Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

New Scan Engine causing memory leaks..?

Updated: 10 Aug 2010 | 9 comments
cosmos99's picture
0 0 Votes
Login to vote

We have close to 100 machines that are running Windows XP SP3 which are now leaking memory after the latest update to Scan Engine 91.2.1.10.
Our dumps show that the culprit is SavE which is using 105 MB out of 165 MB of paged pool.
The only way to log into these machines after the memory leak is to safe mode into the local account. Once there if I disable Savrtpel.sys and Savrt.sys in Device Manager 'Non Plug and Play Drivers' the problem goes away.

Obviously we can't do that, and upgrading to program 10.1.9 will be a nightmare. There are still literally hundreds of machines that could still fail if they receive this new scan engine..

I should point out that the problem is only visible on our Lenovo ThinCentre family..especially the 8212's.

Any ideas of what could be causing this?

Thank you in advance

Discussion Filed Under:

Comments

tjeerdk's picture
29
Jan
2010
0 Votes 0
Login to vote

 same here... here it happens

 same here... here it happens on intel motherboard 865GBL

added 3 reg keys...and this appears to help...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management]
"PagedPoolSize"=dword:ffffffff
"PoolUsageMaximum"=dword:0000003c
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters]
"IRPStackSize"=dword:00000012
at least no messages when starting explorer and stuff like that...

but it took us 2 to three days to fix the 200 that were broken here
 

TomFoolery's picture
01
Feb
2010
0 Votes 0
Login to vote

Here too

Different HP models having the same problem.
Program: 10.1.6.6010
Scan engine: 91.2.1.10

Changing the paged pool size and pool usage max is fine for now, but I'd like to get a fix.

SavE associated with savrt.sys is using 108MB of the paged pool.
So users are getting many of these symptoms: ghost images, missing icons,  "Insufficient Resources...", "There is insufficient memory...", "Not enough system resources..." 
The number of affected computers is growing and the townfolk are getting restless.

I appreciate the assistance,
thanks

teiva-boy's picture
01
Feb
2010
0 Votes 0
Login to vote

Call Support and see if there

Call Support and see if there are any known issues with your build.  In some cases, there are known issues that are ONLY known to internal folks where they have workarounds that they need you to try before they go into the mainstream KB articles... 

There is an online portal, save yourself the long hold times. Create ticket online, then call in with ticket # in hand :-) http://mysupport.symantec.com "We backup data to restore, we don't backup data just to back it up."

Paul Murgatroyd's picture
04
Feb
2010
0 Votes 0
Login to vote

Hi All, We updated the

Hi All,

We updated the AV engine yesterday (for multi day definitions) and today (for daily certified definitions) to address some Page Pool memory issues.
 
The maintenance release makes changes only to the 32 bit driver (naveng.sys and navex15.sys) files. They will be updated to version 20091.2.2.11 but the information displayed in the product GUI will remain the same.
 
Hope this helps

thanks

Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint

MusicMan1's picture
09
Feb
2010
0 Votes 0
Login to vote

Paul, where should  these sys

Paul, where should  these sys files be on the clients?  I have found different versions in different locations such as:
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub
and
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100207.006

I would assume that those files in the latest virus def folder would take precedence over those in the BinHub folder, correct?  We have machines that are experiencing this issue yet thay have version 20091.2.2.11 in their virus defs folders...  Just an FYI.   I am looking into migrating to End Point Protectino Manager, but in the interim I have to address this issue (and I  already had a ticket open with the helpdesk where I Was told there are no known problems with our version but we should upgrade anyway from 10.1.5 to 10.1.9)

Someone Else's picture
09
Feb
2010
0 Votes 0
Login to vote

No known problems with 10.1.5?

Who told you there are no known problems with 10.1.5?  That is false.  There are serious security vulnerabilities in 10.1.5, 10.1.6, and 10.1.7.  SYM07-018, SYM07-019, SYM07-024, SYM08-022, SYM09-007, and SYM09-008 just for starters.

MusicMan1's picture
09
Feb
2010
0 Votes 0
Login to vote

Well, leet me quantify

Well, leet me quantify that....  the tech stated there are no known issues related to a memory leak or other poblem with system resources realted to the client version 10.1.5.  Knowing that by their very nature any AV client is a resource hog and that I always get the same technician with the same language hurdle I gave up on the "official" route, and generally find more assistance from those who have had to deal with it in the real world anyway.

MusicMan1's picture
09
Feb
2010
0 Votes 0
Login to vote

correction, I meant to say

correction, I meant to say "qualify", not "quantify"...

gammhunn's picture
09
Feb
2010
0 Votes 0
Login to vote

Anyone seeing pool usage

Anyone seeing pool usage issues should get some respite with the latest engine updates (released on February 4th) the new engine frees up approx 15MB

See http://service1.symantec.com/SUPPORT/ent-security.... for some additional detail.

That being said, if you are using versions _prior_ to SAV 10.1.8.xxxx (10.1 MR8) or SEP 11 MR4MP2 , you will need to upgrade to avail of further reductions in pool usage.

This is not a memory leak - as definition size increase, so does our pool usage. When 10.1 MR5, MR6MP1 etc was released, the definition size was approx half of what it is now (if memory serves)

So the recommendation here is use the "breathing space" offered by the engine update, and move to a newer version asap.

Hope this helps.