Windows defender Error code: 0x80073b01

Anonymous
2013-05-13T04:39:35+00:00

So yesterday I was on a site and a flash player update popped up and said that there was an update for "flash". I checked the certificate and it looked legit, so I had just clicked ask me later and then Windows Defender freaks out saying virus detected over and over. I tried clicking on the popup but nothing, then it said that windows needed to be restarted to delete a virus(or malware couldn't remember what it said). so I restarted it and i am not getting the error code. I also received an alert stating that windows could not make a backup because of a bad file or virus.

I have also reverted back to a previous backup and still the same problem.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-25T16:13:08+00:00

stunnedjack:

If you have not resolved the problem yet, please note that a possible fix has been posted (by user bhringer) here.

You may wish to try using HitmanPro 3.7 (v3.7.5.198-Beta) with Kickstart 2.2.

A HitmanPro.Kickstart User Manual & FAQ (PDF File) is available here.

"The latest variant of ZeroAccess/Sirefef disables Microsoft Security Essentials and Windows Defender by placing a Reparse Point (Junction/Symbolic Link) on the files of these products. The result is that these antivirus products are disabled by the malware! More info can be found here at KernelMode.info."

"This BETA release of HitmanPro now detects and removes these Reparse Points so that the mentioned AV products will function again."

See original Source.

<EDITED/ADDED>

On june 3, 2013, BETA release of HitmanPro referenced above was RTM'd to final version 3.7.6 Build 201, to include improvements, fixes and "additional repairs of folders and corresponding files in Winsxs folders. In addition, ACL security is reset". See: HitmanPro Release History.

For additional information, see: HitmanPro rescues anti-virus programs from malware attack.

To download the latest version of the tool, please visit HitmanPro 3.7 with Kickstart download site.

HitmanPro.Kickstart User Manual & FAQ (Video & PDF File) is available here.

<EDITED/ADDED>

See probably related/additional information:

Good Luck - Please post back and tell us how it goes.

PD.- David s. cole and Footos29 might wish to give it a shot whilst still awaiting for their disks :-)

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

65 additional answers

Sort by: Newest
  1. Anonymous
    2013-06-02T08:26:01+00:00

    Here's the last one I ran.. I'm having trouble finding the first scan log, but will keep looking               [code]

    HitmanPro 3.7.6.201

    www.hitmanpro.com

       Computer name . . . . : JENS

       Windows . . . . . . . : 6.2.0.9200.X64/4

       User name . . . . . . : JENS\Jennifer

       UAC . . . . . . . . . : Enabled

       License . . . . . . . : Free

       Scan date . . . . . . : 2013-06-01 13:17:25

       Scan mode . . . . . . : Normal

       Scan duration . . . . : 2m 52s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : Internet

       Reboot  . . . . . . . : No

       Threats . . . . . . . : 0

       Traces  . . . . . . . : 21

       Objects scanned . . . : 1,463,047

       Files scanned . . . . : 31,810

       Remnants scanned  . . : 410,904 files / 1,020,333 keys

    Repairs _____________________________________________________________________

       Redirection: en-US -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

    Cookies _____________________________________________________________________

       C:\Users\Jennifer\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net

    [/code]

    Was this answer helpful?

    0 comments No comments
  2. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2013-06-02T01:17:24+00:00

    Having the MBAR and HMP logs is what interests me mostly. I've assumed that all those affected had the engine update as on or about May 14 and that the vulnerability addressed didn't involve ZAccess/Sirefef. and I think the timing of some of the first reports was purely coincidental. However, I did share your thought about some action of MSE-Win Defender acting as a trigger, possibly the creation of the reparse points after the Sirefef detection. Don't expect support logs would provide much than skull cramps ;-)

    Certainly not trying to be argumentative and saying your wrong, it merely is above my pay grade to prove otherwise. After reading The Wonder of Sirefef Plunder my feeling is that this is somewhat of a retaliation targeted attack.

    Couple of asides. The MSE uninstall issues still require some attention, see here. The stable version of HMP 3.7.6 Build 201 should be available Monday or Tuesday, version 3.8 is scheduled for July 1st.

    Edit: Removed comment regarding XP not being affected. Obviously wrong and since XP is indeed affected this would suggest that the vulnerability in the antimalware engine is not the vulnerability this infection is exploiting as the vulnerability that was addressed with the May 14th update only affected 64-bit machines at that time.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-06-01T19:41:09+00:00

    Did you note repair of reparse points/juntions by HitmanPro or MBAR? Logs would be nice.

    1+

    If there were none it almost seems that emptying the Recycle Bin may have been the quick fix. Maybe that was MS Support's advanced method., <large grin>

    Or running HMPK or MBAR ;)

    I think it might be a good idea to compare the contents of each tool's logs, and depending on which one was first ran, we might get an idea of what exactly was the cleaning done by each tool.

    Further, would you think we may also get some further feedback on the issue if WD's support files were created/requested now? For instance, about the date it happened and if the 'new' engine was already installed?

    On Unyclept's thread, for example, he confirmed Sirefef was quarantined "by MSE" on May 26 (a week after the engine's update) making MSE to break (first time to notice the issue).

    I don't know why I still have this idea in my head...

    1.- Malware was already present in users' systems some time 'before' the new engine was installed - and took advantage/exploited the vulnerability existing at the time affecting the old/vulnerable engine.

    2.- The issue was triggered by the new engine upon detection (and action taken before its blockage) during RTP or otherwise scan of a crafted file.

    3.- HMPK and/or MBAR cleaning labor now is only referred to the infection remnants (malware not active as it was addressed before MSE's breakage) and repairs of the junctions left behind.

    I know... difficult to tell but, what you think?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-06-01T18:42:53+00:00

    It WORKED !!! I ran v3.7.6.201 , and Boom ... I've been following the thread and I can't thank you enough ALL of you for your help even if it wasn't meant directly for me, it fixed the problem..

    Of course it was directed to you, same as to anyone else affected by this issue. We're glad you made it but you're not done yet :) Time to provide some feedback (same as requested from others above): Are you able to post your logs? You should find it at *C:\Users\All Users\AppData\HitmanPro\Logs* and the file shall be identified as HitmanPro_[DATE]_[TIME].log. Please post the one you ran the very first time. Thanks in advance.

    Was this answer helpful?

    0 comments No comments