Remove Torvel. Description and removal instructions

 
Title: Torvel

Type: Worms
Severity scale:Torvel severity is 54  (54 / 100)
 
Torvel is an Internet worm that spreads through file sharing networks and by e-mail in messages with infected attachments. The parasite sends malicious letters to addresses it finds in the system. It doesn't depend on a particular mail client, as it contacts local mail server directly. Torvel creates infected files with meaningful names and drops them into shared folders of Kazaa, ed2k-it and Xolox peer-to-peer applications. This is done in order to trick other users into downloading and executing such files. The worm runs on every Windows startup. It doesn't carry any destructive payload.


Torvel properties:
• Hides from the user
• Stays resident in background

Automatic Torvel removal:

remover for Torvel

Torvel manual removal:

Kill processes:
smss[X].exe, spool[X].exe, svchost.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Service Host=%Windir%\spool[X].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Service Host=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe spool[X].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\OneLevelDeeper
Delete files:
smss[X].exe, spool[X].exe, svchost.exe
Delete directories:
C:\Windows\mstorvil.{21EC2020-3AEA-1069-A2DD-08002B30309D}
C:\Winnt\mstorvil.{21EC2020-3AEA-1069-A2DD-08002B30309D}
Misc:
[X] are two random characters.

Torvel files can be found in C:\Windows or C:\Winnt folder.

Typical names of infected e-mail attachments:
document.pif, her_details.pif, funny_guy.pif, movie0045.pif, thank_you.pif, torvil.pif, wicker_screensaver.scr, q723523_w9x_wxp_x86_en.exe

Other programs to remove Torvel:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 21/07/04
Information updated: 01/10/05

Additional resources related to Torvel:

Attention: If you know or you have a website or page about Torvel removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Torvel parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: