I have a windows 2000 server running iis5 (everything is patched).
A few days ago it started doing this thing where it would no longer
serve up web pages.
If I look at services, everything shows running. I can ping the server
and remote into it via terminal server, IIS just isn't doing its job.
This used to be an exchange server too, but we recently (about a month
and a half ago) moved to exchange 2007 on a new server. The exchange
software is still installed on this server but I don't have it
starting with windows. IIS will just stop working and won't work again
(services shows it running) until I reboot. Task manager shows
inetinfo.exe taking 50% of cpu utilization. I'm running AVG Network
Edition.
here is my iis state log:
Opened log file 'C:\iisstate\output\IISState-1468.log'
***********************
Starting new log output
IISState version 3.3.1
Sun Feb 10 00:36:10 2008
OS = Windows 2000
Executable: inetinfo.exe
PID = 1468
Note: Thread times are formatted as HH:MM:SS.ms
***********************
Thread ID: 0
System Thread ID: 5b8
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0006f89c 7c586381 ntdll!ZwReadFile+0xb
01 0006f910 7c2dd578 KERNEL32!ReadFile+0x181
02 0006f93c 7c2dd61e ADVAPI32!ObjectCloseAuditAlarmA+0x2f
03 0006f9b8 7c2d1e18 ADVAPI32!ObjectDeleteAuditAlarmW+0x4
04 0006fbf4 01002884 ADVAPI32!`string'
05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
06 0006ff70 01002fbf inetinfo!main+0x654
07 0006ffc0 7c5989d5 inetinfo!mainCRTStartup+0xff
08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d
Thread ID: 1
System Thread ID: 5e4
Kernel Time: 0:0:0.125
User Time: 0:0:0.78
Thread Type: Other
# ChildEBP RetAddr
00 005dfd1c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 005dfd44 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 005dfd54 6e6f1685 KERNEL32!WaitForSingleObject+0xf
03 005dfd70 01002440 iisadmin!ServiceEntry+0x156
04 005dffa4 7c2dcf43 inetinfo!InetinfoStartService+0x2bd
05 005dffec 00000000 ADVAPI32!
AccessCheckByTypeResultListAndAuditAlarmByHandleW+0x2f
Thread ID: 2
System Thread ID: 624
Kernel Time: 0:0:1.484
User Time: 0:0:4.500
Thread Type: Other
# ChildEBP RetAddr
00 0071fe5c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0071feac 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 0071ff08 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 0071ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
04 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 0071ffb4 7c57b3bc MSVCRT!_endthreadex+0xc1
06 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 3
System Thread ID: 628
Kernel Time: 0:0:1.781
User Time: 0:0:4.406
Thread Type: Other
# ChildEBP RetAddr
00 0075fe5c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0075feac 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 0075ff08 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 0075ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
04 0075ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 0075ffb4 7c57b3bc MSVCRT!_endthreadex+0xc1
06 0075ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 4
System Thread ID: 6d4
Kernel Time: 0:0:0.171
User Time: 0:0:0.31
Thread Type: Other
# ChildEBP RetAddr
00 00e3fc1c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 00e3fc6c 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e3fcc8 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e3fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e3fd30 69df7f6c INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00e3fd70 01002440 NntpSvc!ServiceEntry+0x13f
06 00e3ffa4 7c2dcf43 inetinfo!InetinfoStartService+0x2bd
07 00e3ffec 00000000 ADVAPI32!
AccessCheckByTypeResultListAndAuditAlarmByHandleW+0x2f
Thread ID: 5
System Thread ID: 6d8
Kernel Time: 0:0:0.296
User Time: 0:0:0.46
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 00e7fc1c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 00e7fc6c 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e7fcc8 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e7fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e7fd30 6b561a78 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00e7fd70 01002440 SMTPSVC!ServiceEntry+0x136
06 00e7ffa4 7c2dcf43 inetinfo!InetinfoStartService+0x2bd
07 00e7ffec 00000000 ADVAPI32!
AccessCheckByTypeResultListAndAuditAlarmByHandleW+0x2f
Thread ID: 6
System Thread ID: 6dc
Kernel Time: 0:0:0.125
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00ebfc1c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 00ebfc6c 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 00ebfcc8 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00ebfce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00ebfd30 65f0cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00ebfd70 01002440 w3svc!ServiceEntry+0x1b5
06 00ebffa4 7c2dcf43 inetinfo!InetinfoStartService+0x2bd
07 00ebffec 00000000 ADVAPI32!
