Endpoint Protection Small Business Edition

 View Only
  • 1.  Large kernel paged pool leak with tag "B1O1" from BHDrvx86.sys.

    Posted Feb 12, 2018 02:54 PM

    On 160 out of our 10,000 machines running SEP 12.1.5 and 12.1.6 and Windows Server 2008, I see a large kernel paged pool leak.  It has the tag "B1O1" (that's the letter O, not the number zero) and it is allocated from BHDrvx86.sys, part of Symantec Endpoint Protection.  On each affected machine, there is one allocation of 8,104 bytes about once per second.  Interestingly, this continues until it hits 20,001 allocations, which is about 160 MB of kernel paged pool.

    Also on these machines, SEP itself is in a wonky state, such that when I try to run the client UI (SymCorpUI.exe), I get the error popup from "Symantec Endpoint Protection" stating "Symantec Endpoint Protection cannot open because some Symantec services are stopped. Restart the Symantec servies, and then open Symantec Endpoint Protection."  So, it's not clear which of the issues (error or pool leak) is the cause of the other.

    I couldn't find any other reports of this anywhere, but it seems unlikely that I'm the first to find it since I have quite a few machines affected.

    Does this sound familiar to anyone?

     



  • 2.  RE: Large kernel paged pool leak with tag "B1O1" from BHDrvx86.sys.

    Posted Mar 29, 2018 03:50 PM

    Haven't seen it come up but you may need a full symdiag and process dump for support to review. You should reach out them.