I can't really tell you much about the IISState log file b/c symbols were
not available. IISState needs to be able to reach microsoft.com at least 1
time to download symbols. That will yield better analysis and a clearer
picture of what is going on.
Pat
"Jane S" <jane_s_2004 RemoveThis @yahoo.com> wrote in message
news:ce39d912.0409161428.3b5481d2@posting.google.com...
> Hi! I would be greateful if you could help me interpret the following
> log file...
>
> Our website hangs periodically, once in 1-2 days. I reviewed logs from
> IIS Debug tool; it shows that some threads take really long time (over
> 30 min). Here is part of that log:
>
> 0:000> !runaway
> *** WARNING: symbols timestamp is wrong 0x4060ef9c 0x3c1fe60f for
> C:\WINNT\system32\KERNEL32.DLL
> User Mode Time
> Thread Time
> a8c 0 days 0:37:46.546
> a9c 0 days 0:36:44.921
> a78 0 days 0:36:14.671
> a94 0 days 0:36:07.015
> a80 0 days 0:35:11.718
> a88 0 days 0:34:42.281
> a84 0 days 0:33:08.765
> 2754 0 days 0:29:54.296
> 8908 0 days 0:15:09.203
> 9b70 0 days 0:13:21.140
> a70c 0 days 0:10:55.531
> b05c 0 days 0:09:17.671
> b050 0 days 0:09:05.265
> d074 0 days 0:03:37.750
> d820 0 days 0:03:24.468
> e3b4 0 days 0:01:26.640
> 8c0 0 days 0:00:15.578
> 8c4 0 days 0:00:15.187
>
> When the server was re-started, we ran IISState on it, and created a
> log when the server became very slow (did not hang completely yet). In
> the log created by IISState, i don't see any reference to specific ASP
> pages, only "Unable to locate ASP page" notes.
> Could you point me to how to extract information about what
> specifically causing the server slow down and hang?
>
> Thanks a lot!
>
> -------------------
> Opened log file 'C:\iisstate\output\IISState-2232.log'
>
> ***********************
> Starting new log output
> IISState version 3.3.1
>
> Thu Sep 16 14:31:47 2004
>
> OS = Windows 2000
> Executable: dllhost.exe
> PID = 2232
>
> Note: Thread times are formatted as HH:MM:SS.ms
>
> ***********************
>
>
>
>
> Thread ID: 0
> System Thread ID: 8b4
> Kernel Time: 0:0:0.46
> User Time: 0:0:0.15
> *** WARNING: symbols timestamp is wrong 0x4060ef9b 0x3af32050 for
> C:\WINNT\system32\ntdll.dll
> *** WARNING: symbols timestamp is wrong 0x4060ef9c 0x3c1fe60f for
> C:\WINNT\system32\KERNEL32.DLL
> *** WARNING: symbols timestamp is wrong 0x4050da31 0x3bdfa42d for
> C:\WINNT\system32\ole32.dll
> *** WARNING: symbols timestamp is wrong 0x3e7b8905 0x3a440524 for
> C:\WINNT\system32\dllhost.exe
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0006fd28 7c573b28 ntdll!ZwWriteFile+0xc
> 01 0006fd50 7c573b50 KERNEL32!WaitForSingleObjectEx+0x66
> 02 0006fd60 77aaa701 KERNEL32!WaitForSingleObject+0x4
> 03 0006ff24 010014c6 ole32!OleMetafilePictFromIconAndLabel+0x12d
> 04 0006ffc0 7c581af6 dllhost!WinMainCRTStartup+0x156
> 05 0006fff0 00000000 KERNEL32!GetLocaleInfoW+0x4c3
>
>
>
>
> Thread ID: 1
> System Thread ID: 8c4
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> *** WARNING: symbols timestamp is wrong 0x4060ef9c 0x3bdfa41e for
> C:\WINNT\system32\USER32.DLL
> Thread Type: Other
> # ChildEBP RetAddr
> 00 008fff14 77e115d7 USER32!ValidateHwnd
> 01 008fff30 77abbad5 USER32!HMValidateHandle+0x8a
> 02 008fff70 77abba23 ole32!UtQueryPictFormat+0x17
> 03 008fff8c 77abb95e ole32!UtReadOlePresStmHeader+0xcb
> 04 008fffa8 77ab5046 ole32!CLSIDFromOle1Class+0x50
> 05 008fffbc 000002ca ole32!DdeCommonWndProc+0x159
>
>
>
>
> Thread ID: 2
> System Thread ID: 8cc
> Kernel Time: 0:0:0.15
> User Time: 0:0:0.0
> *** WARNING: symbols timestamp is wrong 0x4050da32 0x3c1fe617 for
> C:\WINNT\system32\TxfAux.Dll
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00a0fc80 6de8b9d0 ntdll!_allmul+0x25
> 01 00a0fd94 6de8b908 TxfAux!WORK_QUEUE::WorkerLoop+0x100
> 02 00a0ffb4 7c57438b TxfAux!WORK_QUEUE::WorkerLoop+0x38
>
>
>
>
> Thread ID: 3
> System Thread ID: 8c8
> Kernel Time: 0:0:7.781
> User Time: 0:0:7.328
> *** WARNING: symbols timestamp is wrong 0x4050da31 0x3bdfa422 for
> C:\WINNT\system32\RPCRT4.DLL
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: *** ERROR: Symbol file could not be found. Defaulted
> to export symbols for C:\WINNT\System32\inetsrv\asp.dll -
> ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 00c6ff74 77d359a3 ntdll!NtRemoveIoCompletion+0x5
> 01 00c6ffa8 77d358d6
> RPCRT4!LRPC_CASSOCIATION::ActuallyAllocateCCall+0x67
> 02 00c6ffb4 7c57438b RPCRT4!LRPC_CASSOCIATION::AllocateCCall+0x1ef
>
>
>
>
> Thread ID: 4
> System Thread ID: 914
> Kernel Time: 0:0:0.46
> User Time: 0:0:0.15
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00caff08 7c573c23 ntdll!NtContinue+0xc
> 01 00caff58 7c578f0d KERNEL32!GetQueuedCompletionStatus+0x65
> 02 00caffec 00000000 KERNEL32!TransactNamedPipe+0x14d
>
>
>
>
> Thread ID: 5
> System Thread ID: 918
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> *** WARNING: symbols timestamp is wrong 0x4050da33 0x3c1fe62d for
> C:\WINNT\system32\COMSVCS.DLL
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 00cefb94 77d3ac56 ntdll!RtlMultiByteToUnicodeN+0xd8
> 01 00cefba0 77b25b87 RPCRT4!OSF_CCONNECTION::TransClose+0x6f
> 02 00cefbc0 77b25a52 ole32!_NULL_IMPORT_DESCRIPTOR+0x47f3
> 03 00cefbd8 77b22ab6 ole32!_NULL_IMPORT_DESCRIPTOR+0x46be
> 04 00cefc18 77b258c6 ole32!CDocFile::CopyTo+0x129
> 05 00cefc88 77ab74c3 ole32!_NULL_IMPORT_DESCRIPTOR+0x4532
> 06 00cefce0 77d94c1a ole32!CDIFat::Fixup+0x498
> 07 00cefcfc 77d9487d RPCRT4!NdrpSetupBeginClientCall+0x9b
> 08 00cefd68 77aa9581 RPCRT4!CStdAsyncProxyBuffer_Release+0x12
> 09 00ceff44 77d95136 ole32!CClientSecurity::CopyProxy+0x11
> 0a 00ceff60 77d46e75 RPCRT4!NdrValidateBothAndLockAsyncHandle+0x8
> 0b 00ceff60 77d46e75 RPCRT4!LRPC_BINDING_HANDLE::BindingCopy+0x7a
> 0c 00ceff70 787f5818 RPCRT4!LRPC_BINDING_HANDLE::BindingCopy+0x7a
>
>
>
>
> Thread ID: 6
> System Thread ID: 91c
> Kernel Time: 0:0:0.15
> User Time: 0:0:0.15
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00d2fee0 7c573a4e ntdll!NtRemoveIoCompletion+0x5
> 01 00d2ff00 7c573a22 KERNEL32!BasepMapModuleHandle+0x28
> 02 77f82091 4affc033 KERNEL32!TlsGetValue+0x11
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 03 0424548b 00000000 0x4affc033
>
>
>
>
> Thread ID: 7
> System Thread ID: 920
> Kernel Time: 0:1:21.781
> User Time: 0:0:33.140
> *** WARNING: symbols timestamp is wrong 0x3ef274f0 0x3cab7f89 for
> C:\WINNT\system32\IISRTL.DLL
> *** ERROR: Symbol file could not be found. Defaulted to export
> symbols for -
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00fafe5c 7c573c23 ntdll!NtContinue+0xc
> 01 00fafeac 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 00faff08 77e11ace USER32!MessageTable+0x29e
> 03 00faff24 6e5a5a7c USER32!MessageTable+0x386
> 04 00faff78 78008593
> IISRTL!CRtlResource::SetDefaultSpinAdjustmentFactor+0x23
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 05 00faffb4 7c57438b MSVCRT!endthreadex+0x93
>
>
>
>
> Thread ID: 8
> System Thread ID: 924
> Kernel Time: 0:1:18.796
> User Time: 0:0:33.750
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00fefe5c 7c573c23 ntdll!NtContinue+0xc
> 01 00fefeac 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 00feff08 77e11ace USER32!MessageTable+0x29e
> 03 00feff24 6e5a5a7c USER32!MessageTable+0x386
> 04 00feff78 78008593
> IISRTL!CRtlResource::SetDefaultSpinAdjustmentFactor+0x23
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 05 00feffb4 7c57438b MSVCRT!endthreadex+0x93
>
>
>
>
> Thread ID: 9
> System Thread ID: 928
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> *** WARNING: symbols timestamp is wrong 0x3ef274f2 0x3cab7f89 for
> C:\WINNT\System32\inetsrv\ISATQ.DLL
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 0110ff7c 6d702957 ntdll!_allmul+0x25
> 01 7c310dd6 f76868ff ISATQ!`string'+0x3
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 02 6aec8b55 00000000 0xf76868ff
>
>
>
>
> Thread ID: 10
> System Thread ID: 92c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 0114ff7c 6d702957 ntdll!_allmul+0x25
> 01 7c310dd6 f76868ff ISATQ!`string'+0x3
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 02 6aec8b55 00000000 0xf76868ff
>
>
>
>
> Thread ID: 11
> System Thread ID: b08
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 01f6fee4 77d31394 ntdll!_allmul+0x25
> 01 01f6ff20 77d3e93f RPCRT4!InitializeDLL+0x78
> 02 01f6ff74 77d3e8c2 RPCRT4!UnicodeToAnsiString+0x14
> 03 01f6ffa8 77d358d6 RPCRT4!MinOf+0x1
> 04 01f6ffb4 7c57438b RPCRT4!LRPC_CASSOCIATION::AllocateCCall+0x1ef
> 05 01f6ffd4 77f87c5e KERNEL32!NlsStrLenW+0x44
>
>
>
>
> Thread ID: 12
> System Thread ID: b18
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: ASP
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> # ChildEBP RetAddr
> 00 0202fe70 7c573c23 ntdll!NtContinue+0xc
> 01 0202fec0 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 0202ff1c 77e11ace USER32!MessageTable+0x29e
> 03 0202ff38 74a01e69 USER32!MessageTable+0x386
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 04 0202ff7c 78008454 asp!GetExtensionVersion+0x2deb
> 05 0202ffb4 7c57438b MSVCRT!endthread+0xc1
>
>
>
>
> Thread ID: 13
> System Thread ID: b1c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: ASP
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> # ChildEBP RetAddr
> 00 0206fe70 7c573c23 ntdll!NtContinue+0xc
> 01 0206fec0 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 0206ff1c 77e11ace USER32!MessageTable+0x29e
> 03 0206ff38 74a01eca USER32!MessageTable+0x386
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 04 0206ff7c 78008454 asp!GetExtensionVersion+0x2e4c
> 05 0206ffb4 7c57438b MSVCRT!endthread+0xc1
>
>
>
>
> Thread ID: 14
> System Thread ID: b20
> Kernel Time: 0:0:0.187
> User Time: 0:0:0.62
> *** WARNING: Unable to verify checksum for
> *** ERROR: Symbol file could not be found. Defaulted to export
> symbols for -
> Thread Type: PDM (Debugger) Thread.
