Edw Ransomware (. Edw File) — Removal Guide

What is Edw virus?

The renaming will be executed by this pattern: .edw. In the course of encryption, a file entitled, for example, “report.docx” will be renamed to “report.docx.id-9ECFA84E.[].edw”.

In each directory with the encoded files, a FILES ENCRYPTED.txt text file will appear. It is a ransom money memo. It contains information on the ways of paying the ransom and some other information. The ransom note usually contains instructions on how to buy the decryption tool from the racketeers. You can get this tool after contacting by email. That is basically the scheme of the crime.

NameEdw Virus
Ransomware family1Dharma ransomware
Extension.edw
Ransomware noteFILES ENCRYPTED.txt
Contact
Detection2Win32/GenKryptik.FWOS, Worm:Win32/IRCbot.I, Win32/Packed.VMProtect.E
SymptomsYour files (photos, videos, documents) have a .edw extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Edw virus

The FILES ENCRYPTED.txt file coming in package with the Edw malware states the following:

all your data has been locked us
You want to return?
write email  or 

In the picture below, you can see what a directory with files encrypted by the Edw looks like. Each filename has the “.edw” extension added to it.

An example of encrypted .edw files.

How did my computer get infected with Edw ransomware?

Nowadays, there are three most exploited ways for malefactors to have the Edw virus settled in your system. These are email spam, Trojan infiltration and peer file transfer.

If you access your inbox and see letters that look like familiar notifications from utility services companies, delivery agencies like FedEx, web-access providers, and whatnot, but whose mailer is unknown to you, beware of opening those letters. They are most likely to have a malware item enclosed in them. Therefore, it is even riskier to open any attachments that come with letters like these.

Another thing the hackers might try is a Trojan file model3. A Trojan is a program that infiltrates into your machine pretending to be something legal. Imagine, you download an installer of some program you want or an update for some program. However, what is unboxed turns out to be a harmful agent that corrupts your data. As the update package can have any name and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The optimal way is to trust the software developers’ official websites.

As for the peer-to-peer file transfer protocols like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded items with the antivirus as soon as the downloading is done.

Sophia Al-Mansoor

Sophia Al-Mansoor

Global Business & E-Commerce Reporter

Sophia analyzes international trade, startup ecosystems, retail transformation, and supply chain logistics for modern digital publications.

Share this article
Twitter Facebook Pinterest