点按此处一切换到中文:Chinese
This ransomware can crack Windows MBR/GPT and $MFT. If you reboot to PE system, you cannot recover your files if your computer is MBR mode. [Warning] Only for studying purposes!
When the ransomware starts, it will first backup $MFT and MBR, and overwrite new code to MBR. Once MBR is written, the computer isn't able to boot up again. Once $MFT is written, the data will not be able to recover in PE mode.
Only for studying purposes.