Remove Reatle. Description and removal instructions

 
Title: Reatle
Also known as: Lebreat
Type: Worms
Severity scale:Reatle severity is 71  (71 / 100)
 
Reatle, also known as Lebreat, is a dangerous multifunctional Internet worm that distributes itself by e-mail in messages with infected attachments. It scans the system for e-mail addresses and uses own mail engine to spread. The parasite also can spread by exploiting other computers running Windows with unpatched security flaws. Reatle runs on every system startup and secretly works in background. It turns off Windows Firewall, disables essential Windows security features and system utilities, runs hidden FTP server. Reatle downloads and installs another dangerous Internet worm called Rants, attempts to attack the official web site of well-known security company.


Reatle properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Reatle removal:

remover for Reatle

Reatle manual removal:

Kill processes:
ccapp.exe, windows.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\win=C:\WINNT\System32\windows.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Symantec=C:\WINNT\System32\ccapp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\win=C:\WINNT\System32\windows.exe
Delete files:
ccapp.exe, windows.exe
Misc:
The worm keeps its files in the default system directory C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32. Names of infected e-mail attachments may vary.

Reatle modifies these registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=1
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\NoAutoUpdate=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsWindowsUpdate\AU\AUOptions=1
To enable essential Windows functions change the value of above keys to "0".

To enable essential Windows functions change the value of following keys to "1":
HKEY_CURRENT_USER\Software\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Security Center\UpdatesDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=0

Other programs to remove Reatle:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 18/07/05
Information updated: 18/07/05

Additional resources related to Reatle:

Attention: If you know or you have a website or page about Reatle removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Reatle parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites: