Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2021

How to remove KEYPASS ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

KEYPASS ransomware – a dangerous cryptovirus that infiltrates systems via fake software installers

.Keypass ransomware virus

KEYPASS ransomware is a dangerous cryptovirus that belongs to the family of STOP ransomware. Once installed, it makes changes to the Windows Registry to gain boot persistence. That makes its removal a bit more difficult but possible with proper anti-malware software.

The malware uses AES-256 cipher to encrypt files and adds a .keypass extension. Additionally, the virus connects to its C&C servers to receive the encryption key and make user's files useless without it. Victims are informed about this attack via the !!!KEYPASS_DECRYPTION_INFO!!!.txt ransom note that requires a $300 ransom in Bitcoin in exchange for the decryptor for the locked data.

The victim receives 72 hours to pay this fee. For that, users need to contact the cybercriminals using a provided email address (keypass@bitmessage.ch). Note that this cryptovirus has nothing to do with the well-known KeePass password management software.

NAME KEYPASS
TYPE Ransomware, file-locker
RANSOM note “!!!KEYPASS_DECRYPTION_INFO!!!.txt”
Ransom amount $300 in Bitcoin has to be paid in 72 hours
other features Manual control. Used to customize the ransom note and change the ransom amount, email address, victim ID, etc.
DISTRIBUTION WAYS Spam emails, questionable sources, file-sharing platforms
ELIMINATION Remove any computer virus by performing a full system scan with a trustworthy anti-malware tool
System fix Revert any changes this infection has made to the Registry and other core system settings and files by using the time-proven FortectIntego system repair tool

KeyPass ransomware was first discovered by Kaspersky Lab experts on the 8th of August,[1] and infection submissions came from over 20 countries across the globe, with Brazil and Vietnam being hit the most. As of now, security experts are not sure about how the virus spreads, but several users reported that it appeared after they installed the Windows hacking tool KMSpico. In contrast, others stated that no changes were made before the infection occurred.

This file-locking parasite comes with a hidden feature called “Manual control”. It can only be activated by using a specific key combination that allows hackers to take manual control[2] of the virus. This allows them to modify the victim's ID, file extension, encryption key, and several other preferences related to the file encryption process.

Security experts also noticed that in the Command & Control server is not reachable or the infected device is not connected to the internet, the malware uses a hard-coded key, which makes the ransomware removal and file retrieval a much easier task.

However, if the computer is connected to the network, the virus does not only encrypts your regular personal files like pictures, databases, documents, and similar but instead skips a few folders on the machine, allowing the system to boot properly. After the encryption process is complete, most of the files become inaccessible, leaving the device in a complete mess.

Keypass ransomware

The ransom note that is retrieved from the C&C server after the file encryption states the following:

Attention! 
All your files, documents, photos, databases and other important files are encrypted and have the extension: .KEYPASS
The only method of recovering files is to purchase an decrypt software and unique private key.
After purchase you will start decrypt software, enter your unique private key and it will decrypt all your data.
Only we can give you this key and only we can recover your files.
You need to contact us by e-mail keypass@bitmessage.ch send us your personal ID and wait for further instructions.
For you to be sure, that we can decrypt your files – you can send us a 1-3 any not very big encrypted files and we will send you back it in a original form FREE.
Price for decryption $300. 
This price avaliable if you contact us first 72 hours.
E-mail address to contact us:
keypass@bitmessage.ch
Reserve e-mail address to contact us:
keypass@india.com
Your personal id: –

While the ransomware virus developers demand a $300 ransom, the payment type is not mentioned. However, hackers usually rely on digital currency (Bitcoin, Monero, Litecoin, etc.) for all the transactions. This way, money transfers remain anonymous and prevent law enforcement from tracking and punishing scammers. 

Nevertheless, we do not recommend contacting cyber criminals, as the chance of retrieving the key is quite low. Additionally, it might encourage bad actors to improve the malware code and increase the number of infections. Thus, better take care of the ransomware by using anti-malware software, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, and then recover your files from a backup.

Keypass virus

Unfortunately, this malware can also be used as a backdoor for other infections, such as banking trojans and other malware forms[3]. We recommend you not to wait and get rid of the virus as soon as possible, as the infection chance increases the longer you wait.

Remember, your computer and data safety is in your own hands. Better prepare for such attacks in advance – keep important files safe and on a USB stick or an external HDD. If you are already infected with Keypass ransomware and have no backups ready, you could try third-party software that could help you to recover your data. See instructions below.

But before proceeding with file recovery, either from backups or by using recovery software, users should take care of their device's overall health. This ransomware causes havoc on system files, which can lead to various abnormal behavior. Use the FortectIntego system repair tool to take care of all system inconsistencies automatically.

Keep your PC safe from ransomware by following safety tips

According to UdenVirus.dk specialists[4], ransomware usually has one main distribution source – spam emails. Cybercriminals take action and send numerous phishing messages to accidental users. Once received, such messages can be found in the Spam section (however, phishing emails might slip through the built-in scanners and get into your Inbox instead). If you encounter this type of content – better eliminate it permanently to avoid severe computer infections.

We advise increasing your PC safety by running an antivirus program[5] on your computer. If you do not already have one, you should consider downloading a trustworthy one. Such anti-malware software will keep your machine secured from various infections if kept up-to-date as required.

Keypass ransomware ransom note

Get rid of the dangerous infection with the help of our removal guides

To remove this hazardous virus, you need to run a full system scan with a reliable anti-malware program and get rid of every component of this ransomware. Experts recommend using such tools as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Of course, you can pick another trustworthy anti-virus of your liking, but make sure it is up-to-date.

The elimination might take a while, but it is critical to get rid of the cyber threat as fast as possible to avoid further damage. Afterward, to complete the removal process by restoring your Registry, host files, and other essential system files, it's highly recommended to use the FortectIntego system repair tool.

Unfortunately, neither the security software nor the repair tools that we recommend recover data encrypted by KEYPASS ransomware. For that, you should follow the tips given below this article. Finally, to protect yourself from ransomware attacks in the future, keep backups of your most valuable files. For that, use cloud services or external drives.

Did this guide help?

Be the first to comment

Read in your language

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.