AccessCheckByTypeResultListAndAuditAlarmByHandleW+0x2f
Thread ID: 7
System Thread ID: 6e0
Kernel Time: 0:0:0.31
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00effc1c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 00effc6c 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 00effcc8 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00effce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00effd30 6fc6b2f0 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00effd70 01002440 ftpsvc2!ServiceEntry+0xc7
06 00efffa4 7c2dcf43 inetinfo!InetinfoStartService+0x2bd
07 00efffec 00000000 ADVAPI32!
AccessCheckByTypeResultListAndAuditAlarmByHandleW+0x2f
Thread ID: 8
System Thread ID: 6f4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0122ff5c 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0122ff88 6d7029ef KERNEL32!GetQueuedCompletionStatus+0x27
02 0122ffb4 7c57b3bc ISATQ!I_AtqOplockThreadFunc+0x32
03 0122ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 9
System Thread ID: 6f8
Kernel Time: 0:0:0.93
User Time: 4:28:44.390
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0126fb68 6b57ef07 SMTPSVC!
CGenericProtoclEventDispatcher::InsertBinding+0xb4
01 0126fb88 6b57f2c2 SMTPSVC!
CGenericProtoclEventDispatcher::InsertBindingWithHash+0x4e
02 0126fcd8 6b586e9d SMTPSVC!CInboundDispatcher::CInboundBinding::Init
+0x197
03 0126fd08 681fd4f1 SMTPSVC!CEventBaseDispatcher::SetContext+0x1d9
04 0126fdd8 681fcc56 seo!
CEventRouterInternal::CDispatcher::AddEventType+0xf5
05 0126fe08 681fd00f seo!CEventRouterInternal::AddDispatcher+0x10b
06 0126fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0xfd
07 0126fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
08 0126feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
09 0126fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0a 0126ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0b 0126ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0c 0126ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0d 0126ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0e 0126ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
0f 0126ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 10
System Thread ID: 6fc
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 012afd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 012afdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 012afdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 012afdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 012afdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 012afe00 681f76ac seo!CEventLock::LockRead+0xd
06 012afe10 681fcf66 seo!CLocker::Lock+0x34
07 012afe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 012afe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 012afeb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 012afef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 012aff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 012aff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 012aff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 012aff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 012affb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 012affec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 11
System Thread ID: 70c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 015efe24 77d59815 ntdll!ZwReplyWaitReceivePortEx+0xb
01 015eff74 77d59086 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 015eff78 77d3b05d RPCRT4!RecvLotsaCallsWrapper+0x9
03 015effa8 77d37e88 RPCRT4!BaseCachedThreadRoutine+0x11f
04 015effb4 7c57b3bc RPCRT4!ThreadStartRoutine+0x18
05 015effec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 12
System Thread ID: 714
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0167fd20 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0167fd70 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0167fd88 778322b2 KERNEL32!WaitForMultipleObjects+0x17
03 0167ffb4 7c57b3bc RTUTILS!TraceServerThread+0xde
04 0167ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 13
System Thread ID: 718
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 016bfeb8 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 016bfee4 77d81fe3 KERNEL32!GetQueuedCompletionStatus+0x27
02 016bff20 77d51684 RPCRT4!COMMON_ProcessCalls+0x9e
03 016bff74 77d514bd RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x99
04 016bff78 77d3af8d RPCRT4!ProcessIOEventsWrapper+0x9
05 016bffa8 77d37e88 RPCRT4!BaseCachedThreadRoutine+0x4f
06 016bffb4 7c57b3bc RPCRT4!ThreadStartRoutine+0x18
07 016bffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 14
System Thread ID: 724
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 016fff20 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 016fff70 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 016fff88 701224fa KERNEL32!WaitForMultipleObjects+0x17
03 016fffb4 7c57b3bc exstrace!RegNotifyThread+0x6f
04 016fffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 15
System Thread ID: 728
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0173ff24 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0173ff74 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0173ff8c 70121e6a KERNEL32!WaitForMultipleObjects+0x17
03 0173ffb4 7c57b3bc exstrace!WriteTraceThread+0x2f
04 0173ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 16
System Thread ID: 72c
Kernel Time: 0:0:0.31
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0177ff64 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0177ff8c 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0177ff9c 6ff2841e KERNEL32!WaitForSingleObject+0xf
03 0177ffb4 7c57b3bc FCACHDLL!CScheduleThread::ScheduleThread+0x22
04 0177ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 17
System Thread ID: 730
Kernel Time: 0:0:0.31
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 018cff00 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 018cff50 75037871 KERNEL32!WaitForMultipleObjectsEx+0xea
02 018cff6c 6fc66e80 WS2_32!WSAWaitForMultipleEvents+0x18
03 018cffb4 7c57b3bc ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc
+0x39
04 018cffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 18
System Thread ID: 734
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0190ff18 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0190ff68 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0190ff80 6b57b026 KERNEL32!WaitForMultipleObjects+0x17
03 0190ffb4 7c57b3bc SMTPSVC!TcpRegNotifyThread+0x136
04 0190ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 19
System Thread ID: 738
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0194ff68 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0194ff90 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0194ffa0 6b57ae5a KERNEL32!WaitForSingleObject+0xf
03 0194ffb4 7c57b3bc SMTPSVC!FreeLibThread+0x1d
04 0194ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 20
System Thread ID: 740
Kernel Time: 0:0:0.78
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01a0ff64 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 01a0ff8c 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 01a0ff9c 69e1771a KERNEL32!WaitForSingleObject+0xf
03 01a0ffb4 7c57b3bc NntpSvc!CScheduleThread::ScheduleThread+0x22
04 01a0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 21
System Thread ID: 744
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Compression Thread
# ChildEBP RetAddr
00 01a4ff5c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 01a4ff84 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 01a4ff94 732c3366 KERNEL32!WaitForSingleObject+0xf
03 01a4ffb4 7c57b3bc compfilt!CompressionThread+0x29
04 01a4ffc0 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 22
System Thread ID: 748
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01f3ff5c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 01f3ff84 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 01f3ff94 69e13d8f KERNEL32!WaitForSingleObject+0xf
03 01f3ffb4 7c57b3bc NntpSvc!CRetryQ::RetryQueueThread+0x36
04 01f3ffc0 77f8d562 KERNEL32!BaseThreadStart+0x52
05 77fce748 ffffffff ntdll!LdrpLoadDll+0x3c5
06 77fcfac0 77fce748 0xffffffff
07 00000000 00000000 ntdll!LoaderLock
Thread ID: 23
System Thread ID: 74c
Kernel Time: 0:0:0.62
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0202fe70 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0202fec0 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 0202ff1c 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 0202ff38 65f09ccb USER32!MsgWaitForMultipleObjects+0x1d
04 0202ff7c 78008454 w3svc!CMTACallbackThread::Thread+0x42
05 0202ffb4 7c57b3bc MSVCRT!_endthread+0xc6
06 0202ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 24
System Thread ID: 750
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0206fea8 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0206fef8 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 0206ff54 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 0206ff70 65f09d47 USER32!MsgWaitForMultipleObjects+0x1d
04 0206ffb4 7c57b3bc w3svc!OleHackThread+0x88
05 0206ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 25
System Thread ID: 77c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 020efce0 74fd1394 ntdll!ZwWaitForSingleObject+0xb
01 020efd1c 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
02 020efe08 750312f5 msafd!WSPSelect+0x24e
03 020efe6c 6e2b3b6e WS2_32!select+0xe7
04 020effb4 7c57b3bc inetsloc!SocketListenThread+0x51
05 020effec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 26
System Thread ID: 780
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0212fe24 77d59815 ntdll!ZwReplyWaitReceivePortEx+0xb
01 0212ff74 77d59086 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0212ff78 77d3b05d RPCRT4!RecvLotsaCallsWrapper+0x9
03 0212ffa8 77d37e88 RPCRT4!BaseCachedThreadRoutine+0x11f
04 0212ffb4 7c57b3bc RPCRT4!ThreadStartRoutine+0x18
05 0212ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 27
System Thread ID: 788
Kernel Time: 0:0:0.390
User Time: 0:0:0.15
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0216ff6c 7c59a301 ntdll!ZwDelayExecution+0xb
01 0216ff8c 7c59a2cc KERNEL32!SleepEx+0x32
02 0216ff98 6d7075e6 KERNEL32!Sleep+0xb
03 0216ffb0 6d70791b ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x4b
04 0216ffb4 7c57b3bc ISATQ!BmonThreadFunc+0x9
05 0216ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 28
System Thread ID: 7a8
Kernel Time: 0:0:1.687
User Time: 0:0:6.250
Thread Type: Other
# ChildEBP RetAddr
00 021ffe5c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 021ffeac 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 021fff08 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 021fff24 679cbbc6 USER32!MsgWaitForMultipleObjects+0x1d
04 021fff7c 780085bc LisRTL!SchedulerWorkerThread+0xa7
05 021fffb4 7c57b3bc MSVCRT!_endthreadex+0xc1
06 021fffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 29
System Thread ID: 7ac
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0223fe5c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0223feac 77e1e9db KERNEL32!WaitForMultipleObjectsEx+0xea
02 0223ff08 77e1ea28 USER32!MsgWaitForMultipleObjectsEx+0x153
03 0223ff24 679cbbc6 USER32!MsgWaitForMultipleObjects+0x1d
04 0223ff7c 780085bc LisRTL!SchedulerWorkerThread+0xa7
05 0223ffb4 7c57b3bc MSVCRT!_endthreadex+0xc1
06 0223ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 30
System Thread ID: 7b0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 022fff50 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 022fff7c 68628940 KERNEL32!GetQueuedCompletionStatus+0x27
02 022fffb4 7c57b3bc LSATQ!AtqPoolThread+0x40
03 022fffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 31
System Thread ID: 7b4
Kernel Time: 0:0:0.0
User Time: 0:0:0.15
Thread Type: Other
# ChildEBP RetAddr
00 0233ff50 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0233ff7c 68628940 KERNEL32!GetQueuedCompletionStatus+0x27
02 0233ffb4 7c57b3bc LSATQ!AtqPoolThread+0x40
03 0233ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 32
System Thread ID: 7bc
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for D:\exchange\bin\PTTRACE.DLL -
Thread Type: Other
# ChildEBP RetAddr
00 023bff20 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 023bff70 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 023bff88 62dd22ff KERNEL32!WaitForMultipleObjects+0x17
WARNING: Stack unwind information not available. Following frames may
be wrong.
