Norton error YOU ARE UNPROTECTED, please click here to repair

When I click this is what I get:
Norton 360
22.25.3.5
BucketID: 0CA3E5F2
Windows 10 Pro
19041.1.amd64fre.vb_release.191206-1406
Norton Autofix Results: 0 item(s)

This happened befroe, and it will happen for another 6 months before Norton Liveupdate stops working just like before. I get a pop up box in the right hand courner of my screen telling me there is a error with Norton. But I get the above when I click it.

I already removed Norton 3 times, and reinstalled. the pattern is to effective to be random. After a install It allowed me to update norton, it will fine for 3 - 5 days, then the pop-up errors start and continue for 2 or 3 months no matter what I do, then I will not be allowd to connect to Live update.

An Norton has followed the pattern 3 - 4 times like clockwork.

I checked all the usually thinks, I looked in the register, I looked in my processes, etc I cannot find ANYTHING or reason that Norton is doing this over and over. The next time I get the pop up I will update this post.

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract:

Detailed description:

Product & version number: 360

OS details:Win 10 Pro

What is the error message you are seeing?

If you have any supporting screenshots, please add them:

Hello @Robert_M2

Is Norton 360 version 22.25.3.5 your current installed version, and if so, are you intentionally remaining on v22?

Are you intentionally using an old offline installer?

Intelligent Updater has been deprecated for legacy Norton products

======

======

======

======

======

AI sourced content may make mistakes

@Robert_M2 Here is a bit of added information for you regarding the bucket ID you presented to us: Do you have a full log from an event ID 1001 to post for review?

The BucketID 0CA3E5F2 on Windows 10 indicates that the following has happened:

In Windows Error Reporting (WER), a bucket ID is an automated, numeric signature created by Microsoft to group identical program crashes or system errors. The specific code 0ca3e5f2 typically represents a signature generated for a localized application or operating system crash. [1, 2]

What the Bucket ID Means

Because these bucket strings are purely used for Microsoft’s internal diagnostic matching, the ID itself doesn’t translate to a readable “error message.” It just means your computer or a specific program encountered a fatal error, grouped it under signature 0ca3e5f2, and likely logged it in your system’s crash history. [1]

How to Find the Crashing Application

To figure out exactly which program or component is throwing this error:

  1. Open the Start Menu, type Event Viewer, and press Enter.
  2. In the left pane, navigate to Windows Logs > Application.
  3. Look for recent events around the time your system or game crashed.
  4. Click on the Event ID 1001 log and check the General tab. It will list the Faulting Application Name and display the full Bucket ID. [1, 2, 3, 4]

How to Troubleshoot Random Crashes: Note - Event ID 1001 is only a logging of the event not the actual cause.

If you are experiencing frequent crashes, freezes, or Blue Screens of Death (BSoD) on your PC, you can use these standard diagnostic steps:

  • Update Your System: Check for missing operating system updates via Settings > Update & Security.
  • Scan for Corrupted Files: Search for and repair broken Windows files by running a DISM and SFC scan. Open Command Prompt as Administrator and enter:
    DISM.exe /Online /Cleanup-Image /RestoreHealth
    Followed by:
    sfc /scannow
  • Check Your Drivers: Ensure your graphics drivers and motherboard chipset drivers are fully updated. [1, 2, 3, 4, 5]

SA

Ok, so I have Windows 10 pro, 22H2 ( May 12, 2026—KB5087544 (OS Builds 19045.7291 and 19044.729 ). I am now having an activation issue. I let Support take over my PC remotely, but stopped them before they damaged it AGAIN, in the registry edit. Each time I have ever allowed it, they damage my system and force me to format/u the entire system.

As you can see, I have 2 devices available, but there is a server error. I used the Agent’s tools and did those repairs. But still nothing is repaired, and Auto fix is NOW giving me the error after Support did their thing.

Win 10 Pro is up to date. I uninstalled Norton and reinstalled the latest version. I used the remove tool, and reinstalled. I have removed it and reinstalled via Safe mode. None of it helped. I did a system DLL scan and found:

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.

Windows Resource Protection found corrupt files and successfully repaired them.
For online repairs, details are included in the CBS log file located at
windir\Logs\CBS\CBS.log. For example, C:\Windows\Logs\CBS\CBS.log. For offline
repairs, details are included in the log file provided by the /OFFLOGFILE flag.

My overall system is stable, its Norton that is giving me a hardtime.

Since, you’re on Windows 10 22H2 build 19045.7291, why are you running Norton 360 v22.25.3.5 in June 2026?

Where did you obtain the installer for v22.25.3.5 installation?
Why Windows 10 machine is repeatedly being rebuilt with a 2022-era Norton product?

Install Norton → everything works → 3–5 days later problems begin.

Why doesn’t v22 upgrade to v24+ during the 3-5 days?
How did this machine arrive at what appears to be a v22 installation in June 2026?
What is preventing the product from taking the normal update/migration path?
If the OP truly remains on v22 for extended periods, something is interrupting the normal product update path.

