| Author |
IIS crashes with Interdev
|
|
| Jorge Dominguez 2004-09-22, 9:26 pm |
|
I need help trying to figure out what is going on with my IIS Server.
Every time I retrieve a file or syunchronize a project within Interdev
the IIS server crashes. I've tried using the iisstate utility but I
can't seem to get it going. I get a message that states "Thread Type:
Possible ASP page. Possible DCOM activity Executing Page: ASP.dll
symbols not found. Unable to locate ASP page. Continuing with other
analysis." The log file is as follows:
Opened log file 'C:\iisstate\output\IISState-1780.log'
***********************
Starting new log output
IISState version 3.3.1
Wed Sep 22 12:48:38 2004
OS = Windows 2000
Executable: inetinfo.exe
PID = 1780
Note: Thread times are formatted as HH:MM:SS.ms
***********************
Thread ID: 0
System Thread ID: 424
Kernel Time: 0:0:0.10
User Time: 0:0:0.10
Thread Type: Other
# ChildEBP RetAddr
00 0006f89c 7c5785d1 ntdll!ZwReadFile+0xb
01 0006f910 7c2e4cd9 KERNEL32!ReadFile+0x181
02 0006f93c 7c2e4b5f ADVAPI32!ScGetPipeInput+0x28
03 0006f9b8 7c2e6632 ADVAPI32!ScDispatcherLoop+0x4a
04 0006fbf4 01002884 ADVAPI32!StartServiceCtrlDispatcherA+0x7
d
05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
06 0006ff70 01002fbf inetinfo!main+0x654
07 0006ffc0 7c581af6 inetinfo!mainCRTStartup+0xff
08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d
Thread ID: 1
System Thread ID: 170
Kernel Time: 0:0:0.100
User Time: 0:0:0.120
Thread Type: Other
# ChildEBP RetAddr
00 0059fd1c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 0059fd44 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 0059fd54 6e6f1685 KERNEL32!WaitForSingleObject+0xf
03 0059fd70 01002440 iisadmin!ServiceEntry+0x156
04 0059ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
05 0059ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
06 0059ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 2
System Thread ID: 690
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 006dfe5c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 006dfeac 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 006dff08 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 006dff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
04 006dff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 006dffb4 7c57438b MSVCRT!_endthreadex+0xc1
06 006dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 3
System Thread ID: 138
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0071fe5c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 0071feac 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0071ff08 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 0071ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
04 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 0071ffb4 7c57438b MSVCRT!_endthreadex+0xc1
06 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 4
System Thread ID: 688
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 00b7fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
01 00b7ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
02 00b7ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
03 00b7ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
04 00b7ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
05 00b7ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 5
System Thread ID: 6f0
Kernel Time: 0:0:0.210
User Time: 0:0:0.100
Thread Type: Other
# ChildEBP RetAddr
00 00e0fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 00e0fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e0fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e0fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e0fd30 65f0cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
05 00e0fd70 01002440 w3svc!ServiceEntry+0x1b5
06 00e0ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
07 00e0ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
08 00e0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 6
System Thread ID: 640
Kernel Time: 0:0:0.80
User Time: 0:0:0.60
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 00e4fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 00e4fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e4fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e4fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e4fd30 6b561a78 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
05 00e4fd70 01002440 SMTPSVC!ServiceEntry+0x136
06 00e4ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
07 00e4ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
08 00e4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 7
System Thread ID: 618
Kernel Time: 0:0:0.20
User Time: 0:0:0.20
Thread Type: Other
# ChildEBP RetAddr
00 00e8fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 00e8fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e8fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e8fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e8fd30 69df7e25 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
05 00e8fd70 01002440 NntpSvc!ServiceEntry+0x13f
06 00e8ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
07 00e8ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
08 00e8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 8
System Thread ID: 660
Kernel Time: 0:0:0.30
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00ecfc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 00ecfc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00ecfcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 00ecfce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00ecfd30 6fc6b2f0 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
05 00ecfd70 01002440 ftpsvc2!ServiceEntry+0xc7
06 00ecffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
07 00ecffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
08 00ecffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 9
System Thread ID: 6e8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0110ff5c 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 0110ff88 6d7029ef KERNEL32!GetQueuedCompletionStatus+0x27
02 0110ffb4 7c57438b ISATQ!I_AtqOplockThreadFunc+0x32
03 0110ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 10
System Thread ID: 6ec
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0114ff50 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 0114ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0114ffb4 7c57438b ISATQ!AtqPoolThread+0x40
03 0114ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 11
System Thread ID: 6ac
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0118ff50 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 0118ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0118ffb4 7c57438b ISATQ!AtqPoolThread+0x40
03 0118ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 12
System Thread ID: 654
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0144feb8 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 0144fee4 77d31394 KERNEL32!GetQueuedCompletionStatus+0x27
02 0144ff20 77d3e93f RPCRT4!COMMON_ProcessCalls+0x9e
03 0144ff74 77d3e8c2 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEven
ts+0x99
04 0144ff78 77d35924 RPCRT4!ProcessIOEventsWrapper+0x9
05 0144ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
06 0144ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
07 0144ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 13
System Thread ID: 680
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0150fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
01 0150ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
02 0150ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
03 0150ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
04 0150ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
05 0150ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 14
System Thread ID: 64c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0154fd20 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 0154fd70 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
02 0154fd88 778322b2 KERNEL32!WaitForMultipleObjects+0x17
03 0154ffb4 7c57438b RTUTILS!TraceServerThread+0xde
04 0154ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 15
System Thread ID: 634
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0159ff20 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 0159ff70 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
02 0159ff88 701224fa KERNEL32!WaitForMultipleObjects+0x17
03 0159ffb4 7c57438b exstrace!RegNotifyThread+0x6f
04 0159ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 16
