Trojan

How to remove “Trojan:Win32/Sapade”?

Malware Removal

The Trojan:Win32/Sapade is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sapade virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:Win32/Sapade?


File Info:

name: B802F8E33628783A7ACE.mlw
path: /opt/CAPEv2/storage/binaries/1992196b2b4cde357ecf21b8720ee14f142b33162b929381db1e6ec1f036faa2
crc32: 331014FD
md5: b802f8e33628783a7ace76f88e659015
sha1: c64500765457ac32211753406410b3adf931c716
sha256: 1992196b2b4cde357ecf21b8720ee14f142b33162b929381db1e6ec1f036faa2
sha512: 2fa20157c27b6d81d7162274b2fbee6994564e296a6845bde3aa46b4b35aced303719aed8cb4bf49599bf76481c91b1d54e213045e36a2ce76c48a1f4949e0d9
ssdeep: 3072:QWuo48+vMlp8cp3qalccmSGzGdbeVIPvl5RAoQDMDkP:Koec8aacmhGs45NoP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160F38E3634D1C8FBE28344304DB1AB76FAF9E4360F239B4363595B9D6E3C945862B192
sha3_384: 8933a9acd5189185e4532517c3fef1269dca306cee543baefbdedb9f1e2ee9c2fc13a9d28852d06f376cc1b85d369949
ep_bytes: 558bec6aff6878d04100681ca4400064
timestamp: 2009-12-07 01:41:11

Version Info:

0: [No Data]

Trojan:Win32/Sapade also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.StartPage.1
FireEyeGeneric.mg.b802f8e33628783a
CAT-QuickHealTrojan.GenericPMF.S29052259
SkyhighBehavesLike.Win32.StartPage.cm
ALYacGen:Variant.StartPage.1
Cylanceunsafe
ZillyaTrojan.StartPage.Win32.10487
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00116d1a1 )
AlibabaTrojan:Win32/StartPage.af6de934
K7GWTrojan ( 00116d1a1 )
ArcabitTrojan.StartPage.1
BitDefenderThetaGen:NN.ZexaF.36680.jqX@ay@wHVn
VirITTrojan.Win32.Startpage.FZW
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/StartPage.NSE
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Startpage-1739
KasperskyTrojan.Win32.StartPage.fjp
BitDefenderGen:Variant.StartPage.1
NANO-AntivirusTrojan.Win32.StartPage.bxosz
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.StartPage.abg
TACHYONTrojan/W32.StartPage.159749.E
EmsisoftGen:Variant.StartPage.1 (B)
F-SecureTrojan.TR/StartPage.NX
DrWebTrojan.StartPage.45922
VIPREGen:Variant.StartPage.1
TrendMicroTROJ_STRTPGE.SMR
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/StartPage.cnc
WebrootTrojan:Win32/Sapade
VaristW32/Agent.EE.gen!Eldorado
AviraTR/StartPage.NX
Antiy-AVLTrojan/Win32.StartPage
KingsoftWin32.Troj.YmdfiveT.xb.151557
XcitiumTrojWare.Win32.StartPage.~JH1@1r3tbm
MicrosoftTrojan:Win32/Sapade
ViRobotTrojan.Win32.A.StartPage.159749.A
ZoneAlarmTrojan.Win32.StartPage.fjp
GDataGen:Variant.StartPage.1
GoogleDetected
AhnLab-V3Win-Trojan/StartPage2.Gen
McAfeeStartPage-LN
MAXmalware (ai score=100)
VBA32Trojan.StartPage
MalwarebytesStartPage.Trojan.Hijacker.DDS
PandaTrj/Startpage.DFN
TrendMicro-HouseCallTROJ_STRTPGE.SMR
RisingTrojan.Win32.StartPage.nuv (CLASSIC)
YandexTrojan.GenAsa!8mogu9suvUc
IkarusTrojan.Win32.StartPage
MaxSecureTrojan.Malware.1065232.susgen
FortinetW32/StartPage.LY!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Sapade?

Trojan:Win32/Sapade removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment