02-17-2009 07:50 AM
Like many others here, I had one computer that reported 3035,2 errors with virus definitions missing or invalid on just about every reboot. Multiple uninstalls, NRTs, registry hacks, and support sessions failed to resolve it.
Thanks to a Microsoft update that created other problems on this computer, I was forced to reformat my hard drive and start from scratch.
After installing XP SP3, I thought that was a perfect opportunity to finally fix this !#$%& error. So I installed the downloaded NIS9 (16.2.0.7), hopeful that on reboot, that illusive green check mark would finally appear and stay. No such luck.
Checking the Event Log showed SRTSP failed to load with Event ID 7026. How is that possible? I just installed it on a virgin machine!!! !#$%&
So I started to do some digging. I looked in Documents and Settings for the Symantec files. Some seemed to be missing. Oh, I forgot that on a fresh install, the 'Show Hidden File and Folders' was not checked and 'Hide Protected Operating System Files' was. After changing that, there it was.
In the directory list, separate from my Documents and Settings folder was a DOCUME~1 folder. It was set-up just like the standard Documents and Settings folder, with All Users, etc. It was under this directory structure that I found the missing Symantec files.
So I tried to delete it. In use. A HA! I went in to Services, stopped Norton Internet Security, and successfully deleted this directory. Restarted the NIS service, did an Update in NIS, rebooted, crossed fingers and toes.
A green checkmark that has withstood 6 reboots over 12 hours.
For others with this error, I would be curious to know if this also resolved your issue.
02-17-2009 09:57 AM
02-17-2009 01:14 PM
02-17-2009 04:35 PM
02-17-2009 06:26 PM
Hi troyn-
I sent you a private message on the forum website about this issue. Click on the envelope icon in the upper right of any forum page to access your messages.
Thanks,
Matt Powers
Symantec Corp.
02-17-2009 07:28 PM
ChristopherA: I saw a DOCUME~1 directory IN ADDITION TO a Documents and Settings.
I need to get my PC up and running. I will try to ghost it and reformat again to verify/test this.
02-17-2009 08:45 PM - edited 02-17-2009 08:51 PM
Well, my fix was short lived after 32 Microsoft updates and a reboot after installing some apps.
The culprit involves SRTSP. On start-up, it cannot find the definitions, eventhough they are there. The value in the registry is valid.
Doing a LiveUpdate does not correct the problem, as SRTSP still reports an error. Using the intelligent updater fixes whatever SRTSP does not like - until the next reboot.
Here is the intelligent updater log:
Tue Feb 17 23:47:48 2009 : **************************************************
Tue Feb 17 23:47:48 2009 : Starting Intelligent Updater - Version 5.0.1.4
Tue Feb 17 23:47:48 2009 : **************************************************
Tue Feb 17 23:47:48 2009 : AUTH SYMSIGNED BEGIN: Started.
Tue Feb 17 23:47:48 2009 : AUTH SYMSIGNED CLASS3 BEGIN: Entering CriticalSection Initialization .
Tue Feb 17 23:47:48 2009 : AUTH SYMSIGNED CLASS3: Succeeded find the class 3 ID, returning TRUE.
Tue Feb 17 23:47:48 2009 : AUTH SYMSIGNED END: Finished processing. Returns TRUE
Tue Feb 17 23:47:48 2009 : IU RES SYMSIGNED SUCCESS: Successfully verified Symantec Signature for the iuResource.dll
Tue Feb 17 23:47:48 2009 : IU RES LOAD: Successfully loaded the resource file..
Tue Feb 17 23:47:48 2009 : IU MODE: IU is running is FULL mode.
Tue Feb 17 23:47:50 2009 : CONFIG LOAD SUCCESS: Successfully loaded the configuration file: iuConfig.xml.
Tue Feb 17 23:47:50 2009 : IU INFO: File-name : 20090217-022-v5i32.EXE
Tue Feb 17 23:47:50 2009 : IU INFO: Creation-date : 20090217
Tue Feb 17 23:47:50 2009 : PROCESSING ENTRY: VIRSCAN.zip - Virus Definitions
Tue Feb 17 23:47:50 2009 : Entry details:
Tue Feb 17 23:47:50 2009 : Update-File: VIRSCAN.zip
Tue Feb 17 23:47:50 2009 : Update-Desc: Virus Definitions
Tue Feb 17 23:47:50 2009 : Auth DLL Name: SAVIUAuth
Tue Feb 17 23:47:50 2009 : Auth DLL Location: local
Tue Feb 17 23:47:50 2009 : Auth Content-Type: virus definitions x32
Tue Feb 17 23:47:50 2009 : Deploy Content-Type: virus definitions x32
Tue Feb 17 23:47:50 2009 : Deplo DLL Name: SAVIUDeploy
Tue Feb 17 23:47:50 2009 : Deploy DLL Location: local
Tue Feb 17 23:47:50 2009 : AUTH DLL LOCATION: IU will read the DLL location from registry - SAVIUAuth
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG FAILURE: Failed while reading the value for key named
Tue Feb 17 23:47:50 2009 : DEPLOY DLL LOCATION: IU will read the DLL location from registry - SAVIUDeploy
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG FAILURE: Failed while reading the value for key named
Tue Feb 17 23:47:50 2009 : IGNORE ENTRY: Ignoring entry for VIRSCAN.zip because of registry read failure. Error occurred while reading the path for the Authorization DLL from the registry.
Tue Feb 17 23:47:50 2009 : IU failed while deploying V because a compatible product could not be found on the system. Please make sure that a compatible Symantec product is installed on the system.