System Thread ID: 54c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 015dff24 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 015dff74 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
02 015dff8c 70121e6a KERNEL32!WaitForMultipleObjects+0x17
03 015dffb4 7c57438b exstrace!WriteTraceThread+0x2f
04 015dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 17
System Thread ID: 63c
Kernel Time: 0:0:0.0
User Time: 0:0:0.20
Thread Type: Other
# ChildEBP RetAddr
00 0169ff64 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 0169ff8c 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 0169ff9c 6ff2841e KERNEL32!WaitForSingleObject+0xf
03 0169ffb4 7c57438b FCACHDLL!CScheduleThread::ScheduleThread
+0x22
04 0169ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 18
System Thread ID: 630
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 017dff18 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 017dff68 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
02 017dff80 6b57b026 KERNEL32!WaitForMultipleObjects+0x17
03 017dffb4 7c57438b SMTPSVC!TcpRegNotifyThread+0x136
04 017dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 19
System Thread ID: 710
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0181ff68 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 0181ff90 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 0181ffa0 6b57ae5a KERNEL32!WaitForSingleObject+0xf
03 0181ffb4 7c57438b SMTPSVC!FreeLibThread+0x1d
04 0181ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 20
System Thread ID: 720
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0185ff00 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 0185ff50 75037871 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0185ff6c 6fc66e80 WS2_32!WSAWaitForMultipleEvents+0x18
03 0185ffb4 7c57438b ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThrea
dFunc+0x39
04 0185ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 21
System Thread ID: 620
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0189ff64 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 0189ff8c 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 0189ff9c 69e17598 KERNEL32!WaitForSingleObject+0xf
03 0189ffb4 7c57438b NntpSvc!CScheduleThread::ScheduleThread+
0x22
04 0189ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 22
System Thread ID: 650
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 018dff5c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 018dff84 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 018dff94 69e13c14 KERNEL32!WaitForSingleObject+0xf
03 018dffb4 7c57438b NntpSvc!CRetryQ::RetryQueueThread+0x36
04 018dffc0 77f88b43 KERNEL32!BaseThreadStart+0x52
05 77fd0348 ffffffff ntdll!LdrpLoadDll+0x3c5
06 77fd03e0 77fd0348 0xffffffff
07 00000000 00000000 ntdll!LoaderLock
Thread ID: 23
System Thread ID: 58c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Compression Thread
# ChildEBP RetAddr
00 0191ff5c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 0191ff84 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 0191ff94 732c3366 KERNEL32!WaitForSingleObject+0xf
03 0191ffb4 7c57438b compfilt!CompressionThread+0x29
04 0191ffc0 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 24
System Thread ID: 838
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0198fe70 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 0198fec0 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0198ff1c 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 0198ff38 65f09ccb USER32!MsgWaitForMultipleObjects+0x1d
04 0198ff7c 78008454 w3svc!CMTACallbackThread::Thread+0x42
05 0198ffb4 7c57438b MSVCRT!_endthread+0xc6
06 0198ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 25
System Thread ID: 5e4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 019cfea8 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
01 019cfef8 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
02 019cff54 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
03 019cff70 65f09d47 USER32!MsgWaitForMultipleObjects+0x1d
04 019cffb4 7c57438b w3svc!OleHackThread+0x88
05 019cffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 26
System Thread ID: 840
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01a4fce0 74fd1394 ntdll!ZwWaitForSingleObject+0xb
01 01a4fd1c 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
02 01a4fe08 750312f5 msafd!WSPSelect+0x24e
03 01a4fe6c 6e2b3b6e WS2_32!select+0xe7
04 01a4ffb4 7c57438b inetsloc!SocketListenThread+0x51
05 01a4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 27
System Thread ID: 848
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 01a8fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
01 01a8ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
02 01a8ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
03 01a8ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
04 01a8ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
05 01a8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 28
System Thread ID: 844
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 01acfdfc 74fd1394 ntdll!ZwWaitForSingleObject+0xb
01 01acfe38 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
02 01acff24 750312f5 msafd!WSPSelect+0x24e
03 01acff88 6d7075bd WS2_32!select+0xe7
04 01acffb0 6d70791b ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
05 01acffb4 7c57438b ISATQ!BmonThreadFunc+0x9
06 01acffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 29
System Thread ID: 430
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01b0ff4c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 01b0ff74 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 01b0ff84 69de42a5 KERNEL32!WaitForSingleObject+0xf
03 01b0ffb4 7c57438b NntpSvc!CNewsTree::NewsTreeCrawler+0x1d0
04 01b0ffc0 2e626577 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
05 6f637261 00000000 0x2e626577
Thread ID: 30
System Thread ID: 4b0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01b4ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 01b4ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
02 01b4ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
03 01b4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 31
System Thread ID: 718
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01b8ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 01b8ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
02 01b8ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
03 01b8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 32
System Thread ID: 880
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01bcff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 01bcff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
02 01bcffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
03 01bcffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 33
System Thread ID: 884
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01c0ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
01 01c0ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
02 01c0ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
03 01c0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 34
System Thread ID: 888
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01c4ff48 7c573b28 ntdll!ZwWaitForSingleObject+0xb
01 01c4ff70 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
02 01c4ff80 69ddabe8 KERNEL32!WaitForSingleObject+0xf
03 01c4ffb4 7c57438b NntpSvc!FeedScheduler+0x5c
04 01c4ffc0 2e626577 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
05 6f637261 00000000 0x2e626577
Thread ID: 35
System Thread ID: 88c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 01c8fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
01 01c8ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
02 01c8ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
03 01c8ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
04 01c8ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
05 01c8ffec 00000000 KERNEL32!BaseThreadStart+0x52
*****
Dump name is formatted as: PID-Timestamp.dmp
Creating C:\iisstate\output\1780-1095871722.dmp - mini user dump
*****
Closing open log file C:\iisstate\output\IISState-1780.log
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-22, 9:26 pm |
| This shows an idle process. I did not see any activity. To catch a crash
run:
iisstate -p <pid of inetinfo> -sc <enter>
Then do the Interdev thing.
Then a log should be created.
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:%23cp$kcMoEHA.592@TK2MSFTNGP11.phx.gbl...
>
> I need help trying to figure out what is going on with my IIS Server.
