www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media component. That points to a hacked site, not a malicious business.

The files do nothing on their own; a script already running on a PC fetches them. If you only visited the site or saw the name in a log, nothing is proven. If a script on your PC fetched them, change your passwords from another device, then scan and clean or reset Windows.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with a script or attachment that downloads PowerShell files from www.beinke-aufzuege.de.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of four URLhaus entries for www.beinke-aufzuege.de: PowerShell files named secured_stub.ps1, millssecured_stub.ps1, pwsecured_stub.ps1 and mlsecured_stub.ps1 in one folder under components/com_media, two online, all tagged Formbook
The four URLhaus entries for www.beinke-aufzuege.de that we read on 6 October 2026. Two were still marked online. Our own check was a plain request to the home page, so this table of reports, not a screenshot of the site, is the main evidence.

Www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site): summary

TypeA hacked website: URLhaus lists four PowerShell loader files tagged Formbook (an information stealer for Windows) in a planted folder
RiskHigh if a script on your PC fetched the files: form data, passwords, keystrokes and screenshots may be taken. Low if you only visited the site or saw the name
SymptomsOften none. A script window after opening an attachment, unknown startup tasks, or aspnet_compiler.exe running with no reason are the signs in the reports
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove startup entries, reset Windows if unsure. Site owner: remove the folder and close the way in
Our check (6 October 2026)One plain request to the home page: HTTP 200 from nginx. A working site clears nothing; the rating comes from URLhaus
Running since / first seenDomain age not known (no public RDAP record); first files reported 5 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo Microsoft name is known for these files, because we did not open them. For FormBook in general Microsoft uses Trojan:Win32/Formbook
NameWww.beinke-aufzuege.de
Evidence4 write-ups by security sites; details still limited
First seen5 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against the URLhaus data for www.beinke-aufzuege.de held in our database, an RDAP lookup that found no public record, one plain request of our own from our server (no browser, no clicks), and published material from Microsoft, Malpedia, SOC Prime, Sucuri, CSO and the FTC.

We did not download the files, did not access the server and infected no PC; the steps follow Microsoft's pages and Sucuri's guide and were not tried on this case.

What www.beinke-aufzuege.de is, and what we know about it

www.beinke-aufzuege.de is not a program on your PC. It is the address of a German website whose name reads as Beinke lifts (Aufzüge is German for lifts or elevators). URLhaus, the abuse.ch malware tracker, lists four PowerShell scripts on it, all tagged Formbook, a password stealer for Windows.

The files sit in a folder with random names inside the site's own media component. That pattern usually means someone planted them on a hacked site, not that the business itself spreads malware. We could not confirm who runs the site, and we found no public write-up of this case.

  1. 1

    What URLhaus lists

    Four file addresses, all in /components/com_media/fkqabmp/ntxqre1/edfwcgi/. Two were added on 5 October 2026 a minute apart (mlsecured_stub.ps1 and pwsecured_stub.ps1) and two on 6 October 2026 (secured_stub.ps1 at 07:18 UTC and millssecured_stub.ps1 at 08:32 UTC). Every entry carries the threat label malware_download, the reporter abuse_ch and the tags Formbook, powershell and ps1.

  2. 2

    Why it looks like a hacked site

    components/com_media is the folder of the media manager in Joomla, a widely used website system. A real Joomla site has no folders called fkqabmp, ntxqre1 or edfwcgi there. Random nested folders inside a normal system folder are a common way to hide planted files. This is our reading of the path; we have not seen the server, and the owner may know more.

  3. 3

    What the file names say

    A stub, in this trade, is the small piece that unpacks and starts the real malware. The prefixes ml, pw and mills look like labels for different buyers or campaigns. Files called secured_stub.ps1 also appear on other servers in URLhaus this week, for example on aksiyononline.best, where they are tagged MassLogger. That shows a shared naming habit, not a proven link.

  4. 4

    What we could not confirm

    We did not download the files, so we cannot tell you what each script does, which FormBook build it leads to or where it sends data. We do not know how the files got onto the site, who the owner is, or which email or attachment makes a victim's PC ask for them.

