Norton 360 v. 21.2.0.38: 3038,104's

Of course I got that message, and of course I rebooted to get the scan.  The surprise is that doing that with the second HD which is identical physically required a few hours (after a forced dismount, of course) whereas the C: drive went much more quickly.  Either there is a much faster way to do a surface scan when you don't have an OS kernel to deal with, or something was short-changed.  I invoked the possibility of that part of chkdsk, which is only invoked on boot, may not see all of a 2 TB HD, but has never been looked at because it's never used.  I have several ways to boot from DVD and invoke a command line that can run a chkdsk; the original Windows installation disks, a boot fix DVD generated by Windows 7 that I keep for emergencies, and boot DVDs generated by Norton and Acronis.  If questions about the C: drive do persist, I'll use the OS-generated DVD (actually make a new one to get the latest revisions from Windows Update).

 

But the problem occurs when a new x64 virus definitions update comes, and has survived several re-installations, meaning that the location of the software on the HD doesn’t affect anything.

<< Of course I got that message, and of course I rebooted to get the scan  >>

 

It didn't sound like it from what you wrote, which is why I asked.

 

<< To my amazement, checking C: took only a few minutes, apparently because it executes during the early stages of a boot and has the undivided atttention of the machine.  If this turns out to be an 8-bit utility that sees only 63 MB of a 2 TB HD or some such, I can use a boot DVD and the command line.  >>

 

Sorry I can't help you.

Unless someone is familiar with this problem or can look at my Norton logs (or tell me where to look) and such, I don't have a lot of hope for seredipity here.  This has been the most serious and persistent problem that I have ever had, in fact.

 

Note a couple of posts back that I found 64 Security Log entries about N360 application protection denying access with the sme time tag as a failed x64 virus definitions update.  That's as close to a smoking gun as anything I've seen but nobody turned a hair here, meaning to me that it ws probably nothing.

There was a patch yesterday, to 21.4.0.13 that may have fixed my problem.  I did get a 8920,208 but Autofix claimed success in repairing my installation.  Re-running LU added the failed update.  QuickScan started successfully afterward.  This breaks a pattern of Autofix not seeing the problem, and QuickScan faling with a 3038,104 afterward.

 

I hope my inputs and upload were helpful in finding a fix.  On the other hand, we should wait a few days to see if all this holds up.  Twice before we have thought that the problem was solved and been disappointed.

The good news is that I downloaded and installed a major update of virus definitions tonight without a 8920,208 error.

 

The bad news is that I had another 3038,104 when I tried to run a QuickScan.  Computer clock was corrected yesterday, is 7 seconds slow.  Did not correct.

 

Yesterday I replaced an old UPS with a new higher capacity unit.  This involved shuting down while things were being rewired in the prime power and cold booting so the machine has been up a little over 24 hours.

 

The Symatec page for 3038,104 has changed.  My link includes scads of system and error information and I don't have a simple way to provide a short link.  The key phrase at the beginning is:

 

Symantec is aware of this issue and is currently working on a fix.

This problem can happen when the computer has not been restarted for a while. As a workaround until the problem is fixed, make sure to restart your computer on a daily basis.

 

There is a recommendation to disable Windows 8 "fast boot" as a partial work-around but I'm running Windows 7.  I'm sure that Symatec understands that insisting that everybody restart every morning is unacceptable except as a temporary workaround, and that the new error page states clearly that my problem is recognized and has a high priority.

 

My current case is 16661922 but I did not ask for an online chat because when Symatec has a fix they will roll it out to everyone, and the person on the other end will not be able to help.  Since I'm not interesting in wasting people's time while putting them in a difficult postion, I'll watch for the next Patch or other update.

 

If there is anything I can do that will provide information, such as testing fixes, I will be more than happy to participate.

 

My Security Log shows this entry:

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
7/9/2014 11:14:13 PM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,7/9/2014 11:14:13 PM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,9556,C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\buih.exe,14456,Access Process Data,Unauthorized access blocked

There is only one log entry of this type.  Before the patch to build 21.4.0.13, I had 64 log entries of this general type.

Hi, motorfingers. Has anyone from Symantec asked you for logs etc, in this thread ?

 

I asked if someone could contact you maybe via PM in regards to providing info, so it can be properly investigated .

Not yet.  But it appears that this problem is widespread enough so that the Symantec 3038,104 page aknolwedges the problem, gives booting every morning as a workaround, and states that they are addressing the problem, so I expect that they have accessed logs and such.

