Click on screenshot to zoom
Danger level 9
Type: Trojans
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Changes background
  • Connects to the internet without permission
  • Shows commercial adverts
  • Slow internet connection
  • System crashes
  • Annoying Pop-up's
Other mutations known as:
Trojan.Reveton.F, Trojan.Reveton.C , Trojan.Reveton.D

Trojan.Reveton

Trojan.Reveton is a computer that infects users with Ukash virus ransomware applications. It infects users in various countries, and changes the appearance of the ransom message based on the user's location. Basically, Trojan.Reveton is a multi-lingual infection that locks the user's computer and then displays a security message that is localized according to where the user lives. The message displayed covers the entire screen and Trojan.Reveton claims that the user has to pay a fine for being in possession of illegal material.

Most of the users get infected with the Trojan.Reveton through a drive-by download. The Trojan is known to arrive as a randomly named .dll file. It manages to take over your computer, because it enters Windows startup folder and creates a shortcut file for itself. Thus, once Trojan.Reveton is in, it does not allow you to access your desktop and displays the fake security message once you turn on your PC and the system loads.

The message that is displayed by Trojan.Reveton renders your computer unusable, because it does not allow you to access the desktop no matter what you do. The message looks like it has come from a legal law enforcement institution. For example, there might be FBI Moneypak that pretends to be an FBI representative. Then there is Cuerpo Nacional de Policia (Spain), Guardia di Finanza (Italy), Metropolitan Police Virus (UK), Bundespolizei National Cyber Crimes Unit (Germany) and many more variants of the ransom message displayed by Trojan.Reveton.

The main message in all of these notifications is that your computer has been blocked due to the fact that you have engaged in illegal activity. Mostly you are accused of storing illegally downloaded copyrighted material that is against your local laws, and then the user is threatened by an imprisonment sentence up to a few years for whatever he has "done". Naturally, the accusations displayed by Trojan.Reveton are groundless, but a lot of users panic enough to actually pay the ransom fee that varies from 100 USD and 100 euro to 50 pounds (depending on your locale).

It should be noted that Trojan.Reveton does not unlock your computer even if you do pay the ransom, thus it has to be removed from your computer immediately. Do not pay this ransomware a single cent. Follow the instructions below to remove Trojan.Reveton and get your computer back to normal:

1. Restart the computer and press F8 before the system boots up.
2. System boot menu will appear. Select Safe Mode with Networking and press Enter.
3. Open your Internet browser and access http://www.pcthreat.com/download-sph to download SpyHunter.
4. Install SpyHunter to remove Trojan.Reveton from your computer.

For Windows XP:

1. Reboot your computer and press F8 before Windows logo shows up.
2. Use arrow keys to navigate and choose Safe Mode with Networking. Hit Enter.
3. Access the Internet and follow this link to download SpyHunter
4. Open Start menu and launch Run.
5. Type "msconfig" into the Run box and press Enter.
6. When System Configuration menu loads, click the Startup tab and uncheck all programs on the list. Click OK and exit the menu.
7. Restart your computer in Normal mode to install SpyHunter.
8. Launch the full system scan and terminate the malware.

Download Spyware Removal Tool to Remove* Trojan.Reveton
  • Quick & tested solution for Trojan.Reveton removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan.Reveton

Files associated with Trojan.Reveton infection:

ms02A447E6.dat
dcomverc.exe
AdvService.exe
GOLD CLOCK.exe
C860A046F7934EBC36672B76381C1C.exe
pxkshxta.exe
nd.bin
KML81V7a.exe
svchost2.exe
sched.exe
NEUSBw32.dll
USB3Sw32.dll
appmgmts.dll
0_0u_l.exe
PATCH.exe
install_0_msi.exe
roper0dun.exe

Trojan.Reveton DLL's to remove:

NEUSBw32.dll
USB3Sw32.dll
appmgmts.dll

Trojan.Reveton processes to kill:

dcomverc.exe
AdvService.exe
GOLD CLOCK.exe
C860A046F7934EBC36672B76381C1C.exe
pxkshxta.exe
KML81V7a.exe
svchost2.exe
sched.exe
0_0u_l.exe
PATCH.exe
roper0dun.exe
install_0_msi.exe
Disclaimer

Comments

  1. Grace Devine Aug 4, 2014

    Hello team,
    I just have one question,if I download the 'SPYWARE REMOVAL TOOL TO REMOVE TROJAN REVETON ',EVEN THOUGH i READ THAT IT IS '100% FREE SCAN FOR WINDOWS' BUT IS IT 100% FREE TO REMOVE TROJAN REVETON ?

    THANK YOU FOR YOUR TIME

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.