KEYHolder Virus – Removal Instructions

KEYHolder is new piece of “ransomware.” The goal of KEYHolder is to hold some part of an infected user’s system hostage for a “ransom.” The user must pay a ransom to decrypt and have access to their data again. KEYHolder attempts to render a user’s data unreadable but recoverable. This is the same tactic employed by a kidnapper to extract money from somebody willing to do anything to save a loved one. Although a user’s data may not be loved, there are many pieces of data that are critical to a user’s life. Many people have important documents, banking information, passwords, school work, resumes. Despite the availability of external drives and cloud-based storage, a large number of users do not keep any kind of backup of critical files.

The developers of KEYHolder understand and leverage this dependency on critical data to force people to pay a ransom in bitcoin. The relative anonymity of bitcoin offers the data-kidnappers a degree of safety in receiving their funds. KEYHolder can affect all recent versions of windows, from windows XP to Windows 8.


KEYHolder scans an infected user’s computer for data files and makes a list of what it finds. It then attempts to encrypt all of the files on this list using an encryption method that can only be decrypted with the private key that is now stored on the KEYHolder servers. Once encryption is complete, KEYHolder changes a user’s windows desktop background to a message stating that all data files have been encrypted.

KEYHolder pops up an application window explaining how the data files have been encrypted, that a ransom is being demanded, how much the ransom is (1.5 bitcoin to start), how to pay, and a countdown timer until the payment deadline. If the user follows instructions of the KEYHolder virus and makes the required ransom payment then clicks the appropriate button, then the files are actually decrypted. If the countdown expires without payment, then the ransom increases and the timer resets. KEYHolder will continue to wait patiently for payment without causing any additional damage other than to demand increasing amounts of ransom to decrypt the user’s data files.

KEYHolder Virus

KEYHolder Virus Removal Instructions

The virus removal instructions we have outlined below has been proven remove the KEYHolder virus.

** PLEASE NOTE: If the KEYHolder Virus is on a computer running “WINDOWS 8” see the Windows 8 Virus Removal Instructions

Remember: you must be on the infected computer when performing these 3 easy steps to remove the virus.

STEP 1: Start the computer in Safe Mode with Networking
a. Before starting this step, it is STRONGLY SUGGESTED that you write down our 24HR Toll Free tech support phone number incase you run into any issues or would like any additional help with your PC.

If you need help, this is the number to call!

b. To begin, go ahead and turn off the infected computer and wait roughly 20 seconds, then turn it back on.

c. Next Immediately as the computer begins to turn on, press F8 many times. Pressing F8 allows you to access the Advanced Options Menu. You should see an image like the one below.

Selection the option Safe Mode with Networking

d. Next use your arrow keys and select the Safe Mode with Networking option. Press enter when you have selected that option and the computer will begin to boot into safe mode.

STEP 2: Download the KEYHolder Virus Removal Program
a. Now it is time to open the “Run Command” box.

b.On your keyboard, push and hold the “Windows” key, then press the “R” key. See keyboard diagram below.

Keyboard Shortcut Diagram

c. After you have pressed the “Windows” and “R” key, the Windows Run Box will open. Type the following and press OK:


Windows Run Box

After clicking OK, your computer will connect to the internet and download our recommended virus removal program called Spyhunter.

STEP 3: Installing the KEYHolder Virus Removal Program
a. When you see the download box, click the “Run” button. The picture of the download box is below.

Spyhunter Download Box Click Run

b. Now you should be downloading a program called “Spyhunter 4” this program has been developed by a company called Enigma Software. Through their extensive work on Malware research they have developed one of the worlds most successful Virus and Malware removal programs. This program offers easy “point and click” virus removal for KEYHolder.

c. After this program runs the scan, you should see a list of “threats” found on your computer. These Threats can be very harmful and may ruin the computer if not removed. To remove these threats click “fix Threats” and then “register” the program to permanently remove the KEYHolder virus and any other threats found.

*** After registering Spyhunter4 we highly recommend restarting the computer. Then we would like you to make sure everything is working properly. You should notice that the KEYHolder virus has been completely removed. If it has not been removed or the computer is not working 100% to your liking call us immediately at 1-888-895-6053 and one of our techs will help get it working properly again.

Need further assistance? Call us toll free and one of our friendly technicians will kindly walk you through the virus removal process.

Leave a Comment