royalcuts.co.uk: a barber shop site that served fake Chrome installers and CoinMiner files, and what to do

royalcuts.co.uk presents a UK barber shop, but URLhaus lists five Windows program downloads on it, named like Chrome installers, two tagged CoinMiner. All five were offline on 10 October 2026. If you opened one, treat your Windows PC as infected, scan it offline and change passwords from another device. If you own the site, it was most likely broken into.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If an .exe file from royalcuts.co.uk, such as ChromeSetup.exe, Chrome.exe or Setup.exe keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove royalcuts.co.uk (CoinMiner, ChromeSetup.exe) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of five URLhaus entries for royalcuts.co.uk: google.exe, Chrome.exe, 3.exe, ChromeSetup.exe and Setup.exe, two tagged CoinMiner, all offline
The five URLhaus entries for royalcuts.co.uk that we read on 10 October 2026, with the addresses defanged. Our own check was a plain request, so this table is the main evidence.

Royalcuts.co.uk (CoinMiner, ChromeSetup.exe): summary

TypeA malware download address for Windows on a barber shop website: five .exe files named like Chrome installers, two tagged CoinMiner
RiskHigh if you opened one of the files: a hidden miner and possibly more. Low if you only saw the name
SymptomsA loud fan and high CPU while idle, a slower PC, a new startup entry or task, or a CoinMiner alert in Windows Security
How to get rid of itDisconnect, uninstall unknown programs, switch off startup entries, run a full scan and Microsoft Defender Offline, change passwords from another device, reset Windows if in doubt
Our check (10 October 2026)One plain request: status 200 and the barber shop title. A normal answer clears nothing; the rating comes from URLhaus
Running since / first seenFirst malware URL reported 21 September 2026, last on 24 September 2026. No registration date: no RDAP data returned
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
PlatformWindows, by the .exe ending; no source says other systems are affected
Detection namesMicrosoft Defender Antivirus names the miner family Trojan:Win32/CoinMiner (Microsoft Security Intelligence); we did not check these five files against it
NameRoyalcuts.co.uk
Evidence5 write-ups by security sites; details still limited
First seen21 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for royalcuts.co.uk, one plain request from our server, Microsoft Security Intelligence, Bitdefender, the WordPress.org guide to hacked sites and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow those pages and were not tried on a live infection.

What royalcuts.co.uk is, and what we know about it

royalcuts.co.uk is a web address, not a program on your PC. Its home page presents a barber shop in the UK, but the abuse.ch project URLhaus lists five Windows program files on it as malware downloads. Two are tagged CoinMiner, and three carry names that copy Google Chrome installers.

If you only saw the name in a warning, a firewall log or a blocked link, nothing was installed on your PC by that. If you downloaded and opened one of the .exe files, treat the Windows PC as infected and follow the plan on this page. If you own the site, it was most likely broken into, and the section for owners shows the order of the clean-up.

  1. 1

    What URLhaus lists

    Five file addresses at the root of royalcuts.co.uk. Four were added on 21 September 2026 within ten seconds of each other, at 13:01 UTC. The fifth, google.exe, was added on 24 September 2026 at 13:37 UTC. One reporter, adrian__luca, submitted all five.

  2. 2

    What the names say

    ChromeSetup.exe is the real name of Google's Chrome installer for Windows, and Chrome.exe is the name of the browser program itself. google.exe, Setup.exe and 3.exe are generic. Copying a famous name is the oldest trick for making a download look safe.

  3. 3

    What the tags say

    Chrome.exe and 3.exe carry the tag CoinMiner, which marks a program that mines cryptocurrency with your computer. The other three have no tag, so we cannot say which family they belong to. All five have the threat type malware_download.

  4. 4

    Where things stand now

    URLhaus marked all five files offline when we read the data on 10 October 2026. The home page still answered our plain request with the barber shop title. An offline file is gone from that address, but a PC that already ran it is not cleaned by that.