03 023bffb4 7c57b3bc PTTRACE!TermAsyncTrace+0x51b
04 023bffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 33
System Thread ID: 7c0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 023fff24 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 023fff74 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 023fff8c 62dd189b KERNEL32!WaitForMultipleObjects+0x17
WARNING: Stack unwind information not available. Following frames may
be wrong.
03 023fffb4 7c57b3bc PTTRACE!DebugAssert+0x4f3
04 023fffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 34
System Thread ID: 7c8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0753ff54 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0753ff7c 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0753ff8c 60fae241 KERNEL32!WaitForSingleObject+0xf
03 0753ffb4 7c57b3bc phatq!CSMTP_RETRY_HANDLER::RetryThreadRoutine
+0xce
04 0753ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 35
System Thread ID: 7ec
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0c5eff2c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c5eff7c 07541e87 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c5effb0 07541fa3 TRANMSG!CEventLogWrapper::Monitor+0x8f
03 0c5effb4 7c57b3bc TRANMSG!EvntlogMonitorThread+0x9
04 0c5effc0 0010dcd8 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
05 00000000 00000000 0x10dcd8
Thread ID: 36
System Thread ID: 7f4
Kernel Time: 0:0:0.15
User Time: 0:0:0.31
Thread Type: Other
# ChildEBP RetAddr
00 0c66fed8 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c66ff28 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c66ff40 6102a1d9 KERNEL32!WaitForMultipleObjects+0x17
03 0c66ffb0 6105e7af reapi!CReIntf::RunPeriodicThread+0x2fd
04 0c66ffb4 7c57b3bc reapi!PeriodicThread+0x9
05 0c66ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 37
System Thread ID: 7f8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0c6aff2c 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c6aff7c 62e50623 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c6affb0 62e5073f DSACCESS!CEventLogWrapper::Monitor+0x8f
03 0c6affb4 7c57b3bc DSACCESS!EvntlogMonitorThread+0x9
04 0c6affc0 0010fdd0 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
05 00000000 00000000 0x10fdd0
Thread ID: 38
System Thread ID: 7fc
Kernel Time: 0:0:0.62
User Time: 0:0:0.125
Thread Type: Other
# ChildEBP RetAddr
00 0c6efdf8 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c6efe48 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c6efe60 62e14d17 KERNEL32!WaitForMultipleObjects+0x17
03 0c6effb0 62e2d699 DSACCESS!CDscUtilityThread::ThreadBody+0xce
04 0c6effb4 7c57b3bc DSACCESS!CDscUtilityThread::ThreadFunc+0x9
05 0c6effec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 39
System Thread ID: 804
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0c73ff18 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c73ff68 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c73ff80 62f2304e KERNEL32!WaitForMultipleObjects+0x17
03 0c73ffb0 62f2538c EPOXY!CSharedMemoryHeap::MemSyncThread+0x31
04 0c73ffb4 7c57b3bc EPOXY!CSharedMemoryHeap::MemSyncThreadStub+0x9
05 0c73ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 40
System Thread ID: 808
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0c81ff4c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0c81ff74 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0c81ff84 62e14af1 KERNEL32!WaitForSingleObject+0xf
03 0c81ffb4 7c57b3bc DSACCESS!DschExpiryThread+0x7b
04 0c81ffc0 02400fa8 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
05 00000030 00000000 0x2400fa8
Thread ID: 41
System Thread ID: 824
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0c9dfed8 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c9dff28 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c9dff40 60f73170 KERNEL32!WaitForMultipleObjects+0x17
03 0c9dff9c 6b56dccd phatq!CConnMgr::GetNextConnection+0x1e1
04 0c9dffb4 7c57b3bc SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
05 0c9dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 42
System Thread ID: 82c
Kernel Time: 0:0:0.421
User Time: 0:0:0.15
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for D:\exchange\bin\ifsproxy.dll -
Thread Type: Other
# ChildEBP RetAddr
00 0ca3ff34 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0ca3ff60 6112216b KERNEL32!GetQueuedCompletionStatus+0x27
WARNING: Stack unwind information not available. Following frames may
be wrong.
