This is a detection for shortcut files (LNK) created by variants of the Ransom:Win32/Reveton family. If your PC is detected with this threat, then it is likely that you have also been infected with a Ransom:Win32/Reveton variant.
Ransom:Win32/Reveton variants arrive on your PC with a random name. They create a shortcut file in the Windows startup folder with the LNK extension, for example <startup folder>\ctfmon.lnk, to ensure the trojan is run every time you log on to Windows.
The Ransom:Win32/Reveton!lnk shortcut file uses an icon that resembles the following:
When opened, either by Windows when you log on, or manually if you click the shortcut, the link runs an installed copy of the Ransom:Win32/Reveton variant. We have seen it try to run the following variants, among others: