The Frivinho virus falls under the ransomware type of infection. Malware of this type encrypts all user’s data on the computer (photos, documents, excel tables, audio files, videos, etc) and appends its specific extension to every file, leaving the PLS_READ_ME.txt text files in every folder with the encrypted files.
What is known about the Frivinho virus?
Frivinho will add its own .Frivinho0🥶 extension to the title of every encrypted file. For instance, a file named “photo.jpg” will be changed to “photo.jpg.Frivinho0🥶”. In the same manner, the Excel file with the name “table.xlsx” will be changed to “table.xlsx.Frivinho0🥶”, and so forth.
In each directory containing the encrypted files, a PLS_READ_ME.txt text file will be created. It is a ransom money note. Therein you can find information on the ways of paying the ransom and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. You can obtain this decryptor after contacting [email protected] through email. That is it.
Frivinho Summary:
| Name | Frivinho Virus |
| Extension | .Frivinho0🥶 |
| Ransomware note | PLS_READ_ME.txt |
| Ransom | 0.1473766 BTC |
| Contact | [email protected] |
| Detection | Gator.Adware.Advertising.DDS Virus Removal, Adware:Win32/Trickler Virus Removal, Trojan:MSIL/AgentTesla.AQF!MTB Virus Removal |
| Symptoms | Your files (photos, videos, documents) get a .Frivinho0🥶 extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Frivinho virus |
The PLS_READ_ME.txt document coming in package with the Frivinho malware states the following:
Oops, what happend? All of your files have been encrypted Your computer was infected with Frivinho Ransomware. Your files have been encrypted and you won\'t be able to decrypt them without our help. What can I do to get my files back? You can buy our special decryption software, this software will allow you to recover all of your data and remove the ransomware from your computer.The price for the software is $1,500. Payment can be made in Bitcoin or Robux. How do I pay, where do I get Bitcoin? Purchasing Bitcoin varies from country to country, you are best advised to do a quick google search yourself to find out how to buy Bitcoin. Many of our customers have reported these sites to be fast and reliable: Coinmama - hxxps://www.coinmama.com Bitpanda - hxxps://www.bitpanda.com Payment informationAmount: 0.1473766 BTC Check this pastebin to get the my newest Bitcoin Adress: hxxps://pastebin.com/raw/wZnisRDV And by cheking the pastebin, you can see more information about how you can pay.
In the picture below, you can see what a directory with files encrypted by the Frivinho looks like. Each filename has the “.Frivinho0🥶” extension appended to it.
How did my machine catch Frivinho ransomware?
There is a huge number of possible ways of ransomware injection.
Nowadays, there are three most popular methods for evil-doers to have ransomware acting in your digital environment. These are email spam, Trojan injection and peer file transfer.
- If you access your inbox and see letters that look just like notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are very likely to have a harmful item attached to them. So it is even riskier to open any attachments that come with emails like these.
- Another thing the hackers might try is a Trojan file scheme. A Trojan is an object that infiltrates into your machine disguised as something else. Imagine, you download an installer for some program you want or an update for some service. However, what is unpacked reveals itself a harmful agent that encodes your data. As the update file can have any name and any icon, you have to make sure that you can trust the resource of the stuff you’re downloading. The optimal thing is to trust the software developers’ official websites.
- As for the peer-to-peer file transfer protocols like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is reasonable to scan the folder containing the downloaded files with the antivirus as soon as the downloading is done.
How to remove ransomware?
It is crucial to inform you that besides encrypting your files, the Frivinho virus will probably deploy Vidar Stealer on your machine to seize your credentials to various accounts (including cryptocurrency wallets). The mentioned spyware can extract your credentials from your browser’s auto-filling cardfile.
How сan I avoid ransomware infiltration?
Frivinho ransomware doesn’t have a endless power, neither does any similar malware.
You can armour your computer from ransomware injection within several easy steps:
- Never open any emails from unknown mailers with unknown addresses, or with content that has nothing to do with something you are waiting for (can you win in a lottery without even taking part in it?). If the email subject is likely something you are waiting for, scrutinize all elements of the questionable email with caution. A hoax letter will surely have mistakes.
- Never use cracked or untrusted programs. Trojans are often shared as a part of cracked products, most likely as a “patch” to prevent the license check. Understandably, untrusted programs are difficult to distinguish from reliable ones, as trojans may also have the functionality you seek. Try searching for information on this software product on the anti-malware message boards, but the optimal way is not to use such software.
FAQ
🤔 How can I open “.Frivinho0🥶” files?Is it possible to open“.Frivinho0🥶” files?
Negative. That is why ransomware is so frustrating. Until you decode the “.Frivinho0🥶” files you will not be able to access them.
🤔 I really need to decrypt those “.Frivinho0🥶” files ASAP. How can I do that?
Hopefully, you have made a copy of those important files. In case you haven’t, there is still a chance that you do have a Restore Point from some time ago to roll back the whole system to the moment when it had no virus yet, but already had your files. All other solutions require time.
🤔 What to do if the Frivinho malware has blocked my computer and I can’t get the activation code.
🤔 And what should I do now?
Some of the blocked data can be located elsewhere.
- If you exchanged your important files through email, you could still download them from your online mailbox.
- You might have shared photographs or videos with your friends or family members. Just ask them to post those images back to you.
- If you have initially downloaded any of your files from the Web, you can try to do it again.
- Your messengers, social networks pages, and cloud disks might have all those files too.
- Maybe you still have the needed files on your old PC, a laptop, mobile, memory stick, etc.
USEFUL TIP: You can employ data recovery utilities1 to retrieve your lost information since ransomware encrypts the copies of your files, deleting the authentic ones. In the video below, you can see how to recover your files with PhotoRec, but remember: you can do it only after you remove the virus with an antivirus program.
I need your help to share this article.
It is your turn to help other people. I have written this article to help people like you. You can use the buttons below to share this on your favorite social media Facebook, Twitter, or Reddit.
Brendan SmithReferences
- Here’s the list of Top 10 Data Recovery Software Of 2023.

Leave a Comment