 

The unusual things about my system are the 4.33 GHz eight-core CPU (AMD lists is at 4.0 GHz but System Info lists it as 4.33 GHz, the "turbo" rate), 1.866 GHz RAM, and two 2 TB HDs on the motherboard SATA 3 bus.  Also, there are a lot of things installed, but nothing exotic.  The motherboard is a popular ASUS model.  I think the only thing that is likely to cause the problems that I observed in my logs is the eight-core processor; I say that because it appears that N360 is not recognizing some of its own processes.

First, let me say I have not taken the time to read all nine pages of your thread.  I did scan the first 3 or so.  And, it appears that your problems persist.

I would like to point you toward a thread that i started on june 9 which was actually a second thread that I had originated on thsi issue.  My history is much like yours.  And, I have noticed many other threads regarding 3038,104 although I have not read them all.  I assume that some of them are similar. 

 

I have been a loyal Symantec fan for two decades and tired of reading all the Symantec bashing.  The only reason i did not bash them was because their product worked and when I had a problem they responded quickly.  They have failed on this issue...BUT THEY ARE working on finally with input from people on this forum.

 

Here is the first page to the my thread on 6/9.  http://community.norton.com/t5/Norton-Internet-Security-Norton/3038-104-NOT-SOLVED-Ungoing-problem-that-Norton-has-not-fixed/td-p/1142530

 

The solution to the problem actually was given on the first page.  maybe it has been posted on your thread as well. I did not want to employ it because it did not seem that I should have go back to complete shutdowns.  It seemed that it was Symantec's responsibility to make their product work and adapth to whatever changes MS employed.  But, I wanted the problem to go away......and there was a fix that worked for me.  Norton Symantec began to download itself over and over again with updates that were over 200MB.  Norton reported that it was doing the automatic updates and scans.  It was only the manual updates and scans that were bring the error codes. 

 

That was unacceptable, so I was willing to follow the suggestion by Nikhil_CV and turn off the hybrid shutdown/faststart settings that MS windows adopted with some versions of 7 and 8. 

 

Here is where Nikhil_CV made the suggestion. https://community.norton.com/t5/Norton-Internet-Security-Norton/3038-104-norton-knowledge-base-info-does-not-look-like-my/m-p/1122360#M257172

 

And, here is the location of a discussion abou the MS Faststart setting and how to change it:  http://www.eightforums.com/tutorials/6320-fast-startup-turn-off-windows-8-a.html

 

I want to emphasize that this did fix my problem.  I turned of the faststart setting over two weekes ago and my machine has worked properly ever since.  Let's be fair to all parties including Norton.   MS instigated this shortcut faststart to make users feel good, but it is causes some problems with some machines.  The hybrid shutdown does not allow all programs to reconfigure and reboot properly. 

 

I noticed that the lateest Symantec Knowledge base report does suggest rebooting as a fix.  

 

Doing the MS shutdown without turning off the FASTSTART setting will not fix the problem.  If you choose to do this, you must go into the control panel, select power plans where buttons are assigned their duties and turn OFF the fast start setting at the bottom of the page.  The faststart is a "feel good" user gimmick (IMO) that works for many users, but for some of us it blocks the full and proper implementation of Norton and the error codes continue when we try to run manual updates and scans.

 

   I'll add the frustrating disclaimer here that this may not work for you, but.........

 

I did the reinstalls and all the other stuff.  Changing admin rights is the fix.  Complete shutdown is for me.  I must thank Nikhil_CV again.

 

Good luck.

 

If I am repeating what was already stated on pages 4 through 9, I apologize.  Specially if you tried it and it failed.  But, my machine is working fine. 

 

 

 

 

 

 

Thank you for your helpful post.  I am running Windows 7 Ultimate 64-bit on a high-end workstation and I *never* use sleep.  Windows 7 does not have a fast boot mode or option that I can find.

 

I looked through my power options and other settings once I saw the new 3038,104 page with the fix for some Windows 8 users, and again when I saw your message that said fast boot was available for some Windows 7 systems.  Fast boot might be useful for laptops but I don't see its utility for workstations, and apparently Microsoft agreed when the decisions were made for Windows 7 Ultimate 64-Bit Edition, or perhaps it wasn't ready in time and was deferred to Windows 8.  For whatever reason, I do not see a fast boot option anywhere on my Windows 7 SP 1 Version 6.1.7601.

 

I have no plans to move to Windows 8.1.  My Windows 7 user interface is enhanced with Stardock Fences and ObjectDock, and a touch-screen user interface or dumbed-down content-consumer-centric user interface is less than apprpriate for a power user who is a content generator.

