cogit
asked on
2003 Server Event Error SRV 2019 ... memory leak?
DC servers are exhibiting SRV event error 2019 error ... the services.exe and lsasse.exe are real high .
Process ID Proc.Name Wrkng.Set PagedPool NonPgdPl Pagefile Commit Handles Threads User Gdi
!LogType=memsnap
!ComputerName=server01
!buildnumber=3790
!buildtype=retail
!CSDVersion=Service Pack 2
!SystemTime=03\20\2008 00:50:13.0529 (GMT)
!TickCount=2277234218
00000000 (null) 28672 0 0 0 0 0 2 0 0
00000004 System 241664 0 0 0 32768 2020 95 0 0
0000016C smss.exe 471040 6500 520 131072 131072 26 2 0 0
0000019C csrss.exe 3899392 68900 5840 4751360 4751360 658 10 0 0
000001B4 winlogon.exe 11554816 89980 65120 8187904 8187904 543 19 0 0
000001E4 services.exe 79814656 220948 11920 5283840 5283840 472 19 0 0
000001FC lsass.exe 546848768 164188 76704 537100288 537100288 1767 62 0 0
000002BC svchost.exe 2998272 42060 2568 983040 983040 91 5 0 0
0000034C svchost.exe 3878912 48804 24864 1601536 1601536 305 13 0 0
00000388 svchost.exe 4837376 66748 6904 4030464 4030464 158 10 0 0
000003AC svchost.exe 6385664 41268 6968 4444160 4444160 186 14 0 0
000003C8 svchost.exe 24715264 145524 32480 18452480 18452480 1170 53 0 0
000004AC spoolsv.exe 6811648 71212 6456 4669440 4669440 156 13 0 0
000004C8 msdtc.exe 4308992 39172 5720 1826816 1826816 156 13 0 0
00000528 ASFAgent.exe 3530752 37652 2712 1024000 1024000 108 6 0 0
00000570 cimlistener.exe 974848 50700 7248 3330048 3330048 160 6 0 0
00000588 dfssvc.exe 6144000 60884 5936 3170304 3170304 144 12 0 0
000005A0 dns.exe 9474048 75356 19528 11030528 11030528 228 16 0 0
000005F0 IBMSA.exe 311296 15100 1040 270336 270336 30 2 0 0
000005FC IBMSPSVC.EXE 1204224 14668 1112 307200 307200 34 2 0 0
00000608 ismserv.exe 3760128 55252 6232 1871872 1871872 122 9 0 0
00000610 IBMSPREM.EXE 2195456 25884 1800 1773568 1773568 45 2 0 0
00000618 IBMSPREM.EXE 1753088 23900 1600 544768 544768 31 2 0 0
00000620 slp_srvreg.exe 2027520 24492 2312 651264 651264 33 1 0 0
00000660 bpinetd.exe 5185536 56780 96280 2510848 2510848 100 9 0 0
000006A8 ntfrs.exe 4263936 65564 16360 12460032 12460032 358 22 0 0
000006CC NTRtScan.exe 3670016 33628 3200 1724416 1724416 91 12 0 0
000006E8 svchost.exe 2293760 24340 2152 659456 659456 63 2 0 0
000006F8 locator.exe 2375680 48132 2352 765952 765952 59 3 0 0
00000724 RaidServ.exe 15396864 58092 22000 15138816 15138816 438 25 0 0
00000738 snmp.exe 12312576 92740 15368 7815168 7815168 348 7 0 0
00000760 lserver.exe 12525568 87636 13616 9134080 9134080 253 13 0 0
00000778 tier1slp.exe 1069056 25644 1872 827392 827392 50 2 0 0
000007A8 bpjava-msvc.exe 3788800 52476 63936 1372160 1372160 44 1 0 0
000007F0 TmListen.exe 6189056 109396532 218621736 2887680 2887680 373 10 0 0
0000080C twgipcsv.exe 1843200 23908 1400 561152 561152 33 2 0 0
00000844 twgipc.exe 6103040 72980 6352 2326528 2326528 174 6 0 0
000008A0 winvnc.exe 3579904 55604 5056 1150976 1150976 78 4 0 0
000008F0 wmicimserver.exe 1327104 69420 8640 4591616 4591616 225 11 0 0
00000984 unsecapp.exe 3309568 38884 2472 2035712 2035712 75 2 0 0
000009C8 wmiprvse.exe 7819264 65900 5104 3182592 3182592 232 7 0 0
000009D0 twgescli.exe 5578752 69028 4112 2785280 2785280 168 13 0 0
00000A38 twgmonit.exe 8269824 71404 5352 5222400 5222400 225 3 0 0
00000A58PegasusProviderAda pter.exe 1830912 82228 5632 10313728 10313728 269 9 0 0
00000AEC wmiprvse.exe 7888896 57908 5800 3313664 3313664 262 10 0 0
00000E4C OfcDog.exe 2027520 29540 1760 1642496 1642496 22 1 0 0
00000E84 svchost.exe 4882432 60604 5592 2633728 2633728 189 22 0 0
00000F30 unsecapp.exe 3706880 44756 2752 1282048 1282048 92 4 0 0
