Edw Ransomware
The Edw ransomware is a new file-encrypting malware variant that does not seem to belong to any major family of ransomware clones.
The ransomware appends the ".edw" extension to the names of encrypted files, as well as two strings containing the victim's ID and the contact email used by the ransomware's maker. This means that a file named "photograph.jpg" will become "photograph.jpg.id-alphanumeric string.[edward22w.aol.com].edw". It's safe to assume that the extension matches the name chosen by the ransomware's author - Edward.
The Edw ransomware encrypts media, document and archive file types, leaving them unopenable. The ransom note is both dropped inside a file named "FILES ENCRYPTED.txt" and displayed inside a pop-up window that shows up when encryption completes. Here is the ransom demand in full:
YOUR FILES ARE ENCRYPTED
Don't worry,you can return all your files!
If you want to restore them, follow this link:email edward22w at aol dot com YOUR ID [alphanumeric string]
If you have not been answered via the link within 12 hours, write to us by e-mail:edward22w at tutanota dot com
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.