02 0ca3ffb4 7c57b3bc ifsproxy!CIfsGlobals::operator=+0x9b
03 0ca3ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 43
System Thread ID: 830
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0ca7ff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0ca7ff84 100044a4 KERNEL32!GetQueuedCompletionStatus+0x27
02 0ca7ffb4 7c57b3bc drviis!CThreadPool::ThreadDispatcher+0x35
03 0ca7ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 44
System Thread ID: 834
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cabff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0cabff84 100044a4 KERNEL32!GetQueuedCompletionStatus+0x27
02 0cabffb4 7c57b3bc drviis!CThreadPool::ThreadDispatcher+0x35
03 0cabffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 45
System Thread ID: 838
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cafff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0cafff84 100044a4 KERNEL32!GetQueuedCompletionStatus+0x27
02 0cafffb4 7c57b3bc drviis!CThreadPool::ThreadDispatcher+0x35
03 0cafffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 46
System Thread ID: 83c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cb3ff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0cb3ff84 100044a4 KERNEL32!GetQueuedCompletionStatus+0x27
02 0cb3ffb4 7c57b3bc drviis!CThreadPool::ThreadDispatcher+0x35
03 0cb3ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 47
System Thread ID: 85c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cb7d240 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0cb7d268 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0cb7d278 62e14780 KERNEL32!WaitForSingleObject+0xf
03 0cb7ff7c 780085bc DSACCESS!CDSContext::ListPollThread+0x11f
04 0cb7ffb4 7c57b3bc MSVCRT!_endthreadex+0xc1
05 0cb7ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 48
System Thread ID: 860
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cbbff54 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0cbbff7c 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0cbbff8c 61071fc2 KERNEL32!WaitForSingleObject+0xf
03 0cbbffb0 61072151 reapi!CCategorizerLdapConfig::ListChangeNotify
+0x1a
04 0cbbffb4 7c57b3bc reapi!ListChangeNotify+0x9
05 0cbbffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 49
System Thread ID: 864
Kernel Time: 0:0:0.140
User Time: 0:0:0.93
Thread Type: Other
# ChildEBP RetAddr
00 0cbfff18 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0cbfff68 6105516b KERNEL32!WaitForMultipleObjectsEx+0xea
02 0cbfff98 6102a0de reapi!CLsaClient::ErrorBlock+0x32
03 0cbfffb0 61050dcf reapi!CLsaClient::Communicate+0xd0
04 0cbfffb4 7c57b3bc reapi!ThreadRoutingNode+0x22
05 0cbfffc0 77fb7e64 KERNEL32!BaseThreadStart+0x52
06 0c62fc50 7ffdf000 ntdll!_except_handler3
WARNING: Frame IP not in any known module. Following frames may be
wrong.
07 0c62fc50 7ffdf000 0x7ffdf000
08 00000000 00000000 0x7ffdf000
Thread ID: 50
System Thread ID: 2d0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0c62febc 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0c62ff0c 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0c62ff24 62f28fa0 KERNEL32!WaitForMultipleObjects+0x17
03 0c62ff70 1000d181 EPOXY!CEpoxyQ::HrBind+0x1fe
04 0c62ff9c 10008b38 drviis!CEpoxyClient::HrBindQueue+0x35
05 0c62ffb4 7c57b3bc drviis!
CExchangeStoreDriver::EpoxyRetryThreadRoutine+0x6c
06 0c62ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 51
System Thread ID: 874
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cc8ff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0cc8ff84 6a177aec KERNEL32!GetQueuedCompletionStatus+0x27
02 0cc8ffb4 7c57b3bc nntpfs!CThreadPool::ThreadDispatcher+0x34
03 0cc8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 52
System Thread ID: 878
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cccff5c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0cccff84 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0cccff94 6a1766d1 KERNEL32!WaitForSingleObject+0xf
03 0cccffb4 7c57b3bc nntpfs!CRetryQ::RetryQueueThread+0x36
04 0cccffc0 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 53
System Thread ID: 87c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cd7fec0 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0cd7ff10 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0cd7ff28 62f28fa0 KERNEL32!WaitForMultipleObjects+0x17
03 0cd7ff74 0cd2500f EPOXY!CEpoxyQ::HrBind+0x1fe
04 0cd7ff98 0cd25362 nntpex!CNntpDriverContext::ConnectEpoxy+0x182
05 0cd7ffb4 7c57b3bc nntpex!CNntpDriverContext::ConnectThread+0x62
06 0cd7ffc0 00e3e0ec KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be
wrong.
