The Trojan:Win32/Reveton.R!lnk is a malicious application which is categorized as ransomware. It claims itself as a legitimate law enforcement agency which works to prevent the users from illegal use of the internet. In reality this is nothing more than a notorious ransomware that is developed to trap users all over the world. Once installed, the Trojan:Win32/Reveton.R!lnk block the infected computer completely, and users cannot access their browser as well as other important files at all. There will be a message displayed which shows that your computer is blocked because of any illegal downloads or other illegal activity and you are asked to pay a fine. Even if you pay the fine, they will never unblock your computer, and your important personal information such as credit card numbers, emails, and passwords are also transferred to these cyber criminals which then use this information for the online frauds.

Manual Removal Method of Trojan:Win32/Reveton.R!lnk

Once detected, you have to remove this malicious ransomware Trojan application immediately. You can use the manual removal method to delete this virus if you are an advance level computer user. If you are a new user, and not aware about the registry entries, as well as file issues, you have to choose the automatic removal tool. The manual removal method instructions are detailed below:-

Start the Computer in Safe Mode

Before proceeding towards deleting the files, folders, and registry keys, you have to terminate the normal mode of the infected computer by restarting the machine and go to the boot options through F8 key. Here you have to select the safe mode option from the list.

Delete the Malicious Processes

Once the computer starts working in the safe mode, you have to start the task manager window through Ctrl+Alt+Delete keys, and then click on the processes tab. Your goal is to delete the following related processes of Trojan:Win32/Reveton.R!lnk:-

  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Delete the Associated Files

After removing the processes associated to this dangerous ransomware, you have to delete the files and folders related to Trojan:Win32/Reveton.R!lnk. You have to find the following files along with folders in the system files folder to delete them immediately:-

  • %Desktopdir%\Trojan:Win32/Reveton.R!lnk.lnk
  • %Programs%\Trojan:Win32/Reveton.R!lnk\Trojan:Win32/Reveton.R!lnk.lnk

Delete Registry Entries

The backbone of manual removal process is removing the malicious registry entries created by the Trojan:Win32/Reveton.R!lnk in the windows registry. The changes in the registry are carried out through registry editor which can be started by clicking on the start button, select run, type regedit, and press ok button. Once the registry editor started, you have to find and remove the following associated entries:-

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/Reveton.R!lnk\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/Reveton.R!lnk
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/Reveton.R!lnk\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/Reveton.R!lnk\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/Reveton.R!lnk\DisplayName Trojan:Win32/Reveton.R!lnk

Once the registry entry removal process of the above mentioned entries completed, you have to close the registry editor and start the computer in the normal mode. Always run a complete system scan on the infected computer after updating your existing antivirus program.

How to Remove Trojan:Win32/Reveton.R!lnk ?
Tagged on:                             

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>