Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

Help with IISState Log File

 
   Web Hosting and Web Master Forums (Home) -> IIS RSS
Next:  Only default page will load  
Author Message
david14

External


Since: Feb 23, 2004
Posts: 18



(Msg. 1) Posted: Wed Apr 14, 2004 6:54 pm
Post subject: Help with IISState Log File
Archived from groups: microsoft>public>inetserver>iis (more info?)

Hi

I have successfully run IISState on my server this afternoon. It took about
5 minutes to execute and consumed about 23Mb of RAM.

I am trying to find out why at certain random times throughout the day, (may
be load related), my users report problems with viewing pages on my site. I
have experienced it too and have run IIS State this afternoon during one
such occasion. The problem is simply that the browser does not receive all
of the desired HTML output of an ASP. It is as if the user has pressed stop
halfway through the download.

Can anyone see anything untoward with the following log.

Thanks

David M

Thread ID 30 looks interesting, but I have no idea what it means. 37 and 52
have some other DCOM activity which looks ok.



Opened log file 'C:\iisstate\output\IISState-1052.log'

***********************
Starting new log output
IISState version 3.3.1

Wed Apr 14 15:38:01 2004

OS = Windows 2000
Executable: inetinfo.exe
PID = 1052

Note: Thread times are formatted as HH:MM:SS.ms

***********************




Thread ID: 0
System Thread ID: 418
Kernel Time: 0:0:0.15
User Time: 0:0:0.31
Thread Type: Other
# ChildEBP RetAddr
00 0006f89c 7c586235 ntdll!ZwReadFile+0xb
01 0006f910 7c2e0135 KERNEL32!ReadFile+0x181
02 0006f93c 7c2dffbb ADVAPI32!ScGetPipeInput+0x28
03 0006f9b8 7c2e1995 ADVAPI32!ScDispatcherLoop+0x4a
04 0006fbf4 01002884 ADVAPI32!StartServiceCtrlDispatcherA+0x7d
05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
06 0006ff70 01002fbf inetinfo!main+0x654
07 0006ffc0 7c5987e7 inetinfo!mainCRTStartup+0xff
08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d




