Iwan Virus Files (VoidCrypt Ransomware)

Iwan Virus Files (VoidCrypt Ransomware)

What Is Iwan Virus?

The Iwan virus is a type of ransomware that belongs to the “VoidCrypt Ransomware” family. Its primary goal is to persuade victims to pay a large ransom price to the cyber-criminals responsible for the ransomware. The Read-this.txt and Decryption-Info files are intended to be left by this malware. HTA ransom letters with instructions on how to pay the ransom and negotiate a fair price for your files. The ransom is payable in BitCoin, and the crooks demand that you pay it within a certain time frame, or they will double the amount.

If you want to learn how to get rid of the Iwan virus from your computer and get your files working again, read this post.

Iwan virus Virus Summary

Name Iwan Virus, also known as Ransom:Win32/VoidCrypt.PAA!MTB (Microsoft), Ransom.Win32.VOIDCRYPT.SM (TrendMicro), HEUR:Trojan.Win32.Stosek.gen (Kaspersky)
File Extensions E-mail address, ID number, .Iwan
Type Ransomware, Cryptovirus
Short Description The ransomware encrypts files on your computer system and demands a ransom to be paid to allegedly recover them.
Symptoms The Iwan Virus ransomware will encrypt your files by appending the .[iwantfiles2016@gmail.com][MJ-RQ2396815074].Iwan extensions to them.
Ransom Demanding Notes Read-this.txt and Decryption-Info.HTA
Distribution Method Spam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by malware















Iwan Virus – What We Know About It

This ransomware, like the .Iwan, .hhqa, and .muuq infections, can infect your computer in two different ways:

  • If it’s sent as an attachment in an email.
  • If you get it from a third-party website as a file.

If you downloaded this malware as a file from a dodgy software download site, it’s possible that it was disguised as one of the following programs:

  • Cracks (activators).
  • Patches.
  • Hoax setups.
  • Portable apps.
  • Keygens (key generator activators).

You could possibly be infected with the Iwan virus. by way of e-mail As a result, you may be able to open some of the following documents that the virus may pretend to be:

  • E-receipts.
  • Invoices.
  • Work-related files.
  • Tickets.

Once the Iwan virus has infected your computer, it may download a variety of payload files that are often named randomly and stored in the following directories:

  • %Local%
  • %LocalLow%
  • %AppData%
  • %Temp%
  • %SystemDrive%

When this virus infects your computer, it will leave two ransom notes named Read-this.txt and Decryption-Info.HTA, instructing victims on how to pay the ransom. These notes also include directions on how to contact the crooks for a decryption key produced during the encryption of the files.

.Iwan Files

The AES (Advanced Encryption Standard) and RSA (Rivest–Shamir–Adleman) encryption techniques are used to encrypt the files encrypted by this version of VoidCrypt ransomware. The basic goal of the ciphers is to modify the data in the files and generate a unique decryption key that can be used online or offline. Without the specific key, decryption is nearly impossible.

The following types of files are encrypted by the Iwan virus:

  • Video files (.mp4, .avi, etc.).
  • Document file types (.docx, .pptx, etc.).
  • Image files (.jpg, .png, .etc).
  • Audio (.mp3, .wav, etc.).
  • Archives (.zip, .rar, etc).
  • Other.

After encrypting files, the Iwan malware adds its own file extensions:

Example: Picture.jpg.[iwantfiles2016@gmail.com][MJ-RQ2396815074].Iwan

Remove Iwan Virus and Try to Restore Files

We strongly suggest you to study the removal guide below before attempting to remove the Iwan virus from your computer. It was intended to assist you in effectively and safely removing this infection. Security experts strongly advise using anti-malware software to remove Iwan and infections like it for the best results. Scanning your computer with such a tool will assist in effectively eradicating it from your device by automatically discovering and removing its malware files, as well as protecting your machine in the future.

If you want to try to recover your files but there isn’t a decryptor for this version of STOP Ransomware yet, you can use the alternative file recovery methods listed below. They may not be able to recover all of your files, but they may be able to assist you in recovering some of them.


Attention! All malware victims should seek aid exclusively from trusted sites, according to us. Many instructions promise to be able to restore and decrypt files that have been encrypted by ransomware viruses for free. You should be aware that some of them may only be after your money.

How to Identify Reliable Sources:

  • Always look at the “About Us” section of the website.
  • The content creator’s profile.
  • Check to see if the site is run by genuine people rather than phony names and profiles.
  • Verify your personal profiles on Facebook, LinkedIn, and Twitter.

How to Remove Iwan virus from Windows.

To isolate and eradicate the Iwan malware, start your computer in Safe Mode.

