Back to the homepage

Tee Support Blog

Official News, Step-by-Step Guides and Tools

Best Way to Remove Worm:MSIL/Crilock.A From Windows

Published June 6th, 2014 by Cindy Young

Has your antivirus such as MSE (Microsoft Security Essentials) detected a virus called Worm:MSIL/Crilock.A? Antivirus seems unable to remove the threat completely as it keeps reminding you of the existence of the Worm:MSIL/Crilock.A. The following post will guide you how to stay away from Worm:MSIL/Crilock.A and any potential unwanted programs.

What Is Worm:MSIL/Crilock.A?

Worm:MSIL/Crilock.A is identified as a destructive worm infection which was designed by cyber criminals to smash target computer seriously. It’s first reported by MSE antimalware but cannot be removed completely by any security shield. This is because Worm:MSIL/Crilock.A utilizes advanced technology to hook itself onto affected computer silently. Normally, worm:MSIL/Crilock.A is distributed via hacked websites, spam email attachments or some free downloading resource. Computer users should pay more attention while using distrusted online resource.

Once getting inside, worm:MSIL/Crilock.A will slow down the performance of machine via taking up large amounts of system resource. Though you have run few programs, the usage of CPU would still be high. Besides, worm:MSIL/Crilock.A may modify the browser settings to keep you redirected to some unwanted websites without your permission. Meanwhile, lots of annoying ads may showing up that you cannot stop at all.

Worm:MSIL/Crilock.A is also responsible for the change of MBR (Master Boot Record) so that it could be launched automatically whenever Windows starts. Harmful as the virus is, it would even open a backdoor for remote attackers to reach your machine and reveal your valued information to the public in an attempt to gain illegal revenue. This will cause identity theft by the end.

To safeguard your computer from further damages, you may try to clean up Worm:MSIL/Crilock.A with your favorite antivirus software. Unfortunately the virus reappears again and again that seems not that easy to kill. If so, you can consider the effective manual removal to get rid of worm:MSIL/Crilock.A fully via deleting all its related processes, files and registry entries.

Disadvantage of Worm:MSIL/Crilock.A

  1. Sneaks into random computer without any consent.
  2. Highly consumption of CPU and corresponding slowness.
  3. Annoying pop-ups and icons linked with suspicious pages.
  4. Missing shortcuts on desktop and start menu.
  5. Blocked Firewall, Security Center and task manager.
  6. Sent-out emails to random contacts without user knowledge.
  7. Random and unexpected system freezes or crashes.
  8. Causes identity theft and financial fraud for illegal profits.
  9. Damages the affected PC by bringing in additional infections.

Worm:MSIL/Crilock.A Removal Instructions

Option one: Manually get rid of Worm:MSIL/Crilock.A by following the guides below.

1. Restart your computer and keep pressing F8 key before Windows launches. Use the arrow keys to select the “Safe Mode with Networking” option, and then hit ENTER key to continue.

2. Press Ctrl+Alt+Del or Ctrl+Shift+Esc combination to open Windows Task Manager and end suspicious processes.
If it does not work, please click the Start button, click the Run option, input taskmgr and press OK. The Windows Task Manager should be open.

3. Go to Computer Control Panel from Start menu and open Folder Options. Click View and then tick “Show hidden files and folders” and untick “Hide protected operating system files (Recommended)”. Then press OK.

4. Tap Windows+R keys together to haul out the Run window, then type in regedit and press Ok. When you have Registry Editor opened, track and delete the following registry values created by Worm:MSIL/Crilock.A.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘0’

5. Search for and get rid of the following Worm:MSIL/Crilock.A related files.

%AllUsersProfile%\Programs\{random letters}\
%AllUsersProfile%\Application Data\~r
%AllUsersProfile%\Application Data\~dll

Option two: Automatically uninstall Worm:MSIL/Crilock.A by runnning SpyHunter.

 SpyHunter is a powerful, real-time anti-spyware application that designed to assist the average computer user in protecting their PC from malicious threats like worms, Trojans, rootkits, rogues, dialers, spyware, etc. It is important to notice that SpyHunter removal tool works well and should run alongside existing security programs without any conflicts.

Step 1. Download SpyHunter by clicking on the icon below.

Step 2. Follow the details to complete the installation process. (Double click on the download file and follow the prompts to install the program.)

spyhunter run

spyhunter setup

spyhunter setup

Step 3. After the installation, run SpyHunter and click “Malware Scan” button to have a full or quick scan on your computer.

Step 4. Tick “Select all” and press “Remove” button to get rid of all the detected threats on your computer.