Tue Feb 17 23:47:50 2009 : PROCESSING ENTRY: VIRSCAN.zip - Virus Definitions
Tue Feb 17 23:47:50 2009 : Entry details:
Tue Feb 17 23:47:50 2009 : Update-File: VIRSCAN.zip
Tue Feb 17 23:47:50 2009 : Update-Desc: Virus Definitions
Tue Feb 17 23:47:50 2009 : Auth DLL Name: ISAuthDLL
Tue Feb 17 23:47:50 2009 : Auth DLL Location: local
Tue Feb 17 23:47:50 2009 : Auth Content-Type: virus definitions x32
Tue Feb 17 23:47:50 2009 : Deploy Content-Type: virus definitions x32
Tue Feb 17 23:47:50 2009 : Deplo DLL Name: ISDeployDLL
Tue Feb 17 23:47:50 2009 : Deploy DLL Location: local
Tue Feb 17 23:47:50 2009 : AUTH DLL LOCATION: IU will read the DLL location from registry - ISAuthDLL
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG FAILURE: Failed while reading the value for key named
Tue Feb 17 23:47:50 2009 : DEPLOY DLL LOCATION: IU will read the DLL location from registry - ISDeployDLL
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG FAILURE: Failed while reading the value for key named
Tue Feb 17 23:47:50 2009 : IGNORE ENTRY: Ignoring entry for VIRSCAN.zip because of registry read failure. Error occurred while reading the path for the Authorization DLL from the registry.
Tue Feb 17 23:47:50 2009 : IU failed while deploying V because a compatible product could not be found on the system. Please make sure that a compatible Symantec product is installed on the system.
Tue Feb 17 23:47:50 2009 : PROCESSING ENTRY: VIRSCAN.zip - Virus Definitions
Tue Feb 17 23:47:50 2009 : Entry details:
Tue Feb 17 23:47:50 2009 : Update-File: VIRSCAN.zip
Tue Feb 17 23:47:50 2009 : Update-Desc: Virus Definitions
Tue Feb 17 23:47:50 2009 : Auth DLL Name: Norton X32 AuthDLL
Tue Feb 17 23:47:50 2009 : Auth DLL Location: local
Tue Feb 17 23:47:50 2009 : Auth Content-Type: VirusDefs
Tue Feb 17 23:47:50 2009 : Deploy Content-Type: VirusDefs
Tue Feb 17 23:47:50 2009 : Deplo DLL Name: Norton X32 DeployDLL
Tue Feb 17 23:47:50 2009 : Deploy DLL Location: local
Tue Feb 17 23:47:50 2009 : AUTH DLL LOCATION: IU will read the DLL location from registry - Norton X32 AuthDLL
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while fetching the path for DLL : C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : DEPLOY DLL LOCATION: IU will read the DLL location from registry - Norton X32 DeployDLL
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while opening key
Tue Feb 17 23:47:50 2009 : REG SUCCESS: Success while fetching the path for DLL : C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED BEGIN: Started.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3 BEGIN: Entering CriticalSection Initialization .
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3: Succeeded find the class 3 ID, returning TRUE.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED END: Finished processing. Returns TRUE
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED SUCCESS: Successfully verified Symantec Signature for the authorization dll C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : AUTH LOAD SUCCESS: Successfully loaded the authorization dll - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED BEGIN: Started.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3 BEGIN: Entering CriticalSection Initialization .
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3: Succeeded find the class 3 ID, returning TRUE.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED END: Finished processing. Returns TRUE
Tue Feb 17 23:47:50 2009 : DEPLOY SYMSIGNED SUCCESS: Successfully verified Symantec Signature for the deployment dll C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : DEPLOY LOAD SUCCESS: Successfully loaded the deployment dll - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NUMEng.dll
Tue Feb 17 23:47:50 2009 : AUTHORIZATION SUCCESSFUL: VIRSCAN.zip is successfully authorized for deployment.
Tue Feb 17 23:47:50 2009 : DEPLOY PATH SUCCESS: VIRSCAN.zip will be deployed at location C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton\{0C55C~1\Nort
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED BEGIN: Started.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3 BEGIN: Entering CriticalSection Initialization .
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED CLASS3: Succeeded find the class 3 ID, returning TRUE.
Tue Feb 17 23:47:50 2009 : AUTH SYMSIGNED END: Finished processing. Returns TRUE
Tue Feb 17 23:47:50 2009 : UNRAR LOAD SUCCESS: Successfully loaded the UNRAR DLL.
Tue Feb 17 23:47:50 2009 : UNRAR OPEN SUCCESS: Success opening RAR file VIRSCAN.zip
Tue Feb 17 23:47:57 2009 : UNRAR EXTRACT SUCCESS: Succesfully extracted VIRSCAN.zip to C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton\{0C55C~1\Nort
Tue Feb 17 23:48:04 2009 : POST PROCESS SUCCESS: Successfully performed post processing for VIRSCAN.zip
Tue Feb 17 23:48:04 2009 : Calling ReleaseInstance() on the object of IIntelligentUpdaterDeploymentManager2.
Tue Feb 17 23:48:04 2009 : Calling ReleaseInstance() on the object of IIntelligentUpdaterAuthorizationManager2.
02-17-2009 10:58 PM
Thanks troyn.
What I am interested in, is what folders are inside the DOCUME~1 directory. That directory shouldn't exist. Maybe you can run dir /s on that directory from the command prompt, and print what is inside it?
02-19-2009 12:30 PM
The directory structure was All Users, my user, etc. The contents of All Users\Application Data was only Norton items. There was no Microsoft folder.
I tried to duplicate this and could not. However, I think it could be a key: something could be causing the abbreviated pathing (using the '~') to be misinterpreted. Looking in the registry, only the virus defs use the abbreviated pathing; everything else uses full path names. The definitions are where the problems seem to be.
It would be interesting for an update to remove all usage of the '~' in live update, intelligent update, and registry updates to see if that solved the problem.
