D2 Remover (d2 virus removal tool)

Posted by Daniel - 635 Views

averagecoder_d2remover.gifWell, it’s a virus removal program. From the title you know it will removes the d2 virus from your system. d2 virus is also known as dkernel, lExplorer, decoil daun and dEngines. Below is the information about the virus activities inside an infected system:

Creates lExplore.exe (not iExplore) in c:\windows. The file size is 28 KB.

Creates a folder named I75-D2 in C:\Windows\System32 (WinXP) or in C:\Windows\System (Win98). The folder contains 3 files:

D2.MIX - 39KB
DKERNEL.EXE - 154KB
INZ.D - 1KB

The content of the INZ.D will be like this:

[d2]
start=yes
MyName=decoil daun (d2)
MyPath=C:\WINDOWS\System32\I75-D2\dkernel.exe
ComeAt=Jam 18: 5425/01/2006
Level=Moderate (can cange level of virus)
Winamp=C:\PROGRAM FILES\WINAMP\winamp.exe
Tampungan=C:\WINDOWS\System32\I75-D2\dTemp
Author=FM nibO

Duplicates the file DKERNEL.EXE to some other name ended with .DOC extension in the target folder and the duplicated file’s Icon is not always the same.

Creates these registry entry

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe lExplorer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dKernel"="C:\\WINDOWS\\System32\\I75-D2\\dkernel.exe"
"lExplorer"="C:\\WINDOWS\\lExplorer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe lExplorer.exe"

If you take a look on the Task Manager, lExplorer process and dkernel process will be visible. This virus make the infected system run slower than usual. At 12 PM it will display an annoying graphic, take over the system and force you to stop your works. d2 is also renames winamp.exe into winamp_d2.exe and creates a copy of itself as winamp.exe. Same process also applied to winamp.ini.

This program was built with Visual Basic 6, had been tested on the coder’s machine and worked well, but it may not produces the same result on your system. The coder will take no responsibilities of any kind. Please use it at your own risk.

Download D2-Remover (8 KB)

__________________________

The following posts are programmatically considered as related to the current post by YARPP Plugin:

  1. PDUSpy (A good tool to deal with GSM SMS PDU)
  2. TCPView for Windows, Tool to check TCP and UDP Connections on your system

Related posts brought to you by Yet Another Related Posts Plugin.

share this article

Digg del.icio.us Netscape StumbleUpon Yahoo! MyWeb reddit Furl Magnolia Newsvine Technorati SlashDot Blinklist Simpy Google
This post as PDFPosted in: Tested Software - January 2008


Leave a Reply


Options for your comment:





Get my Full Feed Here or you can subscribe to one of my category based feeds below:
Coffee Break

Latest Blog Entries

Categories

Neighbours and Friends

Comments - Thanks Guys :)

  • Therese Lachance: Hi, Any idea how to have ContuttoPDF fetch the correct page language?
  • Marlena Albu: Super Blog, Dude! I am constantly on the watch for new and interesting sites and postings about audio equipment… which is what...
  • tresloukadu: yo how did u fixed when the tags shows <? and it shows < “& l t ; ” ?? please send me an email.
  • Sean: This is a great piece of code and thanks for adding the updates. Sean’s last blog post: Not All Text Message Marketing Is Created...
  • rodhy: Thank for your code, it very usefull for me. best regard.