W32.Quaters.A: what it is and how to remove it
W32.Quaters.A is a computer worm designed for Windows operating systems. It seems like this parasite was mainly created to spread a message about allegedly incorrectly spent taxpayer money in the United Kingdom.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If W32.Quaters.A keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove W32.Quaters.A yourself 4 steps, about 12 minutes, no software needed.
Start the steps
W32.Quaters.A: summary
| Distribution | Microsoft Outlook self-mail, IRC networks |
|---|---|
| Name | W32.Quaters.A |
| Type | Computer worm, malware |
| Function | Uses the list of Outlook addresses to email itself to potential victims; launches DDoS attacks against particular targets |
| Detection names | No Microsoft detection name is known |
| Damage | Not recorded in the old report |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 4 more facts
| Symptoms | An unknown program in Installed apps |
|---|---|
| Evidence | One write-up by a security site; details still limited |
| First seen | 30 April 2021 |
| Facts checked | 6 October 2026 |
How W32.Quaters.A spreads and got on your PC
From our report of Apr 2021 · not reviewed since
W32.Quaters.A is a computer worm designed for Windows operating systems.
It seems like this parasite was mainly created to spread a message about allegedly incorrectly spent taxpayer money in the United Kingdom. The worm infects various files on the hot system and sends out the Distributed Denial of Service (DDoS) attacks against the www.number-10.gov.uk website.
This mass-mailing worm spreads itself through Microsoft Outlook and IRC networks. The infected computer checks the list of the emails within the Outlook app and sends the malicious spam to those addresses. There are several different (randomly chosen) subject lines that are used in the phishing email, for example:
Clipped to the email message which talks about allegedly suspended account or similar fake issues, is what it seems to be a DOC file. However, it is poorly obfuscated, as the extension .EXE is still visible at the end. Executables in emails are particularly dangerous as they are likely to download and install a malicious payload on the system automatically.
Possibly the most notorious aspect of this worm is that it targeted Tony Blair's website back in 2003. Those infected would see a suspicious popup message titled "Infected by the WIN32.SORT-IT-OUT-BLAIR Virus!" that would display a message directed to Tony Blair. Apparently, the attackers were not happy that the money is spent "on immigrants" rather than the NHS.
If you see such messages on your screen, delete the W32.Quaters.A virus with or another reputable anti-malware. To fix system damage automatically, use .
- Email Account Information.
- Account Billing Information.
- Your Account is on hold.
- ORDER CONFIRMATION:
- Your Account has been suspended, etc.

How to remove W32.Quaters.A
Clean the USB drives as well as the PC, or the worm comes back the next time a stick is plugged in.
Step 1: Clean the USB drives
W32.Quaters.A spreads through USB sticks, so every drive used in this PC is suspect.
In File Explorer, switch on hidden items, delete the shortcuts that look like your folders, and run
attrib -h -r -s /s /d E:\*.*in Command Prompt (with your drive's letter) to restore the hidden ones.Right-click the drive and choose Scan with Microsoft Defender. Turn off AutoPlay for removable drives in Settings > Bluetooth & devices > AutoPlay (Windows 11) or Devices > AutoPlay (Windows 10).
Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 2: Remove it from startup
Whatever W32.Quaters.A installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to W32.Quaters.A or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
After removal and prevention
Protect the files you restore
Restore only after the scans are clean and the PC no longer shows W32.Quaters.A in the list of installed apps; otherwise the restored copies can be damaged again.
Then build a backup that survives the next infection:
- one copy in the cloud with version history
- one on an external drive that is disconnected between backups
- the working copy on the PC
Version history matters because a backup that syncs damaged files overwrites the good ones.
How to do this with the tools built into Windows: the 3-2-1 backup rule on Windows.
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about W32.Quaters.A
What is W32.Quaters.A and why is it on my PC?
W32.Quaters.A is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.
Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need W32.Quaters.A, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.
W32.Quaters.A will not uninstall. What can I do?