  5. 5

    What this means for you

    If you visited the company's pages to look at lifts, that visit is not what URLhaus reports, and the pages themselves are not tagged. The risk is for a Windows PC where a script already ran and fetched one of these PowerShell files. If you run or look after this website, the files need to come down and the way in needs to be closed.

Kind of threat
A real website hosting four PowerShell loader files tagged Formbook, an information stealer for Windows
Where the files are
hxxps://www.beinke-aufzuege[.]de/components/com_media/fkqabmp/ntxqre1/edfwcgi/*secured_stub.ps1
Domain record
Our RDAP lookup found no public record for beinke-aufzuege.de, which is usual for .de names; we have no registration date
URLhaus entries
4 file addresses added 5 and 6 October 2026; 2 online, 2 offline when we read the data
Home page
Answered our plain request with HTTP 200 from an nginx server; no page title was returned
Platform
Windows. PowerShell stubs and FormBook are Windows threats; nothing we read says Mac, iPhone or Android are affected

What www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site) does on an infected PC

What we checked on 6 October 2026, and what we could not

Our server sent one plain request to the home page on 6 October 2026. It was not a browser visit: nothing was clicked, no page scripts ran and no screenshot was taken. The site answered normally. That clears nothing, because the reported files sit deep in a subfolder and a hacked site usually keeps working while it hosts malware.

Our check, 6 October 2026

  • The home page answeredHTTP status 200, no redirect, server header nginx. No page title came back in our plain request. A working home page is expected on a hacked site: the intruder wants the owner to notice nothing.
  • Notification requestThe page text did not mention the browser notification API. Scripts that only run in a browser would not show in a plain request.
  • URLhaus listingFour PowerShell files tagged Formbook in a random folder under components/com_media; secured_stub.ps1 and millssecured_stub.ps1 still online in our copy of the data on 6 October 2026.
  • Who runs the siteNot confirmed. The public RDAP service returned no record for the .de name, and a web search did not show a company page we could tie to it.
  • The files themselvesWe did not request or open any of the listed scripts. We cannot tell you what they contain beyond the names and tags.

Dangerous: do not fetch the listed files The rating is about the four files URLhaus lists, not about the company. Until the owner removes them, treat any request to that folder as a malware download and do not run anything that makes one.

What happened on www.beinke-aufzuege.de, as far as the reports show

We only see the end of the story: the dates when the files were reported. When the site was broken into is not known. Times are UTC.

  1. Unknown

    The site is opened up

    Someone gets the ability to write files under components/com_media. Common ways in for Joomla sites are an outdated core or extension, a stolen admin or hosting password, or another hacked site on the same hosting account. We do not know which applies here.

  2. 5 October 2026, 09:29 UTC

    The first two files are reported

    abuse.ch adds mlsecured_stub.ps1 and, a minute later, pwsecured_stub.ps1. Both are tagged Formbook, powershell and ps1. Both are offline by the time we read the data.

  3. 6 October 2026, 07:18 UTC

    secured_stub.ps1 appears

    A third file with the plain name secured_stub.ps1 is added in the same folder. It is still online when we read the data.

  4. 6 October 2026, 08:32 UTC

    millssecured_stub.ps1 appears

    A fourth file is added, also online. The folder keeps being used across two days, so whoever placed the files still had access on 6 October.

    Table of the four URLhaus entries for www.beinke-aufzuege.de with dates, file names, online status and tags
    All four URLhaus entries for www.beinke-aufzuege.de on 6 October 2026: one folder, four file names, all tagged Formbook.
  5. 6 October 2026

    Our check

    Our plain request to the home page gets HTTP 200 from nginx. The site still works as a website.

What the pattern suggests, and what it does not: new files keep arriving in the same folder while older ones go offline, which looks like an intruder who still has write access and replaces files as they are reported. That is our reading of the dates, not something a report says, and it is the main reason the owner should not only delete the files.