> # ChildEBP RetAddr
> 00 020afddc 7c573c23 ntdll!NtContinue+0xc
> 01 020afe2c 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 020afe88 77e11ace USER32!MessageTable+0x29e
> 03 020afea4 4a00886c USER32!MessageTable+0x386
> 04 020aff7c 7c574499 pdm+0x886c
> 05 020affb0 4a008a09 KERNEL32!MulDiv+0x37
> 06 020affcc 77f82a06 pdm+0x8a09
>
>
>
>
> Thread ID: 15
> System Thread ID: b74
> Kernel Time: 0:0:0.62
> User Time: 0:0:0.62
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0212ff9c 77f842c4 ntdll!NtRemoveIoCompletion+0x5
> 01 0212ffb4 7c57438b ntdll!NtSetValueKey+0x5
> 02 0212ffd4 7c57a1b8 KERNEL32!NlsStrLenW+0x44
> 03 0212ffdc 7c57e597 KERNEL32!LongCompareStringW+0xf22
> 04 ffffffff 00000000 KERNEL32!`string'+0x1f
>
>
>
>
> Thread ID: 16
> System Thread ID: b78
> Kernel Time: 0:3:5.78
> User Time: 1:8:31.687
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 0216fe28 7c573c23 ntdll!NtContinue+0xc
> 01 0216fe78 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 0216fed4 77e11ace USER32!MessageTable+0x29e
> 03 0216fef0 787c3911 USER32!MessageTable+0x386
> 04 000c07f0 000c1b30 COMSVCS!CMtaActivity::AsyncCall+0x923
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 000c2580 000c07f0 0xc1b30
> 06 7886c960 000c2580 0xc07f0
> 07 00102828 7886c960 0xc2580
> 08 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 09 000c31b0 0c7d6d38 0x102828
> 0a 000be1a0 000c31b0 0xc7d6d38
> 0b 0d11b060 000be1a0 0xc31b0
> 0c 04d81070 0d11b060 0xbe1a0
> 0d 04df1d30 04d81070 0xd11b060
> 0e 04e72de8 04df1d30 0x4d81070
> 0f 03279220 04e72de8 0x4df1d30
> 10 0a217b18 03279220 0x4e72de8
> 11 0ab453e0 0a217b18 0x3279220
> 12 0013bfa0 0ab453e0 0xa217b18
> 13 000c3930 0013bfa0 0xab453e0
> 14 000c1b30 000c3930 0x13bfa0
> 15 000c07f0 000c1b30 0xc3930
> 16 000c2580 000c07f0 0xc1b30
> 17 7886c960 000c2580 0xc07f0
> 18 00102828 7886c960 0xc2580
> 19 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 1a 000c31b0 0c7d6d38 0x102828
> 1b 000be1a0 000c31b0 0xc7d6d38
> 1c 0d11b060 000be1a0 0xc31b0
> 1d 04d81070 0d11b060 0xbe1a0
> 1e 04df1d30 04d81070 0xd11b060
> 1f 04e72de8 04df1d30 0x4d81070
> 20 03279220 04e72de8 0x4df1d30
> 21 0a217b18 03279220 0x4e72de8
> 22 0ab453e0 0a217b18 0x3279220
> 23 0013bfa0 0ab453e0 0xa217b18
> 24 000c3930 0013bfa0 0xab453e0
> 25 000c1b30 000c3930 0x13bfa0
> 26 000c07f0 000c1b30 0xc3930
> 27 000c2580 000c07f0 0xc1b30
> 28 7886c960 000c2580 0xc07f0
> 29 00102828 7886c960 0xc2580
> 2a 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 2b 000c31b0 0c7d6d38 0x102828
> 2c 000be1a0 000c31b0 0xc7d6d38
> 2d 0d11b060 000be1a0 0xc31b0
> 2e 04d81070 0d11b060 0xbe1a0
> 2f 04df1d30 04d81070 0xd11b060