Thread ID: 1
System Thread ID: 3e8
Kernel Time: 0:0:0.109
User Time: 0:0:0.15
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 005dfd1c 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 005dfd44 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 005dfd54 6e6f1685 KERNEL32!WaitForSingleObject+0xf
03 005dfd70 01002440 iisadmin!ServiceEntry+0x156
04 005dffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
05 005dffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
06 005dffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 2
System Thread ID: 46c
Kernel Time: 0:20:37.750
User Time: 0:3:31.46
Thread Type: Other
# ChildEBP RetAddr
00 0071ff08 77e1ea48 USER32!NtUserCallOneParam+0xb
01 0071ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
02 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
03 0071ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
04 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 3
System Thread ID: 470
Kernel Time: 0:13:7.703
User Time: 0:2:7.734
Thread Type: Other
# ChildEBP RetAddr
00 0075fe9c 6e5a18aa KERNEL32!InterlockedExchange+0xe
01 0075fecc 6e5a17fd IisRTL!CLKRLinearHashTable::_DeleteIf+0xe3
02 0075fef0 769b425c IisRTL!CLKRHashTable::DeleteIf+0x51
03 0075ff28 769b41ee INFOCOMM!FilteredFlushFileCache+0x5f
04 0075ff34 6e5a5bee INFOCOMM!CacheScavenger+0xc
05 0075ff7c 780085bc IisRTL!SchedulerWorkerThread+0x265
06 0075ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
07 0075ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 4
System Thread ID: 474
Kernel Time: 0:21:5.0
User Time: 0:3:2.578
Thread Type: Other
# ChildEBP RetAddr
00 0079ff08 77e1ea48 USER32!NtUserCallOneParam+0xb
01 0079ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
02 0079ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
03 0079ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
04 0079ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 5
System Thread ID: 478
Kernel Time: 0:13:4.218
User Time: 0:2:3.281
Thread Type: Other
# ChildEBP RetAddr
00 007dfe5c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 007dfeac 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 007dff08 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 007dff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
04 007dff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 007dffb4 7c57b382 MSVCRT!_endthreadex+0xc1
06 007dffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 6
System Thread ID: 4d4
Kernel Time: 0:0:0.46
User Time: 0:0:0.15
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 00f0fc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 00f0fc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 00f0fcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00f0fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00f0fd30 6b561a78 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00f0fd70 01002440 SMTPSVC!ServiceEntry+0x136
06 00f0ffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
07 00f0ffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
08 00f0ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 7
System Thread ID: 4d8
Kernel Time: 0:0:0.62
User Time: 0:0:0.15
Thread Type: Other
# ChildEBP RetAddr
00 00f4fc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 00f4fc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 00f4fcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 00f4fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00f4fd30 65f0cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00f4fd70 01002440 w3svc!ServiceEntry+0x1b5
06 00f4ffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
07 00f4ffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
08 00f4ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 8
System Thread ID: 4f8
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0110ff5c 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0110ff88 6d7029ef KERNEL32!GetQueuedCompletionStatus+0x27
02 0110ffb4 7c57b382 ISATQ!I_AtqOplockThreadFunc+0x32
03 0110ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 9
System Thread ID: 4fc
Kernel Time: 0:16:45.62
User Time: 0:16:33.718
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0114fadc 7c59a0ed ntdll!NtDelayExecution+0xb
01 0114fafc 7c59a0b8 KERNEL32!SleepEx+0x32
02 0114fb08 6e5a2617 KERNEL32!Sleep+0xb
03 0114fb48 6e5a1fb9 IisRTL!CReaderWriterLock3::_LockSpin+0x87
04 0114fb54 6e5a1f13 IisRTL!CLKRLinearHashTable::ReadLock+0x18
05 0114fb74 6e5a1ef2 IisRTL!CLKRLinearHashTable::_FindKey+0x1d
06 0114fb88 769b2625 IisRTL!CLKRHashTable::FindKey+0x59
07 0114fbec 769b2592 INFOCOMM!CheckoutFile+0x3c
08 0114fd18 769b2028 INFOCOMM!TsCreateFile+0xe4
09 0114fd48 65f03f0c INFOCOMM!TsCreateFileFromURI+0x10a
0a 0114fda8 65f0242b w3svc!HTTP_REQUEST::DoGet+0x1c4
0b 0114ff18 65f01d97 w3svc!HTTP_REQUEST::DoWork+0x504
0c 0114ff38 65f047ef w3svc!CLIENT_CONN::DoWork+0x1aa
0d 0114ff4c 6d701a22 w3svc!W3Completion+0x43
0e 0114ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
0f 0114ffb4 7c57b382 ISATQ!AtqPoolThread+0x1a8
10 0114ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 10
System Thread ID: 500
Kernel Time: 0:12:9.859
User Time: 0:11:58.953
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0118ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0118ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0118ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 0118ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 11
System Thread ID: 50c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0164fd20 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 0164fd70 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 0164fd88 778322b2 KERNEL32!WaitForMultipleObjects+0x17
03 0164ffb4 7c57b382 RTUTILS!TraceServerThread+0xde
04 0164ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 12
System Thread ID: 514
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 0169feb8 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0169fee4 77d809da KERNEL32!GetQueuedCompletionStatus+0x27
02 0169ff20 77d50ede RPCRT4!COMMON_ProcessCalls+0x9e
03 0169ff74 77d50d17 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x99
04 0169ff78 77d39a00 RPCRT4!ProcessIOEventsWrapper+0x9
05 0169ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x4f
06 0169ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
07 0169ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 13
System Thread ID: 518
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 016dff20 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 016dff70 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 016dff88 701224fa KERNEL32!WaitForMultipleObjects+0x17
03 016dffb4 7c57b382 exstrace!RegNotifyThread+0x6f
04 016dffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 14
System Thread ID: 51c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0171ff24 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 0171ff74 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 0171ff8c 70121e6a KERNEL32!WaitForMultipleObjects+0x17
03 0171ffb4 7c57b382 exstrace!WriteTraceThread+0x2f
04 0171ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 15
System Thread ID: 520
Kernel Time: 0:0:0.15
User Time: 0:0:0.15
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0191ff64 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 0191ff8c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 0191ff9c 6ff2841e KERNEL32!WaitForSingleObject+0xf
03 0191ffb4 7c57b382 FCACHDLL!CScheduleThread::ScheduleThread+0x22
04 0191ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 16
System Thread ID: 528
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 01a9ff18 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 01a9ff68 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 01a9ff80 6b57b026 KERNEL32!WaitForMultipleObjects+0x17
03 01a9ffb4 7c57b382 SMTPSVC!TcpRegNotifyThread+0x136
04 01a9ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 17
System Thread ID: 52c
Kernel Time: 0:0:0.78
User Time: 0:0:0.46
Thread Status: Thread is in a WAIT state.
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 01adff68 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 01adff90 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 01adffa0 6b57ae5a KERNEL32!WaitForSingleObject+0xf
03 01adffb4 7c57b382 SMTPSVC!FreeLibThread+0x1d
04 01adffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 18
System Thread ID: 530
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: HTTP Compression Thread
# ChildEBP RetAddr
00 01b9ff5c 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 01b9ff84 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 01b9ff94 732c3366 KERNEL32!WaitForSingleObject+0xf
03 01b9ffb4 7c57b382 compfilt!CompressionThread+0x29
04 01b9ffc0 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 19
System Thread ID: 558
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01c0fe70 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 01c0fec0 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 01c0ff1c 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 01c0ff38 65f09ccb USER32!MsgWaitForMultipleObjects+0x1d
04 01c0ff7c 78008454 w3svc!CMTACallbackThread::Thread+0x42
05 01c0ffb4 7c57b382 MSVCRT!_endthread+0xc6
06 01c0ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 20
System Thread ID: 55c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01c4fea8 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 01c4fef8 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 01c4ff54 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 01c4ff70 65f09d47 USER32!MsgWaitForMultipleObjects+0x1d
04 01c4ffb4 7c57b382 w3svc!OleHackThread+0x88
05 01c4ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 21
System Thread ID: 31c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 01ccfce0 74fd1394 ntdll!NtWaitForSingleObject+0xb
01 01ccfd1c 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
02 01ccfe08 750312f5 msafd!WSPSelect+0x24e
03 01ccfe6c 6e2b3b6e WS2_32!select+0xe7
04 01ccffb4 7c57b382 inetsloc!SocketListenThread+0x51
05 01ccffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 22
System Thread ID: 5b4
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 01d4fdfc 74fd1394 ntdll!NtWaitForSingleObject+0xb
01 01d4fe38 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
02 01d4ff24 750312f5 msafd!WSPSelect+0x24e
03 01d4ff88 6d7075bd WS2_32!select+0xe7
04 01d4ffb0 6d70791b ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
05 01d4ffb4 7c57b382 ISATQ!BmonThreadFunc+0x9
06 01d4ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 23
System Thread ID: 5b8
Kernel Time: 0:0:0.31
User Time: 0:0:0.31
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 01d9ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 01d9ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 01d9ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
03 01d9ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
04 01d9ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 24
System Thread ID: 5c0
Kernel Time: 0:0:6.0
User Time: 0:0:6.906
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 01e1fed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 01e1ff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 01e1ff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
03 01e1ff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
04 01e1ffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
05 01e1ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 25
System Thread ID: 604
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01fbff9c 77f85c42 ntdll!NtDelayExecution+0xb
01 01fbffb4 7c57b382 ntdll!RtlpTimerThread+0x42
02 01fbffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 26
System Thread ID: 750
Kernel Time: 0:4:48.250
User Time: 0:6:25.187
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 022dff74 77d39a74 ntdll!NtDelayExecution+0xb
01 022dffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0xc3
02 022dffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
03 022dffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 27
System Thread ID: 7bc
Kernel Time: 0:15:47.234
User Time: 0:15:42.156
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 023dff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 023dff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 023dffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 023dffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 28
System Thread ID: 830
Kernel Time: 0:16:41.828
User Time: 0:16:26.953
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0251ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0251ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0251ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 0251ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 29
System Thread ID: 920
Kernel Time: 0:0:0.46
User Time: 0:0:0.0
Thread Type: Idle ASP thread
# ChildEBP RetAddr
00 0346ff08 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 0346ff58 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 0346ff70 787f37d4 KERNEL32!WaitForMultipleObjects+0x17
03 0346ffb4 7c57b382 comsvcs!CEventDispatcher::PushEvents+0x44
04 0346ffc0 00000008 KERNEL32!BaseThreadStart+0x52




Thread ID: 30
System Thread ID: 994
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

Remote call is either to a MTA object or object not initialized. Also,
possible utility thread.
DCOM call being made to Process ID: 1612
Waiting on thread id: ffffffff