Why a company website ends up hosting malware

Criminals like real business sites as hosting: the address has a history, is not on block lists and is trusted by mail and web filters more than a domain registered last week. The owner is usually a victim too.

  1. 1

    Old software

    Sucuri's Joomla guide calls outdated software one of the leading causes of infection. The media manager itself has had flaws: in 2013 CSO reported a Joomla bug, fixed in 3.1.5 and 2.5.14, that let attackers upload files the media manager should have refused, and that was used to host malware and phishing. We have no sign that this old flaw was used here.

  2. 2

    Extensions

    Joomla sites run third party extensions, and each one is another piece of code that needs updates. Sucuri says to update the core and all extensions right after a cleanup.

  3. 3

    Stolen logins

    An administrator, FTP or hosting password taken by a stealer (FormBook among them) lets someone upload files without any bug at all. Sucuri says to reset all user passwords and to check for admin accounts that should not exist.

  4. 4

    Backdoors left behind

    Sucuri warns that intruders leave several hidden ways back in, and that all backdoors must be closed for a cleanup to hold. Deleting the four .ps1 files alone is unlikely to be enough.

How a PowerShell stub on a hacked site leads to FormBook

A .ps1 file on a website cannot hurt you by sitting there. It works only when a script already running on a PC downloads it and runs it with PowerShell. We did not see these files; this is how vendors describe FormBook and XLoader chains.

Five steps: an email lure, a first JScript or VBS file, a PowerShell stub fetched from a hacked company site, encrypted stages decoded in memory, and FormBook injected into a trusted Windows program
The chain in five steps as vendors describe it for FormBook and XLoader. Step 3 is the role www.beinke-aufzuege.de plays; the first step for these files is not known.
  1. 1

    An email with a business attachment

    FormBook is mostly spread by malicious email that looks like invoices, shipping documents or quotes. Malpedia lists many such campaigns with trojanized documents.

  2. 2

    A first script runs

    SOC Prime (7 September 2026) describes an XLoader chain that starts with a JScript file from a phishing email. Opening it is the moment the PC is lost.

  3. 3

    PowerShell fetches the stub

    In that chain the next stages are AES encrypted PowerShell scripts. A file like secured_stub.ps1 on a trusted website fits this step: a download from a real company address raises fewer alarms.

  4. 4

    Stages are decoded in memory

    XOR encrypted payloads and a .NET injector follow, loaded in memory rather than saved as ordinary programs.

  5. 5

    FormBook runs inside a trusted program

    SOC Prime names process hollowing into aspnet_compiler.exe, a genuine Windows program. Malpedia notes FormBook's own RunPE crypter for the same purpose. In Task Manager the stealer wears a Microsoft name.

What FormBook is

FormBook is a Windows information stealer that has been sold to criminals for years and is still among the most common. XLoader is its newer descendant. URLhaus tags these files Formbook; it does not say which version.

Sources: Malpedia, SOC Prime and Microsoft, read 6 October 2026.
QuestionWhat the sources saySource
What is it?A form grabber and keylogger; it takes what you type into web forms and other programsMalpedia
Other namesFirst called Babushka Crypter; XLoader is tracked as its successorMalpedia; SOC Prime
How is it sold?As a service to many buyers, so many unrelated campaigns use itSOC Prime; Malpedia
What does it take?Form data, keystrokes, clipboard and screenshots; the XLoader chain adds browser credentials and mail dataMalpedia; SOC Prime
How does it hide?Its own crypter, process hollowing into trusted programs such as aspnet_compiler.exe, and encrypted stagesMalpedia; SOC Prime
What does Microsoft call it?Trojan:Win32/Formbook; Microsoft says Defender detects and removes it and advises a full scanMicrosoft Security Intelligence
Which build is this site's?Not known. URLhaus gives only the tag; we did not open the filesNot available

What www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site) can steal or download

What FormBook takes from a Windows PC

FormBook does not need anyone watching: once it runs, it collects and sends on its own. The list comes from Malpedia and the XLoader chain write-up; a given build may do less or more.