  • Why is the machine apparently staying on v22 in June 2026?
  • Why does everything work for 3–5 days before failing?

Let’s inventory what the OP has now revealed:

  • Multiple occurrences over years.
  • Multiple reinstalls.
  • Norton Remove & Reinstall tool.
  • Safe Mode reinstall.
  • Remote support sessions.
  • Activation error 10250.
  • BFE-related 5013,3 error.
  • SFC found corruption.
  • Apparent v22 UI ecosystem.
  • “Server error” messages.
  • Device limit reached despite screenshot showing 3 of 5 devices used.

And yet we still don’t know:

  • Why the machine appears to be on v22.
  • What installer source was used.
  • What Norton Support diagnosed.
  • Whether LiveUpdate is enabled.
  • Whether product updates ever occur.
  • Whether Norton Account shows stale devices.
  • Whether the activation issue predates the protection issue.

That’s a lot of missing context after multiple support interactions.

And

“Support damaged my system.”

Even if Norton Support was completely ineffective, I’d still expect at least one of the sessions to have uncovered something interesting.

The combination of:

“Reached device limit”

and

“3 of 5 devices used”

alone would normally prompt a technician to check backend account records.

That’s not the kind of inconsistency that usually gets ignored.

=======================

Were my machine. I’d clean uninstall Norton and run Microsoft Defender Antivirus a few weeks (as test) to prove “Norton is giving me a hardtime”

Were Norton proven the likely cause.
Norton Support (or an escalation team) needs to own the case.

============

I don’t understand why you’re using a legacy installer.
I don’t understand why you’re not following best practice – pulling fresh pre-activated install – from your Norton account.

Granted it’s been a few months since my last fresh install…but at that time Norton generated pre-activated download installer.

Regards w Respect

It was an old installation I had from a while ago. Its always worked, and live update always updated it.

I am no longer using that; I am using the latest Norton 360 support that managed to download for me. V22.24.2.6. I wasn’t able to download it from Norton in the normal way.

Why doesn’t v22 upgrade to v24+ during the 3-5 days?

Live update wasn’t working correctly, at least that is what I think. But it wasn’t running that originally; originally, it was running the latest version.

How did this machine arrive at what appears to be a v22 installation in June 2026?

I used an old installation

What is preventing the product from taking the normal update/migration path?

I don’t know, but I was having a live update issue that appears to be fixed now.

If the OP truly remains on v22 for extended periods, something is interrupting the normal product update path.

I haven’t I have obtained and installed in the latest version of Norton.

They check things, they just push buttons, and hope things don’t break. In the past, I have allowed them remote access, and every time I do, they dive into the registry or some other place they have no business, and start deleting things they don’t understand. Then the next thing I know I am forced to format my 126 TB array and start over all because some tech thought they were superman at a keyboard… this time I stopped them before they got to my registry. Most of these people have ZERO Clue when it comes to computers. They are following a script, hoping for the best.
They receive a 6-week training course focused on operating the equipment, not diagnosing problems.

The 3 to 5-device was ignored this last time by the techs. Again, they were just pushing buttons, hoping it was fixed.

I cannot download the file from Norton directly; it isn’t starting. Maybe it’s my server firewall, but I cleared Norton and its domain for all downloads. With no luck.

So you were running Norton 360 v26.x

v22 because – Norton LiveUpdate issue?
You cannot pull a fresh pre-activated download installer from your Norton account because – server firewall?
Are you behind a “server” or do you mean your “router firewall”?

Can you clean uninstall Norton and run Microsoft Defender Antivirus a few weeks (as test) to prove “Norton is causal”

Can you send yourself a link to the pre-activated download installer from your Norton account?

Wow – “storage array” & “server”

The LiveUpdate issue may simply be collateral damage from the activation problem, not evidence that a firewall or network issue caused everything in the first place.

And consider, if user has a 126 TB array, I’d expect them to have:

  • backups,
  • snapshots,
  • RAID management,
  • storage monitoring,
  • some understanding of what specifically failed.

At this point the case includes:

  • Norton activation anomalies (10250).
  • Device-count inconsistency.
  • LiveUpdate history.
  • Multiple reinstall attempts.
  • Support interventions.
  • An apparent large storage environment (126 TB array).
  • Some form of “server firewall” or nontrivial network setup.
  • Prior system file corruption found by SFC.
  • A chronology that spans months, not hours.

This is probably not going to be sorted long-distance by volunteers piecing together clues.
The thread has reached the point where direct observation of the environment would likely produce more insight in 30 minutes than another 30 forum posts.
This is not going to be sorted long distance. OP needs an engineer at the environment.

Why does Norton think the device limit is exceeded when the account shows available seats?
Why is this installation repeatedly ending up in an unprotected or activation-failed state?

1 Like

FWIW!! Disconnect ALL your external connected devices. Reboot. Retry activation of the new version.

SA

Hello @Robert_M2
Care to share your progress

Forum Post Title: Advanced Malware Hijacks Core Drivers, Spoofs Norton Auto-Fix, and Disables All OS Security – Technical Breakdown & Fix.