> Every time I retrieve a file or syunchronize a project within Interdev
> the IIS server crashes. I've tried using the iisstate utility but I
> can't seem to get it going. I get a message that states "Thread Type:
> Possible ASP page. Possible DCOM activity Executing Page: ASP.dll
> symbols not found. Unable to locate ASP page. Continuing with other
> analysis." The log file is as follows:
>
>
> Opened log file 'C:\iisstate\output\IISState-1780.log'
>
> ***********************
> Starting new log output
> IISState version 3.3.1
>
> Wed Sep 22 12:48:38 2004
>
> OS = Windows 2000
> Executable: inetinfo.exe
> PID = 1780
>
> Note: Thread times are formatted as HH:MM:SS.ms
>
> ***********************
>
>
>
>
> Thread ID: 0
> System Thread ID: 424
> Kernel Time: 0:0:0.10
> User Time: 0:0:0.10
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0006f89c 7c5785d1 ntdll!ZwReadFile+0xb
> 01 0006f910 7c2e4cd9 KERNEL32!ReadFile+0x181
> 02 0006f93c 7c2e4b5f ADVAPI32!ScGetPipeInput+0x28
> 03 0006f9b8 7c2e6632 ADVAPI32!ScDispatcherLoop+0x4a
> 04 0006fbf4 01002884 ADVAPI32!StartServiceCtrlDispatcherA+0x7
d
> 05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
> 06 0006ff70 01002fbf inetinfo!main+0x654
> 07 0006ffc0 7c581af6 inetinfo!mainCRTStartup+0xff
> 08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d
>
>
>
>
> Thread ID: 1
> System Thread ID: 170
> Kernel Time: 0:0:0.100
> User Time: 0:0:0.120
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0059fd1c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 0059fd44 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 0059fd54 6e6f1685 KERNEL32!WaitForSingleObject+0xf
> 03 0059fd70 01002440 iisadmin!ServiceEntry+0x156
> 04 0059ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
> 05 0059ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
> 06 0059ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 2
> System Thread ID: 690
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 006dfe5c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 006dfeac 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 006dff08 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 006dff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
> 04 006dff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
> 05 006dffb4 7c57438b MSVCRT!_endthreadex+0xc1
> 06 006dffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 3
> System Thread ID: 138
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0071fe5c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 0071feac 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 0071ff08 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 0071ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
> 04 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
> 05 0071ffb4 7c57438b MSVCRT!_endthreadex+0xc1
> 06 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 4
> System Thread ID: 688
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 00b7fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
> 01 00b7ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
> 02 00b7ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
> 03 00b7ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
> 04 00b7ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
> 05 00b7ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 5
> System Thread ID: 6f0
> Kernel Time: 0:0:0.210
> User Time: 0:0:0.100
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00e0fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 00e0fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 00e0fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 00e0fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
> 04 00e0fd30 65f0cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
> 05 00e0fd70 01002440 w3svc!ServiceEntry+0x1b5
> 06 00e0ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
> 07 00e0ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
> 08 00e0ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 6
> System Thread ID: 640
> Kernel Time: 0:0:0.80
> User Time: 0:0:0.60
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 00e4fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 00e4fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 00e4fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 00e4fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
> 04 00e4fd30 6b561a78 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
> 05 00e4fd70 01002440 SMTPSVC!ServiceEntry+0x136
> 06 00e4ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
> 07 00e4ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
> 08 00e4ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 7
> System Thread ID: 618
> Kernel Time: 0:0:0.20
> User Time: 0:0:0.20
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00e8fc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 00e8fc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 00e8fcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 00e8fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
> 04 00e8fd30 69df7e25 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
> 05 00e8fd70 01002440 NntpSvc!ServiceEntry+0x13f
> 06 00e8ffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
> 07 00e8ffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
> 08 00e8ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 8
> System Thread ID: 660
> Kernel Time: 0:0:0.30
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00ecfc1c 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 00ecfc6c 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 00ecfcc8 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 00ecfce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
> 04 00ecfd30 6fc6b2f0 INFOCOMM!IIS_SERVICE::StartServiceOperat
ion+0x209
> 05 00ecfd70 01002440 ftpsvc2!ServiceEntry+0xc7
> 06 00ecffa4 7c2e4e9b inetinfo!InetinfoStartService+0x2bd
> 07 00ecffb4 7c57438b ADVAPI32!ScSvcctrlThreadW+0xe
> 08 00ecffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 9
> System Thread ID: 6e8
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 0110ff5c 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 0110ff88 6d7029ef KERNEL32!GetQueuedCompletionStatus+0x27
> 02 0110ffb4 7c57438b ISATQ!I_AtqOplockThreadFunc+0x32
> 03 0110ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 10
> System Thread ID: 6ec
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 0114ff50 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 0114ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 0114ffb4 7c57438b ISATQ!AtqPoolThread+0x40
> 03 0114ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 11
> System Thread ID: 6ac
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 0118ff50 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 0118ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 0118ffb4 7c57438b ISATQ!AtqPoolThread+0x40
> 03 0118ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 12
> System Thread ID: 654
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 0144feb8 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 0144fee4 77d31394 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 0144ff20 77d3e93f RPCRT4!COMMON_ProcessCalls+0x9e
> 03 0144ff74 77d3e8c2 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEven
ts+0x99
> 04 0144ff78 77d35924 RPCRT4!ProcessIOEventsWrapper+0x9
> 05 0144ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
> 06 0144ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
> 07 0144ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 13
> System Thread ID: 680
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 0150fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
> 01 0150ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
> 02 0150ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
> 03 0150ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
> 04 0150ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
> 05 0150ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 14
> System Thread ID: 64c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0154fd20 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 0154fd70 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 0154fd88 778322b2 KERNEL32!WaitForMultipleObjects+0x17
> 03 0154ffb4 7c57438b RTUTILS!TraceServerThread+0xde
> 04 0154ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 15
> System Thread ID: 634
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0159ff20 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 0159ff70 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 0159ff88 701224fa KERNEL32!WaitForMultipleObjects+0x17
> 03 0159ffb4 7c57438b exstrace!RegNotifyThread+0x6f
> 04 0159ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 16
> System Thread ID: 54c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 015dff24 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 015dff74 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 015dff8c 70121e6a KERNEL32!WaitForMultipleObjects+0x17
