sometimes IIS stop responding.
usually an IISReset is enough in order to resolve that issue.
i tried the IISSTATE tool. i'm unable to understand the log. Can
someone help me?
Opened log file 'C:\iisstate\output\IISState-2992.log'
***********************
Starting new log output
IISState version 3.3.1
Tue Apr 19 17:40:46 2005
OS = Windows 2000
Executable: inetinfo.exe
PID = 2992
Note: Thread times are formatted as HH:MM:SS.ms
***********************
Thread ID: 0
System Thread ID: bcc
Kernel Time: 0:0:0.31
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0006f89c 7962660d ntdll!ZwReadFile+0xb
01 0006f910 79270135 KERNEL32!ReadFile+0x181
02 0006f93c 7926ffbb ADVAPI32!ScGetPipeInput+0x28
03 0006f9b8 79271995 ADVAPI32!ScDispatcherLoop+0x4a
04 0006fbf4 01002884 ADVAPI32!StartServiceCtrlDispatcherA+0x7d
05 0006fd30 01001e94 inetinfo!StartDispatchTable+0x2f1
06 0006ff70 01002fbf inetinfo!main+0x654
07 0006ffc0 796287f5 inetinfo!mainCRTStartup+0xff
08 0006fff0 00000000 KERNEL32!BaseProcessStart+0x3d
Thread ID: 1
System Thread ID: 980
Kernel Time: 0:0:0.15
User Time: 0:0:0.15
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0059fd1c 7963c4c2 ntdll!NtWaitForSingleObject+0xb
01 0059fd44 79631b1b KERNEL32!WaitForSingleObjectEx+0x71
02 0059fd54 6e651685 KERNEL32!WaitForSingleObject+0xf
03 0059fd70 01002440 iisadmin!ServiceEntry+0x156
04 0059ffa4 792702f7 inetinfo!InetinfoStartService+0x2bd
05 0059ffb4 7962987c ADVAPI32!ScSvcctrlThreadA+0xe
06 0059ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 2
System Thread ID: 5ec
Kernel Time: 0:0:0.531
User Time: 0:0:0.984
Thread Type: Other
# ChildEBP RetAddr
00 006dfe5c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 006dfeac 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 006dff08 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 006dff24 6e505a7c USER32!MsgWaitForMultipleObjects+0x1d
04 006dff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 006dffb4 7962987c MSVCRT!_endthreadex+0xc1
06 006dffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 3
System Thread ID: a24
Kernel Time: 0:0:0.515
User Time: 0:0:0.984
Thread Type: Other
# ChildEBP RetAddr
00 0071fe5c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 0071feac 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 0071ff08 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 0071ff24 6e505a7c USER32!MsgWaitForMultipleObjects+0x1d
04 0071ff7c 780085bc IisRTL!SchedulerWorkerThread+0xa7
05 0071ffb4 7962987c MSVCRT!_endthreadex+0xc1
06 0071ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 4
System Thread ID: 77c
Kernel Time: 0:0:1.140
User Time: 0:0:0.93
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 00b7fe24 7712dbac ntdll!NtReplyWaitReceivePortEx+0xb
01 00b7ff74 7712d9db RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 00b7ff78 7712dd59 RPCRT4!RecvLotsaCallsWrapper+0x9
03 00b7ffa8 7712dd0b RPCRT4!BaseCachedThreadRoutine+0x4f
04 00b7ffb4 7962987c RPCRT4!ThreadStartRoutine+0x18
05 00b7ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 5
System Thread ID: ad0
Kernel Time: 0:0:0.109
User Time: 0:0:0.46
Thread Type: Other
# ChildEBP RetAddr
00 00e0fc1c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 00e0fc6c 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e0fcc8 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e0fce4 788071e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e0fd30 65d9cfd8 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00e0fd70 01002440 w3svc!ServiceEntry+0x1b5
06 00e0ffa4 792702f7 inetinfo!InetinfoStartService+0x2bd
07 00e0ffb4 7962987c ADVAPI32!ScSvcctrlThreadA+0xe
08 00e0ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 6
System Thread ID: 9dc
Kernel Time: 0:0:0.93
User Time: 0:0:0.31
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 00e4fc1c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 00e4fc6c 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e4fcc8 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e4fce4 788071e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e4fd30 78361a78 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00e4fd70 01002440 SMTPSVC!ServiceEntry+0x136
06 00e4ffa4 792702f7 inetinfo!InetinfoStartService+0x2bd
07 00e4ffb4 7962987c ADVAPI32!ScSvcctrlThreadA+0xe
08 00e4ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 7
System Thread ID: 950
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00e8fc1c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 00e8fc6c 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00e8fcc8 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 00e8fce4 788071e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00e8fd30 69cd7e25 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00e8fd70 01002440 NntpSvc!ServiceEntry+0x13f
06 00e8ffa4 792702f7 inetinfo!InetinfoStartService+0x2bd
07 00e8ffb4 7962987c ADVAPI32!ScSvcctrlThreadA+0xe
08 00e8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 8
System Thread ID: a4c
Kernel Time: 0:0:0.15
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00ecfc1c 7962bdd7 ntdll!ZwWaitForMultipleObjects+0xb
01 00ecfc6c 77e13990 KERNEL32!WaitForMultipleObjectsEx+0xea
02 00ecfcc8 77e13a5c USER32!MsgWaitForMultipleObjectsEx+0x153
03 00ecfce4 788071e0 USER32!MsgWaitForMultipleObjects+0x1d
04 00ecfd30 6fbdb2f0 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x209
05 00ecfd70 01002440 ftpsvc2!ServiceEntry+0xc7
06 00ecffa4 792702f7 inetinfo!InetinfoStartService+0x2bd
07 00ecffb4 7962987c ADVAPI32!ScSvcctrlThreadA+0xe
08 00ecffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 9
System Thread ID: c9c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 00f8ff5c 7962fea1 ntdll!NtRemoveIoCompletion+0xb
01 00f8ff88 6d6329ef KERNEL32!GetQueuedCompletionStatus+0x27
02 00f8ffb4 7962987c ISATQ!I_AtqOplockThreadFunc+0x32
03 00f8ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 10
System Thread ID: c90
Kernel Time: 0:0:2.921
User Time: 0:0:0.453
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 00fcff50 7962fea1 ntdll!NtRemoveIoCompletion+0xb
01 00fcff7c 6d632957 KERNEL32!GetQueuedCompletionStatus+0x27
02 00fcffb4 7962987c ISATQ!AtqPoolThread+0x40
03 00fcffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 11
System Thread ID: a84
Kernel Time: 0:0:6.953
User Time: 0:0:1.78
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 0104ff50 7962fea1 ntdll!NtRemoveIoCompletion+0xb
01 0104ff7c 6d632957 KERNEL32!GetQueuedCompletionStatus+0x27
02 0104ffb4 7962987c ISATQ!AtqPoolThread+0x40
03 0104ffec 00000000 KERNEL32!BaseThreadStart+0x52
Thread ID: 12
System Thread ID: 7c8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.
No remote call being made
# ChildEBP RetAddr
00 0128fe24 7712dbac ntdll!NtReplyWaitReceivePortEx+0xb
01 0128ff74 7712d9db RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x74
02 0128ff78 7712dd59 RPCRT4!RecvLotsaCallsWrapper+0x9
03 0128ffa8 7712dd0b RPCRT4!BaseCachedThreadRoutine+0x4f
04 0128ffb4 7962987c RPCRT4!ThreadStartRoutine+0x18
05 0128ffec 00000000 KERNEL32!BaseThreadStart