Kind of threat
A malware download address on what looks like a small business website; five Windows .exe files, two tagged CoinMiner
File names
ChromeSetup.exe, Chrome.exe, google.exe, Setup.exe, 3.exe, all at the site root
First and last report
21 September 2026 and 24 September 2026
Domain registration
Not available: our lookup returned no RDAP data for this .co.uk name, so we give no registration date
Systems at risk
Windows only, by the .exe ending; no source says Mac or phones are affected

What royalcuts.co.uk (CoinMiner, ChromeSetup.exe) does on an infected PC

What we checked on 10 October 2026, and what we could not

Our server sent one plain request to https://royalcuts.co.uk/ on 10 October 2026. There was no browser, no clicks and no screenshot. The server, which identifies itself as nginx, answered with status 200 and the page title Royal Cuts, Best Barber Shop in UK, Professional Haircut and Grooming Services. A normal-looking answer clears nothing.

Our check, 10 October 2026

  • The site answers normallyStatus 200 with a barber shop title and no redirect. That is what a hacked business site usually looks like: the owner's pages stay in place and the bad files sit next to them.
  • Why that is not a clean resultA plain request sees only the first answer of the home page. It does not run scripts, it does not see what other visitors may be shown, and it cannot tell whether more files were added after the reports.
  • Notification requestOur check found no mention of the browser notification feature in the page. This proves little, because no browser ran the page.
  • URLhaus listingFive malware download addresses on this domain, reported between 21 and 24 September 2026. All five were offline when we read the data.
  • The files themselvesWe did not download the five files and did not run them. We cannot tell you exactly what each one does beyond the tags.

Dangerous: do not download anything from it The rating comes from the five URLhaus reports, not from our check. Do not open any file from this address, and do not trust a Chrome download that does not come from google.com.

What happened to royalcuts.co.uk, in dates

The history we can document is four days long. The dates come from our copy of the URLhaus data and from our own request.

Table of five URLhaus entries for royalcuts.co.uk: google.exe, Chrome.exe, 3.exe, ChromeSetup.exe and Setup.exe, two tagged CoinMiner, all offline, added 21 and 24 September 2026
The five URLhaus entries for royalcuts.co.uk that we read on 10 October 2026, with the addresses defanged. Four were added in the same minute on 21 September 2026.
  1. 21 September 2026, 13:01 UTC

    Four files are reported in one minute

    Setup.exe, ChromeSetup.exe, 3.exe and Chrome.exe are added to URLhaus between 13:01:14 and 13:01:24. 3.exe and Chrome.exe get the tag CoinMiner. A batch like this suggests the reporter found the files together, for example in one sample or one folder listing.

  2. 24 September 2026, 13:37 UTC

    A fifth file appears

    google.exe is added by the same reporter, three days later and without a tag. A new file after the first reports suggests that whoever placed them still had access to the server on that day. That is our reading, not a fact from a source.

  3. By 10 October 2026

    All five are offline

    URLhaus shows every file as offline. Either the files were deleted, or the server stopped handing them out. We do not know who removed them.

  4. 10 October 2026

    Our plain request

    The home page answers with status 200 and the barber shop title. We give no registration date because our lookup returned no RDAP data for the name.

We did not read the URLhaus website pages themselves, because they ask for a browser check. The entries above come from the same data in our own copy of the feed, which the server gave us with this job.

What a CoinMiner is, and how fake Chrome installers have spread miners

Microsoft describes CoinMiner as a trojan that uses your PC to mine cryptocurrency for someone else. Bitdefender has reported a campaign in which hacked websites showed fake Chrome update messages that delivered a Monero miner. That campaign is not proven to be this site; it shows how such a trap works.

