Reatle manual removal:
Kill processes:
ccapp.exe, windows.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\win=C:\WINNT\System32\windows.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\win=C:\WINNT\System32\windows.exe
Delete files:ccapp.exe, windows.exe
Misc:The worm keeps its files in the default system directory C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32. Names of infected e-mail attachments may vary.
Reatle modifies these registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
To enable essential Windows functions change the value of above keys to "0".
To enable essential Windows functions change the value of following keys to "1":
HKEY_CURRENT_USER\Software\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\UpdatesDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=0
Post Comment:
Attention: Use this form only if you have additional information about Reatle parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.