Click on screenshot to zoom
Danger level 8
Type: Worms
Common infection symptoms:
  • Connects to the internet without permission
  • Installs itself without permissions
  • Slow Computer
  • Slow internet connection

Worm.Thraegisa.A

Worm.Thraegisa.A is a malicious worm which comes disguised as an Internet chat application installation package. First released in 4 September 2009, Worm.Thraegisa.A will delete Interent cookies and inform its developers of the new infection, all without the user’s knowledge.

This worm is installed under false pretenses and will be drop the following file into the system32 directory of the system:

%windir%\system32\mmá.exe

After the worm firmly roots itself in the system, it will run this batch script:

\delcookes.bat

The above dropped script will delete all cookies from the Internet’s temporary files folder, and when Internet cookies are deleted PC users will find that they need to enter all of their login credentials when logging into their normal websites again. Worm.Thraegisa.A will use this opportunity to steal usernames, passwords and other sensitive information of the user.

As a further attack against the system, Worm.Thraegisa.A will contact its developers through a remote server named katomka.net.ru, to receive register the infection and receive further instructions from its developers. Worm.Thraegisa.A will also make the system more susceptible for other malware infections to infiltrate the system.

There is only one way to regain control of your PC and protect your privacy and security if you are infected with this threat, and that is to completely get rid of Worm.Thraegisa.A for good. This can more easily and safely be achieved by using a powerful security tool which will also offer adequate protection against similar future attacks and threats.

Download Spyware Removal Tool to Remove* Worm.Thraegisa.A
  • Quick & tested solution for Worm.Thraegisa.A removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Worm.Thraegisa.A

Files associated with Worm.Thraegisa.A infection:

syscron.exe
youma1.dll
0.7414822779750169.exe
uaufqma.exe
~TM4A.tmp
~TM19.tmp
youma1.dll
Windows-Update-KB237643-x86-ENU.exe
userinit.exe
uaufqma.exe
syscron.exe
o.dat
ntuser_mssec.exe
jgmkw.exe
e.exe
bin_2024-9_b8.exe
baka10.exe
AviraAutoLoader.exe
Alcohol-120-retail-1-9-8-7612-Ru-XCV-edition_3.exe
445094406604767.exe
0.7414822779750169.exe
Microsoft Startup Controller.exe
~TM4A.tmp
o.dat
bin_2024-9_b8.exe
ntuser_mssec.exe
baka10.exe
Alcohol-120-retail-1-9-8-7612-Ru-XCV-edition_3.exe
Windows-Update-KB237643-x86-ENU.exe
jgmkw.exe
e.exe
~TM19.tmp
Microsoft Startup Controller.exe
userinit.exe
AviraAutoLoader.exe
445094406604767.exe

Worm.Thraegisa.A DLL's to remove:

youma1.dll

Worm.Thraegisa.A processes to kill:

Windows-Update-KB237643-x86-ENU.exe
445094406604767.exe
syscron.exe
bin_2024-9_b8.exe
Alcohol-120-retail-1-9-8-7612-Ru-XCV-edition_3.exe
jgmkw.exe
uaufqma.exe
0.7414822779750169.exe
baka10.exe
e.exe
userinit.exe
AviraAutoLoader.exe
ntuser_mssec.exe
Windows-Update-KB237643-x86-ENU.exe
userinit.exe
uaufqma.exe
syscron.exe
ntuser_mssec.exe
jgmkw.exe
e.exe
bin_2024-9_b8.exe
baka10.exe
AviraAutoLoader.exe
Alcohol-120-retail-1-9-8-7612-Ru-XCV-edition_3.exe
445094406604767.exe
0.7414822779750169.exe
Microsoft Startup Controller.exe
Microsoft Startup Controller.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.