Four boxes showing a possible chain: a lure about a Chrome update, a download of ChromeSetup.exe or Chrome.exe from royalcuts.co.uk, the run, and a hidden miner using the CPU
A possible chain from the file names and tags, not observed on this site: the lure, the fake Chrome download, the run and the hidden miner.
Sources: Microsoft Security Intelligence and Bitdefender, read 10 October 2026. The Bitdefender rows describe an earlier campaign, not royalcuts.co.uk.
WhatWhat a source saysSource
Microsoft's nameTrojan:Win32/CoinMiner, a trojan that uses the PC to mine coins and sends the results to a server the attacker controlsMicrosoft Security Intelligence
How it hidesThe miner may run under a legitimate process name; Microsoft lists file names such as svchost.exe, minerd.exe, cg.exe and amd_gpu.exeMicrosoft Security Intelligence
How it arrivesIt can be bundled with other software such as cracks and key generators, and often drops supporting library filesMicrosoft Security Intelligence
The symptom Microsoft namesThe PC runs slower than usualMicrosoft Security Intelligence
A fake Chrome campaignHacked sites, mainly in Japan, South Korea and Spain, said Chrome's automatic update had failed and offered a manual update package. The download was a Monero minerBitdefender, April 2023
Why the trick worksThe fake message created no urgency, which may have made it more convincing; Chrome never needs a manual update downloadBitdefender, April 2023

A miner does not usually lock your files or show a ransom note. Its cost is quieter: electricity, heat, a fan that never stops, a slower PC and wear on the processor or graphics card. The bigger worry is the three untagged files. A program that calls itself Setup.exe can install anything, so a miner may not be the only thing on a PC that ran one.

The five files: what each name suggests, and what we do not know

The names are all we have for three of the files. The table says what each name copies and what is known about it.

From our copy of the URLhaus data, read 10 October 2026. We did not download or test the files.
FileWhat the name copiesWhat is known
ChromeSetup.exeGoogle's real Chrome installer for WindowsNo tag. The real installer only comes from google.com/chrome
Chrome.exeThe Chrome browser program itselfTagged CoinMiner by the reporter
google.exeA generic Google nameNo tag. Added three days after the others
Setup.exeAny program's installerNo tag. Could install anything
3.exeNothing; a numbered fileTagged CoinMiner by the reporter

If you have one of these names in your Downloads folder, check where it came from before you open it. Right-click the file, choose Properties and look at the Digital Signatures tab. A real Chrome installer is signed by Google LLC. A file with no signature, or a signature from another name, is not Chrome. Do not run it to find out.

What royalcuts.co.uk (CoinMiner, ChromeSetup.exe) can steal or download

What this can cost you

Reading the site name or seeing a block warning costs nothing. The risks below apply to a Windows PC where one of the five files was downloaded and opened.

  • High

    A hidden program that uses your hardware

    A miner runs the processor or graphics card hard for hours. That means a slower PC, more heat, a louder fan, a higher power bill and, on a laptop, a battery that drains fast.

  • High

    Something more than a miner

    Three files have no tag. An installer from an attacker can add other programs, such as a password stealer or a remote access tool. Until you know otherwise, treat saved passwords on that PC as exposed.

  • Medium

    A miner that comes back

    Miners often add a startup entry or a scheduled task so they start again after a restart. Deleting the file you downloaded does not remove those.

  • Medium

    Work PCs and shared networks

    On a work PC, tell your IT team at once. A miner on one machine can be a sign that others on the network were reached the same way.

  • Low

    Nothing, if you only saw the name

    A name in a warning, a firewall log or a blocked download is not an infection.

What you may notice, and what you may not

Miners are built to stay unseen, but they cannot hide the work they do. The signs below follow from Microsoft's description of CoinMiner and from how miners use a PC.

Sources: Microsoft Security Intelligence, read 10 October 2026, and our own reading where the row says so.
SignWhat it means
A loud fan or a hot PC while you do nothingSomething is using the processor or graphics card in the background
High CPU or GPU use in Task ManagerSort by CPU; a process near the top with a name you do not know, or a second svchost.exe with odd use, deserves a look
The PC is slower than usualThe symptom Microsoft names for CoinMiner
Use drops the moment you open Task ManagerSome miners pause when a monitoring tool opens; our reading of how they hide
A new entry in Startup apps or Task SchedulerHow a miner starts again after a restart
Windows Security names a CoinMinerProtection history may show Trojan:Win32/CoinMiner or a similar name
Nothing at allSome miners only run when the PC is idle or locked

How to check the PC for royalcuts.co.uk (CoinMiner, ChromeSetup.exe)

How people could end up running one of these files

We do not know how visitors reached these five files, and no source says. The routes below are common ways a download on a hacked business site reaches a PC, based on the names and on the Bitdefender report.