# ChildEBP RetAddr
00 034afb68 77d4ec77 ntdll!NtRequestWaitReplyPort+0xb
01 034afb94 77d3a2c7 RPCRT4!LRPC_CCALL::SendReceive+0x11e
02 034afba0 77b23b2c RPCRT4!I_RpcSendReceive+0x2c
03 034afbc0 77b239f7 ole32!ThreadSendReceive+0xef
04 034afbd8 77b20aa5 ole32!CRpcChannelBuffer::SwitchAptAndDispatchCall+0x14a
05 034afc18 77b23870 ole32!CRpcChannelBuffer::SendReceive2+0x96
06 034afc28 77a6c767 ole32!CRpcChannelBuffer::SendReceive+0x11
07 034afc88 77ab6ac3 ole32!CAptRpcChnl::SendReceive+0xa9
08 034afce0 77d90328 ole32!CCtxComChnl::SendReceive+0x124
09 034afcfc 77d92b3f RPCRT4!NdrProxySendReceive+0x4c
0a 034aff44 77d95f85 RPCRT4!NdrClientCall2+0x4f5
0b 034aff60 77d77fcb RPCRT4!ObjectStublessClient+0x76
0c 034aff70 787f372e RPCRT4!ObjectStubless+0xf
0d 034affb4 7c57b382
comsvcs!CEventDispatcher::GetEventServerInfoThread+0x10e
0e 034affec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 31
System Thread ID: 62c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: WebDav Worker Thread
# ChildEBP RetAddr
00 0356ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0356ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
02 0356ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
03 0356ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
04 0356ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 32
System Thread ID: 748
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: WebDav Worker Thread
# ChildEBP RetAddr
00 035aff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 035aff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
02 035aff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
03 035affb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
04 035affec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 33
System Thread ID: 3b0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: WebDav Worker Thread
# ChildEBP RetAddr
00 035eff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 035eff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
02 035eff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
03 035effb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
04 035effec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 34
System Thread ID: 944
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: WebDav Worker Thread
# ChildEBP RetAddr
00 0362ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0362ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
02 0362ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
03 0362ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
04 0362ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 35
System Thread ID: 140
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: WebDav Worker Thread
# ChildEBP RetAddr
00 0366ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0366ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
02 0366ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
03 0366ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
04 0366ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 36
System Thread ID: 794
Kernel Time: 0:12:40.843
User Time: 0:13:33.250
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0455ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 0455ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0455ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 0455ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 37
System Thread ID: 638
Kernel Time: 0:15:50.984
User Time: 0:15:25.406
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

DCOM call being made to Process ID: 1564
Waiting on thread id: 0

# ChildEBP RetAddr
00 0471ea64 77d4ec77 ntdll!NtRequestWaitReplyPort+0xb
01 0471ea90 77d3a2c7 RPCRT4!LRPC_CCALL::SendReceive+0x11e
02 0471ea9c 77b23b2c RPCRT4!I_RpcSendReceive+0x2c
03 0471eabc 77b239f7 ole32!ThreadSendReceive+0xef
04 0471ead4 77b20aa5 ole32!CRpcChannelBuffer::SwitchAptAndDispatchCall+0x14a
05 0471eb14 77b23870 ole32!CRpcChannelBuffer::SendReceive2+0x96
06 0471eb24 77a6c767 ole32!CRpcChannelBuffer::SendReceive+0x11
07 0471eb84 77ab6a37 ole32!CAptRpcChnl::SendReceive+0xa9
08 0471ebdc 77d90328 ole32!CCtxComChnl::SendReceive+0x98
09 0471ebf8 77d92b3f RPCRT4!NdrProxySendReceive+0x4c
0a 0471ee40 77d95f85 RPCRT4!NdrClientCall2+0x4f5
0b 0471ee5c 77d77fcb RPCRT4!ObjectStublessClient+0x76
0c 0471ee6c 65f369f2 RPCRT4!ObjectStubless+0xf
0d 0471f4f0 65f04c38 w3svc!CWamInfoOutProc::DoProcessRequestCall+0x163
0e 0471f518 65f03d71 w3svc!CWamInfo::ProcessWamRequest+0xb9
0f 0471fd50 65f03c49 w3svc!WAM_DICTATOR::ProcessWamRequest+0x1e5
10 0471fd74 65f03aa2 w3svc!HTTP_REQUEST::DoWamRequest+0x75
11 0471fd98 65f0249e w3svc!HTTP_REQUEST::ProcessBGI+0x166
12 0471ff18 65f01d97 w3svc!HTTP_REQUEST::DoWork+0x43f
13 0471ff38 65f047ef w3svc!CLIENT_CONN::DoWork+0x1aa
14 0471ff4c 6d701a22 w3svc!W3Completion+0x43
15 0471ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
16 0471ffb4 7c57b382 ISATQ!AtqPoolThread+0x1a8
17 0471ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 38
System Thread ID: 880
Kernel Time: 0:13:5.203
User Time: 0:12:42.437
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 106bff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 106bff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 106bffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 106bffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 39
System Thread ID: b48
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 1ed8ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 1ed8ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 1ed8ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
03 1ed8ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
04 1ed8ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 40
System Thread ID: 7e8
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 1ee0fed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 1ee0ff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 1ee0ff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
03 1ee0ff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
04 1ee0ffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
05 1ee0ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 41
System Thread ID: 634
Kernel Time: 0:10:12.375
User Time: 0:10:5.515
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 026fff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 026fff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 026fffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 026fffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 42
System Thread ID: a78
Kernel Time: 0:0:3.609
User Time: 0:0:4.562
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 05a5fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 05a5ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 05a5ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
03 05a5ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
04 05a5ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 05a5ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 43
System Thread ID: 9c4
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0787ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 0787ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 0787ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
03 0787ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
04 0787ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 44
System Thread ID: 428
Kernel Time: 0:0:1.781
User Time: 0:0:3.296
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 078ffed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 078fff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
02 078fff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
03 078fff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
04 078fffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
05 078fffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 45
System Thread ID: 6bc
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 00c4ff70 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 00c4ff98 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 00c4ffa8 6a8c8f90 KERNEL32!WaitForSingleObject+0xf
03 00c4ffb4 7c57b382 msw3prt!SleeperSchedule+0xf
04 00c4ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 46
System Thread ID: 204
Kernel Time: 0:0:0.0
User Time: 0:0:0.15
Thread Type: Other
# ChildEBP RetAddr
00 011cfc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 011cfc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
02 011cfcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
03 011cfce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
04 011cfd30 6fc6b2f0 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 011cfd70 01002440 ftpsvc2!ServiceEntry+0xc7
06 011cffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
07 011cffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
08 011cffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 47
System Thread ID: 13c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 01f5ff00 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
01 01f5ff50 75037871 KERNEL32!WaitForMultipleObjectsEx+0xea
02 01f5ff6c 6fc66e80 WS2_32!WSAWaitForMultipleEvents+0x18
03 01f5ffb4 7c57b382 ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc+0x39
04 01f5ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 48
System Thread ID: b10
Kernel Time: 0:0:22.31
User Time: 0:0:27.234
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 04e1fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 04e1ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 04e1ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
03 04e1ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
04 04e1ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 04e1ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 49
System Thread ID: 684
Kernel Time: 0:0:23.640
User Time: 0:0:28.390
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 01effe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 01efff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 01efff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
03 01efffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
04 01efffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 01efffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 50
System Thread ID: b88
Kernel Time: 0:0:0.453
User Time: 0:0:0.671
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 0203fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 0203ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0203ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
03 0203ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
04 0203ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 0203ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 51
System Thread ID: 884
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0195ff58 7c599e8e ntdll!NtWaitForSingleObject+0xb
01 0195ff80 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
02 0195ff90 65f19981 KERNEL32!WaitForSingleObject+0xf
03 0195ffb0 65f19c89 w3svc!W3_JOB_QUEUE::QueueThreadProc+0x17
04 0195ffb4 7c57b382 w3svc!W3_JOB_QUEUE::QueueThreadProcStub+0x9
05 0195ffc0 04e1f490 KERNEL32!BaseThreadStart+0x52
WARNING: Frame IP not in any known module. Following frames may be wrong.
06 00000b80 00000000 0x4e1f490




