Uploaded May 2013 | Updated September 2026, 1 week ago
Per viewer suggestion, I take a look at the subtle differences you may notice if you pay (or find a key) for a fake antivirus program. I don't really recommend this anymore for reasons explained in the video.
Per viewer suggestion, I take a look at the subtle differences you may notice if you pay (or find a key) for a fake antivirus program. I don't really recommend this anymore for reasons explained in the video.

![CryptoLocker (Crilock) File Encrypting Ransomware [OBSOLETED]
http://malwareup.org
NOTE: As of August 6th 2014, the information about Cryptolocker in this video is obsolete. Security researchers managed to procure ALL private keys and decryption is now possible for everyone. Simply follow the link, submit an encrypted file and your private key will be emailed to you: https://www.decryptcryptolocker.com/
After two months of struggling, I finally give CryptoLocker a somewhat in depth review. More information about the ransomware can be found here: http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information
Note: Removal for this malware is trivial, since once your files are encrypted, no antivirus can restore them. One can use Malwarebytes to remove the program, but the files will still be damaged. CryptoLocker (Crilock) File Encrypting Ransomware [OBSOLETED]](https://i.ytimg.com/vi/D4t1rr7BBbM/mqdefault.jpg)







![ThinkPoint / Fake MSE Alternate Removal Guide + Manual Removal Instructions
Since this rogue has infected so many computers, I figure Id make another removal video, this time with alternate instructions.
1. Reboot your computer
2. After your manufacturers logo, tap the F8 key
3. Select Safe Mode with Networking
4. Select your operating system
5. Log in as the account named Administrator
6. Run Task Manager
7. Kill hotfix.exe
8. Run explorer.exe
9. Download and install Malwarebytes Anti-Malware from http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe and run a Quick Scan.
IF THIS DOES NOT WORK FOR YOU
10. Download Combofix from http://www.bleepingcomputer.com/download/anti-virus/combofix
11. Click Yes on the disclaimer
12. Click No on the Windows Recovery Console option
13. After the scan, dismiss the log and reboot your machine
MANUAL REMOVAL INSTRUCTIONS
Delete the following files:
%UserProfile%Application Datahotfix.exe (in Windows XP)
%UserProfile%AppDataroaminghotfix.exe (in Windows Vista/7)
(Hint: Type %userprofile% into the path field of an Explorer window to find where it is)
Navagate to the following registry key:
[HKEY_CURRENT_USER/SOFTWARE/MICROSOFT/WINDOWS NT/CURRENT_VERSION/Winlogon]
Edit the key
Shell
so that the data becomes
C:Windowsexplorer.exe
Note: For manual removal, you may need to log on to all accounts on the machine to fix the registry key
http://malwareup.org/donate
http://malwareup.org
http://malwareup.org/chat ThinkPoint / Fake MSE Alternate Removal Guide + Manual Removal Instructions](https://i.ytimg.com/vi/EdaaG96GsU4/mqdefault.jpg)
