The DumbStackz virus belongs under the Chaos ransomware family. Harmful software of this type encrypts all the data on your PC (images, documents, excel tables, music, videos, etc) and adds its specific extension to every file, creating the read_it.txt files in every folder with the encrypted files.
What is DumbStackz virus?
DumbStackz adds its own .DumbStackz extension to the title of each encrypted file. For instance, a file entitled “photo.jpg” will be renamed to “photo.jpg.DumbStackz”. Just like the Excel file with the name “table.xlsx” will become “table.xlsx.DumbStackz”, and so forth.
In each folder containing the encoded files, a read_it.txt text document will appear. It is a ransom money note. Therein you can find information on the ways of contacting the racketeers and some other remarks. The ransom note most probably contains instructions on how to buy the decryption tool from the ransomware developers. You can get this decryptor after contacting [email protected] via email. That is it.
Dumbstackz Summary:
| Name | DumbStackz Virus |
| Ransomware family1 | Chaos ransomware |
| Extension | .DumbStackz |
| Ransomware note | read_it.txt |
| Ransom | 0.001 BTC |
| Contact | [email protected] |
| Detection | Win32:Secat, Trojan:MSIL/FormBook.PRY!MTB |
| Symptoms | Your files (photos, videos, documents) have a .DumbStackz extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Dumbstackz virus |
The read_it.txt document coming in package with the DumbStackz ransomware states the following:
Sheet well your files are locked. Lmao, well, sorry to say you won't be able to get them back without paying a fee. Unless you don't care about your files, I would encourage you to pay. The fee will cost you 0.001 bitcoin. Making this sh*t affordable. Sorry to cause you stress. Now, if you want to make this quick and simple, let\'s cut to the chase. Step 1: Buy the bitcoin. Unless you own Bitcoin, you will obviously need to buy it. Well, where the f*ck do I buy bitcoin?? You may be asking yourself that question. Luckily, there are many places to buy bitcoin. Such as apps like Coinbase, Crypto.com, Changelly Kraken, etc. There are also crypto ATMs to find one near you, go to coinflip.tech and enter a zip code. Or find others. Step 2: Create a Bitcoin wallet. If you are on a mobile device, I recommend downloading Cake Wallet or Trust Wallet. They are wallets that hold many different crypto currencies. Such as Bitcoin. And if you are using a Windows computer, you can use the Wassabi wallet. It is a great and fast wallet to set up. From there, you can send the address you are sending the 0.001 bitcoin to, which is below this line. Or scan the QR code that is shown in my wallpaper. (My Bitcoin Address): 17CqMQFeuB3NTzJ2X28tfRmWaPyPQgvoHV Step 3. Once you have sent the bitcoin successfully and it confirms through the blockchain, don\'t hesitate to contact me. I will provide you with the password to recover all of your files. It is another piece of software, so please disable virus and threat protection to allow it to decrypt successfully. Contact Me Once Paid: [email protected] (This is an email, so you will need to write to me by email.) Your files will be automatically deleted after 2 days from when this ransomware was installed. Do not try after 2 days because you will just be losing your money for nothing. Attempting to reset the computer will also delete all of your files, which you can try if you want. PAY EXACTLY 0.001 BITCOIN OR YOUR FILES WILL NOT BE RELEASED TO YOU. IF ONE OF MY WORKERS IS THE ONE WHO GAVE YOU THIS RANSOMWARE, THEY WILL WAIT FOR THE PAYMENT TO GO THROUGH, AND THEY WILL GIVE YOU THE DECRYPTER. DO NOT TRY NEGOTIATING, OR ME OR MY WORKERS WILL BLOCK YOU. THE AMOUNT WILL NEED TO BE 0.001 BITCOIN, EVEN WITH THE FEES. MAKE SURE TO GET SOME EXTRA BITCOIN FOR EASY PAYMENT. Again, if you have any issues or concerns, please contact me at [email protected] (This is an email, so you will need to write to me by email.) Bitcoin Address Again: 17CqMQFeuB3NTzJ2X28tfRmWaPyPQgvoHV
In the screenshot below, you can see what a directory with files encrypted by the DumbStackz looks like. Each filename has the “.DumbStackz” extension added to it.
How did DumbStackz ransomware end up on my PC?
There are many possible ways of ransomware infiltration.
Nowadays, there are three most popular ways for criminals to have the DumbStackz virus planted in your digital environment. These are email spam, Trojan infiltration and peer-to-peer file transfer.
- If you access your inbox and see letters that look just like notifications from utility services providers, postal agencies like FedEx, Internet providers, and whatnot, but whose mailer is strange to you, beware of opening those emails. They are very likely to have a malware file attached to them. Thus it is even riskier to open any attachments that come with emails like these.
- Another thing the hackers might try is a Trojan horse scheme. A Trojan is a program that infiltrates into your machine pretending to be something different. For example, you download an installer for some program you need or an update for some program. However, what is unboxed reveals itself a harmful program that encrypts your data. Since the update wizard can have any name and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The best thing is to trust the software companies’ official websites.
- As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. So you’d better be using trustworthy websites. Also, it is reasonable to scan the folder containing the downloaded files with the antivirus as soon as the downloading is complete.
How do I get rid of ransomware?
It is crucial to note that besides encrypting your files, the DumbStackz virus will most likely deploy Vidar Stealer on your computer to seize your credentials to different accounts (including cryptocurrency wallets). That program can derive your logins and passwords from your browser’s auto-filling cardfile.
How сan I avert ransomware infiltration?
Dumbstackz ransomware doesn’t have a endless power, neither does any similar malware.
You can armour your system from its attack in several easy steps:
- Ignore any emails from unknown mailboxes with unknown addresses, or with content that has nothing to do with something you are expecting (can you win in a lottery without participating in it?). In case the email subject is likely something you are expecting, scrutinize all elements of the dubious email with caution. A fake letter will always contain a mistake.
- Never use cracked or untrusted programs. Trojan viruses are often spreaded as a part of cracked products, possibly under the guise of “patch” which prevents the license check. But dubious programs are difficult to distinguish from reliable ones, because trojans may also have the functionality you need. You can try to find information about this software product on the anti-malware message boards, but the best way is not to use such software.
FAQ
🤔 How can I open “.DumbStackz” files?Are the “.DumbStackz” files accessible?
There’s no way to do it, unless the files “.DumbStackz” files are decrypted.
🤔 I really need to decrypt those “.DumbStackz” files ASAP. How can I do that?
It’s good if you have fаr-sightedly saved copies of these important files elsewhere. If not, there is still a function of System Restore but it needs a Restore Point to be previously saved. There are other ways to beat ransomware, but they take time.
🤔 What could help the situation right now?
Some of the blocked data can be located elsewhere.
- If you sent or received your critical files through email, you could still download them from your online mail server.
- You may have shared images or videos with your friends or relatives. Simply ask them to send those images back to you.
- If you have initially downloaded any of your files from the Internet, you can try doing it again.
- Your messengers, social media pages, and cloud drives might have all those files too.
- Maybe you still have the needed files on your old computer, a laptop, mobile, external storage, etc.
HINT: You can use file recovery programs2 to get your lost data back since ransomware blocks the copies of your files, deleting the original ones. In the tutorial below, you can see how to recover your files with PhotoRec, but remember: you won’t be able to do it before you kill the ransomware itself with an anti-malware program.

Yes, they are could be SCAM they also ripped me off. Using Paypal offers no protection or refund of your purchase.