Reported as collected

  • Everything typed into web forms
  • Every key you type
  • Clipboard contents
  • Screenshots
  • Browser saved logins
  • Email data and logins
Sources: Malpedia, SOC Prime (7 September 2026) and Microsoft, read 6 October 2026.
DataDetailSource
FormsLogins, card numbers and other data typed into web forms, grabbed before the page encrypts themMalpedia
KeystrokesRecorded in the backgroundMalpedia
Clipboard and screenCopied text and screenshotsMalpedia
Browsers and mailSaved browser credentials and mail dataSOC Prime
ControlContact with a command server that can send further instructionsSOC Prime; Microsoft

What this can cost you

Visiting the company's pages is not the risk. The risks below apply to a Windows PC where a script fetched one of these files and FormBook then ran, and, separately, to the site owner.

  • High

    Passwords and accounts

    Form grabbing and keylogging catch logins as you type them, including new passwords set on the infected PC.

  • High

    Payments

    Card numbers typed into shop or bank forms are form data. Treat any card used on the PC since the infection as exposed.

  • High

    For the site owner: an open door

    Files keep appearing in the folder, so someone still has write access. Mail providers and filters may block the domain while it hosts malware, and visitors and customers may be warned away.

  • Medium

    Work mail and further fraud

    Stolen mail logins are often used to send the next wave of invoice emails to the victim's contacts.

  • Low

    Nothing, if you only saw the name or visited the home page

    A name in a log, or a normal visit to the pages, is not an infection.

What you may notice, and what you may not

FormBook is built to stay quiet. The signs below come from the sources and from what they imply; most victims notice nothing until an account is misused.

SignWhat the reports show
A script or PowerShell window that flashed after opening an attachmentThe chains start with JScript or VBS and move to PowerShell
A Microsoft program running when it should notaspnet_compiler.exe is named as a hiding place; one running on a home PC with no reason is worth a look
A Defender detectionMicrosoft's name is Trojan:Win32/Formbook; Microsoft lists slow performance, changed files and crashes as possible effects
Accounts acting strangelyNew sign ins, password reset emails, mail rules or messages you did not send
For the owner: odd folders or files on the serverRandom folder names under components/com_media, or .ps1 files anywhere in a web folder
Nothing at allMemory only stages are the point of the chain

How to check the PC for www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site)

How a person ends up asking for these files

Nobody types a path like this by hand. The request comes from a script on the PC, so the real question is how that script got there. We cannot say for these files; the routes below are the ones vendors report for FormBook.

  1. 1

    An invoice, order or shipping email

    Fake business documents are the classic FormBook lure. The attachment is often an archive with a script that looks like a PDF when file endings are hidden.

  2. 2

    A link to a real looking site

    Because the files sit on a genuine company domain, a link or download from it passes a quick look at the address bar or the mail filter.

  3. 3

    A document that asks you to allow content

    Malpedia lists campaigns with trojanized documents. Clicking to enable content or open an embedded file starts the chain.

Check your PC before you delete anything

Did something on this PC request a file under /components/com_media/ on www.beinke-aufzuege.de, or did you open an unexpected attachment or script in the last days? A normal visit to the company's pages is not the question. If you saw the address in a firewall or DNS log, look at the full path if your log shows it, and check the device that asked.

While you check, stop using the PC for banking, email, work or shopping. Use a phone or another computer for anything that needs a password.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable on that PC.

  2. 2

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for Trojan:Win32/Formbook, any detection with PowerShell or a script in its name, or anything blocked at the time of the first contact.

  3. 3

    Look at what starts with Windows

    Open Settings > Apps > Startup and look for names you did not install, then open Task Scheduler and look for tasks that run PowerShell, wscript or a program from a user folder. Write down what you find; do not delete yet.

  4. 4

    Look for trusted programs that should not be running

    Open Task Manager and look for aspnet_compiler.exe or a PowerShell process running with no reason. Right click and choose Open file location. Their presence is not proof, and their absence does not clear the PC.