  1. 1

    A fake update message on a website

    A page you visit says Chrome failed to update and offers an update package. The download link points to a file such as ChromeSetup.exe on a site like this one. Real Chrome updates happen inside the browser.

  2. 2

    A link in an email or a chat message

    The link goes straight to an .exe on a real UK business domain, which passes a quick look. The message may promise a missing browser component or a document viewer.

  3. 3

    A search result or an ad for Chrome

    Someone looking for a Chrome download clicks a result that is not google.com. The file has the right name and the wrong source.

  4. 4

    A file dropped by another program

    A first piece of malware can download the next one from a hacked server. In that case you never clicked these addresses, and the first program is the real problem.

Check your Windows PC before you delete anything

Start with one question: did you open an .exe file that came from royalcuts.co.uk? If yes, follow the whole plan, because a quiet check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, stop using the PC for banking, email and work, and disconnect it from Wi-Fi and the network cable if you can.

  1. 1

    Look at Task Manager

    Press Ctrl + Shift + Esc, open the Processes tab and sort by CPU. Right-click any unknown process with high use and choose Open file location. Note the folder; a program in AppData or Temp with a system name is suspect.

  2. 2

    Check Windows Security

    Open Windows Security > Virus & threat protection > Protection history. Look for a CoinMiner name or any detection dated around the time you opened the file. On Windows 10 the app is also reached from Settings > Update & Security > Windows Security.

  3. 3

    Look at Startup apps

    Open Settings > Apps > Startup on Windows 11. On Windows 10 use the Startup tab in Task Manager. Note any entry you do not recognise.

  4. 4

    Look in Task Scheduler

    Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Note it; do not delete it yet.

  5. 5

    Look at Installed apps

    Open Settings > Apps > Installed apps and sort by install date. Anything installed on the day you opened the file that you did not choose is suspect.

How to remove royalcuts.co.uk (CoinMiner, ChromeSetup.exe)

How to remove royalcuts.co.uk

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to royalcuts.co.uk or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever royalcuts.co.uk installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Remove it: the order that works

Follow the steps in this order. A miner can come back from a startup entry or a task, so the offline scan comes after you have seen what is there, and a reset is the end of the plan when doubt remains.

Six numbered steps for a Windows PC that ran a file from royalcuts.co.uk: disconnect, look before deleting, uninstall, run Microsoft Defender Offline, change passwords, reset Windows
The order of actions on a Windows 11 PC that ran one of the five files, with the menu paths.
  1. 1

    Uninstall what you did not choose

    In Settings > Apps > Installed apps, select the three dots next to an unknown program and choose Uninstall. On Windows 10 use Settings > Apps > Apps & features. Then delete the downloaded .exe from your Downloads folder and empty the Recycle Bin.

  2. 2

    Switch off what starts with Windows

    In Settings > Apps > Startup, switch off the entries you noted. In Task Scheduler, right-click a task you noted and choose Disable. Disable first; delete after the scan agrees.

  3. 3

    Run a full scan

    Open Windows Security > Virus & threat protection > Scan options, choose Full scan and select Scan now. Microsoft's page for CoinMiner advises a full scan because it may find other hidden malware. Make sure Cloud-delivered protection is on under Virus & threat protection settings.

  4. 4

    Change passwords from another device

    Use a phone or a different computer. Change your email password first, then banking, then the rest, and turn on two-step sign-in. Do this because the untagged files could have taken more than processor time.

Scan from outside Windows: Microsoft Defender Offline

An offline scan starts before the normal Windows loads, so a program that hides inside Windows has a harder time hiding from it. Microsoft says it targets malware that tries to bypass the Windows shell.

  1. 1

    Prepare

    Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You need an administrator account and the Windows Recovery Environment turned on. To check, open Command Prompt as administrator and run reagentc /info; if it says Disabled, run reagentc /enable.

  2. 2

    Suspend BitLocker if it is on

    If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the scan.

  3. 3

    Start the scan

    Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now, then Scan, then Yes. Windows signs you out, runs the scan and starts again when it ends.

