Reatle manual removal:
Kill processes:
ccapp.exe, windows.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\win=C:\WINNT\System32\windows.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\win=C:\WINNT\System32\windows.exe
Delete files:ccapp.exe, windows.exe
Misc:The worm keeps its files in the default system directory C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32. Names of infected e-mail attachments may vary.
Reatle modifies these registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
To enable essential Windows functions change the value of above keys to "0".
To enable essential Windows functions change the value of following keys to "1":
HKEY_CURRENT_USER\Software\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\UpdatesDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=0
Post Comment: