I have been running kaspersky build 6.0.3.837 for a while and the perfromance has been real good. However, we observed on a few PCs that Kaspersky was getting off-loaded at startup and the PC perfromance had become slow. Efforts to manually load kaspersky from Start>Programs>Kaspersky did not yield any results. Searching the PCs revealed that few folders namely Picture, Documents and Photo were created on the drive(s). Further SystemIL2 was added as a link in the Start Menu. Nothing worked to remove these links/folders and kaspersky would just NOT RUN
I searched the blogs for SYSTEMIL2 and it emerged that these anomalies are due to a virus - SYSTEMIL. EXE (AVG and Kaspersky fail to detect this virus). Enter this description on the kaspersky site and the results are ZERO. According to the blogs this virus was first found on 04 Apr 2008 in Inda and the common file size is about 300-400 KB. Further the virus files have no vendor, product or version information specified in the file header. The virus has been the subject of the following behaviour: -
- Added a Registry auto start to load Program on Boot up.
- Created asa process on disk
- Added as a link in the Start Menu
- Terminated as a Process
- Executed as a process
- Disables Access to task Manager
The virus uses the names SYSTEMIL.EXE; SYSTEMIL2.EXE, DOCUMENTS.EXE, PHOTOS.EXE, PICTURES.EXE
I have even tried booting the windows machine using linux and deleting the infected files (whatever i felt were suspicious) and also disabling System Restore, but once the machine is booted up in Windows the situation is the same and kaspersky gets off-loaded everytime.
Need urgent help as there is danger of the infection spreading to other machines.
