Home
%3CLINGO-SUB%20id%3D%22lingo-sub-826673%22%20slang%3D%22en-US%22%3EApplication%20pool%20gets%20recycled%20due%20to%20anti-virus%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-826673%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20not%20the%20first%20time%20that%20I%20heard%20of%20my%20customers%20complaining%20about%20their%20anti-virus%3A%20after%20a%20certain%20activity%20(such%20as%20a%20regular%20scanning%20for%20system%20files)%2C%20their%20application%20pools%20get%20restarted%20automatically.%3C%2FP%3E%0A%3CP%3EWhen%20this%20issue%20happens%2C%20some%20customers%20are%20seeing%20the%20following%20event%20in%20System%20Event%20Log%3A%3C%2FP%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3ELog%20Name%3A%20System%0ASource%3A%20Microsoft-Windows-WAS%0ADate%3A%20XXXX%0AEvent%20ID%3A%205080%0ATask%20Category%3A%20None%0ALevel%3A%20Information%0AKeywords%3A%20Classic%0AUser%3A%20N%2FA%0AComputer%3A%20XXXX%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%3E%3CBR%20%2F%3E%3CSTRONG%3E%3CFONT%20color%3D%22%23800000%22%3EDescription%3A%3C%2FFONT%3E%3C%2FSTRONG%3E%3CBR%20%2F%3EThe%20worker%20processes%20serving%20application%20pool%20'%3CEM%3E%5BApplication%20pool%20name%5D%3C%2FEM%3E'%20are%20being%20recycled%20due%20to%201%20or%20more%20configuration%20changes%20in%20the%20application%20pool%20properties%20which%20necessitate%20a%20restart%20of%20the%20processes.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3EBut%20the%20anti-virus%20didn't%20make%20any%20modification%20to%20the%20configuration%20file.%20How%20could%20this%20happen%3F%3C%2FP%3E%0A%3CP%3EIn%20fact%2C%20there%20may%20be%20several%20reasons.%20For%20example%2C%20when%20anti-virus%20scans%20the%20concerned%20file%2C%20it%20changed%20the%20%22Last%20modification%20time%22%3B%20It%20can%20also%20occur%20when%20WAS%20tries%20to%20detect%20if%20the%20configuration%20file%20has%20been%20changed%2C%20while%20anti-virus%20is%20scanning%20the%20file%20at%20the%20same%20time%20hence%20WAS%20detects%20the%20handle%20on%20the%20file%20and%20considers%20it%20being%20modified.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EOne%20effective%20way%20to%20avoid%20this%20scenario%20is%20by%20excluding%20the%20related%20configuration%20files%20of%20IIS%20from%20the%20anti-virus%20scanning%20scope.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EHere%20is%20an%20exclusion%20list%20that%20you%20may%20consider%20configuring%20your%20anti-virus.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CBR%20%2F%3EAttention%3C%2FSTRONG%3E%3A%20this%20is%20not%20an%20official%20list%20provided%20by%20Microsoft%2C%20it%20is%20simply%20a%20recommended%20list%20summarized%20according%20to%20our%20support%20experience.%20You%20should%20find%20your%20own%20compromise%20between%20security%20and%20performance.%20If%20you%20need%20any%20further%20information%2C%20please%20contact%20your%20anti-virus%20vendor.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20folder%20for%20x86%20compiled%20ASP.Net%20Code%3C%2FSTRONG%3E%3A%20%25WINDIR%25%5CMicrosoft.NET%5CFramework%5C%7Bversion%7D%5CTemporary%20ASP.NET%20Files%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20folder%20for%20x64%20compiled%20ASP.Net%20Code%3C%2FSTRONG%3E%3A%20%25WINDIR%25%5CMicrosoft.NET%5CFramework64%5C%7Bversion%7D%5CTemporary%20ASP.NET%20Files%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EIIS%20Configuration%20Folder%3C%2FSTRONG%3E%3A%20%25WINDIR%25%5CSystem32%5CInetsrv%5CConfig%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20Content%20Location%20(where%20the%20web.config%20is%20located)%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5CWWWRoot%20(or%20the%20customized%20folder)%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20Logging%20Location%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5CLogs%5CLogFiles%20(or%20the%20customized%20folder)%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20FREB%20Logging%20Location%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5Cinetpub%5Clogs%5CFailedReqLogFiles%20(or%20the%20customized%20folder)%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20HTTP.SYS%20Logging%20Location%3C%2FSTRONG%3E%3A%20%25WINDIR%25%5CSystem32%5CLogFiles%5CHTTPERR%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20History%20Location%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5CHistory%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20Backup%20Location%3C%2FSTRONG%3E%3A%20%25WINDIR%25%5CSystem32%5CInetsrv%5Cbackup%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20folder%20for%20storing%20Compressed%20Content%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5Ctemp%5CIIS%20Temporary%20Compressed%20Files%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20folder%20for%20compiled%20ASP%20templates%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5Ctemp%5CASP%20Compiled%20Templates%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20Configuration%20Isolation%20Path%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5Ctemp%5CappPools%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDefault%20Folder%20for%20Error%20pages%3C%2FSTRONG%3E%3A%20%25SYSTEMDRIVE%25%5CInetpub%5Ccusterr%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20this%20is%20useful%20for%20you.%3C%2FP%3E%0A%3CP%3Eoriginally%20written%20by%3A%20Jin%20Wang%3CBR%20%2F%3Ereviewed%20by%3A%20Muna%20AlHassan%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CEM%3EArticles%20you%20may%20be%20interested%20in%3A%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EMicrosoft%20Anti-Virus%20Exclusion%20List%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CA%20href%3D%22http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F953.microsoft-anti-virus-exclusion-list.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F953.microsoft-anti-virus-exclusion-list.aspx%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EIIS%20Application%20Pool%20Recycling%20Events%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CA%20href%3D%22http%3A%2F%2Flinqto.me%2FWASCodes%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Flinqto.me%2FWASCodes%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ECommon%20reasons%20why%20your%20application%20pool%20may%20unexpectedly%20recycle%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CA%20href%3D%22http%3A%2F%2Fblogs.msdn.com%2Fb%2Fjohan%2Farchive%2F2007%2F05%2F16%2Fcommon-reasons-why-your-application-pool-may-unexpectedly-recycle.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fblogs.msdn.com%2Fb%2Fjohan%2Farchive%2F2007%2F05%2F16%2Fcommon-reasons-why-your-application-pool-may-unexpectedly-recycle.aspx%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-826673%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20not%20the%20first%20time%20that%20I%20heard%20of%20my%20customers%20complaining%20about%20their%20anti-virus%3A%20after%20a%20certain%20activity%20(such%20as%20a%20regular%20scanning%20for%20system%20files)%2C%20their%20application%20pools%20get%20restarted%20automatically.%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Microsoft

