notes that Chrome never needs a manual update package from a web page.
Is it safe to visit royalcuts.co.uk now?
We cannot call it safe. The reported files were offline on 10 October 2026, and the home page looked normal to our plain request, but that request ran no scripts and saw only the first answer.
Whoever placed the files may still have access. There is no need to visit it, and you should not download anything from it.
Does this affect my Mac or my phone?
No source says so. The five files end in .exe, which is a Windows program format, and they do not run on macOS, iPhone or Android.
If you downloaded one on another device, delete it and do not move it to a Windows PC. If you typed a password on a page linked from this site, change that password anyway.
Will Fortect remove royalcuts.co.uk?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For royalcuts.co.uk, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for royalcuts.co.uk (entries read from our copy of the feed) (read October 10, 2026)
- Microsoft Security Intelligence: Trojan:Win32/CoinMiner (read October 10, 2026)
- Bitdefender: Attackers Compromise Website to Display Fake Chrome Updates and Deploy Cryptominer (read October 10, 2026)
- WordPress.org Documentation: FAQ My site was hacked (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 10, 2026)