Viruses on smartphones Realme is a much more serious problem more common than it seems. Even if you did not install suspicious APK files, malware could penetrate through advertising banners in the browser, phishing links in instant messengers, or vulnerabilities in the firmware Realme UI. The main danger: some viruses disguise themselves as system processes (for example, com.realme.securitycheck), which complicates their detection by standard antiviruses.

In this article - 4 working methods for removing viruses from phones Realme (including models GT Neo 5, Narzo 60 Pro, Realme 10 Pro+ and others), and also list of signs of infectionwhich are often ignored. We will pay special attention hidden threats in the folder /system/priv-app/that survive after resetting the settings. All instructions are adapted to the latest version Realme UI 5.0 (based on Android 14).

Signs of a virus on Realme: how to recognize an infection

The first signal is uncharacteristic behavior of the phonewhich is not associated with overheating or battery wear. For example, if Realme C55 starts to spontaneously open a browser with advertising or send SMS to short numbers, this is almost guaranteed to be a virus. But there is something less. obvious symptoms:

  • ๐Ÿ”‹ The battery runs out in 2-3 hours at minimal load (check Settings โ†’ Battery โ†’ Battery usage - if there is an unknown process with a consumption of >15%, this is an alarming sign).
  • ๐Ÿ“ฑ New applications appear with names like System Update, Flash Service or Android Security (they are not in the official one Google Play).
  • ๐Ÿ’ฐ Money is debited from the account (even small amounts of 1-5 rubles) or an SMS is received with confirmation payments that you did not make.
  • ๐Ÿ” An antivirus (for example, Malwarebytes or Dr.Web) finds threats, but cannot remove them, giving an error. Access denied.

Viruses that block access to settings or imitate system ones are especially insidious notifications (for example, โ€œYour phone is infected! Click here to cleanโ€). Such threats are often distributed through APK files from unverified sources or through vulnerabilities in MediaTek Helioprocessors (used in Realme 8/9/10 series).

โš ๏ธ Attention: If after rebooting the phone the virus symptoms return, this means that malicious code has been introduced into the system partition. In this case, only a full reset from flashing will help (see section 4).
๐Ÿ“Š How do you usually protect your Realme from viruses?
I install an antivirus
I donโ€™t download APK from unknown sources
I regularly update the firmware
Not at all protecting
Other

Method 1: Removing the virus manually (without resetting)

If the virus has not yet been deeply integrated into the system, it can be removed without losing data. This method is suitable for advertising viruses (show ads) and Trojansthat do not block access to the settings. steps:

  1. Start the phone in safe mode:

    Hold the power button โ†’ hold your finger on the option Disable โ†’ a prompt will appear to go in Safe Mode. Only system applications work in this mode, which will help identify the virus.

  2. Check the list of installed applications:

    Go to Settings โ†’ Applications โ†’ Manage applications โ†’ sort by installation date. Delete anything suspicious, especially if the name contains typos (for example, GoogIe Play instead of Google Play).

  3. Clear cache and browser data:

    Viruses often penetrate through Chrome or Realme Browser. Go to Settings โ†’ Applications โ†’ Browser โ†’ Storage โ†’ Clear cache/data.

  4. Disable administrator rights for unknown applications:

    B Settings โ†’ Security โ†’ Device administrators check if there are any third-party apps. If there are, uncheck them and remove them.

If a virus blocks access to settings, try turn it off via ADB (requires a computer). Connect Realme via USB, turn on USB debugging (Settings โ†’ About phone โ†’ Build number - tap 7 times, then return to Advanced โ†’ For developers) and run the command:

adb shell pm uninstall -k --user 0 name.of.package.virus

To find out the name of the package, use the command:

adb shell pm list packages | grep "suspicious_word"

โ˜‘๏ธ Checklist before manual cleaning

Done: 0 / 5

Method 2: Using antiviruses (which work on Realme)

Standard Google Play Protect often misses viruses, especially if they are disguised as system files. For Realme we recommend specialized antivirusesthat they can. scan folder /system:

Antivirus Effectiveness against viruses on Realme Features Cons
Malwarebytes โญโญโญโญโญ Finds rootkits and spyware, scans system folders Paid version is needed to remove some threats
Dr.Web Light โญโญโญโญ Good detects Trojans and ransomware banners Many false positives for Chinese firmware
Bitdefender โญโญโญโญโญ Cloud scanning, minimal CPU load Requires registration for complete cleaning
Kaspersky โญโญโญ Good for phishing attacks Significantly slows down Realme with 4โ€“6 GB of RAM

Before scanning:

  • ๐Ÿ“ฑ Disable battery optimization for the antivirus (Settings โ†’ Battery โ†’ Battery optimization โ†’ Find antivirus โ†’ Disable).
  • ๐Ÿ” Enable Deep scanning (not fast!).
  • ๐Ÿ›ก๏ธ After removing the virus reboot phone โ€”some threats are restored before reboot.
โš ๏ธ Attention: If the antivirus finds a virus in the folder /system/app/ or /system/priv-app/, but cannot remove it, this means that malicious code is embedded in the firmware. In this case, only flashing will help (see section). 4).
๐Ÿ’ก

If the antivirus does not start due to a virus, download its APK on another device, rename the file to update.apk and transfer it to Realme via a USB channel. Viruses often block installation by name. (for example, malwarebytes.apk).

