Solved

How to identify which application/driver/process is causing the non paged pool leak

Posted on 2008-06-17
5
770 Views
Last Modified: 2008-07-01
Hi Experts,

One of my  servers is having a non paged memory leak (in the event viewer I can find errors source:srv eventid 2019  The server was unable to allocate from the system non paged pool because the pool was empty).
The server is running windows server 2003 SP1 (IBM hardware  Xseries366) I have already used the poolmon utility to capture the poolsnap and I identify that there is a leak in the following tags :  AFDC,AFDE and FILE

Anyone have more knowledge about those tags (whats the application/etc..)? And I will appreciate if you can guide me on how to solve the leaking in those tags (installing the latest firmware?)

I appreciate any help,

Regards,
Boaz Galil:
0
Comment
Question by:dpatel_team
  • 3
  • 2
5 Comments
 

Author Comment

by:dpatel_team
Comment Utility
any idea on this issue?
0
 
LVL 38

Expert Comment

by:ChiefIT
Comment Utility
0
 

Author Comment

by:dpatel_team
Comment Utility
Yes ofcourse I used Poolmon - with Poolmon I identify that I have a leak at the following pools - AFDC/AFDE/FILE , but what is the next step ?
0
 
LVL 38

Assisted Solution

by:ChiefIT
ChiefIT earned 500 total points
Comment Utility
According to this article the AFDC and AFDE files might be a Heuristic virus. Heuristic, by definition, is a loose practice to a solution. So, this may be a viru in its infantcy, (a trial and error method to create a virus if you will). If your AV software is set to scan for Heuristic viruses, your AV software may be chewing on those files that and causing a memory leak.

http://gordano.biz/kb.htm?q=3161

How is this important?
http://www.claymania.com/virus-specific.html
I love this article that is real and to the point. No AV package is 100%. Scanning for Heuristic viruses can warn you, but most likely a AV product will not delete the suspected file until it becomes a full blown virus. What I like about this article is that it points out best met computing practices is the best tool to prevent viruses while a AV/AS package is still important.

In your case, I would look at a cleaning tool for w32\downloader and its variants. This might be a good start.
http://www.spywareguide.com/product_show.php?id=3510

It is not uncommon that a Heuristic scan causes a memory leak because the AV package doesn't know what to do with it.
0
 

Accepted Solution

by:
dpatel_team earned 0 total points
Comment Utility
The problem was solved by updating the IBM drivers,

I guess thats the first thing you need (updating drivers) to do whenver you bump into a non-page pool leak...

Thanks guys for your help.
0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

Learn about cloud computing and its benefits for small business owners.
In the modern office, employees tend to move around the workplace a lot more freely. Conferences, collaborative groups, flexible seating and working from home require a new level of mobility. Technology has not only changed the behavior and the expe…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now