Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2019

How to remove Pennywise ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Pennywise is a ransomware virus which encrypts data with AES but does not provide any contact details

Pennywise virus image

Pennywise ransomware is a data locker that first showed up in October 2017 as a new variant of the notorious Jigsaw virus. Its goal is to lock all personal users' photos, videos, documents and other files with the help of strong AES encryption algorithm[1] and then demand ransom payment in Bitcoin for the decryption tool. After file encryption and the addition of .beep file extension, Pennywise ransomware drops a ransom note which is screen locker, displaying the character Pennyzayzom from Stephen King's novel “It.” In early February 2019, security researchers noticed a new version of the virus that uses .pennywise file extension and sends a message “And remember my dear researchers….. I'M NOT A JIGSAW VARIANT!!!!!!!!!.” This variant is decryptable with the help of the key PsTqQNhR77oKJXvBWE3YZc.[2] Just as previously, hackers do not provide any contact details in the message.

Name Pennywise
Type Ransomware
First discovered October 2017
Related files Setup.exe, 
Cipher AES
Variants .beep, .pennywise
Ransom note Screen locker
Decryptable? Use PsTqQNhR77oKJXvBWE3YZc to decrypt files locked with .pennywise; .beep files not decryptable
Removal Scan your device with anti-malware software like FortectIntego or SpyHunterCombo Cleaner[3]

Researchers link Pennywise ransomware to the infamous Jigsaw ransomware which emerged on the cyberspace in April. This ransomware family has expanded rapidly over the next months, and the most common versions are Ramsley, Jokers House, DarkLocker, and HACKED.

Even though some variants remain undecryptable, you should remove Pennywise virus and try to recover your data using a Jigsaw decryptor. Moreover, there is a possibility to retrieve all the files from backup copies[4] which are stored in the cloud or external hard drive. These methods will help you to avoid financial losses since Pennywise ransomware authors seem to be highly unreliable and aggressive.

After Pennywise ransomware has encoded user’s data, it opens a pop-up, which serves as a ransom note. The victims are provided with the following message:

Your personal files are being deleted. Your photos, videos, documents, etc…

But, don’t worry! It will only happen if you don’t comply.
However I’ve already encrypted your personal files, so you cannot access them.
Every hour I select some of them to delete permanently, therefore I won’t be able to access them, either.
If you turn off your computer or try to close me, when I start next time you will get 1000 files deleted as a punishment.
Yes you will want me to start next time, since I am the only one that is capable to decrypt your personal data for you.
Meanwhile….. You want a balloon? Hahahahaha_

Pennywise virus illustration

Desperate computer users are urged to pay the ransom since the hackers threaten to delete one file each hour permanently. Besides, people who wouldn’t agree to follow the rules are warned that they will receive a punishment — next time Pennywise ransomware infects their computer, the bad actors will delete 1 thousand encrypted files.

Remember, that you should not tolerate this kind of behavior. Get help from a security software like FortectIntego or SpyHunterCombo Cleaner to start Pennywise removal safely. Shortly after, you will be ready to try data retrieval methods. It is also wise to use the anti-malware system not only in case of ransomware attack but also to prevent this type of infections in the first place.

Distribution techniques of ransomware viruses

This ransomware family keeps spreading via infected e-mail attachments, and this virus is not an exception. Hackers employ fraudulent messages carrying an executable of the ransomware. The letters might impersonate well-known companies or brands to lure gullible people into clicking on it.

Once the e-mail or its attachment is opened, it might infiltrate a trojan which opens backdoors to the ransomware or the crypto-malware itself. Therefore, we advise you to monitor your online activity carefully. It is important to be able to recognize malicious e-mail letters and avoid opening them.

Besides, experts from NoVirus.uk[5] warn that some of the ransomware variants also spread as fake software updates which might be displayed as pop-up ads on bogus websites. Be aware that they are designed to look remarkably genuine. Thus, stay away from Adobe Flash Player, VLC Media Player update and similar offers that are presented on unauthorized pages.

Pennywise file virus

The quickest way to eliminate Pennywise

We suggest using a reliable antivirus system, such as FortectIntego or SpyHunterCombo Cleaner for Pennywise removal since it will not only serve as an uninstaller but also protect your computer from identical infections in the future. Thus, you should download it and run an entire system scan as soon as possible.

However, the .pennywise file virus might prevent you from employing a security software. You can circumvent it by booting your PC into Safe Mode. If you don’t know how to do that, check the manual elimination guide below.

Additionally, you should know that if you want to remove Pennywise virus manually, it will be time-consuming and require extreme focus. The best solution would be to opt for an entirely automatic termination or combine both removal methods together.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.