07 6ff2b060 ffffffff 0xe3e0ec
08 0009bab0 6ff2b060 0xffffffff
09 00000000 00000000 FCACHDLL!g_critInit
Thread ID: 54
System Thread ID: 880
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cfbff4c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0cfbff74 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0cfbff84 69de4384 KERNEL32!WaitForSingleObject+0xf
03 0cfbffb4 7c57b3bc NntpSvc!CNewsTree::NewsTreeCrawler+0x1d0
04 0cfbffc0 77fa2ea1 KERNEL32!BaseThreadStart+0x52
05 00e3f974 00000000 ntdll!RtlLogStackBackTrace+0x141
Thread ID: 55
System Thread ID: 884
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0cffff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0cffff84 69e0e150 KERNEL32!GetQueuedCompletionStatus+0x27
02 0cffffb4 7c57b3bc NntpSvc!CThreadPool::ThreadDispatcher+0x34
03 0cffffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 56
System Thread ID: 888
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0d03ff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0d03ff84 69e0e150 KERNEL32!GetQueuedCompletionStatus+0x27
02 0d03ffb4 7c57b3bc NntpSvc!CThreadPool::ThreadDispatcher+0x34
03 0d03ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 57
System Thread ID: 88c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0d07ff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0d07ff84 69e0e150 KERNEL32!GetQueuedCompletionStatus+0x27
02 0d07ffb4 7c57b3bc NntpSvc!CThreadPool::ThreadDispatcher+0x34
03 0d07ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 58
System Thread ID: 890
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0d0bff58 7c585463 ntdll!NtRemoveIoCompletion+0xb
01 0d0bff84 69e0e150 KERNEL32!GetQueuedCompletionStatus+0x27
02 0d0bffb4 7c57b3bc NntpSvc!CThreadPool::ThreadDispatcher+0x34
03 0d0bffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 59
System Thread ID: 894
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0d0fff48 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d0fff70 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d0fff80 69ddacdf KERNEL32!WaitForSingleObject+0xf
03 0d0fffb4 7c57b3bc NntpSvc!FeedScheduler+0x5c
04 0d0fffc0 77fa2ea1 KERNEL32!BaseThreadStart+0x52
05 00e3f974 00000000 ntdll!RtlLogStackBackTrace+0x141
Thread ID: 60
System Thread ID: 8a4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0d17fe24 77d59815 ntdll!ZwReplyWaitReceivePortEx+0xb
01 0d17ff74 77d59086 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0d17ff78 77d3b05d RPCRT4!RecvLotsaCallsWrapper+0x9
03 0d17ffa8 77d37e88 RPCRT4!BaseCachedThreadRoutine+0x11f
04 0d17ffb4 7c57b3bc RPCRT4!ThreadStartRoutine+0x18
05 0d17ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 61
System Thread ID: 998
Kernel Time: 0:0:0.0
User Time: 0:0:0.15
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d25fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d25fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d25fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d25fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d25fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d25fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d25fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d25fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d25fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d25feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d25fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d25ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d25ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d25ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d25ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d25ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d25ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 62
System Thread ID: 76c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d29fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d29fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d29fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d29fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d29fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d29fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d29fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d29fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d29fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d29feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d29fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d29ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d29ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d29ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d29ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d29ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d29ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 63
System Thread ID: 980
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d2dfd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d2dfdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d2dfdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d2dfdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d2dfdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d2dfe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d2dfe10 681fcf66 seo!CLocker::Lock+0x34
07 0d2dfe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d2dfe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d2dfeb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d2dfef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d2dff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d2dff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d2dff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d2dff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d2dffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d2dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 64
System Thread ID: 8e4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d35fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d35fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d35fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d35fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d35fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d35fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d35fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d35fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d35fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d35feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d35fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d35ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d35ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d35ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d35ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d35ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d35ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 65
System Thread ID: 80c
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d39fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d39fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d39fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d39fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d39fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d39fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d39fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d39fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d39fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d39feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d39fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d39ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d39ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d39ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d39ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d39ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d39ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 66
System Thread ID: 8a0
Kernel Time: 0:0:0.62
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d3dfd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d3dfdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d3dfdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d3dfdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d3dfdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d3dfe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d3dfe10 681fcf66 seo!CLocker::Lock+0x34
07 0d3dfe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d3dfe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d3dfeb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d3dfef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d3dff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d3dff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d3dff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d3dff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d3dffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d3dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 67
System Thread ID: 538
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d41fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d41fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d41fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d41fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d41fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d41fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d41fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d41fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d41fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d41feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d41fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d41ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d41ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d41ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d41ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d41ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d41ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 68
System Thread ID: 94c
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: Idle ASP thread
# ChildEBP RetAddr
00 0d67ff08 7c59a26d ntdll!ZwWaitForMultipleObjects+0xb
01 0d67ff58 7c59a180 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0d67ff70 787f67ee KERNEL32!WaitForMultipleObjects+0x17
03 0d67ffb4 7c57b3bc COMSVCS!CEventDispatcher::PushEvents+0x4e
04 0d67ffc0 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 69
System Thread ID: 8d4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
Remote call is either to a MTA object or object not initialized. Also,
possible utility thread.