> 30 04e72de8 04df1d30 0x4d81070
> 31 03279220 04e72de8 0x4df1d30
>
>
>
>
> Thread ID: 17
> System Thread ID: b7c
> Kernel Time: 0:2:59.343
> User Time: 1:7:28.703
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 021afe28 7c573c23 ntdll!NtContinue+0xc
> 01 021afe78 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 021afed4 77e11ace USER32!MessageTable+0x29e
> 03 021afef0 787c3911 USER32!MessageTable+0x386
> 04 000c1b30 000c3930 COMSVCS!CMtaActivity::AsyncCall+0x923
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 000c07f0 000c1b30 0xc3930
> 06 000c2580 000c07f0 0xc1b30
> 07 7886c960 000c2580 0xc07f0
> 08 00102828 7886c960 0xc2580
> 09 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 0a 000c31b0 0c7d6d38 0x102828
> 0b 000be1a0 000c31b0 0xc7d6d38
> 0c 0d11b060 000be1a0 0xc31b0
> 0d 04d81070 0d11b060 0xbe1a0
> 0e 04df1d30 04d81070 0xd11b060
> 0f 04e72de8 04df1d30 0x4d81070
> 10 03279220 04e72de8 0x4df1d30
> 11 0a217b18 03279220 0x4e72de8
> 12 0ab453e0 0a217b18 0x3279220
> 13 0013bfa0 0ab453e0 0xa217b18
> 14 000c3930 0013bfa0 0xab453e0
> 15 000c1b30 000c3930 0x13bfa0
> 16 000c07f0 000c1b30 0xc3930
> 17 000c2580 000c07f0 0xc1b30
> 18 7886c960 000c2580 0xc07f0
> 19 00102828 7886c960 0xc2580
> 1a 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 1b 000c31b0 0c7d6d38 0x102828
> 1c 000be1a0 000c31b0 0xc7d6d38
> 1d 0d11b060 000be1a0 0xc31b0
> 1e 04d81070 0d11b060 0xbe1a0
> 1f 04df1d30 04d81070 0xd11b060
> 20 04e72de8 04df1d30 0x4d81070
> 21 03279220 04e72de8 0x4df1d30
> 22 0a217b18 03279220 0x4e72de8
> 23 0ab453e0 0a217b18 0x3279220
> 24 0013bfa0 0ab453e0 0xa217b18
> 25 000c3930 0013bfa0 0xab453e0
> 26 000c1b30 000c3930 0x13bfa0
> 27 000c07f0 000c1b30 0xc3930
> 28 000c2580 000c07f0 0xc1b30
> 29 7886c960 000c2580 0xc07f0
> 2a 00102828 7886c960 0xc2580
> 2b 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 2c 000c31b0 0c7d6d38 0x102828
> 2d 000be1a0 000c31b0 0xc7d6d38
> 2e 0d11b060 000be1a0 0xc31b0
> 2f 04d81070 0d11b060 0xbe1a0
> 30 04df1d30 04d81070 0xd11b060
> 31 04e72de8 04df1d30 0x4d81070
>
>
>
>
> Thread ID: 18
> System Thread ID: b88
> Kernel Time: 0:3:2.546
> User Time: 1:7:14.609
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 0226fe28 7c573c23 ntdll!NtContinue+0xc
> 01 0226fe78 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 0226fed4 77e11ace USER32!MessageTable+0x29e
> 03 0226fef0 787c3911 USER32!MessageTable+0x386
> 04 000c31b0 0c7d6d38 COMSVCS!CMtaActivity::AsyncCall+0x923
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 000be1a0 000c31b0 0xc7d6d38
> 06 0d11b060 000be1a0 0xc31b0
> 07 04d81070 0d11b060 0xbe1a0
> 08 04df1d30 04d81070 0xd11b060
> 09 04e72de8 04df1d30 0x4d81070