1. Keep Windows key() + R

2. A window called “Run” will appear. Type “msconfig” in the box and click OK.

3. Select “Boot” from the drop-down menu. Select “Safe Boot” from the drop-down menu, then “Apply” and “OK.”

Tip: Make sure to reverse those changes by unticking Safe Boot after that, because your system will always boot in Safe Boot from now on.

4. To enter Safe Mode, click “Restart” when requested.

5. Safe Mode is identified by the wording displayed on the screen’s corners.

Step 2: Remove the Iwan malware and any related software from your computer.

Here is a method in few easy steps that should be able to uninstall most programs. No matter if you are using Windows 10, 8, 7, Vista or XP, those steps will get the job done. Dragging the software or its folder to the recycle bin is a very bad decision. If you do so, bits and parts of the application are left behind, which might result in your PC’s performance being unsteady, file type association issues, and other unpleasant activities. Uninstalling an application is the right approach to remove it from your computer. To do that: 

1. Press and hold the Windows Logo Button as well as the “R” key on your keyboard. There will be a pop-up window.

2. Type “appwiz.cpl” into the field and hit ENTER.

3. This will bring up a window showing all of the programs that have been installed on the computer. Select the software you wish to uninstall and click “Uninstall.”

Follow the instructions above and you will successfully uninstall most programs.

Step 3: Remove all Iwan virus-related registries from your PC.

The following are the most commonly targeted registries on Windows machines:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

You can get to them by going to the Windows registry editor and erasing any Iwan virus-created values. This can be accomplished by following the steps below:

1. Click OK after reopening the Run window and typing “regedit.”

2. When you open it, you can freely go to the Run and RunOnce keys, which are depicted above in their respective locations.

3. You can delete the virus’s value by right-clicking on it and delete it.

Tip: To find a virus-created value, you can right-click on it and click “Modify” to see which file it is set to run. If this is the virus file location, remove the value.

Before starting “Step 4”, please boot back into Normal modein case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Step 4: Use SpyHunter Anti-Malware Tool to scan for the Iwan malware.

1. Go to the SpyHunter download page to download it.

2. Wait for SpyHunter to update automatically after you’ve installed it.


3. Once the update has been completed, go to the ‘Malware/PC Scan‘ page. There will be a new window open. Select ‘Start Scan‘ from the drop-down menu.


4. After SpyHunter has finished scanning your PC for any linked threat files and located them, click the ‘Next’ button to try to have them deleted automatically and permanently.


It is highly suggested that you restart your PC after any threats have been removed.

Step 5 (Optional): Try to Restore Files Encrypted by Iwan virus.

The Iwan virus and other ransomware attacks encrypt your files with an encryption mechanism that can be tough to decrypt. As a result, we’ve recommended a data recovery approach that may be able to assist you to avoid direct decryption and restore your files. Keep in mind that this strategy may not be 100 percent efficient in all instances, but it may help you a little or a lot in some.

1. Click on the following link to get the recommended Data Recovery software:

EaseUS Data Recovery Software

Simply click on the link and on the website menus on the top, choose Data Recovery – Data Recovery Wizard for Windows or Mac (depending on your OS), and then download and execute the tool.

Get rid of Iwan virus from Mac OS X.

Step 1: Delete all files and objects associated with the Iwan virus.

1. To open Utilities, press the ⇧+⌘+U keys together. Another option is to click “Go” and then “Utilities,” as shown in the image below:

2. Double-click Activity Monitor to open it:

3. Look for any suspicious processes related to or belonging to the Iwan malware in the Activity Monitor:

Tip: Select the “Force Quit” option to quit a process completely.

4. Press the “Go” button once more, but this time choose Applications. Another option is to use the ⇧+⌘+A buttons.

5. Search the Applications menu for any suspicious apps or apps with names that sound close to or are the same as the Iwan malware. If you come across it, right-click it and select “Move to Trash.”

6: Select Accounts, then Login Items from the drop-down menu. After that, your Mac will display a list of items that will begin immediately when you log in. Look for any suspicious apps that are similar or identical to the Iwan malware. Select the Minus (“-“) symbol to conceal the app that you want to stop from running automatically.

7: Manually remove any remaining files that may be linked to this threat by following the sub-steps below:

  • Navigate to Finder.
  • Type the name of the software you wish to uninstall in the search bar.
  • Change the two drop-down menus above the search bar to “System Files” and “Are Included” to see all of the files related to the application you want to uninstall. Keep in mind that some of the files you remove might not be related to the app, so be cautious about what you delete.
  • If all of the files are related, press and hold the ⌘+A buttons to select them all and then drag them to the “Trash” folder.

In case you cannot remove Iwan virus via Step 1 above:

If you can’t discover the virus files and objects in your Applications or the other areas we mentioned before, you can hunt for them manually in your Mac’s Libraries. Please read the following disclaimer before proceeding:

Disclaimer! If you are about to tamper with Library files on Mac, be sure to know the name of the virus file, because if you delete the wrong file, it may cause irreversible damage to your MacOS. Continue on your own responsibility!