Thread ID: 52
System Thread ID: b64
Kernel Time: 0:0:0.156
User Time: 0:0:0.31
Thread Type: Other
# ChildEBP RetAddr
00 0211ff20 77f8c35a ntdll!NtRemoveIoCompletion+0xb
01 0211ffb4 7c57b382 ntdll!RtlpWorkerThread+0x6b
02 0211ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 53
System Thread ID: b0c
Kernel Time: 0:0:0.625
User Time: 0:0:0.578
Thread Status: Thread is in a WAIT state.
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 05c5f62c 74fd1394 ntdll!NtWaitForSingleObject+0xb
01 05c5f668 74fdaa24 msafd!SockWaitForSingleObject+0x1a8
02 05c5f6e4 75031c62 msafd!WSPSend+0x1be
03 05c5f72c 769b465b WS2_32!send+0x94
04 05c5f760 65f2cc06 INFOCOMM!TcpSockSend+0xeb
05 05c5f798 65f38289 w3svc!HTTP_REQ_BASE::WriteFile+0x10a
06 05c5f7b4 77d77fb0 w3svc!WAM_REQUEST::SyncWriteClient+0x63
07 05c5f7dc 77d95ad7 RPCRT4!Invoke+0x30
08 05c5fa54 77d8f77e RPCRT4!NdrStubCall2+0x655
09 05c5fab8 77b22548 RPCRT4!CStdStubBuffer_Invoke+0xc8
0a 05c5fafc 77b22823 ole32!SyncStubInvoke+0x61
0b 05c5fb44 77ab6e81 ole32!StubInvoke+0xa8
0c 05c5fba8 77aa9a11 ole32!CCtxComChnl::ContextInvoke+0xbb
0d 05c5fbc4 77b2242d ole32!MTAInvoke+0x18
0e 05c5fbf4 77b22b58 ole32!AppInvoke+0xb5
0f 05c5fcb4 77b20360 ole32!ComInvokeWithLockAndIPID+0x29e
10 05c5fcf4 77d52156 ole32!ThreadInvoke+0x1b7
11 05c5fd2c 77d37ee1 RPCRT4!DispatchToStubInC+0x32
12 05c5fd84 77d37db5 RPCRT4!RPC_INTERFACE::DispatchToStubWorker+0x100
13 05c5fda4 77d38081 RPCRT4!RPC_INTERFACE::DispatchToStub+0x5e
14 05c5fdd4 77d58bda RPCRT4!RPC_INTERFACE::DispatchToStubWithObject+0xa9
15 05c5fe10 77d5717a RPCRT4!LRPC_SCALL::DealWithRequestMessage+0x1cd
16 05c5fe28 77d57689 RPCRT4!LRPC_ADDRESS::DealWithLRPCRequest+0x10c
17 05c5ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x229
18 05c5ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
19 05c5ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
1a 05c5ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
1b 05c5ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 54
System Thread ID: a28
Kernel Time: 0:0:0.734
User Time: 0:0:0.531
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 05e9ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 05e9ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 05e9ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 05e9ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 55
System Thread ID: 290
Kernel Time: 0:0:0.0
User Time: 0:0:0.31
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 05f1ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
01 05f1ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
02 05f1ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
03 05f1ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 56
System Thread ID: 60c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0605ebe0 77f8385e ntdll!ZwWaitForMultipleObjects+0xb
01 0605ffb4 7c57b382 ntdll!RtlpWaitThread+0x1b9
02 0605ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 57
System Thread ID: ae0
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0609ff80 74fd6363 ntdll!NtRemoveIoCompletion+0xb
01 0609ffb4 7c57b382 msafd!SockAsyncThread+0x52
02 0609ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 58
System Thread ID: b2c
Kernel Time: 0:0:0.109
User Time: 0:0:0.156
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 0216fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 0216ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0216ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
03 0216ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
04 0216ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 0216ffec 00000000 KERNEL32!BaseThreadStart+0x52




Thread ID: 59
System Thread ID: a14
Kernel Time: 0:0:0.31
User Time: 0:0:0.62
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made
# ChildEBP RetAddr
00 021ffe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
01 021fff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 021fff78 77d39a00 RPCRT4!RecvLotsaCallsWrapper+0x9
03 021fffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x4f
04 021fffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
05 021fffec 00000000 KERNEL32!BaseThreadStart+0x52

*****

Dump name is formatted as: PID-Timestamp.dmp

Creating C:\iisstate\output\1052-1081953860.dmp - mini user dump

*****

Closing open log file C:\iisstate\output\IISState-1052.log

 >> Stay informed about: Help with IISState Log File 
Back to top
Login to vote
patfilot

External


Since: Aug 24, 2003
Posts: 1478



(Msg. 2) Posted: Wed Apr 14, 2004 6:54 pm
Post subject: Re: Help with IISState Log File [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Inetinfo appears to be OK. The problem is most likely in the DLLHosts.
Next time it happens, try running IISState against any DLLHosts that are
active.

