. Newware Files Encrypted (Newware Virus) — How to Remove?
What Is Known About the Newwarevirus? Newware Adds Its Own. Newware Extension to Every File’s Name. for Example, an Image Entitled “Photo. Jpg” Will Be Changed...
What is known about the Newwarevirus?
Newware adds its own .newware extension to every file’s name. For example, an image entitled “photo.jpg” will be changed to “photo.jpg.newware”. In the same manner, the Excel sheet named “table.xlsx” will be renamed to “table.xlsx.newware”, and so on.
In every directory containing the encrypted files, a HOW_TO_RECOVER_DATA.html text document will appear. It is a ransom money note. Therein you can find information on the ways of paying the ransom and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the Newware developers. That is pretty much the scheme of the malefaction.
| Name | Newware Virus |
| Ransomware family1 | MedusaLocker ransomware |
| Extension | .newware |
| Ransomware note | HOW_TO_RECOVER_DATA.html |
| Detection2 | Trojan:Win32/FormBook.RR!MTB, Ransom:Win32/Cerber, Trojan-Ransom.Win32.Wanna.apno |
| Symptoms | Your files (photos, videos, documents) get a .newware extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Newware virus |
In the picture below, you can see what a directory with files encrypted by the Newware looks like. Each filename has the “.newware” extension added to it.
How did Newware ransomware end up on my PC?
Nowadays, there are three most popular methods for criminals to have the Newware virus acting in your system. These are email spam, Trojan introduction and peer file transfer.
If you open your inbox and see emails that look just like notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose mailer is strange to you, beware of opening those emails. They are very likely to have a harmful item enclosed in them. So it is even riskier to download any attachments that come with emails like these.
Another option for ransom hunters is a Trojan horse model3. A Trojan is a program that infiltrates into your machine disguised as something different. Imagine, you download an installer for some program you want or an update for some program. However, what is unboxed turns out to be a harmful program that encodes your data. Since the update file can have any name and any icon, you’d better be sure that you can trust the resource of the things you’re downloading. The optimal way is to use the software companies’ official websites.
As for the peer-to-peer file transfer protocols like torrents or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded files with the antivirus as soon as the downloading is complete.