Torcho.com: what it is and how to remove it
Torcho.com virus is a browser hijacker which also spreads as Torcho Web. Its primary mission is to inject its malicious plug-ins and irrelevant toolbars into users' computers.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like Torcho.com usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove Torcho.com yourself 3 steps, about 9 minutes, no software needed.
Start the steps
Torcho.com: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Torcho.com |
| Type | Information stealer |
| Symptoms | An unknown program in Installed apps |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 3 more facts
| Evidence | One write-up by a security site; details still limited |
|---|---|
| First seen | 6 April 2016 |
| Facts checked | 7 October 2026 |
What Torcho.com does
From our report of Apr 2016 · not reviewed since
The important information you should know about Torcho.com virus
Torcho.com virus is a browser hijacker which also spreads as Torcho Web.
Its primary mission is to inject its malicious plug-ins and irrelevant toolbars into users' computers. After doing this, it tends to install diverse "helper objects" which are responsible for keeping the hijacker on your system and preventing you from deleting it. That's why security experts have been actively saying that you need to use anti-spyware software to remove Torcho.com from the system.
Another negative aspect of this malevolent plug-in is that it tends to redirect you to highly questionable websites. It seeks to promote predetermined websites and earn the money from their advertising. However, visiting such web pages can be dangerous as you can never know which of them are infected with serious viruses might hijack your computer.
Additionally, you should keep in mind, that Torcho.com redirect may end up on a webpage trying to steal your personal information. You may also notice reappearing pop-up ads on your browser and even slow downs. They are especially bothersome while trying to browse the web.
Furthermore, you should be aware that the majority of browser hijackers are designed to spy on users' online activity. However, their aim is to collect non-personal information and transfer it to third parties. Since Torcho.com is also a browser hijacker, remember that it might spy on you as well.
Considering these effects and further severe damage this potentially unwanted program might inflict, it is crucial to remove Torcho.com virus as soon as possible. But before proceeding to that step, you should find out more about the hijacker and its distribution ways in order to protect your computer from future malware hijacks.

From our report of Apr 2016 · not reviewed since
How can this search engine hijack my computer?
As it has already been mentioned in the previous section, torcho.com is spread along with freeware and shareware, such as video streaming software, download managers, or PDF creators.
It works in the same manner as Websearch.allsearches.info, start.mysearchs.com, Findpages.net and many other browser hijackers that sneak into user's computer silently and initiates suspicious activities. To avoid Torcho.com hijack in the future, you have to be more careful not only when downloading but also when installing free programs.
Avoid Quick or Basic installation mode because it may hide check boxes including various additional installers and install various adwares and PUPs automatically. Instead, choose Advanced or Custom installation option that discloses all available check boxes and allows to make changes. Later on, opt out of such suggestions as to set torcho.com as a default search engine or homepage.
Besides, you may see programs, such as add-ons, plug-ins, toolbars or extensions marked as default and we highly recommend deselecting them as well. If you have already installed torcho.com plug-in, take your time and perform Torcho.com removal steps given on the next page.
How to remove Torcho.com
How to remove Torcho.com and secure your accounts
A stealer usually takes what it wants within minutes and may already be gone.
The scan comes first, then the accounts.
Step 1: Scan the PC, then run the offline scan
A scan finds the parts of Torcho.com that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 2: Change passwords from another device and sign out other sessions
Torcho.com can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after Torcho.com, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Delete from macOS
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
From our report of Apr 2016 · not reviewed since
How to remove torcho.com virus from my computer?
Having in mind that this browser hijacker spreads in one pack with various browser helper objects and similar components, you may notice its reappearance right after rebooting your computer.
Of course, if you don't want to keep this misleading search engine on the system and don't want to install additional software, you can also opt for manual removal option. However, you should still think about reliable anti-spyware or anti-virus, which could help you avoid browser hijackers and similar unwanted programs.
Questions about Torcho.com
Is Torcho.com a virus?
Most programs that appear the way Torcho.com did are not viruses in the strict sense. They are potentially unwanted programs:
- real software that arrives bundled with other downloads and then shows offers
- changes browser settings
- starts with Windows
Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.
Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.
Torcho.com will not uninstall. What can I do?
First restart the PC and try again, because the program may have been running and locked its own files. If the uninstaller is missing or fails, start Windows in Safe Mode, where most third-party programs do not start, and remove Torcho.com from Installed apps there.
If it still refuses, delete its startup entry and its scheduled task, restart, and try once more. A program that actively prevents removal is behaving like malware, so finish with a Microsoft Defender offline scan. Avoid third-party uninstallers offered on search ads; several of them are unwanted programs themselves.
I have two-step verification. Am I protected?
Partly. Two-step verification stops an attacker who has only your password. But stealers also take session cookies, which represent a login that already passed the second step.
With a cookie, an attacker can open the account until the session expires or you sign out of all devices. So, after an infection, end all sessions as well as changing passwords.
Passkeys and hardware security keys resist phishing better, but a stolen session still needs to be ended. Review trusted devices and remove any you do not recognise.
Should I report Torcho.com to the police?
Yes, if money was lost or accounts were misused. A police report gives you a reference number that banks, exchanges and insurers often ask for. Include when you first saw torcho.com in the list of installed apps, the accounts and amounts involved, any wallet addresses or messages, and what you downloaded before it started.
In the US, use the FBI's IC3; in the UK, Report Fraud; in other countries, the national police cybercrime unit. Reporting rarely brings money back quickly, but it helps link cases and is often required for refunds.
Can I change my passwords on the infected PC?
Not while the spyware may still be running. A keylogger or stealer would capture the new passwords too. Use a phone or another computer that was never infected, or wait until the Microsoft Defender offline scan on this PC comes back clean.
Start with your main e-mail account, because it can reset every other password, then banking and payment accounts. When you return to this PC, sign in to the browser again only after the scans are clean and you have ended old sessions.
Which stealer caused Torcho.com?
It has not been identified. People who reported Torcho.com saw torcho.com in the list of installed apps, but without the file that caused it, nobody can tell which stealer family was involved. Several families are sold to many criminals at once, and they produce the same result.
If you still have the program or archive you downloaded before this started, keep it unopened; a scan or an upload to a multi-engine scanner can reveal the family. Whatever it was, the steps are the same:
- secure accounts from another device
- scan the PC offline
- remove the download that carried it
Do I need to reinstall Windows to get rid of Torcho.com?
Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see torcho.com in the list of installed apps again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.
Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.
Nothing has happened yet. Do I still need to change passwords?
Yes. Stolen logs are often sorted and sold before anyone uses them, so the quiet period can last weeks.
The criminals look for the most valuable accounts first, usually crypto, banking and e-mail, and may only reach yours later. Changing passwords and ending sessions now makes the copy worthless whenever it is used.
It takes an evening. Start with e-mail, then money, then everything else saved in the browser, and turn on two-step verification as you go. Watch for login alerts over the following months.
The scan found nothing. Am I safe from Torcho.com?
The PC may well be clean, but your data may not be. Many stealers run for a minute, send what they find and delete themselves, so a clean scan after torcho.com in the list of installed apps is common. What matters now is the accounts:
- change passwords from another device
- sign out of all sessions
- turn on two-step verification
Move crypto to a new wallet. Watch for sign-in alerts and password-reset e-mails for a few weeks. If anything suspicious starts with Windows again, scan offline once more or reset the PC.
Will Fortect remove Torcho.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Torcho.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)