We searched the web for a fix to our problem – couldn’t find one for antivirus 360. Here were the symptoms we identified on a PC:

* Windows registry would only stay open for 10 seconds
* Windows CMD would not open
* Anti-virus and Firewall were disabled and removed
* Windows Security Center disabled – you don’t see the shield
* Browser redirected to malicious websites
* Not able to download or update ANY security products

We suggest you use which does a great job of removing most of the malicious files. Before you install (or any security software including being able to download windows updates) you need to search for and remove the following entries, otherwise Malwarebytes (or any other security software) will not work properly, download or install:

* Winconfig.dll
* A360.exe
* Winsystems.dll
* DELETE all files in the "PREFETCH" folder

On deletion of the above files, you can now download and install .

TIP: We couldn’t update so we had to update the database manually. Click here for manual download.

Here are the keys, data items, files and folders that you should remove:

Registry Keys Infected:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{d263fa6d-84cc-48a8-9af6-c664362b7a5b}

HKEY_CLASSES_ROOTCLSID{d263fa6d-84cc-48a8-9af6-c664362b7a5b}

HKEY_LOCAL_MACHINESOFTWAREUAC

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesUACd.sys

Registry Data Items:

HKEY_CURRENT_USERSOFTWAREPoliciesMicrosoftInternet ExplorerControl PanelHomepage

HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterAntiVirusDisableNotify (Disabled.SecurityCenter)

HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterFirewallDisableNotify (Disabled.SecurityCenter)

HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterUpdatesDisableNotify (Disabled.SecurityCenter)

Folders Infected:

A360 (Rogue.A360Antivirus)

Files Infected:

A360.lnk

Help.lnk

Registration.lnk

A360.lnk

MicrosoftInternet ExplorerQuick LaunchA360.lnk

C:WINDOWSsystem32uacinit.dll

C:WINDOWSsystem32UACftdrxsnm.dll C:WINDOWSsystem32UACpulqeavn.dat C:WINDOWSsystem32UACrtaxtmsn.log

On completing this scan/removal and rebooting Malwarebytes you should now be able to update automatically (and other security software including windows update should now be ok too)

Installing Antivirus and a Firewall

You should now install your antivirus (this will also activate the appropriate product updates as well as Windows Security updates – you should now see the Windows Security Shield in the TASK BAR).

We use avast! – download, install and run a boot scan (it will prompt you to do this after installation) which should find these infected files:

C:documents and settingsuserlocal settingsPgmm.ltm [Trojan]

C:DOCUME~1userLOCALS~1PGMM.LTM [Trojan]

C:WINDOWSsystem32kernel32.dll

C:WINDOWSsystem32winsock.dll

C:WINDOWSsystem32wsock32.dll

You will be advised to restart your PC.

Having restarted your PC you will now need to download and install a Firewall. We recommend and it is 100% FREE!

For added assurance I suggest you download Spyware Terminator. It’s 100% FREE and will monitor every action. It also comes with a handy ‘Safe Web Search’ tool which places a GREEN shield next to safe websites.

Lastly you will need to update Windows Security. Click here. Safe surfing folks!

* Be very careful when making any changes to the Windows Registry. We suggest you make a Windows Registry backup before making any changes.

Safe surfing folks!
Julian Evans

Dani AI

Generated

Good starting point: has identified the classic FakeAV behavior and is right to warn about raw registry edits; ’s extra guide can help too. Add a safer, repair-first workflow that avoids blind deletion: isolate and back up data, stop active malicious processes, scan outside the running OS when necessary, remove persistence (startup/tasks/services), repair networking/browser hooks, then update and harden the PC. Antivirus 360 is a rogue “scareware” family — follow an established removal checklist rather than deleting registry keys at random. BleepingComputer removal guide. (bleepingcomputer.com)

Practical, ordered recovery (apply these in sequence):

  • Physically isolate the PC (disconnect network) and copy personal files to external media (use a Live USB if Windows is unstable).
  • If Windows won’t let you run tools, boot a rescue environment and scan from outside the OS (creates a clean scanning context). See Kaspersky’s Rescue Disk instructions. Kaspersky Rescue Disk instructions.
  • If Windows is usable, run a process-stopper (to free files/processes) and then run a deep, on-demand malware scan followed by a second-opinion scanner — don’t reboot between the killer and the scanner unless instructions say so. BleepingComputer removal guide. (bleepingcomputer.com)

Repair commands to run from an elevated Command Prompt after removing active malware (these fix common network/browser/stack corruption):

netsh winsock reset
netsh int ip reset resetlog.txt
ipconfig /flushdns
sfc /scannow

Use netsh winsock reset for Winsock corruption and follow with a reboot; reinstallation of some network software may be required afterward. netsh winsock docs. (learn.microsoft.com)

Persistence cleanup and final steps: use Autoruns to find and disable autostart entries, scheduled tasks and BHOs (do not delete until you understand an entry). Reset the hosts file to Microsoft defaults if redirects persist. After cleanup, fully update Windows, reinstall trusted endpoint protection, change all important passwords, and keep a clean image or system backup. If unsure at any step, stop and get professional help — improper registry or driver edits can render Windows unbootable. Autoruns (Sysinternals) · Reset hosts file (Microsoft). (learn.microsoft.com)

Recommended Answers

All 2 Replies

If you are not comfortable with Registry work, then keep out as a wrong move can and will, mash your Operating system.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.