 

I use this computer for everything but the main reason for its existence as a high-end workstation is to do major number-cruncing for research work that I publish in the IEEE and elsewhere.  When either of two types of project is in progress, this machine will use 100% of all eight cores 24/7 for weeks or months at a time, and since outputs are infrequent, interrupting the process costs many GHz-core-hours each time.  Even when not doing that, I never shut down or reboot the machine unless I must, to apply a Windows Update, install or un-install software, or do maintenane or upgrade to the computer.

 

One thing that I have found in my logs is multiple application protection access rejections by N360 from the CONHOST process.  This happened many times when a Live Update got a 8920,208 error, which problem was apparently solved recently with the update to N360 21.4.0.13.  I still see it once when I get a 3038,104 error.  This happened this morning.  The error log:

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
7/11/2014 7:04:24 AM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,7/11/2014 7:04:24 AM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,4724,C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\cltlmh.exe,1232,Access Process Data,Unauthorized access blocked


I feel certain that this is directly related to the 3038,104.  I have been posting some of these logs on my thread, and the Symantec page ond 3038,104 announces that they are focusing on this problem.  I have announced my willingness to cooperate to any extent that Symantec deems appropriate short of destrcution of my data but they have not contaced me, which implies that they have sufficient resources for their purposes without my additional data.

 

I am awiating the Symatec solution to the 3038,104 problem.  I expect that I will not have to wait much longer, since the error now has their full attention.  I do expect that since the problem seems to be that N360 is not recognizing its own threads in some instances, the solution will require an update to the core engine, and we wil see the soluton as build 21.5 or 22.0.


F4E wrote:

Hi, motorfingers. Has anyone from Symantec asked you for logs etc, in this thread ?

 

I asked if someone could contact you maybe via PM in regards to providing info, so it can be properly investigated .


FYI,  I was never able to capture the log files associated with this problem (Live Update Virus Definition Installation Failures and 3038,104 errors) using the Norton Report Assistant per  HarryP's  "workaround", so I eventually gave up trying.   The Norton Report Assistant requires a system reboot in order to begin its log collection task.  Also the Norton Report Assistant cannot run for very long, as the files get too large to analyze.

 

And as we already know, rebooting temporarily remedies this 3038,104 problem.  So unfortunately, the process (system reboot followed by running the Norton Report Assistant) that enables Symantec to analyze the problem is also the process (system reboot) that prevents Symantec from analyzing this problem.

 

DD

 

Live Update/3038,104 Problem First Identified by Me Last November

 

Live Update/ 3038,104 Problem Characteristics Summary

 

Troubleshooting Steps/Exonerations For My Live Update/3038,104 Problem

 

My Home PC

NAV Version 21.2.0.38 (Automatic Live Update has been Disabled)
2010 Milwaukee PC Desktop - Windows 7 64 Bit Sp1

My Fathers PC (which he uses, but I own)
NAV Version 21.1.0.18  (Automatic Live Update has been Disabled)
2013 Dell 17R 5720 Inspiron Laptop - Windows 7 64 Bit Sp1

 

It looks like a patched version that runs a scrolling log and produces a freeze-frame when the error occurss is in order here.

Have had two more 3038,104 errors since last post.  Each time, the Security History gives this warning entry for the time of the error:

 

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
7/13/2014 7:00:12 PM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,7/13/2014 7:00:12 PM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,23208,C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\buih.exe,20704,Access Process Data,Unauthorized access blocked


 

I've had three 3038,104 errors since my last post.  All of them are accompained by a sercurity log entry like this:

 

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
7/17/2014 10:14:55 AM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,7/17/2014 10:14:55 AM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,3776,C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\cltlmh.exe,4600,Access Process Data,Unauthorized access blocked



It seems that a process run by CONHOST.EXE, probalby part of the scan initiation process becaue it happens during initialization, attempts to access cltlmh.exe.  This may be innocent but this always happens when I get the 3038,104 but not when a QuickScan succeeds.

Download Process Explorer from Microsoft - http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx which is going to give you a tree list of all running processes.  When you see CONHOST.EXE, have a look what's above it in the tree and you should find the software (or program) that is starting it.

Post back...

I just rebooted after a 3038,104 error but will look at Process Explorer instantly the next time I see a 3038,104 error.  Since the 3038,104 is repeatable, I can start Process Explorer and invoke the error while it is running, and match up the process numbers from the N360 Security log.

