Uploaded November 2013 | Updated September 2026, 2 weeks ago
malwareup.org
NOTE: As of August 6th 2014, the information about Cryptolocker in this video is obsolete. Security researchers managed to procure ALL private keys and decryption is now possible for everyone. Simply follow the link, submit an encrypted file and your private key will be emailed to you: decryptcryptolocker.com
After two months of struggling, I finally give CryptoLocker a somewhat in depth review. More information about the ransomware can be found here: bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information
Note: Removal for this malware is trivial, since once your files are encrypted, no antivirus can restore them. One can use Malwarebytes' to remove the program, but the files will still be damaged.
malwareup.org
NOTE: As of August 6th 2014, the information about Cryptolocker in this video is obsolete. Security researchers managed to procure ALL private keys and decryption is now possible for everyone. Simply follow the link, submit an encrypted file and your private key will be emailed to you: decryptcryptolocker.com
After two months of struggling, I finally give CryptoLocker a somewhat in depth review. More information about the ransomware can be found here: bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information
Note: Removal for this malware is trivial, since once your files are encrypted, no antivirus can restore them. One can use Malwarebytes' to remove the program, but the files will still be damaged.







![ThinkPoint / Fake MSE Alternate Removal Guide + Manual Removal Instructions
Since this rogue has infected so many computers, I figure Id make another removal video, this time with alternate instructions.
1. Reboot your computer
2. After your manufacturers logo, tap the F8 key
3. Select Safe Mode with Networking
4. Select your operating system
5. Log in as the account named Administrator
6. Run Task Manager
7. Kill hotfix.exe
8. Run explorer.exe
9. Download and install Malwarebytes Anti-Malware from http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe and run a Quick Scan.
IF THIS DOES NOT WORK FOR YOU
10. Download Combofix from http://www.bleepingcomputer.com/download/anti-virus/combofix
11. Click Yes on the disclaimer
12. Click No on the Windows Recovery Console option
13. After the scan, dismiss the log and reboot your machine
MANUAL REMOVAL INSTRUCTIONS
Delete the following files:
%UserProfile%Application Datahotfix.exe (in Windows XP)
%UserProfile%AppDataroaminghotfix.exe (in Windows Vista/7)
(Hint: Type %userprofile% into the path field of an Explorer window to find where it is)
Navagate to the following registry key:
[HKEY_CURRENT_USER/SOFTWARE/MICROSOFT/WINDOWS NT/CURRENT_VERSION/Winlogon]
Edit the key
Shell
so that the data becomes
C:Windowsexplorer.exe
Note: For manual removal, you may need to log on to all accounts on the machine to fix the registry key
http://malwareup.org/donate
http://malwareup.org
http://malwareup.org/chat ThinkPoint / Fake MSE Alternate Removal Guide + Manual Removal Instructions](https://i.ytimg.com/vi/EdaaG96GsU4/mqdefault.jpg)