00000510 nfUMSagent.exe 2826240 49988 2200 1130496 1130496 44 3 0 0
00000CB0 csrss.exe 3416064 43844 3592 1257472 1257472 154 11 0 0
00000A34 winlogon.exe 2895872 84948 8576 3620864 3620864 254 17 13 36
00000E98 userinit.exe 3080192 40908 2680 2023424 2023424 58 4 0 5
00000D6C rdpclip.exe 3284992 58476 2600 1032192 1032192 78 5 4 5
000004EC explorer.exe 10506240 96652 10608 5935104 5935104 286 13 59 121
00000684 winvnc.exe 2760704 52364 2312 905216 905216 43 2 0 5
00000D18 BacsTray.exe 3186688 58036 2400 864256 864256 36 2 12 9
00000B74 PccNTMon.exe 3522560 53044 2792 1490944 1490944 53 4 33 55
00000B78 tracker.exe 4923392 63684 2616 1966080 1966080 44 2 9 27
00000D2C cmd.exe 1687552 27932 1416 1515520 1515520 30 1 0 4
00000A80 memsnap.exe 1462272 27060 1408 421888 421888 21 1 0 4
Process ID Proc.Name Wrkng.Set PagedPool NonPgdPl Pagefile Commit Handles Threads User Gdi
!LogType=memsnap
!ComputerName=server01
!buildnumber=3790
!buildtype=retail
!CSDVersion=Service Pack 2
!SystemTime=03\20\2008 00:50:13.0529 (GMT)
!TickCount=2277234218
00000000 (null) 28672 0 0 0 0 0 2 0 0
00000004 System 241664 0 0 0 32768 2020 95 0 0
0000016C smss.exe 471040 6500 520 131072 131072 26 2 0 0
0000019C csrss.exe 3899392 68900 5840 4751360 4751360 658 10 0 0
000001B4 winlogon.exe 11554816 89980 65120 8187904 8187904 543 19 0 0
000001E4 services.exe 79814656 220948 11920 5283840 5283840 472 19 0 0
000001FC lsass.exe 546848768 164188 76704 537100288 537100288 1767 62 0 0
000002BC svchost.exe 2998272 42060 2568 983040 983040 91 5 0 0
0000034C svchost.exe 3878912 48804 24864 1601536 1601536 305 13 0 0
00000388 svchost.exe 4837376 66748 6904 4030464 4030464 158 10 0 0
000003AC svchost.exe 6385664 41268 6968 4444160 4444160 186 14 0 0
000003C8 svchost.exe 24715264 145524 32480 18452480 18452480 1170 53 0 0
000004AC spoolsv.exe 6811648 71212 6456 4669440 4669440 156 13 0 0
000004C8 msdtc.exe 4308992 39172 5720 1826816 1826816 156 13 0 0
00000528 ASFAgent.exe 3530752 37652 2712 1024000 1024000 108 6 0 0
00000570 cimlistener.exe 974848 50700 7248 3330048 3330048 160 6 0 0
00000588 dfssvc.exe 6144000 60884 5936 3170304 3170304 144 12 0 0
000005A0 dns.exe 9474048 75356 19528 11030528 11030528 228 16 0 0
000005F0 IBMSA.exe 311296 15100 1040 270336 270336 30 2 0 0
000005FC IBMSPSVC.EXE 1204224 14668 1112 307200 307200 34 2 0 0
00000608 ismserv.exe 3760128 55252 6232 1871872 1871872 122 9 0 0
00000610 IBMSPREM.EXE 2195456 25884 1800 1773568 1773568 45 2 0 0
00000618 IBMSPREM.EXE 1753088 23900 1600 544768 544768 31 2 0 0
00000620 slp_srvreg.exe 2027520 24492 2312 651264 651264 33 1 0 0
00000660 bpinetd.exe 5185536 56780 96280 2510848 2510848 100 9 0 0
000006A8 ntfrs.exe 4263936 65564 16360 12460032 12460032 358 22 0 0
000006CC NTRtScan.exe 3670016 33628 3200 1724416 1724416 91 12 0 0
000006E8 svchost.exe 2293760 24340 2152 659456 659456 63 2 0 0
000006F8 locator.exe 2375680 48132 2352 765952 765952 59 3 0 0
00000724 RaidServ.exe 15396864 58092 22000 15138816 15138816 438 25 0 0
00000738 snmp.exe 12312576 92740 15368 7815168 7815168 348 7 0 0
00000760 lserver.exe 12525568 87636 13616 9134080 9134080 253 13 0 0
00000778 tier1slp.exe 1069056 25644 1872 827392 827392 50 2 0 0
000007A8 bpjava-msvc.exe 3788800 52476 63936 1372160 1372160 44 1 0 0
000007F0 TmListen.exe 6189056 109396532 218621736 2887680 2887680 373 10 0 0
0000080C twgipcsv.exe 1843200 23908 1400 561152 561152 33 2 0 0
00000844 twgipc.exe 6103040 72980 6352 2326528 2326528 174 6 0 0
000008A0 winvnc.exe 3579904 55604 5056 1150976 1150976 78 4 0 0
000008F0 wmicimserver.exe 1327104 69420 8640 4591616 4591616 225 11 0 0
00000984 unsecapp.exe 3309568 38884 2472 2035712 2035712 75 2 0 0
000009C8 wmiprvse.exe 7819264 65900 5104 3182592 3182592 232 7 0 0
000009D0 twgescli.exe 5578752 69028 4112 2785280 2785280 168 13 0 0
00000A38 twgmonit.exe 8269824 71404 5352 5222400 5222400 225 3 0 0
00000A58PegasusProviderAda
00000AEC wmiprvse.exe 7888896 57908 5800 3313664 3313664 262 10 0 0
00000E4C OfcDog.exe 2027520 29540 1760 1642496 1642496 22 1 0 0
00000E84 svchost.exe 4882432 60604 5592 2633728 2633728 189 22 0 0
00000F30 unsecapp.exe 3706880 44756 2752 1282048 1282048 92 4 0 0
00000510 nfUMSagent.exe 2826240 49988 2200 1130496 1130496 44 3 0 0
00000CB0 csrss.exe 3416064 43844 3592 1257472 1257472 154 11 0 0
00000A34 winlogon.exe 2895872 84948 8576 3620864 3620864 254 17 13 36
00000E98 userinit.exe 3080192 40908 2680 2023424 2023424 58 4 0 5
00000D6C rdpclip.exe 3284992 58476 2600 1032192 1032192 78 5 4 5
000004EC explorer.exe 10506240 96652 10608 5935104 5935104 286 13 59 121
00000684 winvnc.exe 2760704 52364 2312 905216 905216 43 2 0 5
00000D18 BacsTray.exe 3186688 58036 2400 864256 864256 36 2 12 9
00000B74 PccNTMon.exe 3522560 53044 2792 1490944 1490944 53 4 33 55
00000B78 tracker.exe 4923392 63684 2616 1966080 1966080 44 2 9 27
00000D2C cmd.exe 1687552 27932 1416 1515520 1515520 30 1 0 4
00000A80 memsnap.exe 1462272 27060 1408 421888 421888 21 1 0 4
do you have nortons? if so check this out: http://support.microsoft.com/default.aspx?scid=kb;en-us;272568&sd=ee
possible reasons would be antivirus drivers in the kernal.As a quick fix would be to restart the server.
Bring the server up to date with the drivers and MS patches.
Bring the server up to date with the drivers and MS patches.
ASKER
I am thinking the following: ... I have OU's with 40,000 objects!
It may be related to the lsass.exe
Memory Leak Occurs in the Lsass.exe Process on a Windows Server 2003-Based Domain Controller
SYMPTOMS
On a Microsoft Windows Server 2003-based domain controller, the memory usage may continue to increase, and therefore, you may have to periodically restart the server. If you use System Monitor to view the Local Security Authority Service (Lsass.exe) process, you see that the memory usage for the Lsass.exe process continues to grow. (To monitor this process, see the Process\Private Bytes and the Process\Virtual Bytes performance counters.)
Back to the top
CAUSE
This problem occurs because of a memory leak that is associated with the Lsass.exe process. The rate of the leak depends on the number of groups and of group members that exist in the domain, and on the number of group-related queries.
http://support.microsoft.com/kb/829993
It may be related to the lsass.exe
Memory Leak Occurs in the Lsass.exe Process on a Windows Server 2003-Based Domain Controller
SYMPTOMS
On a Microsoft Windows Server 2003-based domain controller, the memory usage may continue to increase, and therefore, you may have to periodically restart the server. If you use System Monitor to view the Local Security Authority Service (Lsass.exe) process, you see that the memory usage for the Lsass.exe process continues to grow. (To monitor this process, see the Process\Private Bytes and the Process\Virtual Bytes performance counters.)
Back to the top
CAUSE
This problem occurs because of a memory leak that is associated with the Lsass.exe process. The rate of the leak depends on the number of groups and of group members that exist in the domain, and on the number of group-related queries.
http://support.microsoft.com/kb/829993
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I download the patch that is not support by microsoft but will not put on the production dc's .