 

For now, what I have from Process Explorer is that there are two instances running, both invoked by csrss.exe, which is in

C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_b4d8d57efdc6b4f3

 

Also, is your OS clock accurate or still glitching from time to time??

It's normal to have one csrss.exe per user at the same time (say your user account and SYSTEM).  It's also fine to have more than one in Windows/System32 .

Worry if you have two instances running for the exact same user OR if the source of the running ,(or one of the running), csrss.exe file(s) is someplace other than Windows/System32.

 

My OS clock never glitched.  It does wander, as nearly all consumer PC clocks do, particularly if the machine is rarely booted.  I've been keeping track of the computer clock vs. time-b.nist.gov as part of my error log.  This morning it was 13 seconds slow, and I did not run nistime-32bits.exe, my usual utility to synch my motherboard clock.  In response to one user here who insisted that I replace the motherboard battery, I found that it was under the video card (!!!!) and when I could risk the computer being down for a day or two with complications I did change it.  The old one read 3.13 Volts and the new one read 3.36 Volts, so the old one was a little more tired that I would have expected but was good.

 

The defining incident that immediately precedes a 3038,104 error seems to be a download of a major virus definitions x64 update.  Before a recent patch, it would sometimes get a 8920,208 error when trying to apply the virus definitions x64 update, after what apeared to be a successful download.  But with or without the 8920,208 error a virus defintions x64 update seems to put N360 in a state where a manual QuickScan will result in a 3938,104 error.

 

I do have two instances of csrss.exe running, both using conhost.exe as a child process, with different amounts of memory committed.  Neither is color-coded by Process Explorer, nor is its child process.  I do have two copies of csrss.exe on my computer, one in C:\Windows\System32 and the other in

C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_b4d8d57efdc6b4f3

Both active processes are run from the file in System32.

 

The command line from one conhost.exe process is

\??\C:\Windows\system32\conhost.exe (Process 3480 from csrss.exe process 648) "1007773521-1760694224-681365219-1144346584-10794912391818132883-349166011-1940873375

The other is

\??\C:\Windows\system32\conhost.exe (Process 1368 from csrss.exe process 876) "1196674835-142793130814240514743684370541156981410-84607237-518438225-1206036427

 

I just started a DVD that uses massive Java and an instance of IE (GM Service Information) and have two more conhost.exe intances, and have two more conhost.exe processes from csrss.exe process 876.  I just closed the Java app and yes, the second two conhost.exe instances winked out in Process Explorer.

OK, had another 3038,104 and immediately invoked Process Explorer.  An unexpected complication is scads of blocked accesses *from* Process Explorer but I did find this one from the time of the error:

 

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Action,Reaction
7/19/2014 12:52:49 AM,Medium,Unauthorized access blocked (Set Registry Security Key),Blocked,No Action Required,7/19/2014 12:52:49 AM,C:\WINDOWS\SYSTEM32\SVCHOST.EXE,744,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\ROOT\LEGACY_BHDRVX64\0000\Control\,Set Registry Security Key,Unauthorized access blocked

From Process Explorer, process 744 is:
C:\Windows\system32\svchost.exe -k DcomLaunch
64-bit image

So, something called DcomLaunch

 

Please let me know if I'm doing this right, or what else I can do.

See in "Services" if everything, at the exception of Windows Defender, is properly configured:

 

http://www.sevenforums.com/tutorials/236709-services-restore-default-services-windows-7-a.html

 

Also, what you see in "Category: Norton Product Tamper Protection" is normal, no problem there.

Try, in order to test, to disable WU, Sleep, Hibernation from Control Panel and in N360, Optimizer, Auto LU and Norton Community Watch and every other configurable automated task/setting.

I know, it's asking a lot, but I believe that the trial & error method is your best bet for now.

Post back with every step you have done and results. 

 

 

I just got another 3038,104, and it is repeatable.  I clicked the button to go to the web site because I found that the link includes lots of system information that is conveyed to Norton when you do that.

 

Here's the current error that was concurrent with the 3038,104:

Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
7/19/2014 8:36:43 PM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,7/19/2014 8:36:43 PM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,23128,C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\buih.exe,20424,Access Process Data,Unauthorized access blocked

Actor Process 23128
CONHOST.EXE, no longer active

Target 20424
C:\Windows\system32\wbem\wmiprvse.exe

 

I ran QS again and did not see a new error in the log, but there was one from Process Explorer about once a second so it' spossible that I missed it in the crowd.

 

I'll work through your instructions and get back with you each step.  Thank you.