I am going to try the suggestion
According to user Kenoindallas, he did pretty much what I am suggesting and seemed like it worked...whether or not you think it will work, I am simply looking for a method by which I can recover the old registry file/list. I see where you're coming from but Kenoindallas's account leaves me with some hope.
I am running Windows 7.
You can use ShadowExplorer to pick a previous restore point
Within that restore point, browse to the user's registry hive (C:\Users\[username]\NTUSER.DAT)
Export NTUSER.DAT to a temp location
Open regedit and Load Hive underneath HKEY_USERS > choose your NTUSER.DAT file
Now you can navigate to HKEY_USERS\[Temp_Hive_Name]\Software\CryptoLocker\Files
I haven't tested this, but it seems like it should work. You could probably even export the CryptoLocker key and import it into HKCU and run ListCrilock.exe to produce your list.
Maybe someone can confirm this - I don't have anything to test with at this point.
So I have a second infected machine quarantined. I am going to export the regkey - Import it and try running the ListCrilock. I should know in the next 20 minutes or so if this works.
I'll post my results here shortly.