  4. 4

    Read the result

    Open Windows Security > Virus & threat protection > Protection history. Microsoft says the offline scan works on x64 Windows 11 and on Windows 10, not on ARM Windows, and that Microsoft Defender Antivirus must be the main antivirus.

  5. 5

    Reset if doubt remains

    If something was found and you are not sure everything went, back up your documents to an external disk and open Settings > System > Recovery > Reset this PC. Choose Remove everything after a real infection; do not restore old programs from the backup.

If you own or manage royalcuts.co.uk or another hacked site

Program files at the root of a barber shop website mean someone had write access to the server. We do not know which system the site runs on. The WordPress.org guide to hacked sites gives an order that fits most sites, and a clean-up that skips the way in will be undone.

Six numbered steps for a site owner: write down what you saw, call the host and change logins, scan your own PC, delete the files, replace core files, update and watch
The order of the clean-up for a business site that served malware, following the WordPress.org guide to hacked sites.
  1. 1

    Write down what you saw and take a copy

    WordPress.org advises a note of what you saw and when, and a snapshot of the site even while infected, before the clean-up. Here the notes start with the five .exe names and the dates 21 and 24 September 2026.

  2. 2

    Tell your host and lock every door

    Ask the host whether other sites on the account are hit and what their logs show for those dates. Change every access point for every user: SFTP or FTP, the hosting control panel, the database and the site admin. On WordPress, replace the secret keys in wp-config.php so every logged-in session ends.

  3. 3

    Scan your own computer first

    WordPress.org says attacks often start on the site owner's own machine, with trojans that capture FTP and admin logins. Run a full scan on every computer used to manage the site, with a second scanner if you can.

  4. 4

    Delete the files and look for more

    Remove the five .exe files and any other program file in the web root or uploads. Check .htaccess, which WordPress.org names as the file most often changed, and index.php, header.php, footer.php and functions.php. Remove any admin user you did not add.

  5. 5

    Replace core files from a clean copy

    On WordPress, download the same version you run and copy /wp-admin and /wp-includes over by SFTP. Do not use the reinstall button in the dashboard; WordPress.org says it only overwrites existing files, and hacks add new ones.

  6. 6

    Update, change passwords again and watch

    When the site is clean, update the system, themes and plugins, and change all passwords again. Register the site with Google Search Console and Bing Webmaster Tools, as WordPress.org suggests, to see blocklist warnings early. Ask URLhaus to review the entries once the files are gone.

If you use a Mac, an iPhone or an Android phone

The five files are Windows programs by their .exe ending. We found nothing that says they run on anything else.

Your deviceWhat we knowWhat to do
MacAn .exe file does not run on macOSNothing to remove for these files. Delete the download
iPhone or iPadNo source mentions itNothing to remove. Do not send the file to a Windows PC
AndroidAn .exe does not install on AndroidNothing to remove for these files; delete the download

After removal: passwords, accounts and prevention

A known business address is not a safe source of programs. This site probably belongs to an honest barber shop, and the files on it were still dangerous.

Do

  • Download Chrome only from google.com/chrome, and let it update itself under Settings > About Chrome.
  • Check the digital signature of an installer before you run it: right-click, Properties, Digital Signatures.
  • Keep Windows, your browser and Windows Security up to date, with real-time and cloud-delivered protection on.
  • Watch Task Manager when the fan runs loud for no reason.
  • Use an authenticator app for email and banking.

Don't

  • Do not install a browser update offered by a web page.
  • Do not trust a program because its name is ChromeSetup.exe or Setup.exe.
  • Do not download programs from a site whose business has nothing to do with software.
  • Do not rely on a quiet scan after you ran an unknown installer.

Questions about royalcuts.co.uk (CoinMiner, ChromeSetup.exe)

What is royalcuts.co.uk?

It is a website that presents a barber shop in the UK, and URLhaus lists it for handing out malware. Five Windows program files on it were reported between 21 and 24 September 2026, two of them tagged CoinMiner, and all five were offline when we read the data on 10 October 2026.

The home page still answered our plain request with the barber shop title. If you only saw the name in a warning, you are not infected by that.

Is royalcuts.co.uk a virus?

A website is not a virus, but this one is listed as a source of malware. URLhaus gives all five file addresses the threat type malware_download.