> 0a 03279220 04e72de8 0x4df1d30
> 0b 0a217b18 03279220 0x4e72de8
> 0c 0ab453e0 0a217b18 0x3279220
> 0d 0013bfa0 0ab453e0 0xa217b18
> 0e 000c3930 0013bfa0 0xab453e0
> 0f 000c1b30 000c3930 0x13bfa0
> 10 000c07f0 000c1b30 0xc3930
> 11 000c2580 000c07f0 0xc1b30
> 12 7886c960 000c2580 0xc07f0
> 13 00102828 7886c960 0xc2580
> 14 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 15 000c31b0 0c7d6d38 0x102828
> 16 000be1a0 000c31b0 0xc7d6d38
> 17 0d11b060 000be1a0 0xc31b0
> 18 04d81070 0d11b060 0xbe1a0
> 19 04df1d30 04d81070 0xd11b060
> 1a 04e72de8 04df1d30 0x4d81070
> 1b 03279220 04e72de8 0x4df1d30
> 1c 0a217b18 03279220 0x4e72de8
> 1d 0ab453e0 0a217b18 0x3279220
> 1e 0013bfa0 0ab453e0 0xa217b18
> 1f 000c3930 0013bfa0 0xab453e0
> 20 000c1b30 000c3930 0x13bfa0
> 21 000c07f0 000c1b30 0xc3930
> 22 000c2580 000c07f0 0xc1b30
> 23 7886c960 000c2580 0xc07f0
> 24 00102828 7886c960 0xc2580
> 25 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 26 000c31b0 0c7d6d38 0x102828
> 27 000be1a0 000c31b0 0xc7d6d38
> 28 0d11b060 000be1a0 0xc31b0
> 29 04d81070 0d11b060 0xbe1a0
> 2a 04df1d30 04d81070 0xd11b060
> 2b 04e72de8 04df1d30 0x4d81070
> 2c 03279220 04e72de8 0x4df1d30
> 2d 0a217b18 03279220 0x4e72de8
> 2e 0ab453e0 0a217b18 0x3279220
> 2f 0013bfa0 0ab453e0 0xa217b18
> 30 000c3930 0013bfa0 0xab453e0
> 31 000c1b30 000c3930 0x13bfa0
>
>
>
>
> Thread ID: 19
> System Thread ID: b90
> Kernel Time: 0:3:1.703
> User Time: 1:5:33.406
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 022afe28 7c573c23 ntdll!NtContinue+0xc
> 01 022afe78 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 022afed4 77e11ace USER32!MessageTable+0x29e
> 03 022afef0 787c3911 USER32!MessageTable+0x386
> 04 000c3930 0013bfa0 COMSVCS!CMtaActivity::AsyncCall+0x923
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 000c1b30 000c3930 0x13bfa0
> 06 000c07f0 000c1b30 0xc3930
> 07 000c2580 000c07f0 0xc1b30
> 08 7886c960 000c2580 0xc07f0
> 09 00102828 7886c960 0xc2580
> 0a 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 0b 000c31b0 0c7d6d38 0x102828
> 0c 000be1a0 000c31b0 0xc7d6d38
> 0d 0d11b060 000be1a0 0xc31b0
> 0e 04d81070 0d11b060 0xbe1a0
> 0f 04df1d30 04d81070 0xd11b060
> 10 04e72de8 04df1d30 0x4d81070
> 11 03279220 04e72de8 0x4df1d30
> 12 0a217b18 03279220 0x4e72de8
> 13 0ab453e0 0a217b18 0x3279220
> 14 0013bfa0 0ab453e0 0xa217b18
> 15 000c3930 0013bfa0 0xab453e0
> 16 000c1b30 000c3930 0x13bfa0
> 17 000c07f0 000c1b30 0xc3930
> 18 000c2580 000c07f0 0xc1b30
> 19 7886c960 000c2580 0xc07f0
> 1a 00102828 7886c960 0xc2580
> 1b 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 1c 000c31b0 0c7d6d38 0x102828
> 1d 000be1a0 000c31b0 0xc7d6d38
> 1e 0d11b060 000be1a0 0xc31b0