> 03 015dffb4 7c57438b exstrace!WriteTraceThread+0x2f
> 04 015dffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 17
> System Thread ID: 63c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.20
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0169ff64 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 0169ff8c 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 0169ff9c 6ff2841e KERNEL32!WaitForSingleObject+0xf
> 03 0169ffb4 7c57438b FCACHDLL!CScheduleThread::ScheduleThread
+0x22
> 04 0169ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 18
> System Thread ID: 630
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 017dff18 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 017dff68 7c578f0d KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 017dff80 6b57b026 KERNEL32!WaitForMultipleObjects+0x17
> 03 017dffb4 7c57438b SMTPSVC!TcpRegNotifyThread+0x136
> 04 017dffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 19
> System Thread ID: 710
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 0181ff68 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 0181ff90 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 0181ffa0 6b57ae5a KERNEL32!WaitForSingleObject+0xf
> 03 0181ffb4 7c57438b SMTPSVC!FreeLibThread+0x1d
> 04 0181ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 20
> System Thread ID: 720
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0185ff00 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 0185ff50 75037871 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 0185ff6c 6fc66e80 WS2_32!WSAWaitForMultipleEvents+0x18
> 03 0185ffb4 7c57438b ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThrea
dFunc+0x39
> 04 0185ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 21
> System Thread ID: 620
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0189ff64 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 0189ff8c 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 0189ff9c 69e17598 KERNEL32!WaitForSingleObject+0xf
> 03 0189ffb4 7c57438b NntpSvc!CScheduleThread::ScheduleThread+
0x22
> 04 0189ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 22
> System Thread ID: 650
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 018dff5c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 018dff84 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 018dff94 69e13c14 KERNEL32!WaitForSingleObject+0xf
> 03 018dffb4 7c57438b NntpSvc!CRetryQ::RetryQueueThread+0x36
> 04 018dffc0 77f88b43 KERNEL32!BaseThreadStart+0x52
> 05 77fd0348 ffffffff ntdll!LdrpLoadDll+0x3c5
> 06 77fd03e0 77fd0348 0xffffffff
> 07 00000000 00000000 ntdll!LoaderLock
>
>
>
>
> Thread ID: 23
> System Thread ID: 58c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Compression Thread
> # ChildEBP RetAddr
> 00 0191ff5c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 0191ff84 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 0191ff94 732c3366 KERNEL32!WaitForSingleObject+0xf
> 03 0191ffb4 7c57438b compfilt!CompressionThread+0x29
> 04 0191ffc0 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 24
> System Thread ID: 838
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0198fe70 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 0198fec0 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 0198ff1c 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 0198ff38 65f09ccb USER32!MsgWaitForMultipleObjects+0x1d
> 04 0198ff7c 78008454 w3svc!CMTACallbackThread::Thread+0x42
> 05 0198ffb4 7c57438b MSVCRT!_endthread+0xc6
> 06 0198ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 25
> System Thread ID: 5e4
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 019cfea8 7c573c23 ntdll!ZwWaitForMultipleObjects+0xb
> 01 019cfef8 77e119e6 KERNEL32!WaitForMultipleObjectsEx+0xea
> 02 019cff54 77e11ace USER32!MsgWaitForMultipleObjectsEx+0x153
> 03 019cff70 65f09d47 USER32!MsgWaitForMultipleObjects+0x1d
> 04 019cffb4 7c57438b w3svc!OleHackThread+0x88
> 05 019cffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 26
> System Thread ID: 840
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01a4fce0 74fd1394 ntdll!ZwWaitForSingleObject+0xb
> 01 01a4fd1c 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
> 02 01a4fe08 750312f5 msafd!WSPSelect+0x24e
> 03 01a4fe6c 6e2b3b6e WS2_32!select+0xe7
> 04 01a4ffb4 7c57438b inetsloc!SocketListenThread+0x51
> 05 01a4ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 27
> System Thread ID: 848
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 01a8fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
> 01 01a8ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
> 02 01a8ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
> 03 01a8ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
> 04 01a8ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
> 05 01a8ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 28
> System Thread ID: 844
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 01acfdfc 74fd1394 ntdll!ZwWaitForSingleObject+0xb
> 01 01acfe38 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
> 02 01acff24 750312f5 msafd!WSPSelect+0x24e
> 03 01acff88 6d7075bd WS2_32!select+0xe7
> 04 01acffb0 6d70791b ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
> 05 01acffb4 7c57438b ISATQ!BmonThreadFunc+0x9
> 06 01acffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 29
> System Thread ID: 430
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01b0ff4c 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 01b0ff74 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 01b0ff84 69de42a5 KERNEL32!WaitForSingleObject+0xf
> 03 01b0ffb4 7c57438b NntpSvc!CNewsTree::NewsTreeCrawler+0x1d0
> 04 01b0ffc0 2e626577 KERNEL32!BaseThreadStart+0x52
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 6f637261 00000000 0x2e626577
>
>
>
>
> Thread ID: 30
> System Thread ID: 4b0
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01b4ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 01b4ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 01b4ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
> 03 01b4ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 31
> System Thread ID: 718
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01b8ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 01b8ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 01b8ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
> 03 01b8ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 32
> System Thread ID: 880
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01bcff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 01bcff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 01bcffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
> 03 01bcffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 33
> System Thread ID: 884
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01c0ff58 7c573c73 ntdll!ZwRemoveIoCompletion+0xb
> 01 01c0ff84 69e0dfd8 KERNEL32!GetQueuedCompletionStatus+0x27
> 02 01c0ffb4 7c57438b NntpSvc!CThreadPool::ThreadDispatcher+0x
34
> 03 01c0ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
>
>
>
> Thread ID: 34
> System Thread ID: 888
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01c4ff48 7c573b28 ntdll!ZwWaitForSingleObject+0xb
> 01 01c4ff70 7c573b50 KERNEL32!WaitForSingleObjectEx+0x71
> 02 01c4ff80 69ddabe8 KERNEL32!WaitForSingleObject+0xf
> 03 01c4ffb4 7c57438b NntpSvc!FeedScheduler+0x5c
> 04 01c4ffc0 2e626577 KERNEL32!BaseThreadStart+0x52
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 6f637261 00000000 0x2e626577
>
>
>
>
> Thread ID: 35
> System Thread ID: 88c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 01c8fe24 77d37ba7 ntdll!ZwReplyWaitReceivePortEx+0xb
> 01 01c8ff74 77d37b4c RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0
x74
> 02 01c8ff78 77d35924 RPCRT4!RecvLotsaCallsWrapper+0x9
> 03 01c8ffa8 77d358d6 RPCRT4!BaseCachedThreadRoutine+0x4f
> 04 01c8ffb4 7c57438b RPCRT4!ThreadStartRoutine+0x18
> 05 01c8ffec 00000000 KERNEL32!BaseThreadStart+0x52
>
> *****
>
> Dump name is formatted as: PID-Timestamp.dmp
>
> Creating C:\iisstate\output\1780-1095871722.dmp - mini user dump
>
> *****
>
> Closing open log file C:\iisstate\output\IISState-1780.log
>
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
| |
| Jorge Dominguez 2004-09-22, 9:26 pm |
| Pat,
I can't get a log, or a dump when the IIS Server crashes using the
IISSTATE tool; the server simply crashes. However, using the Windows
Debugging tool I get this log when I attach to the Inetinfo process. At
that point if I do the Interdev thing, then Interdev just hangs waiting
to connect to the server until I stop the debugger. When I stop the
debugger Interdev then give me the follolling message. "Unable to open
web project {project name}. Unable to connect to server at {server
name} on port 80. (socket code 10053)"
Any thoughts???
