Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2017

How to remove Sad ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Sad hackers release Sad ransomware

The picture illustrating Sad ransomware note

Sad virus defines crypto-malware which encodes data and demands ransom 0.3 BTC in exchange to the decryption software called decrypter.exe.[1] The latter is available on a specific website accessible via Tor browser. 

During the infiltration, the malware drops the following files[2]:

  • _HELPME_DECRYPT_.txt
  • _HELPME_DECRYPT_.hta
  • _HELPME_DECRYPT_.html

All of them display a slightly different message. The .txt file includes the link to the general information about bitcoins and ways to purchase them.

The .hta file states that the data has been encoded using AES-256 cipher. According to the style of the message, the developer seems to be a non-native English speaker. The file also includes Tor link to the decrtypter.exe – the tool to decode the data affected by Sad ransomware.

Furthermore, the .html file displays less information and urges victims to purchase the decryption software. The malware also leaves picture.exe file in Shared folder.

The malware is already detectable by the majority of security tools as MSIL.Trojan-Ransom.Sad.A, Ransom.Sad, Ransom.CryptXXX, Ransom_SAD.A , etc. The malware seems to disguise under tGVkDTIb.exe file, though executable files may vary.

The malware appends an extension comprised of random hexadecimal characters. There is no information whether Sad Decryptor functions properly. Instead of paying the ransom, concentrate on the elimination of the malware. FortectIntego or MalwarebytesMalwarebytes will help you complete Sad removal.

Ransomware distribution trends

Usually, trojanized ransomware might be foisted as rogue applications in highly dubious websites, such as gaming, gambling, and sites with adult content.

Alternatively, some ransomware developers prefer using exploit kits and hide their malware under fake Adobe Flash Player update[3]. Do not forget that spam emails also remain a popular distribution method.

In order to limit the risk of Sad hijack, pay attention to the programs and source you download from. Be wary of spam emails which are supposedly sent by the official institutions. Installing a couple of different type anti-malware tools might be practical as well. They will help you evade websites infected with exploit kits or phishing sites promoting counterfeited software updates. Let us move on Sad ransomware removal.The screenshot of Sad ransom messages

Sad elimination steps

Though the malware has quite sufficient GUI and operation mode, it is not known whether it deletes shadow volume copies and causes Sad removal troubles. If the anti-virus program does not respond, restart the system in Safe Mode.

Later on, you should be able to launch the security tool and eliminate the malware. Only after you remove Sad virus completely, proceed to data recovery. There is also an additional method which helps you access the operating system. Not only English users should be wary of the malware, but other users residing in the Czech Republic, Bulgaria[4], or Spain.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.