  5. 5

    Check your accounts from another device

    Look at sign in activity and mail forwarding rules of your email, bank and work accounts. This tells you more than a file check.

  6. 6

    A scan helps, but it does not clear the PC

    Microsoft says Defender detects and removes FormBook and advises a full scan with current definitions. Treat a clean result as one data point. We did not infect a PC, so the order of the plan is our judgement from Microsoft's pages, not a tested result.

How to remove www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site)

How to remove www.beinke-aufzuege.de

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like www.beinke-aufzuege.de add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after www.beinke-aufzuege.de, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of www.beinke-aufzuege.de that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Www.beinke-aufzuege.de can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you run or look after www.beinke-aufzuege.de

This part is for the owner, the web agency or the host. The files are still being added, so removing them is the first step, not the last. The steps follow Sucuri's Joomla cleanup guide; we have not seen the server.

  1. 1

    Back up the current state, then take the folder down

    Copy the site and the database for evidence, then remove /components/com_media/fkqabmp/ and everything below it. Sucuri says to back up before any change.

  2. 2

    Compare the site with clean Joomla files

    Sucuri says to compare the installation against a clean copy of the same Joomla version and to check recently modified files. Look in images, media, templates, tmp and the web root as well.

  3. 3

    Hunt for backdoors

    Search PHP files for functions such as eval, base64_decode and gzinflate, which Sucuri names as common in backdoors, and check the database for injected content.

  4. 4

    Check every account

    Remove administrator accounts you do not recognise, then reset all Joomla, FTP, SSH, database and hosting passwords and turn on two factor sign in. Do this from a PC you trust; a stealer on the admin's own PC may be how the site was opened.

  5. 5

    Update Joomla and every extension

    Install the current Joomla release and current versions of all extensions and templates; remove the ones you do not use.

  6. 6

    Ask for the listing to be reviewed

    When the files are gone, URLhaus marks them offline. Sucuri also advises requesting a review in Google Search Console if the site was flagged. Watch the folder for a few weeks: new files mean a way in is still open.

If you use a Mac, an iPhone or an Android phone

PowerShell stubs and FormBook are Windows threats. We found nothing that says these files affect anything else.

Your deviceWhat we knowWhat to do
MacPowerShell stubs and the FormBook builds in these reports target WindowsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes these files on iOSNothing to remove. Change passwords you used on an affected Windows PC
AndroidNo source mentions itNothing to remove for this threat

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything typed into it while FormBook ran. Do the account steps from another device first.

Five steps in order: disconnect the PC, change passwords from another device, run a Defender Offline scan, then for the site owner take the files down and update, reset passwords and request a review
The order of actions for a PC that fetched the files, and for the owner of the website. Steps follow Microsoft's pages and Sucuri's Joomla guide; we did not test them here.
  1. 1

    Change passwords from a clean device

    Start with email, then bank, work, shopping and cloud accounts. Anything typed on the PC while FormBook ran is known.

  2. 2

    Sign out other sessions and turn on two step sign in

    The FTC says to sign out of all devices and to turn on two factor authentication, and to check recovery details and forwarding rules.

  3. 3

    Call your bank about cards used on the PC

    Form data includes card numbers typed into payment pages. Ask for any such card to be blocked and replaced.

  4. 4

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Antivirus (offline scan) and select Scan now. The PC restarts and scans before Windows loads; results appear in Protection history.

  5. 5

    If you are not sure, reset Windows

    Microsoft puts the reset at Settings > System > Recovery > Reset this PC. Keep my files removes apps and settings; Remove everything wipes the PC. Back up documents first and have your BitLocker recovery key ready.

  6. 6

    Restore only documents by hand

    Copy back documents and photos, not programs or scripts.

  7. 7

    Watch your accounts for weeks

    Turn on alerts. The FTC says to report stolen personal information at IdentityTheft.gov. If a work account was on the PC, tell your IT team the same day.

Keep a PC, and a website, out of this kind of chain

For a PC the chain starts with an attachment; for a website it starts with old software or a stolen login.

