Severity scale  
  (70/100)

Rendul. How to Remove? (Uninstall Guide)

removal by - -   | Type: Viruses
12
Rendul is a dangerous macro virus that infects Microsoft Word documents. Once executed, Rendul installs itself to the system and creates several infected text documents. Then it runs a payload. The virus lowers Microsoft Word security settings, disables the Windows Firewall, the Task Manager and the Registry Editor, alters system configuration. It also changes mouse settings and deletes all executables, images, text and spreadsheet documents, archives and some other files it finds in the root of the main hard disk, main Windows folder and default system directory. Rendul also deletes vital components of Microsoft Excel and Microsoft Powerpoint. The virus may display certain messages and hide the taskbar. Rendul properties:
• Hides from the user
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Rendul. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Rendul. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2006-01-26 04:51)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2006-01-26 04:51)
Hitman Pro
Webroot SecureAnywhere AntiVirus

Rendul manual removal

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCloseKey=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFavoritesMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar=HJx02
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=HJx03
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\Lendur
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Lendur
Delete files:
exemple.doc, girls.doc, information.doc, joke.doc, list.doc, music.doc, news.doc
Delete directories:
C:\Windows\Hzjl
C:\Windows\Sgba
C:\Windows\Texts
C:\Windows\Vnbz
Misc:
Exact file location:
exemple.doc - C:\Windows\Texts
girls.doc - C:\Windows\Vnbz
information.doc - C:\My Documents
joke.doc - C:\Windows\Sgba
list.doc - C:\My Shared Folder
music.doc - C:\Windows\Application Data
news.doc - C:\Windows\Hzjl

Information updated:

Comments on Rendul

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)