Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2019

How to remove Frend ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Frend ransomware is malware designed to lock up files and demand victims to contact hackers via undogdianact1986@aol.com email address

Frend ransomware

Frend ransomware is a newly-discovered malware that stems from Dharma/Crysis family. The main executable, shafao.exe, is usually delivered with the help of spam emails, brute-force attacks, fake updates, pirated software installers, etc. When the infection is triggered, malware populates modifications all over the system and starts the encryption procedure. Databases, videos, music, pictures, documents, compressed files, and other data gets encrypted with the help of AES or DES cipher, and an extension .frend is added. Additionally, Frend virus drops a ransom note FILES ENCRYPTED.txt and a pop-up window that prompts victims to contact hackers via undogdianact1986@aol.com or FobosAmerika@protonmail.ch. To regain access to data, users are asked to pay ransom payment in Bitcoins, although most security experts[1] recommend refraining from contacting malware authors.

Name Frend
Type Ransomware
Family Dharma/Crysis
Main executable shafao.exe
Cipher AES or DES
File extension .frend
Ransom note FILES ENCRYPTED.txt
Contact undogdianact1986@aol.com or FobosAmerika@protonmail.ch
Decryptable? No
Elimination Use anti-malware software like FortectIntego or SpyHunterCombo Cleaner

Fend ransomware, along with many similar variants like ETH or Qwex, is well-known file-locking malware that is recognized by multiple AV vendors as:[2]

  • TR/Dropper.Gen
  • Ransom.Crysis.Generic
  • Trojan.Encoder.3953
  • TrojWare.Win32.Crysis.D@6sd9xy
  • Ransom:Win32/Wadhrama.C
  • BehavesLike.Win32.Ransom.nc
  • Trojan.Ransom.Crysis.E

In total, 54 engines detect the threat at the time of the writing, so make sure you pick anti-virus software that can recognize and remove Fend ransomware. We suggest using Avira-based software FortectIntego or SpyHunterCombo Cleaner. In most cases, reputable security applications can also prevent malware from entering and corrupting files in the first place.

Unfortunately, most of those infected do not take adequate security measures and are surprised when they can't open files encrypted by .frend file virus. A brief .txt file informs victims about the infection:

all your data has been locked us
You want to return?
write email undogdianact1986@aol.com or FobosAmerika@protonmail.ch

On the other hand, the pop-up window which is titled undogdianact1986@aol.com, explains to users what to do in detail. According to criminals, they can submit one file (not larger than 1MB) for test decryption to make sure the decryptor works. Additionally, Frend ransomware authors warn victims that modifying data in any way or trying other recovery methods will result in permanent data loss.

However, you should not trust bad actors. Be paying the ransom you confirm that the illegal business employed by Frend virus developers is lucrative, and they will keep producing new malware and infect more people. Additionally, you might never even receive the decryptor, so you are risking not only to lose your files permanently but also money.

Thus, do not pay criminals. Take care of Frend ransomware removal using anti-malware software and then opt for alternative data recovery methods if you do not have backups ready. We explain the procedure below.

Frend ransomware virus

Ransomware is one of the most dangerous threats currently – here's what to do to protect yourself

With the appearance of modern ransomware viruses in 2013, the epidemic of file locking and demanding ransom began. Users all over the world faced a harsh reality: they either have to pay ransom in digital coins or lose their files forever. While most of users and organizations refuse to pay, a small percentage still do (although, only less than a half of those retrieve their files, according to reports)[3] and it proved to be one of the most successful money extortion methods. Thus, ransomware developers keep looking for sophisticated ways to infect users and make them pay.

Recovering from ransomware is difficult in most cases. Even if files can be decrypted with the official tool released by security researchers, it is still a procedure that requires times and patience. Therefore, to form a shield from the infection, follow these tips:

  • Use a reputable anti-malware solution at all times;
  • Backup your data regularly;
  • Patch software and the operating system as soon as updates are released;
  • Avoid dubious websites;
  • Watch out for attachments and hyperlinks in spam emails;
  • Scan each downloaded executable file[4] with tools like Virus Total;
  • Use ad-block.

Terminate Frend ransomware and protect your files from further compromise

As long as Frend virus will remain on your system, every single file that uses a particular file extension (hackers target the most commonly used files, like .pdf, .jpg, .dat, .html, .txt, .mpg and so on) will be encrypted as soon as it enters your computer. Therefore, you need to remove Frend ransomware and only then proceed with file recover and the operation of the machine. Furthermore, crypto malware can often be installed via other trojans, so there is a chance that your device is infected much more thank you initially thought.

Use anti-malware software for full Frend ransomware removal. If you notice that the virus is tampering with the security software, you should enter Safe Mode with Networking as explained below. Additionally, you could also try System Restore. Once you complete the elimination, you can start recovering files from backups or by using third-party software.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.