DCOM call being made to Process ID: 2364
Waiting on thread id: ffffffff
# ChildEBP RetAddr
00 0d6bfb68 77d4f404 ntdll!NtRequestWaitReplyPort+0xb
01 0d6bfb94 77d3b96c RPCRT4!LRPC_CCALL::SendReceive+0x124
02 0d6bfba0 7cef6bee RPCRT4!I_RpcSendReceive+0x2c
03 0d6bfbc0 7cef6ab9 ole32!ThreadSendReceive+0xef
04 0d6bfbd8 7cef3ab6 ole32!CRpcChannelBuffer::SwitchAptAndDispatchCall
+0x14f
05 0d6bfc18 7cef692d ole32!CRpcChannelBuffer::SendReceive2+0x96
06 0d6bfc28 7ce3cc2d ole32!CRpcChannelBuffer::SendReceive+0x11
07 0d6bfc88 7ce87f7f ole32!CAptRpcChnl::SendReceive+0xa9
08 0d6bfce0 77d91320 ole32!CCtxComChnl::SendReceive+0x124
09 0d6bfcfc 77d93b47 RPCRT4!NdrProxySendReceive+0x4c
0a 0d6bff44 77d96f9c RPCRT4!NdrClientCall2+0x4f5
0b 0d6bff60 77d7998b RPCRT4!ObjectStublessClient+0x76
0c 0d6bff70 787f6732 RPCRT4!ObjectStubless+0xf
0d 0d6bffb4 7c57b3bc COMSVCS!CEventDispatcher::GetEventServerInfoThread
+0x152
0e 0d6bffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 70
System Thread ID: 704
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d73fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d73fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d73fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d73fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d73fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d73fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d73fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d73fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d73fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d73feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d73fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d73ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d73ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d73ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d73ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d73ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d73ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 71
System Thread ID: 7e0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d78fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d78fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d78fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d78fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d78fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d78fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d78fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d78fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d78fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d78feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d78fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d78ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d78ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d78ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d78ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d78ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d78ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 72
System Thread ID: 79c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0d7cfe24 77d59815 ntdll!ZwReplyWaitReceivePortEx+0xb
01 0d7cff74 77d59086 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0d7cff78 77d3b05d RPCRT4!RecvLotsaCallsWrapper+0x9
03 0d7cffa8 77d37e88 RPCRT4!BaseCachedThreadRoutine+0x11f
04 0d7cffb4 7c57b3bc RPCRT4!ThreadStartRoutine+0x18
05 0d7cffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 73
System Thread ID: 50c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d94fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d94fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d94fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d94fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d94fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d94fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d94fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d94fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d94fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d94feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d94fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d94ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d94ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d94ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d94ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d94ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d94ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 74
System Thread ID: 858
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d98fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d98fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d98fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d98fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d98fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d98fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d98fe10 681fcf66 seo!CLocker::Lock+0x34
07 0d98fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d98fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d98feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d98fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d98ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d98ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d98ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d98ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d98ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d98ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 75
System Thread ID: 7e8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0d9cfd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0d9cfdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0d9cfdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0d9cfdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0d9cfdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0d9cfe00 681f76ac seo!CEventLock::LockRead+0xd
06 0d9cfe10 681fcf66 seo!CLocker::Lock+0x34
07 0d9cfe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0d9cfe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0d9cfeb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0d9cfef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0d9cff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0d9cff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0d9cff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0d9cff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0d9cffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0d9cffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 76
System Thread ID: a00
Kernel Time: 0:0:0.46
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0da0fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0da0fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0da0fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0da0fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0da0fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0da0fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0da0fe10 681fcf66 seo!CLocker::Lock+0x34
07 0da0fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0da0fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0da0feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0da0fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0da0ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0da0ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0da0ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0da0ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0da0ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0da0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 77
System Thread ID: 800
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0da4fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0da4fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0da4fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0da4fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0da4fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0da4fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0da4fe10 681fcf66 seo!CLocker::Lock+0x34
07 0da4fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0da4fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0da4feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0da4fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0da4ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0da4ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0da4ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0da4ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0da4ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0da4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 78
System Thread ID: 8f8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0da8fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0da8fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0da8fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0da8fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0da8fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0da8fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0da8fe10 681fcf66 seo!CLocker::Lock+0x34
07 0da8fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0da8fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0da8feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0da8fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0da8ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0da8ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0da8ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0da8ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0da8ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0da8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 79
System Thread ID: 7dc
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dacfd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dacfdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dacfdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dacfdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dacfdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dacfe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dacfe10 681fcf66 seo!CLocker::Lock+0x34
