Windows defender Error code: 0x80073b01

Anonymous
2013-05-13T04:39:35+00:00

So yesterday I was on a site and a flash player update popped up and said that there was an update for "flash". I checked the certificate and it looked legit, so I had just clicked ask me later and then Windows Defender freaks out saying virus detected over and over. I tried clicking on the popup but nothing, then it said that windows needed to be restarted to delete a virus(or malware couldn't remember what it said). so I restarted it and i am not getting the error code. I also received an alert stating that windows could not make a backup because of a bad file or virus.

I have also reverted back to a previous backup and still the same problem.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-25T16:13:08+00:00

stunnedjack:

If you have not resolved the problem yet, please note that a possible fix has been posted (by user bhringer) here.

You may wish to try using HitmanPro 3.7 (v3.7.5.198-Beta) with Kickstart 2.2.

A HitmanPro.Kickstart User Manual & FAQ (PDF File) is available here.

"The latest variant of ZeroAccess/Sirefef disables Microsoft Security Essentials and Windows Defender by placing a Reparse Point (Junction/Symbolic Link) on the files of these products. The result is that these antivirus products are disabled by the malware! More info can be found here at KernelMode.info."

"This BETA release of HitmanPro now detects and removes these Reparse Points so that the mentioned AV products will function again."

See original Source.

<EDITED/ADDED>

On june 3, 2013, BETA release of HitmanPro referenced above was RTM'd to final version 3.7.6 Build 201, to include improvements, fixes and "additional repairs of folders and corresponding files in Winsxs folders. In addition, ACL security is reset". See: HitmanPro Release History.

For additional information, see: HitmanPro rescues anti-virus programs from malware attack.

To download the latest version of the tool, please visit HitmanPro 3.7 with Kickstart download site.

HitmanPro.Kickstart User Manual & FAQ (Video & PDF File) is available here.

<EDITED/ADDED>

See probably related/additional information:

Good Luck - Please post back and tell us how it goes.

PD.- David s. cole and Footos29 might wish to give it a shot whilst still awaiting for their disks :-)

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

65 additional answers

Sort by: Most helpful
  1. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2013-06-01T14:31:22+00:00

    David s. cole,

    Great to hear things are looking better for you as well.

    Wonder if the infection may have also disabled Carbonite, I'd be very suspect of any recent Carbonite backups.

    Like the reference to the Morlock. Perhaps the malware should be Sirefef.Morlock as it more or less locked up Windows Defender. ;-)

    Did you note repair of reparse points/juntions by HitmanPro or MBAR? Logs would be nice. If there were none it almost seems that emptying the Recycle Bin may have been the quick fix. Maybe that was MS Support's advanced method., <large grin>

    Please keep us posted if you encounter further issues.

    Thanks for your help!

    bhringer

    Was this answer helpful?

    0 comments No comments
  2. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2013-06-01T14:15:17+00:00

    Footos29,

    Great to hear things are looking better, your feedback is much appreciated and helpful to others.

    I echo the requests of RickCP for log files, especially curious regarding reparse points/junctions.

    You may be interested in my additional suggestions and comments posted (May 31, 2013) in another thread regarding this same issue.  See page 2 Security Essentials Will Not Download Or Run Or Uninstall.

    Thanks for your help.

    bhringer

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-06-01T09:19:22+00:00

    TO ALL...

     

    This IS the solution!

     

    Just make sure that you run the MBAR Rootkit scan TWICE! That is: run the program and let it cleanse your nasties, reboot and run it the second time and...voila! Siredef detected and deleted!

     

    Apparently its hiding at the $Recycle Bin folder per Log below

     

    Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)...

    Done!

    Infected: c:$Recycle.Bin\S-1-5-18$c1a69442954af3e37352f355b4c20d4c\U --> [Trojan.Siredef.C]

    Infected: c:$Recycle.Bin\S-1-5-21-3273266631-3058561546-3722927689-1001$c1a69442954af3e37352f355b4c20d4c\U --> [Trojan.Siredef.C]

    Infected: c:$Recycle.Bin\S-1-5-18$c1a69442954af3e37352f355b4c20d4c\L --> [Trojan.Siredef.C]

    Infected: c:$Recycle.Bin\S-1-5-21-3273266631-3058561546-3722927689-1001$c1a69442954af3e37352f355b4c20d4c\L --> [Trojan.Siredef.C]

    Infected: c:$Recycle.Bin\S-1-5-18$c1a69442954af3e37352f355b4c20d4c --> [Trojan.Siredef.C]

    Infected: c:$Recycle.Bin\S-1-5-21-3273266631-3058561546-3722927689-1001$c1a69442954af3e37352f355b4c20d4c --> [Trojan.Siredef.C]

    Scan finished

    Creating System Restore point...

    Cleaning up...

    Executing an action fixdamage.exe...

    Success!

    Queuing an action fixdamage.exe

    Removal successful. No system shutdown is required

    Far out!  I'll try it now.....

    GULL DANG!  It found one.....Siredef.!  I had seen weird files hanging in the recycle bin a couple times.

    Now to run it again..  Nothing found on second try.  DEFENDER IS NOW WORKING.  I will reboot and run it again.

    And Carbonite just popped up a message ..it was trying to back this junk up and couldn't.

    So I wonder how compromised our data is?  I feel like one of the Eloi sheep being attacked by nasty underground Morlocks.

    MS needs to stop these attacks with a final solution.

    Thanks for the persistent efforts!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-06-01T09:17:37+00:00

    In other words, did I pop for $25 bucks yet?  :)  no not yet.

    No, no need to pay. HitmanPro offers you a free license for 30 days (if you are a home user), even when running the program from a USB flash drive.

    Also FYI, quarantining the infected file(s) will make an encrypted copy of the infection on the computer itself - not on the flash drive.

    HitmanPro automatically selects quarantine on infections that were identified by only one other security vendor in the cloud. The infection is set to delete when more vendors marked it as malware.

    You may wish to try again with the most recent beta (with improvements) v3.7.6.201 released today, and/or alternatively - MBAR Beta 1.06; both, as suggested above by user bhringer.

    Good Luck!

    In the meantime still no email from MS defender dept. with the "'advanced methods."

    Any news?

    Thanks for further suggestion and the solution posted below.  I will have to pick up a regular flash drive because aparently my 64gig ultra Sd card is not compatible with hitman.

    And Alas....I regret to say, MS has NOT yet sent me these "advanced methods" yet.  But maybe monday.  I will call them again.  In the meantie I will try these new updated software rootkits and see what appens.

    MS needs to do an emergencyupdate!

    Was this answer helpful?

    0 comments No comments