Windows defender Error code: 0x80073b01

Anonymous
2013-05-13T04:39:35+00:00

So yesterday I was on a site and a flash player update popped up and said that there was an update for "flash". I checked the certificate and it looked legit, so I had just clicked ask me later and then Windows Defender freaks out saying virus detected over and over. I tried clicking on the popup but nothing, then it said that windows needed to be restarted to delete a virus(or malware couldn't remember what it said). so I restarted it and i am not getting the error code. I also received an alert stating that windows could not make a backup because of a bad file or virus.

I have also reverted back to a previous backup and still the same problem.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-25T16:13:08+00:00

stunnedjack:

If you have not resolved the problem yet, please note that a possible fix has been posted (by user bhringer) here.

You may wish to try using HitmanPro 3.7 (v3.7.5.198-Beta) with Kickstart 2.2.

A HitmanPro.Kickstart User Manual & FAQ (PDF File) is available here.

"The latest variant of ZeroAccess/Sirefef disables Microsoft Security Essentials and Windows Defender by placing a Reparse Point (Junction/Symbolic Link) on the files of these products. The result is that these antivirus products are disabled by the malware! More info can be found here at KernelMode.info."

"This BETA release of HitmanPro now detects and removes these Reparse Points so that the mentioned AV products will function again."

See original Source.

<EDITED/ADDED>

On june 3, 2013, BETA release of HitmanPro referenced above was RTM'd to final version 3.7.6 Build 201, to include improvements, fixes and "additional repairs of folders and corresponding files in Winsxs folders. In addition, ACL security is reset". See: HitmanPro Release History.

For additional information, see: HitmanPro rescues anti-virus programs from malware attack.

To download the latest version of the tool, please visit HitmanPro 3.7 with Kickstart download site.

HitmanPro.Kickstart User Manual & FAQ (Video & PDF File) is available here.

<EDITED/ADDED>

See probably related/additional information:

Good Luck - Please post back and tell us how it goes.

PD.- David s. cole and Footos29 might wish to give it a shot whilst still awaiting for their disks :-)

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

65 additional answers

Sort by: Oldest
  1. Anonymous
    2013-06-16T22:10:05+00:00

    It WORKED !!! I ran v3.7.6.201 , and Boom ... I've been following the thread and I can't thank you enough ALL of you for your help even if it wasn't meant directly for me, it fixed the problem..

    Of course it was directed to you, same as to anyone else affected by this issue. We're glad you made it but you're not done yet :) Time to provide some feedback (same as requested from others above): Are you able to post your logs? You should find it at *C:\Users\All Users\AppData\HitmanPro\Logs* and the file shall be identified as HitmanPro_[DATE]_[TIME].log. Please post the one you ran the very first time. Thanks in advance.

    Thank you RickCP, Hitman worked for me too. Although I'm not Jennifer, I thought I would contribute so that people like me might find it useful. I've had a similar problem with Windows Defender; two days ago, while I was working on this laptop, a message popped up saying that Windows Defender detected a malware and is working to get rid of it. And then after a second, it popped up "An error has occurred during initialization. If this problem continues, please contact your system administrator.

    Error code: 0x80073b01". Windows Defender wouldn't start at all.

    I tried system restoration with no success, and wondered if I needed to buy a new Windows 8 pro disc - I haven't got one because this laptop came with it already installed.

    So I found this thread, tried the Hitman program, and WD is back! Here is the log (first and last, at this point):

    [code]

    HitmanPro 3.7.6.201

    www.hitmanpro.com

       Computer name . . . . : [my name]

       Windows . . . . . . . : 6.2.0.9200.X64/4

       User name . . . . . . : [my PC name]

       UAC . . . . . . . . . : Enabled

       License . . . . . . . : Free

       Scan date . . . . . . : 2013-06-16 22:30:10

       Scan mode . . . . . . : Normal

       Scan duration . . . . : 1m 44s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : Internet

       Reboot  . . . . . . . : No

       Threats . . . . . . . : 0

       Traces  . . . . . . . : 1159

       Objects scanned . . . : 1,493,425

       Files scanned . . . . : 36,778

       Remnants scanned  . . : 407,840 files / 1,048,807 keys

    Repairs _____________________________________________________________________

       Redirection: en-GB -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: en-US -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: ja-JP -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

    Cookies _____________________________________________________________________

       C:\Users[my PC name]\AppData\Roaming\Microsoft\Windows\Cookies\EWKN96MN.txt

       C:\Users[my PC name]\AppData\Roaming\Microsoft\Windows\Cookies\G51OMR6B.txt

       C:\Users[my PC name]\AppData\Roaming\Microsoft\Windows\Cookies\HN1B9KMN.txt

       C:\Users[my PC name]\AppData\Roaming\Microsoft\Windows\Cookies\IXW60I51.txt

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:ad.dmm.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:ad.yieldmanager.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:ads.us.e-planning.net

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:adserver.twitpic.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:adtech.de

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:advertising.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:apmebf.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:ar.atwola.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:at.atwola.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:atdmt.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:atwola.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:c1.atdmt.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:casalemedia.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:dmm.112.2o7.net

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:doubleclick.net

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:invitemedia.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:kakakucom.112.2o7.net

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:media6degrees.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:mediaplex.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:questionmarket.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:revsci.net

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:ru4.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:serving-sys.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:statse.webtrendslive.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:tacoda.at.atwola.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:www.googleadservices.com

       C:\Users[my PC name]\AppData\Roaming\Mozilla\Firefox\Profiles\ug1w7foc.default\cookies.sqlite:www.sexpixbox.com

    [/code]

    That's it.

    I thought I would find a few malware stuff as "Threats", but none appeared, although there are some dodgy-looking cookies (embarrassing!). I'm wondering if this PC is now clean and safe...I'm running a full WD scan now. I'll try running some other virus/malware detection programs too.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-06-17T01:09:07+00:00

    You're welcome and many thanks for your feedback on this nasty issue.

    I thought I would find a few malware stuff as "Threats"...

    Yes, HMP is only showing the repairs it performed (plus the cookies) after the real 'culprit' (ZA/Sirefef) was (I think) detected and quarantined by WD 'before' getting disabled. Could you please take a look at your WD's History and provide as much detail as you can about the info contained therein?

    I would also suggest you run HMP one more time.

    ... although there are some dodgy-looking cookies (embarrassing!).

    These cookies may be used by some PUP/Adware programs you may like to identify and remove as well. You may wish to use a good adware remover such as AdwCleaner. Please also tell us about whatever is detected and removed by this tool.

    Again, thanks in advance for your feedback.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-06-17T15:31:25+00:00

    OS- WIn * 64 bit

    Had the same issue and resolved it by removing the malware using MBAR malware remover software. Thanks for the help...cheers!!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-06-17T21:20:13+00:00

    Hi RickCP, thank you for your reply.

    I opened WD and these were all detected items:

    Exploit: Java/CVE-2013-0422 (Removed)

    Exploit: Java/CEV-2013-0431 (Removed)

    TrojanDropper:Win32/Sirefef.gen!E (Quarantined)

    TrojanDropper:Win32/Sirefef.gen!G (Quarantined)

    TrojanDropper:Win32/Sirefef.gen!E (Quarantined)

    Trojan:Win64/Sirefef.AE (Quarantined)

    Trojan:Win64/Sirefef.AE (Quarantined)

    All of them were of "severe" alert.

    I've deleted them all. Hitman didn't find anything, and I also ran AdwCleaner, and it didn't find anything either.

    Does this mean I can relax now??

    Was this answer helpful?

    0 comments No comments