. Newware Files Encrypted (Newware Virus) — How to Remove?

What is known about the Newwarevirus?

Newware adds its own .newware extension to every file’s name. For example, an image entitled “photo.jpg” will be changed to “photo.jpg.newware”. In the same manner, the Excel sheet named “table.xlsx” will be renamed to “table.xlsx.newware”, and so on.

In every directory containing the encrypted files, a HOW_TO_RECOVER_DATA.html text document will appear. It is a ransom money note. Therein you can find information on the ways of paying the ransom and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the Newware developers. That is pretty much the scheme of the malefaction.

NameNewware Virus
Ransomware family1MedusaLocker ransomware
Extension.newware
Ransomware noteHOW_TO_RECOVER_DATA.html
Detection2Trojan:Win32/FormBook.RR!MTB, Ransom:Win32/Cerber, Trojan-Ransom.Win32.Wanna.apno
SymptomsYour files (photos, videos, documents) get a .newware extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Newware virus

In the picture below, you can see what a directory with files encrypted by the Newware looks like. Each filename has the “.newware” extension added to it.

That is how encrypted “.newware” files look.

How did Newware ransomware end up on my PC?

Nowadays, there are three most popular methods for criminals to have the Newware virus acting in your system. These are email spam, Trojan introduction and peer file transfer.

If you open your inbox and see emails that look just like notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose mailer is strange to you, beware of opening those emails. They are very likely to have a harmful item enclosed in them. So it is even riskier to download any attachments that come with emails like these.

Another option for ransom hunters is a Trojan horse model3. A Trojan is a program that infiltrates into your machine disguised as something different. Imagine, you download an installer for some program you want or an update for some program. However, what is unboxed turns out to be a harmful program that encodes your data. Since the update file can have any name and any icon, you’d better be sure that you can trust the resource of the things you’re downloading. The optimal way is to use the software companies’ official websites.

As for the peer-to-peer file transfer protocols like torrents or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded files with the antivirus as soon as the downloading is complete.

Robert Thorne

Robert Thorne

Automotive & Future Transportation Editor

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.

Share this article
Twitter Facebook Pinterest