It's not the first time that I heard of my customers complaining about their anti-virus: after a certain activity (such as a regular scanning for system files), their application pools get restarted automatically.

When this issue happens, some customers are seeing the following event in System Event Log:

Log Name: System
Source: Microsoft-Windows-WAS
Date: XXXX
Event ID: 5080
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: XXXX


Description:
The worker processes serving application pool '[Application pool name]' are being recycled due to 1 or more configuration changes in the application pool properties which necessitate a restart of the processes.

But the anti-virus didn't make any modification to the configuration file. How could this happen?

In fact, there may be several reasons. For example, when anti-virus scans the concerned file, it changed the "Last modification time"; It can also occur when WAS tries to detect if the configuration file has been changed, while anti-virus is scanning the file at the same time hence WAS detects the handle on the file and considers it being modified.


One effective way to avoid this scenario is by excluding the related configuration files of IIS from the anti-virus scanning scope.


Here is an exclusion list that you may consider configuring your anti-virus.


Attention
: this is not an official list provided by Microsoft, it is simply a recommended list summarized according to our support experience. You should find your own compromise between security and performance. If you need any further information, please contact your anti-virus vendor.

  • Default folder for x86 compiled ASP.Net Code: %WINDIR%\Microsoft.NET\Framework\{version}\Temporary ASP.NET Files
  • Default folder for x64 compiled ASP.Net Code: %WINDIR%\Microsoft.NET\Framework64\{version}\Temporary ASP.NET Files
  • IIS Configuration Folder: %WINDIR%\System32\Inetsrv\Config
  • Default Content Location (where the web.config is located): %SYSTEMDRIVE%\Inetpub\WWWRoot (or the customized folder)
  • Default Logging Location: %SYSTEMDRIVE%\Inetpub\Logs\LogFiles (or the customized folder)
  • Default FREB Logging Location: %SYSTEMDRIVE%\inetpub\logs\FailedReqLogFiles (or the customized folder)
  • Default HTTP.SYS Logging Location: %WINDIR%\System32\LogFiles\HTTPERR
  • Default History Location: %SYSTEMDRIVE%\Inetpub\History
  • Default Backup Location: %WINDIR%\System32\Inetsrv\backup
  • Default folder for storing Compressed Content: %SYSTEMDRIVE%\Inetpub\temp\IIS Temporary Compressed Files
  • Default folder for compiled ASP templates: %SYSTEMDRIVE%\Inetpub\temp\ASP Compiled Templates
  • Default Configuration Isolation Path: %SYSTEMDRIVE%\Inetpub\temp\appPools
  • Default Folder for Error pages: %SYSTEMDRIVE%\Inetpub\custerr

 

Hope this is useful for you.

originally written by: Jin Wang
reviewed by: Muna AlHassan

Articles you may be interested in:

Microsoft Anti-Virus Exclusion List
http://social.technet.microsoft.com/wiki/contents/articles/953.microsoft-anti-virus-exclusion-list.a...

IIS Application Pool Recycling Events
http://linqto.me/WASCodes

Common reasons why your application pool may unexpectedly recycle
http://blogs.msdn.com/b/johan/archive/2007/05/16/common-reasons-why-your-application-pool-may-unexpe...