Windows defender Error code: 0x80073b01

Anonymous
2013-05-13T04:39:35+00:00

So yesterday I was on a site and a flash player update popped up and said that there was an update for "flash". I checked the certificate and it looked legit, so I had just clicked ask me later and then Windows Defender freaks out saying virus detected over and over. I tried clicking on the popup but nothing, then it said that windows needed to be restarted to delete a virus(or malware couldn't remember what it said). so I restarted it and i am not getting the error code. I also received an alert stating that windows could not make a backup because of a bad file or virus.

I have also reverted back to a previous backup and still the same problem.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-25T16:13:08+00:00

stunnedjack:

If you have not resolved the problem yet, please note that a possible fix has been posted (by user bhringer) here.

You may wish to try using HitmanPro 3.7 (v3.7.5.198-Beta) with Kickstart 2.2.

A HitmanPro.Kickstart User Manual & FAQ (PDF File) is available here.

"The latest variant of ZeroAccess/Sirefef disables Microsoft Security Essentials and Windows Defender by placing a Reparse Point (Junction/Symbolic Link) on the files of these products. The result is that these antivirus products are disabled by the malware! More info can be found here at KernelMode.info."

"This BETA release of HitmanPro now detects and removes these Reparse Points so that the mentioned AV products will function again."

See original Source.

<EDITED/ADDED>

On june 3, 2013, BETA release of HitmanPro referenced above was RTM'd to final version 3.7.6 Build 201, to include improvements, fixes and "additional repairs of folders and corresponding files in Winsxs folders. In addition, ACL security is reset". See: HitmanPro Release History.

For additional information, see: HitmanPro rescues anti-virus programs from malware attack.

To download the latest version of the tool, please visit HitmanPro 3.7 with Kickstart download site.

HitmanPro.Kickstart User Manual & FAQ (Video & PDF File) is available here.

<EDITED/ADDED>

See probably related/additional information:

Good Luck - Please post back and tell us how it goes.

PD.- David s. cole and Footos29 might wish to give it a shot whilst still awaiting for their disks :-)

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

65 additional answers

Sort by: Oldest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2013-06-21T00:25:36+00:00

    ... it looks like it mostly happened on June 13th.

    Yeap, that's what I wanted to confirm: The order of things...

    • Sirefef was indeed detected and quarantined by WD on June 13th 'before' getting disabled.
    • As per your log, it would appear HMP found no remnants or additional malware, and only performed the needed repairs to re-enable WD on June 16th.
    • The two Java Exploits detected and 'removed' by WD on June 17th, might (or might not) be related to Sirefef. I don't know :-). Depending on where they were located (in the Java cache?) I might suspect these were just failed attack attempts in a recent past.

    Anyway, I'm glad all is well now. Take care!

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-06-21T00:39:39+00:00

    This was helpful.  I installed Hitman and it was able to find malware that was preventing Defender from starting.

    <Correction>

    In fact, Sirefef was first detected and quarantined by WD 'before' getting disabled. See its detection's date and time in WD's quarantined items section (if you haven't removed it from there yet).

    What HMP did for you, was to remove its remnants (and possibly some additional malware, if any) and performed the needed repairs (removed the reparse points created in WD's folders) to re-enable WD.

    Anyway, I'm glad WD is up and running again for you too. Take care!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-06-24T00:47:43+00:00

    Thanks for posting all of this. I too was hit on June 13 and I saw this thread that day but didn't page into it very far. I ran HitmanPro this afternoon and it let MSE/Defender run again. I'm doing a full scan with it now. I didn't run the MBAM RootKit. I already had MBAM (non paid) installed but I assume it doesn't run the same things as the MBAM RootKit version mentioned.

    However, Windows Update isn't able to check for updates right now. Code 80073712.

    Is it possible either of the "additional repairs" will help me get that working?