Pat

"David Morgan" <david.RemoveThis@davidmorgan.me.uk> wrote in message
news:eiTqmBjIEHA.3144@TK2MSFTNGP10.phx.gbl...
 > Hi
 >
 > I have successfully run IISState on my server this afternoon. It took
about
 > 5 minutes to execute and consumed about 23Mb of RAM.
 >
 > I am trying to find out why at certain random times throughout the day,
(may
 > be load related), my users report problems with viewing pages on my site.
I
 > have experienced it too and have run IIS State this afternoon during one
 > such occasion. The problem is simply that the browser does not receive
all
 > of the desired HTML output of an ASP. It is as if the user has pressed
stop
 > halfway through the download.
 >
 > Can anyone see anything untoward with the following log.
 >
 > Thanks
 >
 > David M
 >
 > Thread ID 30 looks interesting, but I have no idea what it means. 37 and
52
 > have some other DCOM activity which looks ok.
 >
 >
 >
 > Opened log file 'C:\iisstate\output\IISState-1052.log'
 >
 > ***********************
 > Starting new log output
 > IISState version 3.3.1
 >
 > Wed Apr 14 15:38:01 2004
 >
 > OS = Windows 2000
 > Executable: inetinfo.exe
 > PID = 1052
 >
 > Note: Thread times are formatted as HH:MM:SS.ms
 >
 > ***********************
 >
 >
 >
 >
 > Thread ID: 0
 > System Thread ID: 418
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.31
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0006f89c 7c586235 ntdll!ZwReadFile+0xb
 > 01 0006f910 7c2e0135 KERNEL32!ReadFile+0x181
 > 02 0006f93c 7c2dffbb ADVAPI32!ScGetPipeInput+0x28
 > 03 0006f9b8 7c2e1995 ADVAPI32!ScDispatcherLoop+0x4a
 > 04 0006fbf4 01002884 ADVAPI32!StartServiceCtrlDispatcherA+0x7d
 > 05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
 > 06 0006ff70 01002fbf inetinfo!main+0x654
 > 07 0006ffc0 7c5987e7 inetinfo!mainCRTStartup+0xff
 > 08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d
 >
 >
 >
 >
 > Thread ID: 1
 > System Thread ID: 3e8
 > Kernel Time: 0:0:0.109
 > User Time: 0:0:0.15
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 005dfd1c 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 005dfd44 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 005dfd54 6e6f1685 KERNEL32!WaitForSingleObject+0xf
 > 03 005dfd70 01002440 iisadmin!ServiceEntry+0x156
 > 04 005dffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
 > 05 005dffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
 > 06 005dffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 2
 > System Thread ID: 46c
 > Kernel Time: 0:20:37.750
 > User Time: 0:3:31.46
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0071ff08 77e1ea48 USER32!NtUserCallOneParam+0xb
 > 01 0071ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
 > 02 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
 > 03 0071ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
 > 04 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 3
 > System Thread ID: 470
 > Kernel Time: 0:13:7.703
 > User Time: 0:2:7.734
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0075fe9c 6e5a18aa KERNEL32!InterlockedExchange+0xe
 > 01 0075fecc 6e5a17fd IisRTL!CLKRLinearHashTable::_DeleteIf+0xe3
 > 02 0075fef0 769b425c IisRTL!CLKRHashTable::DeleteIf+0x51
 > 03 0075ff28 769b41ee INFOCOMM!FilteredFlushFileCache+0x5f
 > 04 0075ff34 6e5a5bee INFOCOMM!CacheScavenger+0xc
 > 05 0075ff7c 780085bc IisRTL!SchedulerWorkerThread+0x265
 > 06 0075ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
 > 07 0075ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 4
 > System Thread ID: 474
 > Kernel Time: 0:21:5.0
 > User Time: 0:3:2.578
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0079ff08 77e1ea48 USER32!NtUserCallOneParam+0xb
 > 01 0079ff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
 > 02 0079ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
 > 03 0079ffb4 7c57b382 MSVCRT!_endthreadex+0xc1
 > 04 0079ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 5
 > System Thread ID: 478
 > Kernel Time: 0:13:4.218
 > User Time: 0:2:3.281
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 007dfe5c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 007dfeac 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 007dff08 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 007dff24 6e5a5a7c USER32!MsgWaitForMultipleObjects+0x1d
 > 04 007dff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
 > 05 007dffb4 7c57b382 MSVCRT!_endthreadex+0xc1
 > 06 007dffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 6
 > System Thread ID: 4d4
 > Kernel Time: 0:0:0.46
 > User Time: 0:0:0.15
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 00f0fc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 00f0fc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 00f0fcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 00f0fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
 > 04 00f0fd30 6b561a78 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
 > 05 00f0fd70 01002440 SMTPSVC!ServiceEntry+0x136
 > 06 00f0ffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
 > 07 00f0ffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
 > 08 00f0ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 7
 > System Thread ID: 4d8
 > Kernel Time: 0:0:0.62
 > User Time: 0:0:0.15
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 00f4fc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 00f4fc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 00f4fcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 00f4fce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
 > 04 00f4fd30 65f0cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
 > 05 00f4fd70 01002440 w3svc!ServiceEntry+0x1b5
 > 06 00f4ffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
 > 07 00f4ffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
 > 08 00f4ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 8
 > System Thread ID: 4f8
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.0
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 0110ff5c 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0110ff88 6d7029ef KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0110ffb4 7c57b382 ISATQ!I_AtqOplockThreadFunc+0x32
 > 03 0110ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 9
 > System Thread ID: 4fc
 > Kernel Time: 0:16:45.62
 > User Time: 0:16:33.718
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 0114fadc 7c59a0ed ntdll!NtDelayExecution+0xb
 > 01 0114fafc 7c59a0b8 KERNEL32!SleepEx+0x32
 > 02 0114fb08 6e5a2617 KERNEL32!Sleep+0xb
 > 03 0114fb48 6e5a1fb9 IisRTL!CReaderWriterLock3::_LockSpin+0x87
 > 04 0114fb54 6e5a1f13 IisRTL!CLKRLinearHashTable::ReadLock+0x18
 > 05 0114fb74 6e5a1ef2 IisRTL!CLKRLinearHashTable::_FindKey+0x1d
 > 06 0114fb88 769b2625 IisRTL!CLKRHashTable::FindKey+0x59
 > 07 0114fbec 769b2592 INFOCOMM!CheckoutFile+0x3c
 > 08 0114fd18 769b2028 INFOCOMM!TsCreateFile+0xe4
 > 09 0114fd48 65f03f0c INFOCOMM!TsCreateFileFromURI+0x10a
 > 0a 0114fda8 65f0242b w3svc!HTTP_REQUEST::DoGet+0x1c4
 > 0b 0114ff18 65f01d97 w3svc!HTTP_REQUEST::DoWork+0x504
 > 0c 0114ff38 65f047ef w3svc!CLIENT_CONN::DoWork+0x1aa
 > 0d 0114ff4c 6d701a22 w3svc!W3Completion+0x43
 > 0e 0114ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
 > 0f 0114ffb4 7c57b382 ISATQ!AtqPoolThread+0x1a8
 > 10 0114ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 10
 > System Thread ID: 500
 > Kernel Time: 0:12:9.859
 > User Time: 0:11:58.953
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 0118ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0118ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0118ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 0118ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 11