Do

  • Treat an unexpected invoice, order or shipping notice with an attachment as an attack until the sender confirms it another way.
  • Show file endings in File Explorer so a .js or .vbs file posing as a PDF is visible.
  • Keep Windows and Microsoft Defender updated.
  • Site owners: keep Joomla, extensions and templates current and remove unused ones.
  • Site owners: use two factor sign in for the admin panel and the hosting account.
  • Use a password manager and two step sign in for your own accounts.

Don't

  • Do not trust a download only because it comes from a real company domain.
  • Do not open archives or scripts you did not expect.
  • Do not change your passwords on the PC you suspect.
  • Site owners: do not only delete the reported files; find the way in.
  • Do not take a working home page or a clean scan as proof that all is well.

Questions about www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site)

What is www.beinke-aufzuege.de?

It is the address of a German website whose name reads as Beinke lifts. URLhaus, the malware tracker run by abuse.ch, lists four PowerShell files on it, all tagged Formbook, added on 5 and 6 October 2026.

They sit in random folders inside the Joomla media component, which points to a hacked site. We could not confirm who runs it and did not download the files.

Is www.beinke-aufzuege.de safe to visit?

The pages themselves are not what URLhaus lists, and our plain request to the home page got a normal answer. But a site that hosts planted malware may hold more than was reported, and the intruder still seemed to have access on 6 October.

Until the owner cleans it, avoid downloading anything from it and never run a file or script that came from it.

Is the company spreading malware on purpose?

Nothing we read suggests that. Files in random folders such as fkqabmp/ntxqre1/edfwcgi inside a normal Joomla folder are typical of a break in.

Criminals use real business sites because their addresses are trusted more than new domains. The owner is most likely a victim and may not know yet. Telling them helps.

What is FormBook?

FormBook is an information stealer for Windows, sold to criminals as a service for years.

Malpedia describes it as a form grabber and keylogger that also takes clipboard contents and screenshots; its successor XLoader adds browser credentials and mail data in recent chains. Microsoft calls it Trojan:Win32/Formbook. It usually arrives through invoice or shipping emails.

I saw www.beinke-aufzuege.de in my firewall or DNS log. Am I infected?

Not necessarily. A visit to the company's pages would also show the name. What matters is whether the device asked for a file under /components/com_media/.

If your log shows full paths, check for that. If not, and the device opened an unexpected attachment or script recently, disconnect it and run the checks on this page, then change passwords from another device.

How do I remove FormBook from Windows?

Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, check startup apps and Task Scheduler for entries that run PowerShell or scripts, and remove what you can tie to the malware.

If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test this on an infected PC.

I run this website. What should I do?

Back up the current state for evidence, remove the planted folder under components/com_media, compare the site with clean Joomla files, look for backdoors and unknown admin accounts, reset every password from a trusted PC with two factor sign in, and update Joomla and all extensions.

Then watch the folder: new files mean the way in is still open. Sucuri's Joomla guide covers each step.

Does this affect Mac, iPhone or Android?

We found nothing that says so. PowerShell stubs and FormBook are Windows threats, and every source we read describes Windows. On a Mac, iPhone or Android phone there is nothing to remove for this threat, but change any password that was typed on an affected Windows PC, and do it from the clean device.

Will resetting Windows remove it, and are my accounts safe afterwards?

A reset with Remove everything wipes the scripts and the stealer, without having to find every piece. It does not undo what was already sent.

Passwords and card numbers typed while FormBook ran stay exposed until you change them from another device, sign out other sessions and turn on two step sign in. Restore documents by hand, not a full system image.

Will Fortect remove www.beinke-aufzuege.de?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For www.beinke-aufzuege.de, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove Beast

Beast - a malicious tool that can give access to your computer to cybercriminals Beast is just another virus that belongs to a broad family of Remote Administration Tools (ifTrojansHigh riskGabriel E. Hall ·

Questions and experiences: www.beinke-aufzuege.de (FormBook PowerShell stubs on a hacked site)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year