07 0dacfe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dacfe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dacfeb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dacfef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dacff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dacff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dacff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dacff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dacffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dacffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 80
System Thread ID: a28
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0db0fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0db0fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0db0fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0db0fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0db0fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0db0fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0db0fe10 681fcf66 seo!CLocker::Lock+0x34
07 0db0fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0db0fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0db0feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0db0fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0db0ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0db0ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0db0ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0db0ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0db0ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0db0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 81
System Thread ID: 9dc
Kernel Time: 0:0:0.31
User Time: 0:0:0.15
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0db4fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0db4fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0db4fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0db4fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0db4fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0db4fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0db4fe10 681fcf66 seo!CLocker::Lock+0x34
07 0db4fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0db4fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0db4feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0db4fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0db4ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0db4ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0db4ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0db4ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0db4ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0db4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 82
System Thread ID: 810
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0db8fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0db8fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0db8fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0db8fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0db8fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0db8fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0db8fe10 681fcf66 seo!CLocker::Lock+0x34
07 0db8fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0db8fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0db8feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0db8fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0db8ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0db8ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0db8ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0db8ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0db8ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0db8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 83
System Thread ID: a60
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dc0fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dc0fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dc0fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dc0fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dc0fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dc0fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dc0fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dc0fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dc0fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dc0feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dc0fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dc0ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dc0ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dc0ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dc0ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dc0ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dc0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 84
System Thread ID: 7a0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dc4fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dc4fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dc4fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dc4fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dc4fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dc4fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dc4fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dc4fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dc4fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dc4feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dc4fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dc4ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dc4ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dc4ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dc4ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dc4ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dc4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 85
System Thread ID: 390
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dc8fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dc8fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dc8fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dc8fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dc8fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dc8fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dc8fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dc8fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dc8fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dc8feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dc8fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dc8ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dc8ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dc8ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dc8ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dc8ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dc8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 86
System Thread ID: 280
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dd0fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dd0fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dd0fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dd0fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dd0fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dd0fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dd0fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dd0fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dd0fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dd0feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dd0fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dd0ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dd0ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dd0ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dd0ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dd0ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dd0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 87
System Thread ID: 9fc
Kernel Time: 0:0:0.31
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dd4fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dd4fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dd4fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dd4fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dd4fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dd4fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dd4fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dd4fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dd4fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dd4feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dd4fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dd4ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dd4ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dd4ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dd4ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dd4ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dd4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 88
System Thread ID: a68
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0dd8fd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0dd8fdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0dd8fdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0dd8fdf4 68511894 RWNH!CShareLockNH::ShareLockInternal+0x3e
04 0dd8fdfc 681f4782 RWNH!CShareLockNH::ShareLock+0x18
05 0dd8fe00 681f76ac seo!CEventLock::LockRead+0xd
06 0dd8fe10 681fcf66 seo!CLocker::Lock+0x34
07 0dd8fe4c 681fd728 seo!
CEventRouterInternal::GetDispatcherByClassFactory+0x54
08 0dd8fe6c 6b56c2f8 seo!CEventRouter::GetDispatcherByClassFactory
+0x30
09 0dd8feb0 6b56410a SMTPSVC!SMTP_CONNECTION::GlueDispatch+0x85
0a 0dd8fef0 6b563c39 SMTPSVC!SMTP_CONNECTION::ProcessInputBuffer+0x32d
0b 0dd8ff18 6b564569 SMTPSVC!SMTP_CONNECTION::ProcessReadIO+0x17c
0c 0dd8ff3c 6b56166b SMTPSVC!SMTP_CONNECTION::ProcessClient+0x14d
0d 0dd8ff4c 6d701a22 SMTPSVC!SmtpCompletion+0x15
0e 0dd8ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0dd8ffb4 7c57b3bc ISATQ!AtqPoolThread+0x1a8
10 0dd8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 89
System Thread ID: 178
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0ddcfd8c 7c59a0a2 ntdll!ZwWaitForSingleObject+0xb
01 0ddcfdb4 7c57b40f KERNEL32!WaitForSingleObjectEx+0x71
02 0ddcfdc4 685118ee KERNEL32!WaitForSingleObject+0xf
03 0ddcfdf4 685...(message truncated)
>> Stay informed about: IIS stops working about once an hour