First restart the PC and try again, because the program may have been running and locked its own files. If the uninstaller is missing or fails, start Windows in Safe Mode, where most third-party programs do not start, and remove W32.Quaters.A from Installed apps there.
If it still refuses, delete its startup entry and its scheduled task, restart, and try once more. A program that actively prevents removal is behaving like malware, so finish with a Microsoft Defender offline scan. Avoid third-party uninstallers offered on search ads; several of them are unwanted programs themselves.
How did W32.Quaters.A get on my computer?
The route for W32.Quaters.A is not documented yet. Malware that shows W32.Quaters.A in the list of installed apps usually arrives with something you ran yourself:
- a cracked program or game cheat
- a free tool from a mirror site
- a fake installer found through a search ad
- a file on a USB drive
Some infections are dropped later by a loader that was already on the PC. To find your source, sort Installed apps by install date and look at the Downloads folder for the days before the sign appeared. Remove that item as well; otherwise the same infection may come back after the clean-up.
Are my files on the USB drive lost?
Usually not. USB worms hide the real folders and put shortcuts with the same names in their place. After scanning the drive on a cleaned PC, open it in File Explorer, choose View > Show > Hidden items, and your folders appear, faded.
Clear their Hidden attribute in Properties, delete the shortcuts and any unknown script files, then scan once more. Copy important files to a safe place before using the drive again. If anything is missing, a data recovery tool run from the cleaned PC may still find it.
What should I do about my accounts?
Treat them as possibly exposed while W32.Quaters.A was active. The reports only describe W32.Quaters.A in the list of installed apps, but there is no analysis yet that rules out data theft, and many infections like this one come bundled with a stealer.
After the clean-up, use a phone or another computer to change your e-mail password first, then banking, shopping and social accounts. End all active sessions in each account's security page and turn on two-step verification with an authenticator app. If you use crypto wallets on the PC, move the funds to a new wallet created on a clean device.
Should I reset my PC because of W32.Quaters.A?
Only if the signs point to deeper access. Reset when you see W32.Quaters.A in the list of installed apps again after removal, when Windows Security cannot start or update, when remote access tools you did not install keep appearing, or when you simply cannot trust the PC any more.
Otherwise, the plan in this guide plus an offline scan is enough. If you do reset, choose Remove everything and Cloud download for a fresh copy of Windows, restore only documents and photos, and reinstall programs from their official sites. Change important passwords from the clean system afterwards.
Should I scan my other computers too?
It is a good idea, even for malware that does not spread by itself. The same download, USB stick or loader may have been used on other PCs in the household, and shared folders can carry files between them.
Run a full scan followed by the Microsoft Defender offline scan on each Windows PC that shared drives or files with the infected one. Do not copy programs or installers from the infected PC until it is clean, and change Wi-Fi and router passwords if they were saved on it.
Should I worry about W32.Quaters.A?
It deserves attention, not panic. The reported sign, W32.Quaters.A in the list of installed apps, shows that code from someone else is running on the PC, and such code rarely arrives alone. It is not known yet whether W32.Quaters.A itself steals data, but the same sources that spread it often add a password stealer.
Remove it with the steps in this guide, run an offline scan, and change your important passwords from another device once the PC is clean. If the sign returns after removal, a reset of Windows is the more reliable fix. Most people who follow the plan carefully do not need to go that far.
The PC is still slow after removing W32.Quaters.A. What now?
Restart the PC first; some changes only take effect after a reboot. Then open Task Manager and check the Processes and Startup apps tabs for anything unfamiliar using the processor, disk or network. If something remains, run the Microsoft Defender offline scan once more.
Slowness can also come from a second infection installed alongside W32.Quaters.A, or from programs that were damaged during the clean-up. If nothing helps, back up your files and reset Windows. Copy only documents and photos before a reset, and scan the copies.
Will Fortect remove W32.Quaters.A?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For W32.Quaters.A, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)
- Microsoft Learn: How Microsoft names malware (read October 6, 2026)