1: As seen below, click “Go” and then “Go to Folder.”

2: Enter “/Library/LauchAgents/” and hit OK:

3: Delete any viral files with the same or similar names as the Iwan malware. Do not remove anything if you feel there is no such file.

You can repeat the same procedure with the following other Library directories:

→ ~/Library/LaunchAgents

Tip: ~ is there on purpose, because it leads to more LaunchAgents.

Step 3 (Optional): Try to Restore Files Encrypted by Iwan virus.

The Iwan virus and other ransomware attacks encrypt your files with an encryption mechanism that can be tough to decrypt. As a result, we’ve recommended a data recovery approach that may be able to assist you to avoid direct decryption and restore your files. Keep in mind that this strategy may not be 100 percent efficient in all instances, but it may help you a little or a lot in some.

1. Click on the following link to get the recommended Data Recovery software:

EaseUS Data Recovery Software

Simply click the link and select Data Recovery – Data Recovery Wizard for Windows or Mac (depending on your OS) from the website choices at the top, then download and execute the tool.

Iwan virus FAQ

 What is Iwan virus ransomware and how does it work?

The Iwan virus is a ransomware infection, which is malicious software that stealthily infiltrates your computer and encrypts your files or limits access to the computer itself.

Many ransomware viruses employ advanced encryption algorithms to prevent you from accessing your files. The purpose of ransomware is to force you to pay a ransom in order to regain access to your files.

How does Iwan virus ransomware infect my computer?

There are various ways to do so. The Iwan virus is a ransomware that infects computers via phishing e-mails, containing virus attachment.

This attachment is frequently disguised as a legitimate document, such as an invoice, bank paperwork, or even a plane ticket, and it fools people.

A drive-by download occurs once you download and execute this attachment, and your machine is infected with the ransomware virus.

If you download a false installer, crack, or patch from a low-reputation website or click on a virus link, you may become a victim of the Iwan virus. Many individuals claim to have been infected with ransomware after downloading torrents.

How to open .Iwan virus files?

You can’t do it. The .Iwan virus files are encrypted at this point. They can only be opened once they’ve been decrypted.

Decryptor did not decrypt my data. What now?

 Don’t freak out, and make a backup of your files. If a decryptor failed to successfully decrypt your .Iwan virus files, do not despair; the infection is still relatively young.

Using a decryptor to restore files encrypted by the Iwan virus ransomware is one option. However, because this is a new virus, the decryption keys for it may not yet be available to the public. As soon as this decryptor is launched, we will update this article and keep you informed.

How Do I restore “.Iwan virus” files (Other Methods)?

Yes, files can occasionally be recovered. If you want to restore, we’ve proposed a few file recovery procedures that might help restore .Iwan virus files.

These procedures do not provide a 100% guarantee that you will be able to recover your files. Your chances of success are substantially higher if you have a backup plan.

How do I get rid of Iwan virus ransomware virus?

Using professional anti virus software to remove this ransomware attack is the safest and most effective method. It will search for and detect the Iwan virus ransomware, then delete it without causing any further damage to your vital data. Virus files with the Iwan suffix.

Remember that infections like the Iwan virus ransomware can also install Trojans and keyloggers, which can steal your passwords and accounts. Scanning your computer with anti-malware software will ensure that all of these virus components have been eradicated and that your machine is safe in the future.

What to Do If nothing works?

You still have a lot of options. If none of the preceding procedures appear to be effective, try these methods:

  • Attempt to find a safe computer from which you can access your personal accounts such as OneDrive, iDrive, Google Drive, and so on.
  • Contact your friends, relatives, and others to see if they have any of your essential images or documents that you may have provided them.
  • Also, see whether any of the encrypted data can be re-downloaded from the web.
  • Another ingenious method for recovering some of your information is to find another old computer, a flash drive or even a CD or a DVD where you may have saved your earlier documents. You might be surprised by what you find.
  • You can also go to your email account to check if you have the ability to send attachments to others. The content of the email is usually preserved on your account, and you can re-download it. But, most crucially, make sure you’re doing this on a secure computer and that you’ve already removed the infection.

More advice can be found on our forums, where you can also ask any questions you have concerning your ransomware issue.

How to Report Ransomware to Authorities?

You can report a ransomware infection to your local police department if your computer has been infected. It can assist authorities all around the world in tracking down and identifying the people responsible for the virus that has infected your computer. We’ve included a list of government websites where you can register a report if you’ve been a victim of cybercrime below:

Cyber-security authorities in charge of responding to ransomware attack reports in various parts of the world include:

Depending on your local authorities, reports may be replied to in a variety of timescales.


Loading Facebook Comments ...