I have finally resolved a highly sophisticated, silent infection on my machine. I want to share the exact timeline, mechanics, and recovery steps here. This malware successfully deceived both Norton’s internal health metrics and their official technical support tools.

If this threat hadn’t eventually caused a severe cascade of local errors while trying to lock me out, I would have never known it was running. It used almost zero system resources, ran completely silent, and successfully survived Safe Mode and all standard cleanup utilities.

1. The Deceptive Timeline of Symptoms

  • The Silent Sabotage (LiveUpdate Failure): The very first sign of trouble was that Norton LiveUpdate completely stopped functioning. The malware quietly severed Norton’s connection to its update servers so it couldn’t download new signatures.

  • The Spoofed “Green Light” Loop: When LiveUpdate broke, Norton began throwing error pop-ups. However, when I clicked the “Auto-Fix” option, the malware intercepted the process, fed Norton fake success metrics, and forced the UI to display a reassuring green light indicating the system was protected. This deception successfully kept my guard down for an entire month.

  • The Activation Trap: I eventually realized LiveUpdate still wasn’t working, so I uninstalled Norton to perform a clean reinstall. The moment I attempted to reactivate, the malware intercepted the connection to Norton’s licensing servers and forced an error stating “You have exceeded your maximum number of activations.”

  • Blinding Official Technical Support: I called Norton Technical Support, who confirmed my subscription license was perfectly valid and active. However, when they attempted to use their official automated removal and remediation tools on my machine, none of their support tools functioned. The malware completely blocked their software from executing.

2. Advanced Capabilities & Total Security Blackout

Once Norton was removed, the malware dropped its disguise and initiated a total system lockdown:

  • Survives Safe Mode via Driver Hijacking: Standard cleanup tools and diagnostic environments failed because the malware remained fully active even when booting into Windows Safe Mode. It achieved this by binding its malicious code directly to my mandatory core hardware drivers—specifically my display and audio drivers. Because Windows must load these drivers to boot (even in Safe Mode), the virus was executed every single time.

  • The Network Vacuum (65,535 Ports Open): The virus disabled Windows Defender and dropped all local Windows firewalls. It then flung open every single local port on my PC, effectively turning my machine into a wide-open listening post.

  • Network-Driven Persistence (Shadow Copying): Every time the computer reconnected to the internet, the malware used a shadow copy function to instantly regenerate itself if any piece of it was deleted.

  • Administrative Takeover & Keylogging: The virus elevated its privileges to take over the native, hidden Windows Administrator account. With total system dominance, it planted a keylogger to monitor all activity and locked me out of my own security configurations.

3. How I Successfully Cleaned It (The Winning Strategy)

Because the virus was buried deep within the Windows core registry, administrative policies, and hardware drivers, the only way to destroy it was a completely isolated, highly technical manual reset:

  1. Network Isolation: I completely disconnected the machine from the internet. This was the ultimate winning move. It killed the malware’s shadow-copy regeneration capabilities and stopped it from fighting back. (Note: My external network-level firewall, a Ubiquiti UniFi Dream Machine (UDM), remained completely unaffected and kept my other household devices safe from the open ports on this PC).

  2. Bypassing the GUI with PowerShell: Since the standard Windows visual menus were corrupted and security executables were blocked, I used PowerShell to force-reset all Windows 10 Group Policies and permissions, stripping the malware of its administrative hold over the OS.

  3. Surgical Driver Purge: Because the malware was riding inside my hardware stack, I had to completely rip out, scrub, and reinstall my display and audio drivers to strip the virus of its physical hiding spots.

  4. Total Manual Registry Scrubbing: I manually went into the Windows Registry database and completely scrubbed every single remaining Norton key to clear the corrupted activation metrics the virus had left behind.

  5. OS Security & Network Reset: I unblocked and repaired Windows Defender so the native OS could regain its self-defense functions, flushed the DNS, and reset essential network functions to close all the wide-open ports.

I don’t have an official security definition name for this threat, but it is easily the most sophisticated piece of malicious software I have ever encountered. If your Norton LiveUpdate dies, or if official support tools suddenly fail to run on your machine, do not assume it’s a basic software glitch—you might be dealing with a highly persistent, silent kernel/user-level rootkit.

Had it not caused the errors, I would have never known. The virus was monitoring my system activity, network traffic, every key stroke, etc.

I use AI to help organize my thoughts more clearly so that the instructions on how I did what I did were clear

3 Likes

Hello @Robert_M2
Thanks for sharing your progress
Curious, are you now running Norton 360 v26.6?

I am glad you have solved this malware attack. Just reading about your issues is very alarming.

Brings up some good points to me about running old software that can be inherently prone to security vulnerabilities.

Also, would a complete format and reinstall of Windows have rid you of this malware? It seems like you manually cleaned the registry and other components so job well done.

Scary to think how vulnerable Norton V22 was.

I am running the lastest..

1 Like

Okay, you’re running Norton 360 v26.6
Thanks for sharing your progress