Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2020

How to remove 259 ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

259 ransomware is a data-locking malware that is designed to prevent all data access until ransom is paid

259 ransomware

259 virus is a malicious program that stems from a broad malware family known as Dharma ransomware. Spotted in late October 2020, it locks all videos, pictures, music, pictures, documents, and other personal files with the AES (in some cases, DES + RSA) encryption algorithm,[1] appending .[259461356@qq.com].259 extension in the process. Suchlike files lose their original icons and can no longer be accessed.

There are two ransom notes that 259 ransomware delivers:

  • a pop-up window titled “259461356@qq.com” – it shows up as soon as data encryption is finished;
  • a text file “FILES ENCRYPTED.txt,” which can be opened by any text-editing program (usually, Notepad).

In these notes, the attackers indicate that victims need to pay for decryption in Bitcoins, although the precise sum is not specified. They also attempt to discourage users from using alternative methods to recover .259 files, as it may cause permanent damage to data.

Name 259 ransomware / [259461356@qq.com].259 virus
Type Ransomware, data locking malware, cryptovirus
Malware family Dharma 
Encryption method AES, although other algorithms can be used as well
File extension .259, although other strings, such as user ID, are added to each of the files, for example: picture.jpg.id-V724R243.[259461356@qq.com].259 
Ransom note Pop-up window titled “259461356@qq.com” and a text file “FILES ENCRYPTED.txt”
Contact 259461356@qq.com 
File Recovery If no backups are available, recovering data is almost impossible. Nonetheless, we suggest you try the alternative methods that could help you in some cases – we list them below
Malware removal Perform a full system scan with powerful security software, such as SpyHunterCombo Cleaner
System fix Ransomware might damage some Windows system files and configuration settings in a way that would prevent the OS from operating the way it used to. In case you experience crashes, BSODs, errors, and other stability issues, scan your machine with FortectIntego

Since Dharma is a large malware family, there are several ways how the payload may be delivered to victims. Nonetheless, researchers discovered that most infections occur when users attempt to open malicious spam email attachments, which are obfuscated by double extension. In other words, users might believe that they are opening a PDF file, while in reality, they are opening an executable (EXE) file.

259 files virus then modifies Windows system files to perform a successful encryption process of files with predetermined extensions, such as DOC, ZIP, JPG, TXT, XLS, and many others. Unfortunately, this process is rather quick, and it is performed much quicker than one can notice that something is wrong and interrupt the procedure by shutting down the PC.

As soon as 259 ransomware finishes the data-locking process, it delivers two ransom notes to ensure that victims know what happened to their data. Unlike stealthy malware that operates in the background and does everything to remain invisible, ransomware almost always provides some type of note for users to contact the attackers. As usual, hackers leave an email (259461356@qq.com) and other details in the note.

259 ransomware virus

FILES ENCRYPTED.txt is a brief message that only notifies about the contact email, while the popup window includes much more details about what victims have to do:

All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail 259461356@qq.com
Write this ID in the title of your message V724R243
In case of no answer in 24 hours write us to theese e-mails:259461356@qq.com
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

Besides encrypting data, the virus also changes the way Windows operates. For example, it attempts to delete System Restore points, as well as Shadow Copies, to prevent people from using automatic system recovery options. Also, it can change Windows registry keys for persistence. Thus, you should scan your device with FortectIntego after you remove 259 ransomware to automatically repair some of the system files that could have been damaged during the attack.

Speaking of 259 ransomware removal, you should use powerful anti-malware, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, to eliminate all the malware-delivered files and ensure that no incoming files are encrypted in the future.

.259 files can only be recovered safely via backups

As explained by cybercriminals in the ransom note, users need to pay Bitcoin in order to recover .259 virus files. They also warn victims that modifying the file extension or employing third-party security solutions can permanently damage the locked data. While malicious actors could be bluffing, they might also be correct.

259 ransomware encrypted files

Many users mistakenly believe that they can remove .259 extension as soon as they scan their systems with anti-malware. However, it is not the case, and files will remain locked (although ransomware removal is a necessary process for recovery from the infection).

The truth is, if malware was operating correctly during the infection and encryption process, the only secure way to restore locked files is by using backups, as only cybercriminals have a unique key that is required to decrypt data. However, there are several risks involved when it comes to ransom payments to attackers, as they might simply fail to deliver the decryptor in the first place.

Thus, experts[2] do not recommend paying ransoms and instead employ alternative .259 file recovery solutions below. They include using automated Windows recovery options or employing third-party tools.

259 ransomware removal instructions

Many users get extremely anxious after being hit by ransomware, while others know nothing about this type of infection. As a result, many believe that 259 ransomware removal will also restore the encrypted files. However, as explained above, it is not the case at all. The easiest way to restore data is by using backups that are located on a different medium, such as an external hard drive or a Cloud.

259 ransomware detection

If you have no backups, you should first make a copy of your most important files before you remove 259 ransomware from your computer. Otherwise, you might damage the files permanently. Besides, cybersecurity researchers might be able to find bugs within this version of Dharma and release a free decryption tool in the future.

To delete 259 virus from your system, you should employ powerful security applications that can detect the malicious payload.[3] We recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes – these security tools should also prevent you from being infected in the future.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.