Remove Rendul. Description and removal instructions

 
Title: Rendul

Type: Viruses
Severity scale:Rendul severity is 70  (70 / 100)
 
Rendul is a dangerous macro virus that infects Microsoft Word documents. Once executed, Rendul installs itself to the system and creates several infected text documents. Then it runs a payload. The virus lowers Microsoft Word security settings, disables the Windows Firewall, the Task Manager and the Registry Editor, alters system configuration. It also changes mouse settings and deletes all executables, images, text and spreadsheet documents, archives and some other files it finds in the root of the main hard disk, main Windows folder and default system directory. Rendul also deletes vital components of Microsoft Excel and Microsoft Powerpoint. The virus may display certain messages and hide the taskbar.


Rendul properties:
• Hides from the user
• Stays resident in background

Automatic Rendul removal:

remover for Rendul

Rendul manual removal:

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCloseKey=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFavoritesMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar=HJx02
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=HJx03
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\Lendur
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Lendur
Delete files:
exemple.doc, girls.doc, information.doc, joke.doc, list.doc, music.doc, news.doc
Delete directories:
C:\Windows\Hzjl
C:\Windows\Sgba
C:\Windows\Texts
C:\Windows\Vnbz
Misc:
Exact file location:
exemple.doc - C:\Windows\Texts
girls.doc - C:\Windows\Vnbz
information.doc - C:\My Documents
joke.doc - C:\Windows\Sgba
list.doc - C:\My Shared Folder
music.doc - C:\Windows\Application Data
news.doc - C:\Windows\Hzjl

Other programs to remove Rendul:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 26/01/06
Information updated: 26/01/06

Additional resources related to Rendul:

Attention: If you know or you have a website or page about Rendul removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Rendul parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: