Skip to Main NavigationSkip to Secondary NavigationSkip to Content
ResNet Logo
 Home  :: Support  :: Security  :: Info  :: Policies  :: Sign Up  :: FAQ  :: Contact
Security
Viruses
Spyware
Windows Updates
Passwords
Windows Firewall
Protect Your PC
Trojan Horses
Spam
AIM Viruses
Privacy
RealPHX Removal Instructions


ALERT: Before attempting to complete any of these instructions, it is STRONGLY recommended that you make a complete backup of your system Registry. This will allow you to correct any mistakes that you may make, or help to recover from any problems that result from following these instructions.

NOTE: Please note that ResNet cannot provide in-depth technical assistance to non-N.C. State University students. If you are not a student, please contact your Internet Service Provider (ISP) or anti-virus software vendor for assistance.


Removal Instructions:

RealPHX (Trojan.Sinkin):

  1. Reboot your computer in Safe Mode
    1. Reboot the computer
    2. Just before Windows begins to load, press F8
    3. Select Safe Mode
  2. Click on Start, then click Search, then click For Files or Folders...
  3. Enter "av.exe" into the search box (without quotes).
  4. Delete files named "av" or "av.exe" ONLY. Do not delete other files with 'av' as part of the file name.
  5. Click on Start, then click Run...
  6. Enter "regedit" (without quotes).
    WARNING: Editing the registry of your computer could be dangerous. We strongly recommend that you make a backup of your registry before continuing. Check out Symantec's Instructions for backing up your registry.
  7. Browse to "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"
  8. Delete the "Antivirus" Key with a value of "c:\av.exe"
  9. Browse to "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{Random Numbers}\FilesNamedMRU"
  10. Delete the "000" Key with a value of "av.exe"
  11. Close Regedit.
  12. Click on Start, then click on Control Panel.
  13. Double-click on the Internet Options control panel.
  14. Change your default home page.
  15. Open your virus scanner, and run a COMPLETE virus scan on your computer. If your virus scanner definition files are up to date, it should detect and successfully clean RealPHX.
  16. If you have a spyware removal program, run it and let it attempt to detect and clean any spyware that has been installed.
  17. Reset your buddy profile in AIM.
  18. Reboot your computer.

 Home :: Support :: Security :: Info :: Policies :: Sign Up :: FAQ :: Contact

Disclaimer :: NC State University