CoinVault Virus – Removal Instructions

CoinVault is a ransomware virus that became prevalent in 2014. Attacking vulnerabilities in various versions of Windows, CoinVault is implanted through a zip file attached to emails pretending to be official support messages from various legitimate companies such as Fedex. It’s suspected that the CoinVault virus was originally created and released by someone in Russia, but it has since expanded its reaches globally. Users are alerted of the presence of this trojan horse on their machine once the infection has already taken place. A pop-up will appear informing the person that personal files on their system are being encrypted by the program, and the system becomes largely unusable.

Additionally, the system’s wallpaper will change with information about the CoinVault attack and what the demands for its removal are. This version of ransomware is considered more dangerous than others because a file system could be in danger of permanently losing important files if CoinVault is not properly dealt with. It’s estimated that over 250,000 computers have been infected by to date. A very small percentage of these victims of this CoinVault ransomware virus have actually paid the ransom demanded by the bot, but it has still netted millions of dollars for the perpetrator(s). 


CoinVault is disguised as an executable file with several hidden files attached to an email to the user. If CoinVault opened, a private key will be placed on the computer and a profile folder containing the malicious files will be hidden away out of the users reach. Once infection of the targeted system has taken place, CoinVault will begin encrypting important files using RSA cryptography. According to the program interface, the only way to remove the encryption from these files is to pay a predetermined sum via Bitcoin or anonymous cash vouchers by 72 hours from the initial time of infection.

If this amount is not paid in full, the CoinVault worm threatens to permanently disable access to the key needed to decrypt the files. When the deadline is not met, the user will be prompted with the chance to settle on paying a higher sum before the public key to retrieve their files is lost forever. It’s recommended that if a computer has been infected by the CoinVault virus that the user begins taking the proper steps to remove it immediately before any permanent damage can be done.

CoinVault Virus

CoinVault Virus Removal Instructions

The virus removal instructions we have outlined below has been proven remove the CoinVault virus.

** PLEASE NOTE: If the Virus is on a computer running “WINDOWS 8” see the Windows 8 Virus Removal Instructions

Remember: you must be on the infected computer when performing these 3 easy steps to remove the virus.

STEP 1: Start the computer in Safe Mode with Networking
a. Before starting this step, it is STRONGLY SUGGESTED that you write down our 24HR Toll Free tech support phone number incase you run into any issues or would like any additional help with your PC.

If you need help, this is the number to call!

b. To begin, go ahead and turn off the infected computer and wait roughly 20 seconds, then turn it back on.

c. Next Immediately as the computer begins to turn on, press F8 many times. Pressing F8 allows you to access the Advanced Options Menu. You should see an image like the one below.

Selection the option Safe Mode with Networking

d. Next use your arrow keys and select the Safe Mode with Networking option. Press enter when you have selected that option and the computer will begin to boot into safe mode.

STEP 2: Download the CoinVault Virus Removal Program
a. Now it is time to open the “Run Command” box.

b.On your keyboard, push and hold the “Windows” key, then press the “R” key. See keyboard diagram below.

Keyboard Shortcut Diagram

c. After you have pressed the “Windows” and “R” key, the Windows Run Box will open. Type the following and press OK:


Windows Run Box

After clicking OK, your computer will connect to the internet and download our recommended virus removal program called Spyhunter.

STEP 3: Installing the CoinVault Virus Removal Program
a. When you see the download box, click the “Run” button. The picture of the download box is below.

Spyhunter Download Box Click Run

b. Now you should be downloading a program called “Spyhunter 4” this program has been developed by a company called Enigma Software. Through their extensive work on Malware research they have developed one of the worlds most successful Virus and Malware removal programs. This program offers easy “point and click” virus removal.

c. After this program runs the scan, you should see a list of “threats” found on your computer. These Threats can be very harmful and may ruin the computer if not removed. To remove these threats click “fix Threats” and then “register” the program to permanently remove the virus and any other threats found.

*** After registering Spyhunter4 we highly recommend restarting the computer. Then we would like you to make sure everything is working properly. You should notice that the virus has been completely removed. If it has not been removed or the computer is not working 100% to your liking call us immediately at 1-888-895-6053 and one of our techs will help get it working properly again.

Need further assistance? Call us toll free and one of our friendly technicians will kindly walk you through the virus removal process.

Leave a Comment