> 1f 04d81070 0d11b060 0xbe1a0
> 20 04df1d30 04d81070 0xd11b060
> 21 04e72de8 04df1d30 0x4d81070
> 22 03279220 04e72de8 0x4df1d30
> 23 0a217b18 03279220 0x4e72de8
> 24 0ab453e0 0a217b18 0x3279220
> 25 0013bfa0 0ab453e0 0xa217b18
> 26 000c3930 0013bfa0 0xab453e0
> 27 000c1b30 000c3930 0x13bfa0
> 28 000c07f0 000c1b30 0xc3930
> 29 000c2580 000c07f0 0xc1b30
> 2a 7886c960 000c2580 0xc07f0
> 2b 00102828 7886c960 0xc2580
> 2c 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 2d 000c31b0 0c7d6d38 0x102828
> 2e 000be1a0 000c31b0 0xc7d6d38
> 2f 0d11b060 000be1a0 0xc31b0
> 30 04d81070 0d11b060 0xbe1a0
> 31 04df1d30 04d81070 0xd11b060
>
>
>
>
> Thread ID: 20
> System Thread ID: b94
> Kernel Time: 0:0:1.46
> User Time: 0:0:0.453
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 022efe28 7c573c23 ntdll!NtContinue+0xc
> 01 022efe78 77e119e6 KERNEL32!GetQueuedCompletionStatus+0x65
> 02 022efed4 77e11ace USER32!MessageTable+0x29e
> 03 022efef0 787c3911 USER32!MessageTable+0x386
> 04 000c2580 000c07f0 COMSVCS!CMtaActivity::AsyncCall+0x923
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 05 7886c960 000c2580 0xc07f0
> 06 00102828 7886c960 0xc2580
> 07 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 08 000c31b0 0c7d6d38 0x102828
> 09 000be1a0 000c31b0 0xc7d6d38
> 0a 0d11b060 000be1a0 0xc31b0
> 0b 04d81070 0d11b060 0xbe1a0
> 0c 04df1d30 04d81070 0xd11b060
> 0d 04e72de8 04df1d30 0x4d81070
> 0e 03279220 04e72de8 0x4df1d30
> 0f 0a217b18 03279220 0x4e72de8
> 10 0ab453e0 0a217b18 0x3279220
> 11 0013bfa0 0ab453e0 0xa217b18
> 12 000c3930 0013bfa0 0xab453e0
> 13 000c1b30 000c3930 0x13bfa0
> 14 000c07f0 000c1b30 0xc3930
> 15 000c2580 000c07f0 0xc1b30
> 16 7886c960 000c2580 0xc07f0
> 17 00102828 7886c960 0xc2580
> 18 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 19 000c31b0 0c7d6d38 0x102828
> 1a 000be1a0 000c31b0 0xc7d6d38
> 1b 0d11b060 000be1a0 0xc31b0
> 1c 04d81070 0d11b060 0xbe1a0
> 1d 04df1d30 04d81070 0xd11b060
> 1e 04e72de8 04df1d30 0x4d81070
> 1f 03279220 04e72de8 0x4df1d30
> 20 0a217b18 03279220 0x4e72de8
> 21 0ab453e0 0a217b18 0x3279220
> 22 0013bfa0 0ab453e0 0xa217b18
> 23 000c3930 0013bfa0 0xab453e0
> 24 000c1b30 000c3930 0x13bfa0
> 25 000c07f0 000c1b30 0xc3930
> 26 000c2580 000c07f0 0xc1b30
> 27 7886c960 000c2580 0xc07f0
> 28 00102828 7886c960 0xc2580
> 29 0c7d6d38 00102828 COMSVCS!___PchSym_ <PERF> (COMSVCS+0x12c960)
> 2a 000c31b0 0c7d6d38 0x102828
> 2b 000be1a0 000c31b0 0xc7d6d38
> 2c 0d11b060 000be1a0 0xc31b0
> 2d 04d81070 0d11b060 0xbe1a0
> 2e 04df1d30 04d81070 0xd11b060
> 2f 04e72de8 04df1d30 0x4d81070
> 30 03279220 04e72de8 0x4df1d30
> 31 0a217b18 03279220 0x4e72de8
>
>
>
>
> Thread ID: 21
