Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Malware Bytes Freezing During Heuristic Analysis

  • This topic is locked This topic is locked
2 replies to this topic

#1 electriccomputerblue


  • Members
  • 1 posts
  • Local time:05:29 AM

Posted 27 July 2015 - 08:50 AM

I'm running Windows 7 64 Bit. I have Malware Bytes set up to do regular scans. While scanning yesterday, the program would run through and then after getting to heuristic analysis it would just begin finding tens of thousands things and eventually freeze. I assumed the program could be faulty and tried the complete uninstall and reinstall but to no avail. Malware Bytes continues to freeze. I read through the forum rules and believe the first step is to attach my logs. I have attached them below. Thanks for any help!


Attached File  FRST.txt   4.74MB   3 downloads

Attached File  Addition.txt   21.77KB   1 downloads

BC AdBot (Login to Remove)


#2 nasdaq


  • Malware Response Team
  • 40,490 posts
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:29 AM

Posted 28 July 2015 - 08:29 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.

You have a few hundred SearchScopes such as
SearchScopes: HKU\S-1-5-21-3179796635-4150185062-1345659732-1000 -> {0135FDE2-5BA5-42CD-86B8-852568E4B97E} URL = https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=926458&p={searchTerms}

You can open the files and check it.

What I need you to do before I can suggest any remedial action is this:


Reset Default Browsing settings:

Clean the Firefox Cache.

Reset Internet Explorer:
Menu > Tools > Internet Options > Advanced Tab.
Click the Reset button on the bottom of the pane.
Click the Apply button.
Close IE.

Clean the Internet Explorer Cache.

The log also shows that your Chrome was compromised.

Remove Chrome using the the instructions on this page.

Before you do Export your Bookmarks
Chrome will export your bookmarks as a HTML file, which you can then import into another browser.

If you want to save your passwords as well see here: http://www.intowindows.com/how-to-backup-saved-passwords-in-google-chrome-browser/

Re-install Chrome and the Bookmarks.

If you want to save all your settings refer to this page.
Follow the instructions before removing Chrome.

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zeok tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
ipconfig /flushdns;b
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.


Please run the Farbar tool one more time and post a fresh FRST log for my review.

Provide an update on how the computer is behaving after running the above script.

#3 nasdaq


  • Malware Response Team
  • 40,490 posts
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:29 AM

Posted 02 August 2015 - 07:22 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users