D2 Remover (d2 virus removal tool)
Posted by Daniel - 3,323 Views
Well, it’s a virus removal program. From the title you know it will removes the d2 virus from your system. d2 virus is also known as dkernel, lExplorer, decoil daun and dEngines. Below is the information about the virus activities inside an infected system:
Creates lExplore.exe (not iExplore) in c:\windows. The file size is 28 KB.
Creates a folder named I75-D2 in C:\Windows\System32 (WinXP) or in C:\Windows\System (Win98). The folder contains 3 files:
DKERNEL.EXE - 154KB
INZ.D - 1KB
The content of the INZ.D will be like this:
start=yes
MyName=decoil daun (d2)
MyPath=C:\WINDOWS\System32\I75-D2\dkernel.exe
ComeAt=Jam 18: 54 –25/01/2006
Level=Moderate (can cange level of virus)
Winamp=C:\PROGRAM FILES\WINAMP\winamp.exe
Tampungan=C:\WINDOWS\System32\I75-D2\dTemp
Author=FM nibO
Duplicates the file DKERNEL.EXE to some other name ended with .DOC extension in the target folder and the duplicated file’s Icon is not always the same.
Creates these registry entry
"Shell"="Explorer.exe lExplorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dKernel"="C:\\WINDOWS\\System32\\I75-D2\\dkernel.exe"
"lExplorer"="C:\\WINDOWS\\lExplorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe lExplorer.exe"
If you take a look on the Task Manager, lExplorer process and dkernel process will be visible. This virus make the infected system run slower than usual. At 12 PM it will display an annoying graphic, take over the system and force you to stop your works. d2 is also renames winamp.exe into winamp_d2.exe and creates a copy of itself as winamp.exe. Same process also applied to winamp.ini.
This program was built with Visual Basic 6, had been tested on the coder’s machine and worked well, but it may not produces the same result on your system. The coder will take no responsibilities of any kind. Please use it at your own risk.
Download D2-Remover (8 KB)
The following posts are programmatically considered as related to the current post by YARPP Plugin:
Hi, my name is Daniel Nugraha, a single male live on an island called Java, Indonesia. This is the place for me to share my interest in computer programming.
-
Get my Full Feed Here
Popular Entries
- Passing arguments to your VB.NET console application
- Microsoft Excel Import External Data Problem: When Microsoft Query doesn’t recognize some of your parameters
- Resize Image or Crop Image with Joe Lencioni’s Smart Image Resizer, WordPress Setup
- How to Get User Input and allowing more than 256 characters to be entered on .NET Console Application
- ASCII To PDU Converter (Convert ASCII to PDU and vice versa)
- ConsoleProgressBar - Simple Progress Bar Function for your VB.Net Console Application
- An example: Using CPort Delphi Component to read data from your cellphone
- Runtime-Form-Creation. Automatically creating child forms in a Delphi MDI application with a component array
- CPort Component (Serial port interface component for Delphi)
- SmartImageResizer Plugin, WordPress plugin based on Joe Lencioni’s Smart Image Resizer













