Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Trouble removing RealAV

  • Please log in to reply
1 reply to this topic

#1 frankie898


  • Members
  • 1 posts
  • Local time:01:45 AM

Posted 06 December 2008 - 03:15 AM


I believe I have the Real Antivirus malware on my PC. It was discovered a few days ago by a family member and reported to me. I was not home when the problem initially was noticed. I am currently running Windows XP.

After reading about it online, I have the typical symptoms. Flashing WARNING box permanently fixed onto my desktop that reads exactly this: "WARNING: Dangerous Spyware. There are many viruses found on your computer, such as Trojan Horses, PassCapture, etc. Your personal data can come into wrong hands. Please, follow that link to more about your data safety and privacy. Thank"

I also have a system try icon that is a red circle with a white X inside that has a pop-up bubble that reads exactly this: "Warning! Security report. Your computer is infected! It is recommended to start spyware cleaner tool."

Every now and then. my browser will open by itself to the Real Antivirus website where their antivirus "product" is available to buy. According to most things I have read, the product is completely fake and the objective is to steal credit card info.

My problem lies in how to remove it.

According to this website and many others I have visited, there are typical files associated with RealAV. The ones listed on this website are:
c:\Program Files\RealAV
c:\Program Files\RealAV\RealAV.exe
c:\Program Files\RealAV\vscan.tsi
c:\Program Files\RealAV\zlib.dll
c:\Program Files\RealAV\Infected
c:\Program Files\RealAV\Suspicious
%UserProfile%\Start Menu\Programs\RealAV
%UserProfile%\Start Menu\Programs\RealAV\RealAV.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\RealAV.lnk

And the registry info:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "RealAV.exe"

With all this being said, I have tried a few solutions:
1. Running Malwarebytes - Didnt pick up the files, but picked up some other things
2. Symantec AV (last LiveUpdate on 11/28/08) - Didnt pick up the files and, according to them, has had a solution for RealAV since June of this year.
3. Ran Kaspersky free online scan - Picked up all of my Symantec Quarantines and about 6 or so other files that I promptly removed after I got the log from the scan.

Does anyone have any suggestions on how to find/remove it? RealAV seems like the right diagnosis, but its not showing any of the typical files associated with it. Im wondering if it has been changed since the time it was discovered.

Also, as I mentioned before, I have read that it tries to steal credit card info. Can it only steal the information if I buy the fake product and provide my number? Or can it also pull information from things I have ordered online in the past or things I will order in the future until its gone? (i.e. Amazon.com orders, eBay)

Any information or insight will be gladly appreciated!


BC AdBot (Login to Remove)


#2 garmanma


    Computer Masochist

  • Members
  • 27,809 posts
  • Gender:Male
  • Location:Cleveland, Ohio
  • Local time:01:45 AM

Posted 06 December 2008 - 12:22 PM

Please reboot your computer and update Malwarebytes. This time do a FULL scan and post the new log here
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users