Matrix Ransomware is ransomware virus that encrypts user files with either symmetric or asymmetric cryptography. It adds .matrix extension to encrypted files. After finishing encryption process, Matrix creates a text file matrix-readme.rtf or Readme-Matrix.rtf. Virus places this files in every folder with affected files. This text file contains instruction to pay the ransom, where malefactors encourage users to contact them via e-mails: email@example.com, firstname.lastname@example.org or email@example.com.
Dharma virus, unlike similar types of ransomware, does not change desktop background, but creates README.txt or Document.txt.[firstname.lastname@example.org].zzzzz files and places them in each folder with compromised files. Text files contain message stating that users have to pay the ransom using Bitcoins and amount is approximately $300-$500 depending on ransomware version. The private decryption key is stored on a remote server, and there currently impossible to break the encryption of the latest version.
Startpageing123.com is unwanted search engine that can e installed in Google Chrome, Mozilla Firefox and Internet Explorer. Main page of this site resembles popular search engines, and redirects to Google.com. It is set as homepage, default search engine. Startpageing123.com infects browser shortcuts, by modifying shortcut properties. This threat is classified as browser hijacker, because of browser settings modification and search redirects.
Qtipr.com is domain that is used by browser hijackers to override browser settings in Google Chrome, Mozilla Firefox and Internet Explorer. It is almost identical to previously described Fanli90.cn hijacker. The purpose of this computer threat is to display ads, pop-ups and lead users to certain websites, while browsing. Qtipr.com website has yellow header and “Funny collection” name, like all the threats of this type.
Hakunamatata Ransomware is new version of NMoreira Ransomware (NMoreira 2.0). Virus encrypts user files with RSA-2048 and AES-256 encryption algorithms and adds .hakunamatata suffix to affected files. After finishing infection process Hakunamatata creates file “Recovers files yako.html” on the desktop. Hackers offer users to contact them using Bitmessage system and pay the ransom. Amount of ransom is currently unknown, but likely it is somewhere between $300 and $1500. Decryption key is generated during encryption, and currently unknown. Therefore, there is no way to decrypt or restore files unless users has backup.