Method 3: Reset to factory settings (when it really helps)

Reset (Hard Reset) removes viruses that are in the user partition (/data), but does not helpif malicious code penetrated into:

  • ๐Ÿ“ System partition (/system) - a typical case for viruses distributed through firmware from third-party developers.
  • ๐Ÿ”ง Boot or Recovery - such viruses are activated even before loading Android.
  • ๐Ÿ“ฑ Folder /vendor - often used to disguise itself as drivers MediaTek.

If you still decide to reset:

  1. Save important data (photos, contacts) to Google Drive or computer. Viruses may remain in backup copies!
  2. Go to Settings โ†’ Advanced โ†’ Reset โ†’ Delete all data.
  3. After reset do not restore data from a backupuntil you are sure that the phone is clean.

For models Realme GT and Narzo with an unlocked bootloader (bootloader), viruses can survive even after a reset. In this case, you need a complete flashing via SP Flash Tool or Realme Flash Tool.

What to do if the virus returns after the reset?

This means that the malicious code is located in the system partition. You will need:

1. Unlock the bootloader (official instructions on the Realme website).

2. Install custom recovery (TWRP).

3. Flash clean firmware via fastboot.

Details are in section 4.

Method 4: Flashing the phone (as a last resort)

If a virus survived after reset or blocks access to settings, the only reliable way โ€” full flashing. For Realme this can be done in two ways:

Method 1: Through the official Realme Flash Tool

Suitable for most models (Realme 6/7/8/9/10, GT series, Narzo). You will need:

  • ๐Ÿ–ฅ๏ธ Computer with Windows 10/11.
  • ๐Ÿ”Œ USB cable (preferably original).
  • ๐Ÿ“„ Firmware for your model (download from realme official website).

Instructions:

  1. Install Realme Flash Tool and drivers MediaTek (if you have a processor Helio) or Qualcomm (for Snapdragon).
  2. Turn off the phone โ†’ press Volume up + Volume down + Power to enter Fastboot.
  3. Connect the phone to the PC and run Flash Tool. Select the downloaded firmware (file with the extension .ozip).
  4. Click Start and wait until it finishes (do not turn off the phone!).

Method 2: Through custom recovery (TWRP)

Suitable for advanced users. Allows you to flash custom firmware (for example, LineageOS), if the official one does not help. Attention: this method requires unlocking the bootloader, which will reset all data and may void the warranty.

fastboot flashing unlock

fastboot flash recovery twrp.img

fastboot reboot recovery

After installation TWRP flash a clean firmware via the recovery menu.

โš ๏ธ Attention: Flashing through unofficial tools (for example, SP Flash Tool for MediaTek) can lead to briku (breakdown) of the phone if the wrong firmware is selected. Always check the compatibility of the firmware file with your model. embedded in the system partitions. After the procedure, the phone will become โ€œcleanโ€, but all data will be lost. Realme (For example, RMX3708 For Realme 10 Pro+).
๐Ÿ’ก

Reflashing is the only way to remove viruses embedded in system partitions. After the procedure, the phone will become โ€œcleanโ€, but all data will be lost.

How to protect Realme from viruses in the future

Even after successful removal of the virus, the risk of re-infection remains. Basic protection measures for Realme:

  • ๐Ÿ”’ Disable installation from unknown sources: Settings โ†’ Security โ†’ Unknown sources (disable for all browsers).
  • ๐Ÿ›ก๏ธ Update. firmware: Realme regularly closes vulnerabilities in Realme UICheck for updates in Settings โ†’ Update Center.
  • ๐Ÿšซ Do not use "optimizers" and "cleaners" from Play Market - many of them themselves contain malicious code.
  • ๐Ÿ” Check application rights: if the messenger asks access to SMS or contacts for no reason - delete it.

For models with processors MediaTek (Realme C-series, Narzo 50A) it is especially important do not install modified firmware from unverified sources - they often contain backdoors (hidden vulnerabilities).

๐Ÿ’ก

Create a separate user in Android to install suspicious applications: Settings โ†’ System โ†’ Multiple users. Viruses will not be able to access the main profile.

FAQ: Frequently asked questions about viruses on Realme

Is it possible to remove a virus without losing data?

Yes, if the virus is only in the user section. Try safe mode + manual removal (section 2) or antivirus (Malwarebytes or Bitdefender).If the virus is in the system files, you cannot do without resetting or flashing it.

Why does the antivirus not find the virus, but the phone slows down and shows ads?

Most likely, it is advertising virusmasquerading as a system application (for example, com.android.systemCheck the list of applications in Settings โ†’ Applications for suspicious packages with names similar to system ones.

The virus is blocking access to the settings. What to do?

It will help you ADB (section 2) or flashing via Fastboot (section 4), try. go to Recovery (press Volume up + Power) and reset from there.

Is it possible to recover data after reset?

It is possible, but only if you are sure that the backup copy is clean. Viruses can be stored in backups Google Account or Realme Cloud. It is better to transfer data manually (photos, contacts) via a computer.

Which Realme models are most often infected with viruses?

Models with processors MediaTek Helio G (Realme C11/C21/C33, Narzo 30/50are the most vulnerable due to vulnerabilities in drivers. Phones are also at risk. with unlocked bootloader and custom firmware.