 > System Thread ID: 50c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0164fd20 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 0164fd70 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 0164fd88 778322b2 KERNEL32!WaitForMultipleObjects+0x17
 > 03 0164ffb4 7c57b382 RTUTILS!TraceServerThread+0xde
 > 04 0164ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 12
 > System Thread ID: 514
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 >
 > # ChildEBP RetAddr
 > 00 0169feb8 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0169fee4 77d809da KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0169ff20 77d50ede RPCRT4!COMMON_ProcessCalls+0x9e
 > 03 0169ff74 77d50d17 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x99
 > 04 0169ff78 77d39a00 RPCRT4!ProcessIOEventsWrapper+0x9
 > 05 0169ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x4f
 > 06 0169ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 07 0169ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 13
 > System Thread ID: 518
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 016dff20 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 016dff70 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 016dff88 701224fa KERNEL32!WaitForMultipleObjects+0x17
 > 03 016dffb4 7c57b382 exstrace!RegNotifyThread+0x6f
 > 04 016dffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 14
 > System Thread ID: 51c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0171ff24 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 0171ff74 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 0171ff8c 70121e6a KERNEL32!WaitForMultipleObjects+0x17
 > 03 0171ffb4 7c57b382 exstrace!WriteTraceThread+0x2f
 > 04 0171ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 15
 > System Thread ID: 520
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.15
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0191ff64 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 0191ff8c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 0191ff9c 6ff2841e KERNEL32!WaitForSingleObject+0xf
 > 03 0191ffb4 7c57b382 FCACHDLL!CScheduleThread::ScheduleThread+0x22
 > 04 0191ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 16
 > System Thread ID: 528
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 01a9ff18 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 01a9ff68 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 01a9ff80 6b57b026 KERNEL32!WaitForMultipleObjects+0x17
 > 03 01a9ffb4 7c57b382 SMTPSVC!TcpRegNotifyThread+0x136
 > 04 01a9ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 17
 > System Thread ID: 52c
 > Kernel Time: 0:0:0.78
 > User Time: 0:0:0.46
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 01adff68 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 01adff90 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 01adffa0 6b57ae5a KERNEL32!WaitForSingleObject+0xf
 > 03 01adffb4 7c57b382 SMTPSVC!FreeLibThread+0x1d
 > 04 01adffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 18
 > System Thread ID: 530
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: HTTP Compression Thread
 > # ChildEBP RetAddr
 > 00 01b9ff5c 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 01b9ff84 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 01b9ff94 732c3366 KERNEL32!WaitForSingleObject+0xf
 > 03 01b9ffb4 7c57b382 compfilt!CompressionThread+0x29
 > 04 01b9ffc0 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 19
 > System Thread ID: 558
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01c0fe70 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 01c0fec0 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 01c0ff1c 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 01c0ff38 65f09ccb USER32!MsgWaitForMultipleObjects+0x1d
 > 04 01c0ff7c 78008454 w3svc!CMTACallbackThread::Thread+0x42
 > 05 01c0ffb4 7c57b382 MSVCRT!_endthread+0xc6
 > 06 01c0ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 20
 > System Thread ID: 55c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01c4fea8 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 01c4fef8 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 01c4ff54 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 01c4ff70 65f09d47 USER32!MsgWaitForMultipleObjects+0x1d
 > 04 01c4ffb4 7c57b382 w3svc!OleHackThread+0x88
 > 05 01c4ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 21
 > System Thread ID: 31c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01ccfce0 74fd1394 ntdll!NtWaitForSingleObject+0xb
 > 01 01ccfd1c 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
 > 02 01ccfe08 750312f5 msafd!WSPSelect+0x24e
 > 03 01ccfe6c 6e2b3b6e WS2_32!select+0xe7
 > 04 01ccffb4 7c57b382 inetsloc!SocketListenThread+0x51
 > 05 01ccffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 22
 > System Thread ID: 5b4
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 01d4fdfc 74fd1394 ntdll!NtWaitForSingleObject+0xb
 > 01 01d4fe38 74fd3c59 msafd!SockWaitForSingleObject+0x1a8
 > 02 01d4ff24 750312f5 msafd!WSPSelect+0x24e
 > 03 01d4ff88 6d7075bd WS2_32!select+0xe7
 > 04 01d4ffb0 6d70791b ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
 > 05 01d4ffb4 7c57b382 ISATQ!BmonThreadFunc+0x9
 > 06 01d4ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 23
 > System Thread ID: 5b8
 > Kernel Time: 0:0:0.31
 > User Time: 0:0:0.31
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01d9ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 01d9ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 01d9ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
 > 03 01d9ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
 > 04 01d9ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 24
 > System Thread ID: 5c0
 > Kernel Time: 0:0:6.0
 > User Time: 0:0:6.906
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 01e1fed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 01e1ff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 01e1ff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
 > 03 01e1ff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
 > 04 01e1ffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
 > 05 01e1ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 25
 > System Thread ID: 604
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01fbff9c 77f85c42 ntdll!NtDelayExecution+0xb
 > 01 01fbffb4 7c57b382 ntdll!RtlpTimerThread+0x42
 > 02 01fbffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 26
 > System Thread ID: 750
 > Kernel Time: 0:4:48.250
 > User Time: 0:6:25.187
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 >
 > # ChildEBP RetAddr
 > 00 022dff74 77d39a74 ntdll!NtDelayExecution+0xb
 > 01 022dffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0xc3
 > 02 022dffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 03 022dffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 27
 > System Thread ID: 7bc
 > Kernel Time: 0:15:47.234
 > User Time: 0:15:42.156
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 023dff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 023dff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 023dffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 023dffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 28
 > System Thread ID: 830
 > Kernel Time: 0:16:41.828
 > User Time: 0:16:26.953
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 0251ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0251ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0251ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 0251ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 29
