How to remove sysdate.exe

September 23rd, 2009

Has your PC ever been infected with the Sysdate.exe virus? This virus creates a folder named Recycler in the drive where your operating system is installed, and uses that folder as a beachhead to carry out a host of malicious activities. It is pretty easy to understand whether your PC has gotten infected with Sysdate.exe. Simply look for the following telltale signs:

  1. There is a folder named Recycler in the drive where the operating system is installed. Inside that folder there is another folder named something like S-1-5-21-8324555943-4443154761-431384085-6428. Inside this folder, the sysdate.exe file can be seen. You will, however, have to go to Tools > Folder Options > View tab and uncheck the option named “Hide Protected operating System Files” before you can see the executable.
  2. There is an entry in Windows® Registry named Taskman. This entry comes back no matter how many times you delete it.
  3. The executable is at times seen running in the background. However, it is easy to kill it via the Task Manager. It may also appear in the Startup folder.

If you are sure that your PC has gotten infected with Sysdate.exe virus, don’t panic. Removing this virus is not that difficult. Here is how you can remove it:

  1. Click on Start button and click on Run. In the box named Open. Type cmd and press Enter key.
  2. The command prompt will open. In the prompt, type: attrib C:\Recycler –r-h-s. Hit Enter key.
  3. Now, type: attrib C:\Recycler\ S-1-5-21-8324555943-4443154761-431384085-6428 –r –h –s. Hit Enter key.
  4. You will see the icon of the folder named Recycler get altered to that of a normal folder. It is now a regular folder and you will be able to see its contents by opening it.
  5. There will be two files inside the folder named S-1-5-21-8324555943-4443154761-431384085-6428, named Autorun.inf and Sysdate.exe. None of these files can be deleted as of now.
  6. Now, right click on Taskbar and choose the option Task Manager. Using Task Manager, kill the process Explorer.exe.
  7. The explorer will get shut down, but you will see the Task Manager running. Go to File > New Task. Click on the option Browse.
  8. Find the Recycler folder using this Browse function. Select the files Autorun.inf and Sysdate.exe files and press Shift + Delete to remove the files for good. Delete the folder Recycler also.
  9. Type Explorer.exe in the box provided for new task. The explorer will now run again.
  10. Click on Start button, and then on Run. In the box named Open, type Regedit to open the Registry Editor. Navigate to the key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon. Delete the key named Taskman visible in the right hand pane.
  11. Refresh Regedit to see whether the Taskman key comes back. Chances are that it will not be back again.

Now simply reboot your PC and it should be free from Sysdate.exe virus.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • StumbleUpon
  • Twitter

Posted in Viruses

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.