06-02-2012 07:36 AM
I have been working on this problem for several days now. I have finally tied the IntelligentUpdater failed update to the exact time when the issue began to occur.
Hardware & OS: Dell, Vista SP2 32bit
Issue: one of the svchost.exe processes, the one that runs "netsvc" starts and uses up a lot of CPU but, more importantly, keeps consuming memory until the box crashes. Although the process is needed, I have been able to keep more or less working (limping, actually) if I kill it, and continue killing it every time it restarts.
Research and fixes:
(1) I've looked for all kinds of things in blogs and Microsoft site, but nothing I tried has fixed the issue, including running several antispy programs and correcting anything found.
I also run NEP.exe, and it found a couple of things it fixed, but the problem still exists.
(2) Found what I think may be the culprit since the issue reported in Log.IntelligentUpdater.txt coincides exactly with the start of this issue. Here is an excerpt from the log (please find it attached):
Mon May 28 18:04:36 2012 : PROCESSING ENTRY: VIRSCAN.zip - Virus Definitions
Mon May 28 18:04:36 2012 : Entry details:
Mon May 28 18:04:36 2012 : Update-File: VIRSCAN.zip
Mon May 28 18:04:36 2012 : Update-Desc: Virus Definitions
Mon May 28 18:04:36 2012 : Auth DLL Name: Norton X64 AuthDLL
Mon May 28 18:04:36 2012 : Auth DLL Location: local
Mon May 28 18:04:36 2012 : Auth Content-Type: VirusDefs
Mon May 28 18:04:36 2012 : Deploy Content-Type: VirusDefs
Mon May 28 18:04:36 2012 : Deplo DLL Name: Norton X64 DeployDLL
Mon May 28 18:04:36 2012 : Deploy DLL Location: local
Mon May 28 18:04:36 2012 : AUTH DLL LOCATION: IU will read the DLL location from registry - Norton X64 AuthDLL
Mon May 28 18:04:36 2012 : REG SUCCESS: Success while opening key
Mon May 28 18:04:36 2012 : REG FAILURE: Failed while reading the value for key named
Mon May 28 18:04:36 2012 : DEPLOY DLL LOCATION: IU will read the DLL location from registry - Norton X64 DeployDLL
Mon May 28 18:04:36 2012 : REG SUCCESS: Success while opening key
Mon May 28 18:04:36 2012 : REG FAILURE: Failed while reading the value for key named
Mon May 28 18:04:36 2012 : IGNORE ENTRY: Ignoring entry for VIRSCAN.zip because of registry read failure. Error occurred while reading the path for the Authorization DLL from the registry.
Mon May 28 18:04:36 2012 : IU failed while deploying V because a compatible product could not be found on the system. Please make sure that a compatible Symantec product is installed on the system.
I found http://www.symantec.com/business/support/index?pag
IN ADDITION, OBSERVED THAT WHEN THE BOX IS STARTING UP, THE svchost.exe WITH THE MEMORY LEAK STARTS ACTUALLY EATING UP MEMORY WHEN THE ccsvchst.exe PROCESS STARTS . . .
QUESTION #1: Is "Norton X64" in the log referring to the 64-bit version? And if it is, why would my Norton Antivirus 2012 (all up to date) loaded on my 32-bit box be getting a 64-bit error?
QUESTION #2: I really, really, really don't want to reload my PC, and if I do maybe I will run into the same issue anyway . . . I am afraid to proceed with the TECH122906 fix because it does not seem to be the exact same setup. Can you help with this issue? HELP!!!
06-02-2012 07:59 AM
Hello nora-b,
Could you clarify which Norton Product (NIS, NAV, 360) and Version you are running? (Main UI, Support > About - version number should be right there)
"I also run NEP.exe, and it found a couple of things it fixed, but the problem still exists." Do you mean the Norton Power Eraser? If so, what items did it present as needing to be fixed? This is important.
The support document you cite is for Symantec Endpoint Protection which is a corporate version. Please disregard that document unless you are using SEP.
Thanks!
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
06-02-2012 09:26 AM
I am running Norton Antivirus 2012 v.19.7.1.5
Sorry for the misspell, yes, I run Norton Power Eraser. Two things were fixed, but I don't know what they were and cannot find a log . . . Do you know where this would be located?
06-02-2012 09:39 AM
To read the logs, follow the instructions at this link.
You should be able to copy the XML file and save as a .txt file (Notepad) and attach to your next post.
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
06-02-2012 10:20 AM
See the attached log created by the NPE run.
06-02-2012 10:30 AM
I am sorry, but there is virtually nothing there to read.
Did you copy the entire xml file and paste it into notepad?
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
06-03-2012 06:52 AM
this is weird . . . when I click on the link in the post, it brings up the file with contents, and I also see the text in the file I saved. So, to make it easier, I'm going to include the last part of the log in here, where you can see the things that were fixed (or where I thought they were described last). (If you'd like to see the entire file, I can try again to attach the file or maybe send it to you via email--let me know).
========================
<Analyze DateAndTime="Saturday, 02 June 2012 Time: 09:40"><Infections_Detected><DRIVERS Count="0"/><SERVICES Count="1"><Service ID="1"><File_Information><Path>c:\windows\microsof
========================
06-03-2012 07:26 AM
I forgot to mention that, since yesterday when I killed the "svchost.exe -k netsvcs" offending service (as it was eating up memory), it has not restarted by itself again, as it did since Monday. This has not happened in spite of me opening many applications (i.e., IE, Quicken, Outlook, Notebook, WordPad, Excel). Also, I did not change anything, and I am really afraid to reboot or change something - maybe if I keep the box up forever it will stay this way ;-) I do have some security patches to install, though . . .
06-03-2012 07:56 AM
Hello nora-b,
The Norton Power Eraser is a very aggressive tool and has the potential to generate false positives.
I cannot tell from your log if the items removed were infected or legitimate.
I will try to call in some other help to better determine if you have a serious infection.
" I do have some security patches to install, though . . ." What security patches need to be installed?
Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •
06-03-2012 08:51 AM
Security pathes:
- a bunch of .NET ones that I have not been able to install even before the issue being discussed here
- MS Office patches that recently were distributed, but which I could not install in this past few days because the "svchost.exe -k netsvcs" process would consume memory faster than the patch installation could finish
BTW, I stated that there was no "svchost.exe -k netsvcs" process running after the last time I killed it yesterday, but it is not correct. It actually is running but now without consuming memory.
Thanks so much for your help!
