Below is what's logged in the application log (I've removed the user and computer names) I suspect the PC goes to a blue screen when it receives its virus definition.
LOG NAME: APPLICATION
SOURCE: WINDOWS ERROR REPORTING
DATE: 12/22/2015 9:02:37 AM
EVENT ID: 1001
TASK CATEGORY: NONE
LEVEL: INFORMATION
KEYWORDS: CLASSIC
USER: N/A
COMPUTER:
DESCRIPTION:
FAULT BUCKET 0X109_3, TYPE 0
EVENT NAME: BLUESCREEN
RESPONSE:
http://HTTP://WER.MICROSOFT.COM/RESPONSES/RESREDIR.ASPX?SID=22494&BUCKET=0X109_3&STATE=1&ID=561B9F07-485B-4BF2-AB71-0727ED0EEFF4CAB ID: 561B9F07-485B-4BF2-AB71-0727ED0EEFF4
PROBLEM SIGNATURE:
P1: 109
P2: A3A01F5978DEB6C8
P3: B3B72BDFCB5EB48B
P4: FFFFF803EC749000
P5: 3
P6: 6_3_9600
P7: 0_0
P8: 256_1
P9:
P10:
ATTACHED FILES:
C:\WINDOWS\MINIDUMP\122215-25359-01.DMP
C:\USERS\USERNAME\APPDATA\LOCAL\TEMP\WER-195937-0.SYSDATA.XML
C:\WINDOWS\MEMORY.DMP
C:\USERS\USERNAME\APPDATA\LOCAL\TEMP\WER1C14.TMP.WERINTERNALMETADATA.XML
THESE FILES MAY BE AVAILABLE HERE:
C:\PROGRAMDATA\MICROSOFT\WINDOWS\WER\REPORTARCHIVE\KERNEL_109_998C574FB158EEC337A525D5F04A8CDBF132A5_00000000_CAB_0CB745D4
ANALYSIS SYMBOL:
RECHECKING FOR SOLUTION: 0
REPORT ID: 122215-25359-01
REPORT STATUS: 0
HASHED BUCKET:
EVENT XML:
<EVENT XMLNS="
http://HTTP://SCHEMAS.MICROSOFT.COM/WIN/2004/08/EVENTS/EVENT">
<SYSTEM>
<PROVIDER NAME="WINDOWS ERROR REPORTING" />
<EVENTID QUALIFIERS="0">1001</EVENTID>
<LEVEL>4</LEVEL>
<TASK>0</TASK>
<KEYWORDS>0X80000000000000</KEYWORDS>
<TIMECREATED SYSTEMTIME="2015-12-22T14:02:37.000000000Z" />
<EVENTRECORDID>41128</EVENTRECORDID>
<CHANNEL>APPLICATION</CHANNEL>
<COMPUTER>COMPUTERNAME</COMPUTER>
<SECURITY />
</SYSTEM>
<EVENTDATA>
<DATA>0X109_3</DATA>
<DATA>0</DATA>
<DATA>BLUESCREEN</DATA>
<DATA>
http://HTTP://WER.MICROSOFT.COM/RESPONSES/RESREDIR.ASPX?SID=22494&BUCKET=0X109_3&STATE=1&ID=561B9F07-485B-4BF2-AB71-0727ED0EEFF4</DATA>
<DATA>561B9F07-485B-4BF2-AB71-0727ED0EEFF4</DATA>
<DATA>109</DATA>
<DATA>A3A01F5978DEB6C8</DATA>
<DATA>B3B72BDFCB5EB48B</DATA>
<DATA>FFFFF803EC749000</DATA>
<DATA>3</DATA>
<DATA>6_3_9600</DATA>
<DATA>0_0</DATA>
<DATA>256_1</DATA>
<DATA>
</DATA>
<DATA>
</DATA>
<DATA>
C:\WINDOWS\MINIDUMP\122215-25359-01.DMP
C:\USERS\USERNAME\APPDATA\LOCAL\TEMP\WER-195937-0.SYSDATA.XML
C:\WINDOWS\MEMORY.DMP
C:\USERS\USERNAME\APPDATA\LOCAL\TEMP\WER1C14.TMP.WERINTERNALMETADATA.XML</DATA>
<DATA>C:\PROGRAMDATA\MICROSOFT\WINDOWS\WER\REPORTARCHIVE\KERNEL_109_998C574FB158EEC337A525D5F04A8CDBF132A5_00000000_CAB_0CB745D4</DATA>
<DATA>
</DATA>
<DATA>0</DATA>
<DATA>122215-25359-01</DATA>
<DATA>0</DATA>
<DATA>
</DATA>
</EVENTDATA>
</EVENT>