Home Malware Programs Worms Torvel.b

Torvel.b

Posted: March 28, 2006

Torvel.b, also known as Torvil, is an Internet worm that spreads by e-mail in letters with infected attachments, through file sharing networks, via ICQ messages and in IRC chat channels.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 remainder.exe
    2 schost.exe
    3 spool[X].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedOneLevelDeeperHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServiceHostHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exe[filename]
Loading...