Jorge
LOG----------------------------------------
Opened log file 'IIS5'
*** wait with pending attach
Symbol search path is:
SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
ModLoad: 01000000 01006000 C:\WINNT\system32\inetsrv\inetinfo.exe
ModLoad: 77f80000 77ffd000 C:\WINNT\system32\ntdll.dll
ModLoad: 78000000 78045000 C:\WINNT\system32\MSVCRT.dll
ModLoad: 7c570000 7c628000 C:\WINNT\system32\KERNEL32.dll
ModLoad: 7c2d0000 7c332000 C:\WINNT\system32\ADVAPI32.dll
ModLoad: 77d30000 77da1000 C:\WINNT\system32\RPCRT4.DLL
ModLoad: 77e10000 77e75000 C:\WINNT\system32\USER32.dll
ModLoad: 77f40000 77f7e000 C:\WINNT\system32\GDI32.DLL
ModLoad: 77a50000 77b3f000 C:\WINNT\system32\ole32.dll
ModLoad: 6e5a0000 6e5c1000 C:\WINNT\system32\IisRTL.DLL
ModLoad: 75030000 75044000 C:\WINNT\system32\WS2_32.DLL
ModLoad: 75020000 75028000 C:\WINNT\system32\WS2HELP.DLL
ModLoad: 68920000 68925000 C:\WINNT\system32\inetsrv\rpcref.dll
ModLoad: 6e6f0000 6e6f8000 C:\WINNT\system32\inetsrv\iisadmin.dll
ModLoad: 73330000 7333d000 C:\WINNT\system32\inetsrv\COADMIN.DLL
ModLoad: 782f0000 78535000 C:\WINNT\system32\SHELL32.DLL
ModLoad: 70a70000 70ad4000 C:\WINNT\system32\SHLWAPI.dll
ModLoad: 71710000 71794000 C:\WINNT\system32\COMCTL32.dll
ModLoad: 74e30000 74e3c000 C:\WINNT\system32\ADMWPROX.DLL
ModLoad: 76110000 76114000 C:\WINNT\system32\WMI.dll
ModLoad: 775a0000 77630000 C:\WINNT\system32\CLBCATQ.DLL
ModLoad: 779b0000 77a4b000 C:\WINNT\system32\OLEAUT32.dll
ModLoad: 69d00000 69d0d000 C:\WINNT\system32\inetsrv\nsepm.dll
ModLoad: 6e5e0000 6e5f1000 C:\WINNT\system32\IISMAP.dll
ModLoad: 78160000 78187000 C:\WINNT\system32\schannel.dll
ModLoad: 7c340000 7c34f000 C:\WINNT\system32\SECUR32.DLL
ModLoad: 77430000 77440000 C:\WINNT\system32\MSASN1.DLL
ModLoad: 7c740000 7c7c7000 C:\WINNT\system32\CRYPT32.DLL
ModLoad: 7c0f0000 7c151000 C:\WINNT\system32\USERENV.DLL
ModLoad: 75050000 75058000 C:\WINNT\system32\WSOCK32.DLL
ModLoad: 77980000 779a4000 C:\WINNT\system32\DNSAPI.DLL
ModLoad: 6c7e0000 6c7f4000 C:\WINNT\system32\inetsrv\metadata.dll
ModLoad: 65d60000 65d6e000 C:\WINNT\system32\inetsrv\wamreg.dll
ModLoad: 7ca00000 7ca23000 C:\WINNT\system32\rsabase.dll
ModLoad: 74e40000 74e4a000 C:\WINNT\system32\inetsrv\admexs.dll
ModLoad: 671b0000 671bc000 C:\WINNT\system32\inetsrv\svcext.dll
ModLoad: 75500000 75504000 C:\WINNT\system32\Security.dll
ModLoad: 75170000 751bf000 C:\WINNT\system32\NETAPI32.dll
ModLoad: 77bf0000 77c01000 C:\WINNT\system32\NTDSAPI.dll
ModLoad: 77950000 7797a000 C:\WINNT\system32\WLDAP32.DLL
ModLoad: 751c0000 751c6000 C:\WINNT\system32\NETRAP.dll
ModLoad: 75150000 7515f000 C:\WINNT\system32\SAMLIB.dll
ModLoad: 65f00000 65f5a000 C:\WINNT\system32\inetsrv\w3svc.dll
ModLoad: 769b0000 769f2000 C:\WINNT\system32\inetsrv\INFOCOMM.DLL
ModLoad: 6d700000 6d712000 C:\WINNT\system32\inetsrv\ISATQ.DLL
ModLoad: 6e620000 6e625000 C:\WINNT\system32\inetsrv\IISFECNV.DLL
ModLoad: 6e2b0000 6e2b8000 C:\WINNT\system32\inetsloc.dll
ModLoad: 74ff0000 75002000 C:\WINNT\system32\MSWSOCK.dll
ModLoad: 6b540000 6b5b2000 C:\WINNT\system32\inetsrv\SMTPSVC.dll
ModLoad: 773e0000 773f5000 C:\WINNT\system32\ATL.DLL
ModLoad: 77820000 77827000 C:\WINNT\system32\VERSION.dll
ModLoad: 759b0000 759b6000 C:\WINNT\system32\LZ32.DLL
ModLoad: 6ff20000 6ff2e000 C:\WINNT\system32\FCACHDLL.dll
ModLoad: 68510000 68516000 C:\WINNT\system32\RWNH.dll
ModLoad: 70120000 7012c000 C:\WINNT\system32\exstrace.dll
ModLoad: 67390000 67396000 C:\WINNT\system32\STAXMEM.dll
ModLoad: 69db0000 69e4d000 C:\WINNT\system32\inetsrv\NntpSvc.dll
ModLoad: 6d660000 6d665000 C:\WINNT\system32\inetsrv\ISRPC.dll
ModLoad: 6fc60000 6fc7f000 C:\WINNT\system32\inetsrv\ftpsvc2.dll
ModLoad: 6ca80000 6ca86000 C:\WINNT\system32\inetsrv\lonsint.dll
ModLoad: 74fd0000 74fee000 C:\WINNT\system32\msafd.dll
ModLoad: 75010000 75017000 C:\WINNT\System32\wshtcpip.dll
ModLoad: 76930000 7695b000 C:\WINNT\system32\wintrust.dll
ModLoad: 77920000 77943000 C:\WINNT\system32\IMAGEHLP.dll
ModLoad: 782c0000 782cc000 C:\WINNT\System32\rnr20.dll
ModLoad: 77340000 77353000 C:\WINNT\system32\iphlpapi.dll
ModLoad: 77520000 77525000 C:\WINNT\system32\ICMP.DLL
ModLoad: 77320000 77337000 C:\WINNT\system32\MPRAPI.DLL
ModLoad: 773b0000 773df000 C:\WINNT\system32\ACTIVEDS.DLL
ModLoad: 77380000 773a3000 C:\WINNT\system32\ADSLDPC.DLL
ModLoad: 77830000 7783e000 C:\WINNT\system32\RTUTILS.DLL
ModLoad: 77880000 7790e000 C:\WINNT\system32\SETUPAPI.DLL
ModLoad: 774e0000 77513000 C:\WINNT\system32\RASAPI32.DLL
ModLoad: 774c0000 774d1000 C:\WINNT\system32\RASMAN.DLL
ModLoad: 77530000 77552000 C:\WINNT\system32\TAPI32.DLL
ModLoad: 77360000 77379000 C:\WINNT\system32\DHCPCSVC.DLL
ModLoad: 777e0000 777e8000 C:\WINNT\System32\winrnr.dll
ModLoad: 777f0000 777f5000 C:\WINNT\system32\rasadhlp.dll
ModLoad: 6d6f0000 6d6fa000 C:\WINNT\system32\inetsrv\iscomlog.dll
ModLoad: 681e0000 6821c000 C:\WINNT\system32\inetsrv\seo.dll
ModLoad: 67400000 6740e000 C:\WINNT\system32\inetsrv\sspifilt.dll
ModLoad: 732c0000 732c9000 C:\WINNT\system32\inetsrv\compfilt.dll
ModLoad: 6fa20000 6fa2b000 C:\WINNT\system32\inetsrv\gzip.dll
ModLoad: 74180000 741d1000 C:\WINNT\system32\inetsrv\aqueue.dll
ModLoad: 6c850000 6c85c000 C:\WINNT\system32\inetsrv\md5filt.dll
ModLoad: 01920000 01943000 C:\WINNT\system32\rsaenh.dll
ModLoad: 754b0000 754b5000 C:\WINNT\System32\wshnetbs.dll
ModLoad: 6b5c0000 6b602000 C:\WINNT\system32\inetsrv\httpext.dll
ModLoad: 756e0000 756e5000 C:\WINNT\system32\NTLSAPI.DLL
ModLoad: 6e600000 6e615000 C:\WINNT\system32\inetsrv\iislog.dll
ModLoad: 78280000 782b6000 C:\WINNT\system32\kerberos.dll
ModLoad: 76670000 7667e000 C:\WINNT\system32\CRYPTDLL.DLL
ModLoad: 332b0000 332b5000 C:\Program Files\Common Files\Microsoft
Shared\Web Server Extensions\50\bin\fpexedll.dll
(538.578): Break instruction exception - code 80000003 (first chance)
eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
edi=00000000
eip=77f813b1 esp=01ccffa8 ebp=01ccffb4 iopl=0 nv up ei ng nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286
ntdll!DbgBreakPoint:
77f813b1 cc int 3
0:036> gn
(538.578): Break instruction exception - code 80000003 (!!! second
chance !!!)
eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
edi=00000000
eip=77f813b1 esp=01ccffa8 ebp=01ccffb4 iopl=0 nv up ei ng nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286
ntdll!DbgBreakPoint:
77f813b1 cc int 3
Symbol search path is:
SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-22, 9:26 pm |
| OK. That is actually a programmatic break point (which looks like a crash,
but technically isn't). Can you type: kb<enter> after you do the .symfix
<enter>? It will dump the thread.
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:e134$ZNoEHA.3668@TK2MSFTNGP15.phx.gbl...
> Pat,
>
> I can't get a log, or a dump when the IIS Server crashes using the
> IISSTATE tool; the server simply crashes. However, using the Windows
> Debugging tool I get this log when I attach to the Inetinfo process. At
> that point if I do the Interdev thing, then Interdev just hangs waiting
> to connect to the server until I stop the debugger. When I stop the
> debugger Interdev then give me the follolling message. "Unable to open
> web project {project name}. Unable to connect to server at {server
> name} on port 80. (socket code 10053)"
>
> Any thoughts???
>
> Jorge
>
> LOG----------------------------------------
>
> Opened log file 'IIS5'
> *** wait with pending attach
> Symbol search path is:
> SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
> Executable search path is:
> ModLoad: 01000000 01006000 C:\WINNT\system32\inetsrv\inetinfo.exe
> ModLoad: 77f80000 77ffd000 C:\WINNT\system32\ntdll.dll
> ModLoad: 78000000 78045000 C:\WINNT\system32\MSVCRT.dll
> ModLoad: 7c570000 7c628000 C:\WINNT\system32\KERNEL32.dll
> ModLoad: 7c2d0000 7c332000 C:\WINNT\system32\ADVAPI32.dll
> ModLoad: 77d30000 77da1000 C:\WINNT\system32\RPCRT4.DLL
> ModLoad: 77e10000 77e75000 C:\WINNT\system32\USER32.dll
> ModLoad: 77f40000 77f7e000 C:\WINNT\system32\GDI32.DLL
> ModLoad: 77a50000 77b3f000 C:\WINNT\system32\ole32.dll
> ModLoad: 6e5a0000 6e5c1000 C:\WINNT\system32\IisRTL.DLL
> ModLoad: 75030000 75044000 C:\WINNT\system32\WS2_32.DLL
> ModLoad: 75020000 75028000 C:\WINNT\system32\WS2HELP.DLL
> ModLoad: 68920000 68925000 C:\WINNT\system32\inetsrv\rpcref.dll
> ModLoad: 6e6f0000 6e6f8000 C:\WINNT\system32\inetsrv\iisadmin.dll
> ModLoad: 73330000 7333d000 C:\WINNT\system32\inetsrv\COADMIN.DLL
> ModLoad: 782f0000 78535000 C:\WINNT\system32\SHELL32.DLL
> ModLoad: 70a70000 70ad4000 C:\WINNT\system32\SHLWAPI.dll
> ModLoad: 71710000 71794000 C:\WINNT\system32\COMCTL32.dll
> ModLoad: 74e30000 74e3c000 C:\WINNT\system32\ADMWPROX.DLL
> ModLoad: 76110000 76114000 C:\WINNT\system32\WMI.dll
> ModLoad: 775a0000 77630000 C:\WINNT\system32\CLBCATQ.DLL
> ModLoad: 779b0000 77a4b000 C:\WINNT\system32\OLEAUT32.dll
> ModLoad: 69d00000 69d0d000 C:\WINNT\system32\inetsrv\nsepm.dll
> ModLoad: 6e5e0000 6e5f1000 C:\WINNT\system32\IISMAP.dll
> ModLoad: 78160000 78187000 C:\WINNT\system32\schannel.dll
> ModLoad: 7c340000 7c34f000 C:\WINNT\system32\SECUR32.DLL
> ModLoad: 77430000 77440000 C:\WINNT\system32\MSASN1.DLL
> ModLoad: 7c740000 7c7c7000 C:\WINNT\system32\CRYPT32.DLL
> ModLoad: 7c0f0000 7c151000 C:\WINNT\system32\USERENV.DLL
> ModLoad: 75050000 75058000 C:\WINNT\system32\WSOCK32.DLL
> ModLoad: 77980000 779a4000 C:\WINNT\system32\DNSAPI.DLL
> ModLoad: 6c7e0000 6c7f4000 C:\WINNT\system32\inetsrv\metadata.dll
> ModLoad: 65d60000 65d6e000 C:\WINNT\system32\inetsrv\wamreg.dll
> ModLoad: 7ca00000 7ca23000 C:\WINNT\system32\rsabase.dll
> ModLoad: 74e40000 74e4a000 C:\WINNT\system32\inetsrv\admexs.dll
> ModLoad: 671b0000 671bc000 C:\WINNT\system32\inetsrv\svcext.dll
> ModLoad: 75500000 75504000 C:\WINNT\system32\Security.dll
> ModLoad: 75170000 751bf000 C:\WINNT\system32\NETAPI32.dll
> ModLoad: 77bf0000 77c01000 C:\WINNT\system32\NTDSAPI.dll
> ModLoad: 77950000 7797a000 C:\WINNT\system32\WLDAP32.DLL
> ModLoad: 751c0000 751c6000 C:\WINNT\system32\NETRAP.dll
> ModLoad: 75150000 7515f000 C:\WINNT\system32\SAMLIB.dll
> ModLoad: 65f00000 65f5a000 C:\WINNT\system32\inetsrv\w3svc.dll
> ModLoad: 769b0000 769f2000 C:\WINNT\system32\inetsrv\INFOCOMM.DLL