Two files are tagged CoinMiner, a kind of trojan that Microsoft detects as Trojan:Win32/CoinMiner. We did not download the files, so we cannot say exactly what the three untagged ones do. Do not open any file from this address.

Was the barber shop hacked, or is the site criminal?

We cannot prove either, but a hack is the likelier reading. A barber shop has no reason to host Chrome installers, the home page looks like a normal business site, and a fifth file appeared three days after the first four.

That pattern fits someone who had access to the server without the owner knowing. Treat this as our reading, not a finding.

I downloaded ChromeSetup.exe from this site. Am I infected?

Downloading alone does not run a program, but opening it does. If you only downloaded it, delete it and empty the Recycle Bin. If you opened it and approved the Windows prompt, follow the plan on this page:

  • check Task Manager
  • Startup apps and Task Scheduler
  • uninstall unknown programs
  • run a full scan and an offline scan
  • change passwords from another device

How do I know if a miner is running on my PC?

Open Task Manager with Ctrl, Shift and Esc and sort the Processes tab by CPU. A process with a name you do not know, or a system name such as svchost.exe in an odd folder, using a lot of CPU while you do nothing is a warning sign.

A fan that runs loud while the PC is idle and a slower PC point the same way. Windows Security may also list Trojan:Win32/CoinMiner in Protection history.

Can a CoinMiner steal my passwords?

A miner's job is to use your hardware, not to read your data, according to Microsoft's description. The risk here is that three of the five files have no tag, so we do not know what they install. Change your important passwords from another device if you ran any of them, starting with email.

How do I get a real Chrome installer?

Download Chrome only from google.com/chrome. Before you run the installer, right-click it, choose Properties and open the Digital Signatures tab: the real file is signed by Google LLC.

Once installed, Chrome updates itself; you can check under Settings and About Chrome. Bitdefender notes that Chrome never needs a manual update package from a web page.

Is it safe to visit royalcuts.co.uk now?

We cannot call it safe. The reported files were offline on 10 October 2026, and the home page looked normal to our plain request, but that request ran no scripts and saw only the first answer.

Whoever placed the files may still have access. There is no need to visit it, and you should not download anything from it.

Does this affect my Mac or my phone?

No source says so. The five files end in .exe, which is a Windows program format, and they do not run on macOS, iPhone or Android.

If you downloaded one on another device, delete it and do not move it to a Windows PC. If you typed a password on a page linked from this site, change that password anyway.

Will Fortect remove royalcuts.co.uk?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For royalcuts.co.uk, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove 0807.st: archives tagged SmartLoader and Stealc, and what to do if you ran one on Windows

0807.st is a web address that URLhaus lists for three files reported on 10 October 2026: two RAR archives and one DAT file, all tagged SmartLoader and Stealc. SmartLoader is a Windows loader and Stealc is a stealer...TRHigh riskUgnius Kiguolis ·

Remove cablewireltd.site: a Windows VIP Keylogger host serving Crypted.ps1 PowerShell files, and what to do if one ran

cablewireltd.site is a web address that URLhaus lists nine times in September 2026 for malware files: seven PowerShell scripts named Crypted.ps1 and two JavaScript loaders, three of them tagged VIPKeylogger, a...TRHigh riskUgnius Kiguolis ·

Remove AIGPUSniffer: what it is, is it a virus, and how to remove it

AIGPUSniffer.exe is a small Adobe helper that Illustrator and InDesign start for a second or two to test your graphics card before they turn on GPU acceleration. It is not a virus and not part of ASUS software: you...FLMedium riskUgnius Kiguolis ·

Remove TrojanDownloader:PowerShell/Falsip.A

TrojanDownloader:PowerShell/Falsip.A is designed to download malware on your computer TrojanDownloader:PowerShell/Falsip.A is a detection of a Trojan Horse by Microsoft Windows Defender. Programs with Trojan-like features are capable of multipleTrojansHigh riskAlice Woods ·

Questions and experiences: royalcuts.co.uk (CoinMiner, ChromeSetup.exe)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,452 members already hereReading, writing, commenting and voting. 0 verified · 177 joined this year