> System Thread ID: ba4
> Kernel Time: 0:0:9.953
> User Time: 0:0:9.843
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 023cff74 77d37b4c ntdll!RtlTimeToTimeFields+0xf7
> 01 023cffa8 77d358d6 RPCRT4!NdrpConformantStringUnmarshall+0xda
> 02 023cffb4 7c57438b RPCRT4!LRPC_CASSOCIATION::AllocateCCall+0x1ef
>
>
>
>
> Thread ID: 22
> System Thread ID: c1c
> Kernel Time: 0:0:0.93
> User Time: 0:0:0.31
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0286ffb4 7c57438b ntdll!_allmul+0x25
>
>
>
>
> Thread ID: 23
> System Thread ID: 820
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> *** ERROR: Symbol file could not be found. Defaulted to export
> symbols for C:\WINNT\system32\NETAPI32.dll -
> Thread Type: Other
> # ChildEBP RetAddr
> 00 030bff88 751a4848 ntdll!NtContinue+0xc
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 01 030bffb4 7c57438b NETAPI32!RxRemoteApi+0x17a6
> 02 030bffc0 77f88b43 KERNEL32!NlsStrLenW+0x44
> 03 030bffec 00000000 ntdll!RtlpStatusTable+0x66b
>
>
>
>
> Thread ID: 24
> System Thread ID: c98
> Kernel Time: 0:0:0.171
> User Time: 0:0:0.609
> *** ERROR: Symbol file could not be found. Defaulted to export
> symbols for C:\Program Files\Common Files\System\OLE DB\oledb32.dll -
> Thread Type: Other
> # ChildEBP RetAddr
> 00 030fff5c 7c573b28 ntdll!ZwWriteFile+0xc
> 01 030fff84 7c573b50 KERNEL32!WaitForSingleObjectEx+0x66
> 02 030fff94 1f93cf88 KERNEL32!WaitForSingleObject+0x4
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 03 030fffb4 7c57438b oledb32!DllGetClassObject+0xa470
>
>
>
>
> Thread ID: 25
> System Thread ID: c8c
> Kernel Time: 0:0:0.515
> User Time: 0:0:0.468
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0313ff58 7c573b28 ntdll!ZwWriteFile+0xc
> 01 0313ff80 7c573b50 KERNEL32!WaitForSingleObjectEx+0x66
> 02 0313ff90 1f93d152 KERNEL32!WaitForSingleObject+0x4
> WARNING: Stack unwind information not available. Following frames may
> be wrong.
> 03 0313ffb4 7c57438b oledb32!DllGetClassObject+0xa63a
>
>
>
>
> Thread ID: 26
> System Thread ID: 598
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.15
> Thread Type: Idle ASP thread
> # ChildEBP RetAddr
> 00 0317fd54 7c573b28 ntdll!ZwWriteFile+0xc
> 01 0317fd7c 7c573b50 KERNEL32!WaitForSingleObjectEx+0x66
> 02 0317fd8c 7878db85 KERNEL32!WaitForSingleObject+0x4
> 03 0317fd9c 0216dce8
> COMSVCS!CHolder::SafeDispenserDriver::CreateResource+0x83
> WARNING: Frame IP not in any known module. Following frames may be
> wrong.
> 04 00116120 00119ccc 0x216dce8
> 05 00116120 00119ccc 0x119ccc
> 06 00000000 00000000 0x119ccc
>
>
>
>
> Thread ID: 27
> System Thread ID: b64
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0