> ModLoad: 6d700000 6d712000 C:\WINNT\system32\inetsrv\ISATQ.DLL
> ModLoad: 6e620000 6e625000 C:\WINNT\system32\inetsrv\IISFECNV.DLL
> ModLoad: 6e2b0000 6e2b8000 C:\WINNT\system32\inetsloc.dll
> ModLoad: 74ff0000 75002000 C:\WINNT\system32\MSWSOCK.dll
> ModLoad: 6b540000 6b5b2000 C:\WINNT\system32\inetsrv\SMTPSVC.dll
> ModLoad: 773e0000 773f5000 C:\WINNT\system32\ATL.DLL
> ModLoad: 77820000 77827000 C:\WINNT\system32\VERSION.dll
> ModLoad: 759b0000 759b6000 C:\WINNT\system32\LZ32.DLL
> ModLoad: 6ff20000 6ff2e000 C:\WINNT\system32\FCACHDLL.dll
> ModLoad: 68510000 68516000 C:\WINNT\system32\RWNH.dll
> ModLoad: 70120000 7012c000 C:\WINNT\system32\exstrace.dll
> ModLoad: 67390000 67396000 C:\WINNT\system32\STAXMEM.dll
> ModLoad: 69db0000 69e4d000 C:\WINNT\system32\inetsrv\NntpSvc.dll
> ModLoad: 6d660000 6d665000 C:\WINNT\system32\inetsrv\ISRPC.dll
> ModLoad: 6fc60000 6fc7f000 C:\WINNT\system32\inetsrv\ftpsvc2.dll
> ModLoad: 6ca80000 6ca86000 C:\WINNT\system32\inetsrv\lonsint.dll
> ModLoad: 74fd0000 74fee000 C:\WINNT\system32\msafd.dll
> ModLoad: 75010000 75017000 C:\WINNT\System32\wshtcpip.dll
> ModLoad: 76930000 7695b000 C:\WINNT\system32\wintrust.dll
> ModLoad: 77920000 77943000 C:\WINNT\system32\IMAGEHLP.dll
> ModLoad: 782c0000 782cc000 C:\WINNT\System32\rnr20.dll
> ModLoad: 77340000 77353000 C:\WINNT\system32\iphlpapi.dll
> ModLoad: 77520000 77525000 C:\WINNT\system32\ICMP.DLL
> ModLoad: 77320000 77337000 C:\WINNT\system32\MPRAPI.DLL
> ModLoad: 773b0000 773df000 C:\WINNT\system32\ACTIVEDS.DLL
> ModLoad: 77380000 773a3000 C:\WINNT\system32\ADSLDPC.DLL
> ModLoad: 77830000 7783e000 C:\WINNT\system32\RTUTILS.DLL
> ModLoad: 77880000 7790e000 C:\WINNT\system32\SETUPAPI.DLL
> ModLoad: 774e0000 77513000 C:\WINNT\system32\RASAPI32.DLL
> ModLoad: 774c0000 774d1000 C:\WINNT\system32\RASMAN.DLL
> ModLoad: 77530000 77552000 C:\WINNT\system32\TAPI32.DLL
> ModLoad: 77360000 77379000 C:\WINNT\system32\DHCPCSVC.DLL
> ModLoad: 777e0000 777e8000 C:\WINNT\System32\winrnr.dll
> ModLoad: 777f0000 777f5000 C:\WINNT\system32\rasadhlp.dll
> ModLoad: 6d6f0000 6d6fa000 C:\WINNT\system32\inetsrv\iscomlog.dll
> ModLoad: 681e0000 6821c000 C:\WINNT\system32\inetsrv\seo.dll
> ModLoad: 67400000 6740e000 C:\WINNT\system32\inetsrv\sspifilt.dll
> ModLoad: 732c0000 732c9000 C:\WINNT\system32\inetsrv\compfilt.dll
> ModLoad: 6fa20000 6fa2b000 C:\WINNT\system32\inetsrv\gzip.dll
> ModLoad: 74180000 741d1000 C:\WINNT\system32\inetsrv\aqueue.dll
> ModLoad: 6c850000 6c85c000 C:\WINNT\system32\inetsrv\md5filt.dll
> ModLoad: 01920000 01943000 C:\WINNT\system32\rsaenh.dll
> ModLoad: 754b0000 754b5000 C:\WINNT\System32\wshnetbs.dll
> ModLoad: 6b5c0000 6b602000 C:\WINNT\system32\inetsrv\httpext.dll
> ModLoad: 756e0000 756e5000 C:\WINNT\system32\NTLSAPI.DLL
> ModLoad: 6e600000 6e615000 C:\WINNT\system32\inetsrv\iislog.dll
> ModLoad: 78280000 782b6000 C:\WINNT\system32\kerberos.dll
> ModLoad: 76670000 7667e000 C:\WINNT\system32\CRYPTDLL.DLL
> ModLoad: 332b0000 332b5000 C:\Program Files\Common Files\Microsoft
> Shared\Web Server Extensions\50\bin\fpexedll.dll
> (538.578): Break instruction exception - code 80000003 (first chance)
> eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
> edi=00000000
> eip=77f813b1 esp=01ccffa8 ebp=01ccffb4 iopl=0 nv up ei ng nz na
> po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
> efl=00000286
> ntdll!DbgBreakPoint:
> 77f813b1 cc int 3
> 0:036> gn
> (538.578): Break instruction exception - code 80000003 (!!! second
> chance !!!)
> eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
> edi=00000000
> eip=77f813b1 esp=01ccffa8 ebp=01ccffb4 iopl=0 nv up ei ng nz na
> po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
> efl=00000286
> ntdll!DbgBreakPoint:
> 77f813b1 cc int 3
> Symbol search path is:
> SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
>
>
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
| |
| Jorge Dominguez 2004-09-22, 9:26 pm |
| Pat,
Here is the response I get from the debuggger when I type KB<enter> and
then .symfix<enter> after the programmatic break.