 > System Thread ID: 920
 > Kernel Time: 0:0:0.46
 > User Time: 0:0:0.0
 > Thread Type: Idle ASP thread
 > # ChildEBP RetAddr
 > 00 0346ff08 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 0346ff58 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 0346ff70 787f37d4 KERNEL32!WaitForMultipleObjects+0x17
 > 03 0346ffb4 7c57b382 comsvcs!CEventDispatcher::PushEvents+0x44
 > 04 0346ffc0 00000008 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 30
 > System Thread ID: 994
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > Remote call is either to a MTA object or object not initialized. Also,
 > possible utility thread.
 > DCOM call being made to Process ID: 1612
 > Waiting on thread id: ffffffff
 >
 > # ChildEBP RetAddr
 > 00 034afb68 77d4ec77 ntdll!NtRequestWaitReplyPort+0xb
 > 01 034afb94 77d3a2c7 RPCRT4!LRPC_CCALL::SendReceive+0x11e
 > 02 034afba0 77b23b2c RPCRT4!I_RpcSendReceive+0x2c
 > 03 034afbc0 77b239f7 ole32!ThreadSendReceive+0xef
 > 04 034afbd8 77b20aa5
ole32!CRpcChannelBuffer::SwitchAptAndDispatchCall+0x14a
 > 05 034afc18 77b23870 ole32!CRpcChannelBuffer::SendReceive2+0x96
 > 06 034afc28 77a6c767 ole32!CRpcChannelBuffer::SendReceive+0x11
 > 07 034afc88 77ab6ac3 ole32!CAptRpcChnl::SendReceive+0xa9
 > 08 034afce0 77d90328 ole32!CCtxComChnl::SendReceive+0x124
 > 09 034afcfc 77d92b3f RPCRT4!NdrProxySendReceive+0x4c
 > 0a 034aff44 77d95f85 RPCRT4!NdrClientCall2+0x4f5
 > 0b 034aff60 77d77fcb RPCRT4!ObjectStublessClient+0x76
 > 0c 034aff70 787f372e RPCRT4!ObjectStubless+0xf
 > 0d 034affb4 7c57b382
 > comsvcs!CEventDispatcher::GetEventServerInfoThread+0x10e
 > 0e 034affec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 31
 > System Thread ID: 62c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: WebDav Worker Thread
 > # ChildEBP RetAddr
 > 00 0356ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0356ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0356ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
 > 03 0356ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
 > 04 0356ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 32
 > System Thread ID: 748
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: WebDav Worker Thread
 > # ChildEBP RetAddr
 > 00 035aff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 035aff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 035aff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
 > 03 035affb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
 > 04 035affec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 33
 > System Thread ID: 3b0
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: WebDav Worker Thread
 > # ChildEBP RetAddr
 > 00 035eff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 035eff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 035eff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
 > 03 035effb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
 > 04 035effec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 34
 > System Thread ID: 944
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: WebDav Worker Thread
 > # ChildEBP RetAddr
 > 00 0362ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0362ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0362ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
 > 03 0362ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
 > 04 0362ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 35
 > System Thread ID: 140
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: WebDav Worker Thread
 > # ChildEBP RetAddr
 > 00 0366ff30 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0366ff5c 6b5e99c2 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0366ff8c 6b5e997a httpext!CDavWorkerThread::GetWorkCompletion+0x23
 > 03 0366ffb4 7c57b382 httpext!CDavWorkerThread::ThreadDispatcher+0x30
 > 04 0366ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 36
 > System Thread ID: 794
 > Kernel Time: 0:12:40.843
 > User Time: 0:13:33.250
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 0455ff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 0455ff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 0455ffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 0455ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 37
 > System Thread ID: 638
 > Kernel Time: 0:15:50.984
 > User Time: 0:15:25.406
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > DCOM call being made to Process ID: 1564
 > Waiting on thread id: 0
 >
 > # ChildEBP RetAddr
 > 00 0471ea64 77d4ec77 ntdll!NtRequestWaitReplyPort+0xb
 > 01 0471ea90 77d3a2c7 RPCRT4!LRPC_CCALL::SendReceive+0x11e
 > 02 0471ea9c 77b23b2c RPCRT4!I_RpcSendReceive+0x2c
 > 03 0471eabc 77b239f7 ole32!ThreadSendReceive+0xef
 > 04 0471ead4 77b20aa5
ole32!CRpcChannelBuffer::SwitchAptAndDispatchCall+0x14a
 > 05 0471eb14 77b23870 ole32!CRpcChannelBuffer::SendReceive2+0x96
 > 06 0471eb24 77a6c767 ole32!CRpcChannelBuffer::SendReceive+0x11
 > 07 0471eb84 77ab6a37 ole32!CAptRpcChnl::SendReceive+0xa9
 > 08 0471ebdc 77d90328 ole32!CCtxComChnl::SendReceive+0x98
 > 09 0471ebf8 77d92b3f RPCRT4!NdrProxySendReceive+0x4c
 > 0a 0471ee40 77d95f85 RPCRT4!NdrClientCall2+0x4f5
 > 0b 0471ee5c 77d77fcb RPCRT4!ObjectStublessClient+0x76
 > 0c 0471ee6c 65f369f2 RPCRT4!ObjectStubless+0xf
 > 0d 0471f4f0 65f04c38 w3svc!CWamInfoOutProc::DoProcessRequestCall+0x163
 > 0e 0471f518 65f03d71 w3svc!CWamInfo::ProcessWamRequest+0xb9
 > 0f 0471fd50 65f03c49 w3svc!WAM_DICTATOR::ProcessWamRequest+0x1e5
 > 10 0471fd74 65f03aa2 w3svc!HTTP_REQUEST::DoWamRequest+0x75
 > 11 0471fd98 65f0249e w3svc!HTTP_REQUEST::ProcessBGI+0x166
 > 12 0471ff18 65f01d97 w3svc!HTTP_REQUEST::DoWork+0x43f
 > 13 0471ff38 65f047ef w3svc!CLIENT_CONN::DoWork+0x1aa
 > 14 0471ff4c 6d701a22 w3svc!W3Completion+0x43
 > 15 0471ff80 6d7029a6 ISATQ!AtqpProcessContext+0x266
 > 16 0471ffb4 7c57b382 ISATQ!AtqPoolThread+0x1a8
 > 17 0471ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 38
 > System Thread ID: 880
 > Kernel Time: 0:13:5.203
 > User Time: 0:12:42.437
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 106bff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 106bff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 106bffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 106bffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 39
 > System Thread ID: b48
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 1ed8ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 1ed8ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 1ed8ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
 > 03 1ed8ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
 > 04 1ed8ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 40
 > System Thread ID: 7e8
 > Kernel Time: 0:0:0.15
 > User Time: 0:0:0.0
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 1ee0fed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 1ee0ff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 1ee0ff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
 > 03 1ee0ff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
 > 04 1ee0ffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
 > 05 1ee0ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 41
 > System Thread ID: 634
 > Kernel Time: 0:10:12.375
 > User Time: 0:10:5.515
 > Thread Type: HTTP Listener
 > # ChildEBP RetAddr
 > 00 026fff50 7c585323 ntdll!NtRemoveIoCompletion+0xb
 > 01 026fff7c 6d702957 KERNEL32!GetQueuedCompletionStatus+0x27
 > 02 026fffb4 7c57b382 ISATQ!AtqPoolThread+0x40
 > 03 026fffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 42
 > System Thread ID: a78
