Malwareaware

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 27 June 2013

How to remove the Reveton Ransomware (UPDATED)

Posted on 06:32 by Unknown
This piece of malware, known as the Reveton ransomware, is still infecting people. And although the steps I made to remove this malware earlier on in the year still work for some variants, Most variants have adapted so the first method of removal no longer works. That being said, I have decided to write another guide with both methods of removal included.

If you can go into safe mode just fine, this is the guide you will want to follow.

Step 1: In safe mode with networking, open your web browser and go to http://www.malwarebytes.org/

Step 2: Click on free download. Download and Install Malwarebytes Anti-Malware

Step 3: Once Malwarebytes Anti-Malware has been installed, run a full scan.

Step 4: After the scan is complete, it may prompt you to reboot your computer to finish removing any detected items.


If you cannot go into safe mode without the ransomware blocking you from doing anything, or the above method does not work, follow this method. Note that for a few steps, you will need to have access to an uninfected computer if you cannot go into safe mode. These steps are slightly more involved then the above steps, but I have done my best to make it easier to do.

Step 1: Get a flash drive that can store at least 32 MB

Step 2: On an uninfected computer, go here and download the bit version corresponding to the bit type of the uninfected computer.

Step 3: Once the file has been downloaded, insert the flash drive you are going to use.

Step 4: Run the downloaded file.

Step 5: Once you see the start screen of Hitman Pro, click on the little picture of a person preforming a kick at the bottom of the window.

Step 6: You will now see instructions on how to create the Kickstarter Live USB. Click on the flash drive you will be using, then press install kickstart. You will then be presented with a warning that the flash drive will be erased. Click on yes to continue.

Step 7: Once the files have been downloaded and installed onto the flash drive, click the close button and take out the flash drive.

Step 8: Insert the flash drive into the infected computer with the computer turned off. Turn it on and then look for info on how to access the boot menu. If you cannot see any info, keys commonly used for the boot menu are F8, F11, or F12.

Step 9: Restart your computer and start tapping the indicated key. If one key does not work restart the computer and try another key on the above list.

Step 10: Now, select the flash drive with the Kickstart program installed and press enter. Once you see the new screen, press 1.

Step 11: Windows will load normally. After you log in, you will see the ransomware. Wait 15-20 seconds and you will see the Hitman Pro start screen. Click next to start the scanning process.

Step 12: Click No, I only want to perform a one-time scan to check this computer. Then click next.


Step 13: Once Hitman Pro has finished scanning, it will display a list of malware that it found. Click next, and if prompted, choose the 30 day free trial. Hitman Pro will now reboot your computer. Once it boots up, it will be free of the ransomware.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Removal Guides, Windows | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How to remove System Doctor 2014
    There is a new rogue AV making the rounds on the web called System Doctor 2014. For those that have just started reading my blog or for thos...
  • What are Bitcoin Miners?
    For my first post about Bitcoins, and for what I wish to be my last about the subject, we are going to be talking about what Bitcoin miners ...
  • How to keep spies from monitoring you through your computer or your phone.
    Those of you in The United States of America have most likely heard about that whole IRS scandal and the accompanying scandals of wiretappin...
  • Spotlight on Malware: The Gruel Worm.
    It's been around since Windows 2000, but there still is not a way to remove this worm without formatting the hard drive. I speak of the ...
  • I am going to be a billionaire!
    For those of you that have been reading my blog for some time, you know I like to mess with scammers, fake tech support and the like. But th...
  • Use VBScript to pull a joke on your friends.
    Do you want to play a trick on your friends, family, or coworkers? Well this one's for you. You can make a fake piece of malware on your...
  • Spotlight on Malware: MyDoom
    The MyDoom Windows worm, also known as Novarg, and Shimgapi will be the subject of our focus for this post. The MyDoom worm was first discov...
  • CryptoLocker as of 11/3/2013
    If you have read my other posts on this, you know. But for those of you who do not, there is a piece of ransomware that has been making the ...
  • The Big Game: Who's on our side?
    I recently helped a friend of mine remove malware from their computer when she be one mused on how lonely my job must be. "It must be s...
  • Java: No more coffee for you.
    Odds are that every blogger that has a tight focus on computer security has authored a blog post about Java. So why am I wasting your time? ...

Categories

  • Android
  • History Of
  • iOS
  • Java
  • Macs
  • Passwords
  • Removal Guides
  • Spotlight On Malware
  • The CryptoLocker Saga
  • What Does It Mean?
  • What's in a name?
  • Windows

Blog Archive

  • ▼  2013 (151)
    • ►  November (10)
    • ►  October (5)
    • ►  September (15)
    • ►  August (22)
    • ►  July (26)
    • ▼  June (17)
      • How to remove the Reveton Ransomware (UPDATED)
      • News on the new blog.
      • Why read my blog?
      • 6 outdated gadgets that we still use.
      • Why malware writers write malware.
      • Interrupting the fake tech support scammer: Part 2
      • Interrupting the fake tech support scammer: Part 1
      • I am going to be a billionaire!
      • Use VBScript to pull a joke on your friends.
      • Armor For Android
      • 12,000 Views.
      • Fake Tech Support Conversations: FAILS
      • Malwarebytes Anti-Malware
      • Spotlight On Malware: The Ari Virus.
      • There is no good malware: Part 2.
      • How to remove System Doctor 2014
      • There is no good malware: Part 1.
    • ►  May (25)
    • ►  April (15)
    • ►  March (7)
    • ►  February (6)
    • ►  January (3)
Powered by Blogger.

About Me

Unknown
View my complete profile