(408.3ec): Break instruction exception - code 80000003 (first chance)
eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
edi=00000000
eip=77f813b1 esp=01d4ffa8 ebp=01d4ffb4 iopl=0 nv up ei ng nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286
ntdll!DbgBreakPoint:
77f813b1 cc int 3
0:036> kb
ChildEBP RetAddr Args to Child
01d4ffa4 7c57180b 00000000 ffffffff 01d4ffec ntdll!DbgBreakPoint
01d4ffb4 7c57438b 00000000 00000000 00000000
KERNEL32!BaseAttachComplete+0x29
01d4ffec 00000000 7c5717e2 00000000 00000000
KERNEL32!BaseThreadStart+0x52
0:036> .symfix
No downstream store given, using C:\Program Files\Debugging Tools for
Windows\sym
Symbol search path is: SRV**http://msdl.microsoft.com/download/symbols
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-23, 5:54 pm |
| OK. That isn't a crash. That is the initial debugger attachment which
injects a break into the program code. Once you have attached the debugger,
you need to type 'g <enter>', then reproduce the failure, then type 'kb'
<enter> to dump the thread that crashed.
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:uCeFNTOoEHA.1608@TK2MSFTNGP15.phx.gbl...
> Pat,
>
> Here is the response I get from the debuggger when I type KB<enter> and
> then .symfix<enter> after the programmatic break.
>
> (408.3ec): Break instruction exception - code 80000003 (first chance)
> eax=00000000 ebx=00000000 ecx=00000101 edx=ffffffff esi=00000000
> edi=00000000
> eip=77f813b1 esp=01d4ffa8 ebp=01d4ffb4 iopl=0 nv up ei ng nz na
> po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
> efl=00000286
> ntdll!DbgBreakPoint:
> 77f813b1 cc int 3
> 0:036> kb
> ChildEBP RetAddr Args to Child
> 01d4ffa4 7c57180b 00000000 ffffffff 01d4ffec ntdll!DbgBreakPoint
> 01d4ffb4 7c57438b 00000000 00000000 00000000
> KERNEL32!BaseAttachComplete+0x29
> 01d4ffec 00000000 7c5717e2 00000000 00000000
> KERNEL32!BaseThreadStart+0x52
> 0:036> .symfix
> No downstream store given, using C:\Program Files\Debugging Tools for
> Windows\sym
> Symbol search path is: SRV**http://msdl.microsoft.com/download/symbols
>
>
>
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
| |
| Jorge Dominguez 2004-09-24, 5:51 pm |
|
Ok,
I attached the debugger, typed 'g <enter>'. Then I reporiduced the
failure (crash). The computer crashed, and no dump was created.
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-27, 2:48 am |
| Do you mean that a blue screen occurred or that the inetinfo.exe process
terminated? The process could not terminate completely w/WinDBG attached
(it would have hung on the last thread to terminate). Could you describe in
more detail what you mean by 'crash'? Are you actually experiencing a
'hang'?
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:%23o40ISkoEHA.2140@TK2MSFTNGP11.phx.gbl...
>
> Ok,
>
> I attached the debugger, typed 'g <enter>'. Then I reporiduced the
> failure (crash). The computer crashed, and no dump was created.
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
| |
| Jorge Dominguez 2004-09-27, 5:55 pm |
|
No Pat, not a hang, not a blue dump screen either. I'm talking a full
on crash, the computer screen turns multi-color and the PC eventually
reboots, with no trace of the crash in any event log. I have managed to
duplicate this problem on a similiar computer with Win2K Advanced server
installed running IIS 5.0 and Interdev 6.0. All service packs and
patches being up to date.
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-27, 5:55 pm |
| That is a kernel crash. That is why monitoring IIS doesn't get you
anything.
Check the \winnt\ directory for a memory.dmp file.
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:us4LiCJpEHA.3668@TK2MSFTNGP15.phx.gbl...
>
> No Pat, not a hang, not a blue dump screen either. I'm talking a full
> on crash, the computer screen turns multi-color and the PC eventually
> reboots, with no trace of the crash in any event log. I have managed to
> duplicate this problem on a similiar computer with Win2K Advanced server
> installed running IIS 5.0 and Interdev 6.0. All service packs and
> patches being up to date.
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
| |
| Jorge Dominguez 2004-09-28, 8:27 am |
| Pat:
Here is what my memmory dump file shows when I open it with windbugger.
----------------
Loading Dump File [C:\WINNT\MEMORY.DMP]
Kernel Complete Dump File: Full address space is available
Symbol search path is:
SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 2000 Kernel Version 2195 (Service Pack 4) UP Free x86 compatible
Product: Server, suite: Enterprise
Kernel base = 0x80400000 PsLoadedModuleList = 0x8046e8f0
Debug session time: Fri Sep 24 10:11:25 2004
System Uptime: 1 days 1:28:21.422
Loading Kernel Symbols
........................................................................
......................
Loading unloaded module list
............
Loading User Symbols
.....................................................................
****************************************
********************************
*******
*
*
* Bugcheck Analysis
*
*
*
****************************************
********************************
*******
Use !analyze -v to get detailed debugging information.
BugCheck D1, {0, 2, 0, f4168912}
*** ERROR: Module load completed but symbols could not be loaded for
vsdatant.sys
Probably caused by : vsdatant.sys ( vsdatant+28a75 )
Followup: MachineOwner
---------
*** Sent via Developersdex http://www.codecomments.com ***
Don't just participate in USENET...get rewarded for it!
| |
| Pat [MSFT] 2004-09-28, 5:55 pm |
| That's the ZoneAlarm driver (vsdatant.sys) . Check with the vendor to see
if there is an update available.
Pat
"Jorge Dominguez" <arcoweb@msn.com> wrote in message
news:elmQ53VpEHA.1988@TK2MSFTNGP09.phx.gbl...
> Pat:
>
> Here is what my memmory dump file shows when I open it with windbugger.
>
> ----------------
>
> Loading Dump File [C:\WINNT\MEMORY.DMP]
> Kernel Complete Dump File: Full address space is available
>
> Symbol search path is:
> SRV*c:\temp\websymbols*http://msdl.microsoft.com/download/symbols
> Executable search path is:
> Windows 2000 Kernel Version 2195 (Service Pack 4) UP Free x86 compatible
> Product: Server, suite: Enterprise
> Kernel base = 0x80400000 PsLoadedModuleList = 0x8046e8f0
> Debug session time: Fri Sep 24 10:11:25 2004
> System Uptime: 1 days 1:28:21.422
> Loading Kernel Symbols
> .......................................................................
> .....................
> Loading unloaded module list
> ...........
> Loading User Symbols
> ....................................................................
> ****************************************
********************************
> *******
> *
> *
> * Bugcheck Analysis
> *
> *
> *
> ****************************************
********************************
> *******
>
> Use !analyze -v to get detailed debugging information.
>
> BugCheck D1, {0, 2, 0, f4168912}
>
> *** ERROR: Module load completed but symbols could not be loaded for
> vsdatant.sys
> Probably caused by : vsdatant.sys ( vsdatant+28a75 )
>
> Followup: MachineOwner
> ---------
>
>
>
>
> *** Sent via Developersdex http://www.codecomments.com ***
> Don't just participate in USENET...get rewarded for it!
|
|
|
|