May 20, 2015

How to Remove SAPE.Heur.685 Virus Step By Step?

Yesterday Norton Internet security detected a threat on my PC but was unable to remove it. The threat is called SAPE.Heur.685. Every time I try to remove it, it says ‘Access Denied’. Why Norton can’t delete the virus for good? How do I get the virus in the first place? I’ve spent 3 hours searching for a solution and I’ve already downloaded a few software but still nothing helped. What should I do now?

Learn More About SAPE.Heur.685 Virus:

SAPE.Heur.685 is a generic detection used by Norton Internet security or other antivirus products for a file that appears to have trojan-like features or behavior. It can sneak into a vulnerable system by visiting malicious websites, downloading free software from unsafe sources or opening spam email attachments. Once it is installed, the Trojan virus can corrupt the target machine by all means. Typically,you will find that your computer takes significantly more time than usual to start. Whatever you try to launch, they are not responding. In addition, when you open Task Manager, you can see CPU usage is high even you only have few things opened. Generally speaking, if your antivirus reports the virus and take action to remove it, your computer is still good and not compromised. But this virus can disable firewall and block your current security tool in order to hide itself deeply inside the system. Even though it could be reported by Norton, it can’t be removed permanently. The malicious files associated with the Trojan are hidden in every corner of system so you have to find out and manually remove them.

SAPE.Heur.685 Virus is malicious and it can perform various harmful activities once downloaded on a computer. It is capable of deleting important system files at random, adding malicious entries to the Windows registry, changing browser settings & HOSTS file, disabling antivirus program or even downloading other malware to the computer, etc. In addition, the virus can modify your browser settings and other system settings without your permission. As a consequence, your web browser may behave weirdly, for example, you are directed to another site when attempting to visit Google and your default homepage or search engine is changed to other sites you never saw before. The goal of this Trojan is to help install other malware and spyware. It poses a huge risk for all the affected PC. Being as a Trojan virus, it can collect your confidential information like IP address, browsing habits, search terms, and online banking account details in the background and then send to third-parties for illegal purpose. The longer it stays on your computer, the more damages it can bring. To sum up, SAPE.Heur.685 Virus can violate your privacy and ruin your system that should be removed without any delay.

The following instructions require certain levels of computer skills. If you’re not sure how to delete this nasty Trojan, please live chat with YooCare experts now.

Infected Symptoms Are Listed Below:

1. This virus slows down your computer speed which make you in a trouble while opening program and surfing Internet. It takes forever to open a program or website.
2. Antivirus you have installed keeps popping up messages while you are surfing on the internet and showing you computer is at risk but you can’t get rid of it all.
3. This virus will shut down your other anti-virus and anti-spyware programs. And it will also infect and corrupt your registry, leaving your computer totally unsafe.
4. This virus will disable the proper running of many different programs or even disable some functions of your computer.
5. System restore can’t help to remove this Trojan completely.

How Does This Virus Get On Your Computer?

From malicious drive-by-download scripts from corrupted porn and shareware / freeware websites.
Through spam email attachments, media downloads and social networks.
When clicking suspicious pop-ups or malicious links.
Open unknown email or download media files that contain the activation code of the virus.

Note: No matter how the virus accesses your PC, users should know that there are no tools can remove this pesky Trojan automatically at this moment, it is suggested users not spend much time in downloading or paying any security software which claims can delete this stubborn virus. It is totally useless. To completely get rid of SAPE.Heur.685, professional manual guide is needed.

About Trojan Virus Removal:

Currently many computer users had the same experience that this virus couldn’t be removed by any anti-virus applications. So the manual approach is always required to combat this virus. And here is the step-by-step removal guide for all computer users.

1. End the malicious process from Task Manager.

Once SAPE.Heur.685 virus is installed, computer user may notice that CPU usage randomly jumps to 100 percent. At any time Windows always has many running processes. A process is an individual task that the computer runs. In general, the more processes, the more work the computer has to do and the slower it will run. If your system’s CPU spike is constant and remain at a constant 90-95%, users should check from Task Manager and see if there is a suspicious process occupying system resources and then end it immediately.

(The name of the virus process can be random.)

Press Ctrl+Shift+Esc to quickly bring up Task Manager Window:

task manager

2. Show hidden files and folders.

Open Folder Options by clicking the Start button, clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.

Click the View tab.

Under Advanced settings, click Show hidden files and folders, uncheck Hide protected operating system files (Recommended) and then click OK.

Folder Options

3. Open Registry entries. Find out the malicious files and entries and then delete all.

Attention: Always be sure to back up your PC before making any changes.

a. Press Windows key + R to open Run box. In the “Open” field, type “regedit” and click the “OK” button.


Then a Registry Editor window will pop up as the following picture shows:

registry editor

b. Search malicious files and registry entries and then remove all of them:

%AllUsersProfile%\Application Data\.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\[random]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Temp

Video Shows You How to Safely Modify Windows Registry Editor:

SAPE.Heur.685 is a pesky virus that can be acquired from malicious links, spam email messages, or Peer-to-peer connection. It may also be dropped onto your PC by threats like adware, viruses, or malware. The virus is usually used by remote attackers to upload and install further malicious or potentially unwanted software on the system. It displays tons of harmful activities as soon as it is installed on a vulnerable PC. The virus takes up hard disk space and memory to slow down or even crash target PC, it also displays unwanted pop-up ads and provides remote access to hackers. As mentioned above, SAPE.Heur.685 virus can do nothing good on a PC but compromise the entire system or even stealpasswords and other sensible information. Once detect, an immediate removal is needed.

Note: If you are not knowledgeable enough to be able to distinguish the location of this virus, or you are afraid of making mistake during the manual removal, please contact experts from Yoocare Online Tech Support for further help.

Published by & last updated on May 20, 2015 5:43 pm

Leave a Reply

Your email address will not be published. Required fields are marked *

Problems with your PC, Mac or mobile device?

Live Chat Now

Thanks for using YooCare Services!

Here're some of the support team members who are passionate about their works and support our customers 24/7.

As Seen On