    For the record, here's my Hitman log (minus a pile of cookies, none of which were embarrassing):

    HitmanPro 3.7.6.201

    www.hitmanpro.com

       Computer name . . . . : STARBUCK

       Windows . . . . . . . : 6.1.1.7601.X64/2

       Safe Mode Boot  . . . : MINIMAL

       User name . . . . . . : Starbuck\Russ

       UAC . . . . . . . . . : Disabled

       License . . . . . . . : Free

       Scan date . . . . . . : 2013-06-23 18:50:56

       Scan mode . . . . . . : Normal

       Scan duration . . . . : 4m 14s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : No connection

       Reboot  . . . . . . . : No

       Threats . . . . . . . : 0

       Traces  . . . . . . . : 1697

       Objects scanned . . . : 1,975,019

       Files scanned . . . . : 55,543

       Remnants scanned  . . : 901,615 files / 1,017,861 keys

    Suspicious files ____________________________________________________________

       C:\Windows\SysWOW64\FLACDX.ax

          Size . . . . . . . : 97,280 bytes

          Age  . . . . . . . : 460.0 days (2012-03-20 18:43:13)

          Entropy  . . . . . : 8.0

          SHA-256  . . . . . : 1CDCD07CDBB887DE6B46830D46B858467B796D81963483E61E3630CF1543DC8E

          Fuzzy  . . . . . . : 25.0

             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

             The hidden file attribute bit is set. This is not common to most programs.

             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.

             Authors name is missing in version info. This is not common to most programs.

             Version control is missing. This file is probably created by an individual. This is not typical for most programs.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Program contains PE structure anomalies. This is not typical for most programs.

       C:\Windows\SysWOW64\MPCDx.ax

          Size . . . . . . . : 120,832 bytes

          Age  . . . . . . . : 460.0 days (2012-03-20 18:43:13)

          Entropy  . . . . . : 8.0

          SHA-256  . . . . . : 26170AE05858EBDAC4BADDEDBBDAC954244F1FAB6EFD63CAB21E6BF3FEC2F58E

          Fuzzy  . . . . . . : 25.0

             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

             The hidden file attribute bit is set. This is not common to most programs.

             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.

             Authors name is missing in version info. This is not common to most programs.

             Version control is missing. This file is probably created by an individual. This is not typical for most programs.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Program contains PE structure anomalies. This is not typical for most programs.

       C:\Windows\SysWOW64\RLAPEDec.ax

          Size . . . . . . . : 70,656 bytes

          Age  . . . . . . . : 460.0 days (2012-03-20 18:43:14)

          Entropy  . . . . . : 7.9

          SHA-256  . . . . . : 353F8FD96749260C9F8A11ED2C1AC31DBAEC6782DE4C87826770F0ACFA2F87A5

          Fuzzy  . . . . . . : 29.0

             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

             The hidden file attribute bit is set. This is not common to most programs.

             The Entry Point of this file lies in a resource section. This is an indication of malware infection.

             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.

             Authors name is missing in version info. This is not common to most programs.

             Version control is missing. This file is probably created by an individual. This is not typical for most programs.

             Program contains PE structure anomalies. This is not typical for most programs.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

       C:\Windows\SysWOW64\RLMPCDec.ax

          Size . . . . . . . : 107,520 bytes

          Age  . . . . . . . : 460.0 days (2012-03-20 18:43:14)

          Entropy  . . . . . : 8.0

          SHA-256  . . . . . : 60EDCD1605ED87D1CF75275FE83F8D44089364FF0B24842CD897928D4B8DC803

          Fuzzy  . . . . . . : 25.0

             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

             The hidden file attribute bit is set. This is not common to most programs.

             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.

             Authors name is missing in version info. This is not common to most programs.

             Version control is missing. This file is probably created by an individual. This is not typical for most programs.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Program contains PE structure anomalies. This is not typical for most programs.

    Repairs _____________________________________________________________________

       Redirection: Backup -> c:\windows\system32\config

       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)

       Redirection: Drivers -> c:\windows\system32\config

       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)

       Redirection: en-us -> c:\windows\system32\config

       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)

       Redirection: en-US -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpAsDesc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpClient.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpCmdRun.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpCommu.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpEvMsg.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpOAV.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpRTP.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpSvc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MSASCui.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MsMpCom.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MsMpLics.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MsMpRes.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Program Files\Windows Defender)

       Redirection: MpEvMsg.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender-events_31bf3856ad364e35_6.1.7600.16385_none_118cf1dcd54a3dea)

       Redirection: MpAsDesc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpClient.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpCmdRun.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpCommu.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpOAV.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpRTP.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpSvc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MSASCui.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MsMpLics.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MsMpRes.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c)

       Redirection: MpAsDesc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpClient.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpCmdRun.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpCommu.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpOAV.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpRTP.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MpSvc.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MSASCui.exe -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MsMpCom.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MsMpLics.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

       Redirection: MsMpRes.dll -> c:\windows\system32\config

       Disables Windows Defender (C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306)

    Was this answer helpful?

    0 comments No comments