Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2019

How to remove Frendi ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Frendi ransomware is the cryptovirus that delivers two files with information about the attack: HTML window and Encrypted.txt

Frendi ransomwareFrendi ransomware is the file-locking crypto malware that marks encrypted data using .ID-1E857D00.[tlalipidas1978@aol.com].Frendi file extension. This is the newest version in the Dharma ransomware family that hails from the particular Phobos virus and uses file marker with the unique victims' ID and a contact email as the previous versions in the same family. It also delivers a ransom note where victims can see additional contact emails that are not changed from the initial variants. FobosAmerika@protonmail.ch is the main email for virus developers, but we do not recommend contacting them in any instance. Although the ransom demand for your locked files may vary, it is not the best solution. Based on the information about past versions ransom amount may go up to thousands of dollars and increases every few hours. However, paying the ransom can lead to permanent money or even data loss.[1]

Name Frendi ransomware
Version of Phobos virus
Type Cryptovirus
File extension .ID-1E857D00.[tlalipidas1978@aol.com].Frendi
Ransom note Encrypted.txt 
Contact emails tlalpidas1978@aol.com; FobosAmerika@protonmail.ch
Family Dharma ransomware
Elimination Use FortectIntego and remove Frendi ransomware
Possible detection results
  • HEUR/AGEN.1037929
  • Win32:Trojan-gen
  • Trojan.Win32.Malicious.4!c
  • ML.Attribute.HighConfidence
  • Trojan.Win32.73853

Since Frendi ransomware virus is the cyber threat that belongs to a cryptovirus family, it focuses on crypto-extortion and data encryption. Users should be aware that the main focus of these cybercriminals is to get money form their victims and there is no guarantee that the payment could save encrypted data. 

Frendi ransomware hails from a well-known ransomware family that targets people all over the world since 2016.[2] Due to this fact, you shouldn't trust anything that gets promised by people behind this ransomware. As most of the previous versions, .frendi file extension virus creates two files for the victim and delivers them to the screen in the form of HTML window that includes payment instructions and Encrypted.txt which is the initial ransom note. 

Frendi ransomware developers state the following in their ransom message:

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail tlalpidas1978@aol.com
In case of no answer in 24 hours write us to theese e-mails: FobosAmerika@protonmail.ch
If there is no response from our mail, you can install the Jabber client and write to us in support of phobos_help@xmpp.jp, or phobos_helper@exploit.im

Although Frendi ransomware starts the attack with encryption, you cannot notice that until the ransom note is displayed on the computer or files get the appendix which includes victims' ID and the main contact email. .ID-1E857D00.[tlalipidas1978@aol.com].Frendi marks all locked files when your photos, videos, audio files or documents get encrypted using the sophisticated AES algorithm.

Frendi ransomware is designed first to scan the system and encrypt important users' files. However, this virus then can gather information about the victim including details about the affected device or even personal information about the victim. The identity of the computer owners, contact information, name, address, phone number or any account credentials can be gathered. 

Information collected by Frendi ransomware can be used to disable security functions like firewalls, anti-virus programs or execute additional payloads. Ransomware can affect operating system by carrying out different malicious actions or altering data. 

You should ignore the lock screen, ransom note or any other material that encourages to pay the ransom and remove Frendi ransomware as soon as possible. Any further changes that this virus makes can significantly affect the performance of your machine or interfere with the malware termination process. 

Employ a reliable anti-malware program for Frendi ransomware removal and scan the system thoroughly. We recommend FortectIntego as the antivirus tool, but you can also check other suggestions down below. Also, we have a few additional tips for virus elimination process and data recovery options, so read the step-by-step guide thoroughly. 

Frendi ransomware virus

Various phishing email tactics get used for ransomware distribution 

Hackers employ various techniques to spread their products, but when it comes to crypto malware, the main method used to distribute these threats is spam email campaigns. Cybercriminals send out the email that poses as legitimate notifications from company or service and attaches the malicious file to that email as a document or archive.

MS word, excel or PDF documents, ZIP archives contain malicious scripts that get triggered and downloads payload carriers which cause the cyber infection on a targeted device. Whenever the document gets opened the victims gets the suggestion to enable content or built-in script. 

As soon as you do so, malicious macros get launched, and the device gets infected with ransomware distributing programs or the cryptovirus itself. Researchers[3] advise cleaning the email box more often, so you can avoid these infiltrations. Also, paying more attention to emails you get without expecting can give you the advantage of preventing malware infections.

Eliminate all cyber threats and delete Frendi ransomware by scanning the system with professional anti-malware

Remember that Frendi ransomware virus is not a simple program; it is a notorious crypto-extortion based malware that aims to get profit from victims by making their files useless. This is one of the most dangerous cyber threats. 

You need to employ a reliable anti-malware program to remove Frendi ransomware from the machine once and for all. We can recommend FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes for the job. These tools can scan the system fully and indicate potential malware or malicious files.

Remember that Frendi ransomware removal requires paying close attention and possibly employing some Windows features like the Safe Mode or System Restore. We have listed everything you can try when terminating the cryptovirus down below. Also, we have a few options for file recovery after ransomware elimination.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.