Video Guide on Modifying Windows Registry Entries

Attention: Want to safely and completely remove this perky mutating Worm:MSIL/Crilock.A virus infection but you cannot figure out a way? Click here to download SpyHunter tool to remove any stubborn computer threat now!

VN:F [1.9.18_1163]
Rating: 10.0/10 (1 vote cast)

Get a Safer, Cleaner & Faster PC!

A good spyware remover can safeguard your computer at real-time automatically.

  • Terminate latest, stubborn virus/spyware
  • Safe, effective and complete
  • Fix various PC problems

So, pick one of your favorite to protect your system easily.


Malwarebytes Anti-Malware

Download | Review

Malwarebytes is one of the most popular and widely used anti-virus and malware-removal software applications for both home and corporate computer users alike.

SpyHunter

Download | Review

SpyHunter is a powerful, real-time anti-spyware application designed to assist computer users in protecting their PC from trojans, rootkits and others.

How to Remove Trojan:Win32/Crilock.B Safely and Quickly

Published March 22nd, 2014 by Claire Brown

A threat called Trojan:Win32/Crilock.B installs on your computer? Your files have been encrypted and you asked to pay certain fine to decrypt them? You cannot remove Trojan:Win32/Crilock.B, please download SpyHunter to remove it as soon as possible.

Explanation of Trojan:Win32/Crilock.B

Trojan:Win32/Crilock.B is a malicious program that is a specific detection by Microsoft Security Essentials to a malware known as CryptoLocker. This threat is a type of Trojan that can try to encrypt your files on your computer and displays a webpage that asks you to pay a fee to unlock them. So in many cases, we may regard Trojan:Win32/Crilock.B as a kind of ransomware can lock down some programs on the affected computers. And then asks victims to pay some certain fee and get profits by scaring them. (more…)

VN:F [1.9.18_1163]
Rating: 10.0/10 (2 votes cast)

Get a Safer, Cleaner & Faster PC!

A good spyware remover can safeguard your computer at real-time automatically.

  • Terminate latest, stubborn virus/spyware
  • Safe, effective and complete
  • Fix various PC problems

So, pick one of your favorite to protect your system easily.


Malwarebytes Anti-Malware

Download | Review

Malwarebytes is one of the most popular and widely used anti-virus and malware-removal software applications for both home and corporate computer users alike.

SpyHunter

Download | Review

SpyHunter is a powerful, real-time anti-spyware application designed to assist computer users in protecting their PC from trojans, rootkits and others.

Remove Trojan: Win32/Crilock.A – Completely Delete and Get Rid of Trojan: Win32/Crilock.A

Published September 11th, 2013 by Claire Brown

My computer has picked up a detection called Trojan: Win32/Crilock.A, and which is known to have relationship with CryptoLocker. So I find my files, photos and documents are decrypted, and I cannot open them. Can anyone tell me why my computer is infected Trojan: Win32/Crilock.A? Who can help me?

Trojan: Win32/Crilock.A is a Detection of CryptoLocker Ransomware

Trojan: Win32/Crilock.A is known as a detection of CryptoLocker Ransomware and a dropper to introduce other Trojan, malware, and malicious onto the unprotected computers. Once this virus gets into the system, it will take the same actions with CryptoLocker virus. So attackers can see your files, photos, and documents encrypted immediately. In addition, the infected system can be locked, and users usually can see the locked screen and they cannot access into the desktop. In most cases, users find out they are prevented from accessing into some processes, such as downloading a program or file from internet. And it can also turn off the antivirus software installed on the compromised system. As a result, your computer is exposed to other threats directly. (more…)

VN:F [1.9.18_1163]
Rating: 10.0/10 (2 votes cast)

Get a Safer, Cleaner & Faster PC!

A good spyware remover can safeguard your computer at real-time automatically.

  • Terminate latest, stubborn virus/spyware
  • Safe, effective and complete
  • Fix various PC problems

So, pick one of your favorite to protect your system easily.


Malwarebytes Anti-Malware

Download | Review

Malwarebytes is one of the most popular and widely used anti-virus and malware-removal software applications for both home and corporate computer users alike.

SpyHunter

Download | Review

SpyHunter is a powerful, real-time anti-spyware application designed to assist computer users in protecting their PC from trojans, rootkits and others.


SHARING & SPREADING THE KNOWLEDGE:

It is very tough to fight against computer threats on the Internet alone. If it is at your convenience, we would be more than happy if you would like to help us share and spread our webpages with information about solutions and tutorials on fixing PC problems or removing latest threats. Knowledge is the most powerful weapon. Help your friends protect their computers!