Torvel manual removal:
Kill processes:
smss[X].exe, spool[X].exe, svchost.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Service Host=%Windir%\spool[X].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Service Host=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe spool[X].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\OneLevelDeeper
Delete files:smss[X].exe, spool[X].exe, svchost.exe
Delete directories:C:\Windows\mstorvil.{21EC2020-3AEA-1069-A2DD-08002B30309D}
C:\Winnt\mstorvil.{21EC2020-3AEA-1069-A2DD-08002B30309D}
Misc:[X] are two random characters.
Torvel files can be found in C:\Windows or C:\Winnt folder.
Typical names of infected e-mail attachments:
document.pif, her_details.pif, funny_guy.pif, movie0045.pif, thank_you.pif, torvil.pif, wicker_screensaver.scr, q723523_w9x_wxp_x86_en.exe
Post Comment: