Occasional BSOD caused by possible malware

Having installed the new version of Malwarebytes, I have been experiencing the Blue Screen Of Death for the first time in a year or two. I was advised the clean malwarebytes off my computer then reinstall it. I did so and i thought everything was fixed. then the BSOD happened again. as days passed, it just happened every now and then. It also happened as i was typing this post while GMER Rootkit was scanning (thankfully firefox was friendly and managed to save all my text). I've also experienced another problem.

at random times, something causes a command freeze. nothing is able to load. It is an infinite hang where you can't open anything (not even task manager). trying to put you computer in sleep mode will make the screen go black, but not succeed in putting the computer in sleep mode. start menu also won't load. it causes me to have to hold the power button to shut down since there's no way of getting out of it. so far i believe this has happened 4 times since updating Malwarebytes.

Yesterday i walked away from my computer for around 10 minutes. upon returning, the only thing i saw was my background. no start bar, no desktop icons, and no commands were working such as right click, CTRL+ALT+DEL or CTRL+ALT+SHIFT. this is another thing that caused me to have to hold the power button down since nothing else works. this has only happened once.

I experience random program crashes and errors at times as well. I have been unable to make a full scan with both Malwarebytes and MSE for it causes the computer to freeze during the middle of the full scan for either program. I have the required info attached along with the DDS log.


DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_20

Run by Jonny at 14:30:11 on 2011-10-03

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1628 [GMT -4:00]


AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


This may not be an infection causing this

Logs will be closed if you haven't replied within 3 days

Is there a reason you installed a proxy server with FireFox?

FF - prefs.js: network.proxy.http_port - 443

Please don't attach the scans / logs for these tools, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Please run a new MBAM scan being sure to update before scanning.

Post the scan results

Also please describe how your computer behaves at the moment.

Please don't attach the scans / logs, use "copy/paste".

Actually i forget the reason i installed a proxy. i have no need for it. I'll search later as to how to remove it.

During the last two days of following the the instructions in the "i'm infected - what do i do now?" topic and then posting about my problem, i have kept malwarebytes protection module off and i haven't had any issues since disabling it. This makes me believe that some file that malwarebytes detects causes the BSOD. Unsure as to why, but i haven't had any issues since turning it off two days ago. the scan results given are from a quick scan for the computer freezes in the middle of a full scan no matter what i do.

Malwarebytes' Anti-Malware


Database version: 7888

Windows 6.1.7601 Service Pack 1

Internet Explorer 8.0.7601.17514

10/6/2011 5:07:16 PM

mbam-log-2011-10-06 (17-07-16).txt

Scan type: Quick scan

Objects scanned: 195793

Time elapsed: 7 minute(s), 46 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Internet Explorer (Windows)

1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.

Firefox (Windows)

1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.

While we're at it lets do this


Go here to run an online scannner from ESET.

Click the green ESET Online Scanner button.

Read the End User License Agreement and check the box: YES, I accept the Terms of Use.

Click on the Start button next to it.

You may receive an alert on the address bar that "This site might require the following ActiveX control...Click here to install...". Click on that alert and then click Insall ActiveX component.

A new window will appear asking "Do you want to install this software?"".

Answer Yes to download and install the ActiveX controls that allows the scan to run.

Click Start.

Check Remove found threats and Scan potentially unwanted applications.

Click Scan to begin.

If offered the option to get information or buy software. Just close the window.

Wait for the scan to finish

Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt

Copy and paste that log as a reply to this topic.

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=

# OnlineScanner.ocx=

# api_version=3.0.2

# EOSSerial=e3357427fe3a544c9abd38248ef10bd3

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-10-07 01:10:52

# local_time=2011-10-06 09:10:52 (-0500, Eastern Daylight Time)

# country="United States"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=1029 16777214 0 1 53140270 53140270 0 0

# compatibility_mode=5893 16776574 100 94 18529828 69480651 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=435484

# found=0

# cleaned=0

# scan_time=13990

Please do the following to see if it resolves the issue: Post back and let us know please

  • Download and run mbam-clean.exe from here
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' Anti-Malware from here

    • Note: You will need to reactivate the program using the license you were sent via email if using the Pro version
    • Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
      Restart the computer again and verify that MBAM is in the task tray if using the Pro version. Now setup any file exclusions as may be required in your Anti-Virus/Internet-Security/Firewall applications and restart your Anti-Virus/Internet-Security applications. You may use the guides posted in the FAQ's here or ask and we'll explain how to do it.

I'll follow these instructions, but before i do i would like to alert you that i have done this twice already before posting about my BSOD problem in the malware forum. it seemed like it fixed the problem at first but then it happened again.

Oh and as of 5 minutes ago, i got the BSOD when opening Windows Update. this was WITHOUT Malwarebytes protection module opened. After the computer restarted from the crash i opened windows update again and it loaded without a problem.

Now i'm terribly confused where the cause of the problem is... Do you have anything to add or should i proceed with your instructions?

1. Use the System File Checker tool (SFC.exe) to determine which file is causing the issue, and then replace the file. To do this, follow these steps:

Open an elevated command prompt. To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.

2. Type the following command, and then press ENTER:

sfc /scannow <--Note the space, it needs to be there

The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.

unfortunately BSODs still occur. one happened only a few moments ago as i had firefox opened while reading a guide for a game. it was working fine but when i went to switch tabs the program was unresponsive for an unknown reason (no pages were loading or anything. i never even managed to click the tab.). i ended the process of firefox since it wouldn't respond after 5 minutes and reopened it. when the firefox window came up, the BSOD occured.

Malwarebytes was running and so was MSE. is there a small chance that MSE might be causing the problem? I know it isn't conflicting with Malwarebytes in any way for i have MSE set to ignore the processes and folder of malwarebytes and vice versa with Malwarebytes to MSE.

To disable all of Firefox's add-ons, you have to open the browser in its Safe Mode (no relation to Windows' own Safe Mode) by clicking Start > All Programs > Mozilla Firefox > Mozilla Firefox (Safe Mode). A quicker way is to press the Windows key (in XP, follow this by pressing R), type Firefox -safe-mode, and press Enter.

i can run firefox in safe mode which disables all addons but i'm 100% sure that firefox isn't the problem. i haven't installed an addon in a while anyway. i fear this problem may be unidentifiable, i hope not.

When i said maybe MSE is causing the problem, i didn't mean Malwarebytes was involved with MSE to make it occur. I wonder if i did a clean uninstall of MSE then reinstalled it. is it worth a shot?

