A few days ago J'ai mis à jour my PC to Windows 10. Cependant, after some use my PC started to slow down until it was impossible to use – it was due to high memory usage. After a restart, everything came back to normal (total usage around 25% of 8GB of RAM). Cependant, during a few hours of usage the memory builds up again to 70%, and if not restarted it further goes to 100%, and later on even freezes. Task manager does not help very much as it does not show all the processes (added screenshots below). Also tried RAMMap but it gives an error: "error refreshing database". J'ai essayé Googling this question, yet without much success.
I do not know much about PCs, but maybe some of you know this issue, or could help to find out what is using my RAM.
Windows 10 high mémoire usage (unknown reason)
Re: Windows 10 high mémoire usage (unknown reason)
You have a memory leak caused by a driver. Look at the high value of nonpaged kernel memory. In your case this is over 3.7 GB. Vous pouvez utiliser [poolmon](https://docs.microsoft.com/en-us/archive/blogs/ntdebugging/troubleshooting-pool-leaks-part-2-poolmon) to see which driver is causing the high usage.
Install the [Windows WDK](https://docs.microsoft.com/en-us/windows-hardware/drivers/download-the-wdk), run poolmon, sort it via P after pool type so that non paged is on top and via B after bytes to see the tag which uses most memory. Run poolmon by going to the folder where WDK is installed, allez dans Tools (or `C:\Program Files (x86)\Windows Kits\10\Tools\x64`) et cliquez sur `poolmon.exe`.
Now see which pooltag uses most memory as shown here:
Now open a cmd prompt and run the findstr command. To do this, open cmd prompt and type `cd C:\Windows\System32\drivers`. Then type `findstr /s __ *.*`, where __ is the tag (left-most name in poolmon).
Do this to see which driver uses this tag:
Now, allez dans the drivers folder (`C:\Windows\System32\drivers`) and faites un clic droit sur the driver in question (intmsd.sys in the above image example). Click Properties, allez dans the details tab to trouvez le Product Name. Look for an update for that product.
If the pooltag only shows Windows drivers or is listed in the pooltag.txt (`"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\triage\pooltag.txt"`)
you have use [xperf to trace what causes the usage](https://learn.microsoft.com/en-us/shows/defrag-tools/48-wpt-memory-analysis-pool). Install the [WPT from the Windows SDK](https://social.technet.microsoft.com/wiki/contents/articles/4847.install-the-windows-performance-toolkit-wpt.aspx), open a [cmd.exe en tant qu'administrateur](https://superuser.com/a/497256) and run this:
>
xperf -on PROC_THREAD+LOADER+POOL -stackwalk
PoolAlloc+PoolFree+PoolAllocSession+PoolFreeSession -BufferSize 2048
-MaxFile 1024 -FileMode Circular && timeout -1 && xperf -d C:\pool.etl
capture 30 -60s of the grow. Ouvrez le ETL with WPA.exe, add the Pool graphs to the analysis pane.
Put the pooltag column at first place and add the stack column. Now [load the symbols](http://support.microsoft.com/kb/311503/en-us) inside WPA.exe and expand the stack of the tag that you saw in poolmon.
Now find other 3rd party drivers which vous pouvez voir in the stack. Here the `Thre` tag (Thread) is used by AVKCl.exe from G-Data. Look for driver/program updates to fix it.
The user [Hristo Hristov](https://superuser.com/users/735434/hristo-hristov) provided a trace with a high `FMfn` usage during unzipping files:
The tag is used by the driver `WiseFs64.sys` which is part of the "Wise Folder Hider" program. Removing it fixes the leak.
The user [Samuil Dichev](https://superuser.com/users/878526/samuil-dichev) provided a trace with a high `FMic` and `Irp` usage
The tags are used by the program [Razor Cortex](https://www.razerzone.com/eu-en/cortex).
In the sample of the user [chr0n0ss](https://superuser.com/users/918488/chr0n0ss) the `FMic` and `Irp` usage is caused by F-Secure Antivirus Suite:
Removing it and using Windows Defender a résolu le problème for him.
Install the [Windows WDK](https://docs.microsoft.com/en-us/windows-hardware/drivers/download-the-wdk), run poolmon, sort it via P after pool type so that non paged is on top and via B after bytes to see the tag which uses most memory. Run poolmon by going to the folder where WDK is installed, allez dans Tools (or `C:\Program Files (x86)\Windows Kits\10\Tools\x64`) et cliquez sur `poolmon.exe`.
Now see which pooltag uses most memory as shown here:
Now open a cmd prompt and run the findstr command. To do this, open cmd prompt and type `cd C:\Windows\System32\drivers`. Then type `findstr /s __ *.*`, where __ is the tag (left-most name in poolmon).
Do this to see which driver uses this tag:
Now, allez dans the drivers folder (`C:\Windows\System32\drivers`) and faites un clic droit sur the driver in question (intmsd.sys in the above image example). Click Properties, allez dans the details tab to trouvez le Product Name. Look for an update for that product.
If the pooltag only shows Windows drivers or is listed in the pooltag.txt (`"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\triage\pooltag.txt"`)
you have use [xperf to trace what causes the usage](https://learn.microsoft.com/en-us/shows/defrag-tools/48-wpt-memory-analysis-pool). Install the [WPT from the Windows SDK](https://social.technet.microsoft.com/wiki/contents/articles/4847.install-the-windows-performance-toolkit-wpt.aspx), open a [cmd.exe en tant qu'administrateur](https://superuser.com/a/497256) and run this:
>
xperf -on PROC_THREAD+LOADER+POOL -stackwalk
PoolAlloc+PoolFree+PoolAllocSession+PoolFreeSession -BufferSize 2048
-MaxFile 1024 -FileMode Circular && timeout -1 && xperf -d C:\pool.etl
capture 30 -60s of the grow. Ouvrez le ETL with WPA.exe, add the Pool graphs to the analysis pane.
Put the pooltag column at first place and add the stack column. Now [load the symbols](http://support.microsoft.com/kb/311503/en-us) inside WPA.exe and expand the stack of the tag that you saw in poolmon.
Now find other 3rd party drivers which vous pouvez voir in the stack. Here the `Thre` tag (Thread) is used by AVKCl.exe from G-Data. Look for driver/program updates to fix it.
The user [Hristo Hristov](https://superuser.com/users/735434/hristo-hristov) provided a trace with a high `FMfn` usage during unzipping files:
The tag is used by the driver `WiseFs64.sys` which is part of the "Wise Folder Hider" program. Removing it fixes the leak.
The user [Samuil Dichev](https://superuser.com/users/878526/samuil-dichev) provided a trace with a high `FMic` and `Irp` usage
The tags are used by the program [Razor Cortex](https://www.razerzone.com/eu-en/cortex).
In the sample of the user [chr0n0ss](https://superuser.com/users/918488/chr0n0ss) the `FMic` and `Irp` usage is caused by F-Secure Antivirus Suite:
Removing it and using Windows Defender a résolu le problème for him.