Online Tech Support Blog

Archive for December 2008

Here I am providing you the virus description and detail for
How to remove SYSTEMIL.EXE:

You can yourself successfully remove SYSTEMIL.EXE after using the instructions:

1. Search and Delete any Folder looks like Documents, Pictures (having size of 276KB) and showing suspicious Properties info.

Note: Dont try to open them as it will activate the Virus.

2. Update the virus definitions. Reboot computer in SafeMode.

3. Stop SYSTEMIL.EXE virus files process if you can find on the task list; But most of times it disable your Task manager (and fails to open it)

4. Locate SYSTEMIL.EXE virus files and right-click on it to delete virus files program. Or you can try to remove it from Add Remove Control panel, and if not find there then do not worry about this.

5. Delete/Modify any values added to the registry related with SYSTEMIL.EXE, Exit registry editor and restart the computer (for this you can take help of Hijackthis Tool which can offcourse search for this virus and show the Registery entries affected by it).

6.Clean/delete all infected file(s):SYSTEMIL.EXE,or rename SYSTEMIL.EXE virus files;

7.Please delete all your IE temp files, prefetch, junk files & Folders.

8. Run a Checkdisk command for all hard disk partition which are affected by it.

9.Use antivirus program run a whole scan,(However AVG, Kaspersky fails to detect this virus). You can use the free online scaner (different famous antivirus online scanner)on the right site of home;

Following is the information of the virus file SYSTEMIL.EXE

SYSTEMIL.EXE:
The filename SYSTEMIL.EXE first found on Apr 4 2008 in INDIA.
The filename SYSTEMIL.EXE refers to have versions of an executable program.
The most common file size is 276KB (225,280 bytes).
These files have no vendor, product or version information specified in the file header.

SYSTEMIL.EXE has been seen to perform the following behavior(s):

  • Modifies Windows Security Policies to restrict/expand User Privileges on the machine
  • Disables Access to the Windows Registry Editior
  • Disables Access to the Task Manager built into Windows
  • Adds a Registry Key (RUN) to auto start Programs on system start up
  • This process creates other processes on disk
  • Adds a Link in the Start Menu
  • Creates system tray popups, messages, errors and security warnings
  • The Process is packed and/or encrypted using a software packing process
  • Added as a Registry auto start to load Program on Boot up
  • SYSTEMIL.EXE can also use the following file names:
    SYSTEMIL2.EXE
    DOCUMENTS.EXE
    PHOTOS.EXE

    SYSTEMIL.EXE has been the subject of the following behavior:

  • Added as a Registry auto start to load Program on Boot up
    Has code inserted into its Virtual Memory space by other programs

  • Created as a process on disk
  • Added as a Link in the Start Menu
  • Terminated as a Process
  • Executed as a Process
  • New cook at my Home: Darling Pari ..

    WordPress is now working fine..

    At last I have added a Video!

    I wish to all of You

    Merry Christmas and a Very Happy New Year

    Best of Luck & Regards
    Puneet Jain


    December 2008
    M T W T F S S
    1234567
    891011121314
    15161718192021
    22232425262728
    293031