 > Kernel Time: 0:0:3.609
 > User Time: 0:0:4.562
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 > # ChildEBP RetAddr
 > 00 05a5fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
 > 01 05a5ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
 > 02 05a5ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
 > 03 05a5ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
 > 04 05a5ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 05 05a5ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 43
 > System Thread ID: 9c4
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0787ff54 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 0787ff7c 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 0787ff8c 741a99cd KERNEL32!WaitForSingleObject+0xf
 > 03 0787ffb4 7c57b382 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xce
 > 04 0787ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 44
 > System Thread ID: 428
 > Kernel Time: 0:0:1.781
 > User Time: 0:0:3.296
 > Thread Type: SMTP Service Worker Thread
 > # ChildEBP RetAddr
 > 00 078ffed0 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 078fff20 7c599f6c KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 078fff38 741900e1 KERNEL32!WaitForMultipleObjects+0x17
 > 03 078fff9c 6b56dccd aqueue!CConnMgr::GetNextConnection+0x1da
 > 04 078fffb4 7c57b382 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x23
 > 05 078fffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 45
 > System Thread ID: 6bc
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 00c4ff70 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 00c4ff98 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 00c4ffa8 6a8c8f90 KERNEL32!WaitForSingleObject+0xf
 > 03 00c4ffb4 7c57b382 msw3prt!SleeperSchedule+0xf
 > 04 00c4ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 46
 > System Thread ID: 204
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.15
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 011cfc1c 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 011cfc6c 77e1e9fb KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 011cfcc8 77e1ea48 USER32!MsgWaitForMultipleObjectsEx+0x153
 > 03 011cfce4 769c71e0 USER32!MsgWaitForMultipleObjects+0x1d
 > 04 011cfd30 6fc6b2f0 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
 > 05 011cfd70 01002440 ftpsvc2!ServiceEntry+0xc7
 > 06 011cffa4 7c2e02f7 inetinfo!InetinfoStartService+0x2bd
 > 07 011cffb4 7c57b382 ADVAPI32!ScSvcctrlThreadA+0xe
 > 08 011cffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 47
 > System Thread ID: 13c
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 01f5ff00 7c59a059 ntdll!ZwWaitForMultipleObjects+0xb
 > 01 01f5ff50 75037871 KERNEL32!WaitForMultipleObjectsEx+0xea
 > 02 01f5ff6c 6fc66e80 WS2_32!WSAWaitForMultipleEvents+0x18
 > 03 01f5ffb4 7c57b382 ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc+0x39
 > 04 01f5ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 48
 > System Thread ID: b10
 > Kernel Time: 0:0:22.31
 > User Time: 0:0:27.234
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 > # ChildEBP RetAddr
 > 00 04e1fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
 > 01 04e1ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
 > 02 04e1ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
 > 03 04e1ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
 > 04 04e1ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 05 04e1ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 49
 > System Thread ID: 684
 > Kernel Time: 0:0:23.640
 > User Time: 0:0:28.390
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 > # ChildEBP RetAddr
 > 00 01effe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
 > 01 01efff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
 > 02 01efff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
 > 03 01efffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
 > 04 01efffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 05 01efffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 50
 > System Thread ID: b88
 > Kernel Time: 0:0:0.453
 > User Time: 0:0:0.671
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 > # ChildEBP RetAddr
 > 00 0203fe24 77d574d4 ntdll!NtReplyWaitReceivePortEx+0xb
 > 01 0203ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
 > 02 0203ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
 > 03 0203ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
 > 04 0203ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 05 0203ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 51
 > System Thread ID: 884
 > Kernel Time: 0:0:0.0
 > User Time: 0:0:0.0
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0195ff58 7c599e8e ntdll!NtWaitForSingleObject+0xb
 > 01 0195ff80 7c57b3d5 KERNEL32!WaitForSingleObjectEx+0x71
 > 02 0195ff90 65f19981 KERNEL32!WaitForSingleObject+0xf
 > 03 0195ffb0 65f19c89 w3svc!W3_JOB_QUEUE::QueueThreadProc+0x17
 > 04 0195ffb4 7c57b382 w3svc!W3_JOB_QUEUE::QueueThreadProcStub+0x9
 > 05 0195ffc0 04e1f490 KERNEL32!BaseThreadStart+0x52
 > WARNING: Frame IP not in any known module. Following frames may be wrong.
 > 06 00000b80 00000000 0x4e1f490
 >
 >
 >
 >
 > Thread ID: 52
 > System Thread ID: b64
 > Kernel Time: 0:0:0.156
 > User Time: 0:0:0.31
 > Thread Type: Other
 > # ChildEBP RetAddr
 > 00 0211ff20 77f8c35a ntdll!NtRemoveIoCompletion+0xb
 > 01 0211ffb4 7c57b382 ntdll!RtlpWorkerThread+0x6b
 > 02 0211ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 53
 > System Thread ID: b0c
 > Kernel Time: 0:0:0.625
 > User Time: 0:0:0.578
 > Thread Status: Thread is in a WAIT state.
 > Thread Type: Possible ASP page. Possible DCOM activity
 > Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
 > Continuing with other analysis.
 >
 > No remote call being made
 > # ChildEBP RetAddr
 > 00 05c5f62c 74fd1394 ntdll!NtWaitForSingleObject+0xb
 > 01 05c5f668 74fdaa24 msafd!SockWaitForSingleObject+0x1a8
 > 02 05c5f6e4 75031c62 msafd!WSPSend+0x1be
 > 03 05c5f72c 769b465b WS2_32!send+0x94
 > 04 05c5f760 65f2cc06 INFOCOMM!TcpSockSend+0xeb
 > 05 05c5f798 65f38289 w3svc!HTTP_REQ_BASE::WriteFile+0x10a
 > 06 05c5f7b4 77d77fb0 w3svc!WAM_REQUEST::SyncWriteClient+0x63
 > 07 05c5f7dc 77d95ad7 RPCRT4!Invoke+0x30
 > 08 05c5fa54 77d8f77e RPCRT4!NdrStubCall2+0x655
 > 09 05c5fab8 77b22548 RPCRT4!CStdStubBuffer_Invoke+0xc8
 > 0a 05c5fafc 77b22823 ole32!SyncStubInvoke+0x61
 > 0b 05c5fb44 77ab6e81 ole32!StubInvoke+0xa8
 > 0c 05c5fba8 77aa9a11 ole32!CCtxComChnl::ContextInvoke+0xbb
 > 0d 05c5fbc4 77b2242d ole32!MTAInvoke+0x18
 > 0e 05c5fbf4 77b22b58 ole32!AppInvoke+0xb5
 > 0f 05c5fcb4 77b20360 ole32!ComInvokeWithLockAndIPID+0x29e
 > 10 05c5fcf4 77d52156 ole32!ThreadInvoke+0x1b7
 > 11 05c5fd2c 77d37ee1 RPCRT4!DispatchToStubInC+0x32
 > 12 05c5fd84 77d37db5 RPCRT4!RPC_INTERFACE::DispatchToStubWorker+0x100
 > 13 05c5fda4 77d38081 RPCRT4!RPC_INTERFACE::DispatchToStub+0x5e
 > 14 05c5fdd4 77d58bda RPCRT4!RPC_INTERFACE::DispatchToStubWithObject+0xa9
 > 15 05c5fe10 77d5717a RPCRT4!LRPC_SCALL::DealWithRequestMessage+0x1cd
 > 16 05c5fe28 77d57689 RPCRT4!LRPC_ADDRESS::DealWithLRPCRequest+0x10c
 > 17 05c5ff74 77d56d9e RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x229
 > 18 05c5ff78 77d39ad0 RPCRT4!RecvLotsaCallsWrapper+0x9
 > 19 05c5ffa8 77d41c6c RPCRT4!BaseCachedThreadRoutine+0x11f
 > 1a 05c5ffb4 7c57b382 RPCRT4!ThreadStartRoutine+0x18
 > 1b 05c5ffec 00000000 KERNEL32!BaseThreadStart+0x52
 >
 >
 >
 >
 > Thread ID: 54
 > System Thread ID: a28
 > Kernel Time: 0:0:0.734
<font color=purple> > User T<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Help with IISState Log File 
Back to top
Login to vote