This is the first time I ran this awaiting a hang. The threads were
recorded shortly after running the program and the server did not hang
so........ here are the results. Any insight would be appreciated.

Opened log file 'C:\iisstate\output\IISState-252.log'

***********************
Starting new log output
IISState version 3.3.1

Fri Dec 10 08:16:04 2004

OS = Windows 2003 Server
Executable: inetinfo.exe
PID = 252

Note: Thread times are formatted as HH:MM:SS.ms

***********************




Thread ID: 0
System Thread ID: 100
Kernel Time: 0:0:0.0
User Time: 0:0:0.15
Thread Type: Other
# ChildEBP RetAddr
00 0006f9a8 77f4303b SharedUserData!SystemCallStub+0x4
01 0006f9ac 77e4905d ntdll!NtReadFile+0xc
02 0006fa14 77db51f1 kernel32!ReadFile+0x16c
03 0006fa40 77db5297 ADVAPI32!ScGetPipeInput+0x28
04 0006fab0 77dfa7f1 ADVAPI32!ScDispatcherLoop+0x4c
05 0006fcec 01002655 ADVAPI32!StartServiceCtrlDispatcherA+0x91
06 0006fe1c 010027ea inetinfo!StartDispatchTable+0x214
07 0006ff44 01003160 inetinfo!main+0x104
08 0006ffc0 77e4f38c inetinfo!mainCRTStartup+0x12f
09 0006fff0 00000000 kernel32!BaseProcessStart+0x23




Thread ID: 1
System Thread ID: f8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0083fe18 77f43741 SharedUserData!SystemCallStub+0x4
01 0083fe1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
02 0083fe8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
03 0083fe9c 01002cf9 kernel32!WaitForSingleObject+0xf
04 0083ffb8 77e4a990 inetinfo!W3SVCThreadEntry+0x3b
05 0083ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 2
System Thread ID: 11c
Kernel Time: 0:0:0.62
User Time: 0:0:0.78
Thread Type: Other
# ChildEBP RetAddr
00 0087fcc4 77f43741 SharedUserData!SystemCallStub+0x4
01 0087fcc8 77e41817 ntdll!ZwWaitForSingleObject+0xc
02 0087fd38 77e4168f kernel32!WaitForSingleObjectEx+0xac
03 0087fd48 649f24ac kernel32!WaitForSingleObject+0xf
04 0087fd70 010023b6 iisadmin!ServiceEntry+0x214
05 0087ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
06 0087ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
07 0087ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 3
System Thread ID: 118
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00a7ff9c 77f4262b SharedUserData!SystemCallStub+0x4
01 00a7ffa0 77f6b5b2 ntdll!NtDelayExecution+0xc
02 00a7ffb8 77e4a990 ntdll!RtlpTimerThread+0x45
03 00a7ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 4
System Thread ID: 138
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 00b8feb0 77f4372d SharedUserData!SystemCallStub+0x4
01 00b8feb4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 00b8ff5c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
03 00b8ff74 6e0b377a kernel32!WaitForMultipleObjects+0x17
04 00b8ffa0 6e0b6012 COADMIN!NOTIFY_CONTEXT::GetNextContext+0x68
05 00b8ffb8 77e4a990 COADMIN!NOTIFY_CONTEXT::NotifyThreadProc+0x62
06 00b8ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 5
System Thread ID: a00
Kernel Time: 0:0:0.62
User Time: 0:0:0.46
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0180fbc0 77f4372d SharedUserData!SystemCallStub+0x4
01 0180fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 0180fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
03 0180fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
04 0180fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
05 0180fd30 6930d973 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
06 0180fd70 010023b6 ftpsvc2!ServiceEntry+0xac
07 0180ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
08 0180ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
09 0180ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 6
System Thread ID: a04
Kernel Time: 0:0:0.46
User Time: 0:0:0.78
Thread Status: Thread is in a WAIT state.
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0188fbc0 77f4372d SharedUserData!SystemCallStub+0x4
01 0188fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 0188fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
03 0188fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
04 0188fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
05 0188fd30 6b772f7d INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
06 0188fd70 010023b6 SMTPSVC!ServiceEntry+0x129
07 0188ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
08 0188ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
09 0188ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 7
System Thread ID: a44
Kernel Time: 0:0:0.203
User Time: 0:0:0.15
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 01c0ff50 77f430c7 SharedUserData!SystemCallStub+0x4
01 01c0ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
02 01c0ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
03 01c0ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
04 01c0ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 8
System Thread ID: a48
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 01c4ff50 77f430c7 SharedUserData!SystemCallStub+0x4
01 01c4ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
02 01c4ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
03 01c4ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
04 01c4ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 9
System Thread ID: a54
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 01f8fe20 77f4313f SharedUserData!SystemCallStub+0x4
01 01f8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 01f8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 01f8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 01f8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 01f8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 01f8ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 10
System Thread ID: a58
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 01fcfcec 77f4372d SharedUserData!SystemCallStub+0x4
01 01fcfcf0 77f75297 ntdll!NtWaitForMultipleObjects+0xc
02 01fcffb8 77e4a990 ntdll!RtlpWaitThread+0x158
03 01fcffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 11
System Thread ID: a5c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 0200feb4 77f430c7 SharedUserData!SystemCallStub+0x4
01 0200feb8 77e430bc ntdll!ZwRemoveIoCompletion+0xc
02 0200fee4 77c80bd1 kernel32!GetQueuedCompletionStatus+0x27
03 0200ff20 77c80a78 RPCRT4!COMMON_ProcessCalls+0x9f
04 0200ff8c 77c58159 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x115
05 0200ff90 77c60771 RPCRT4!ProcessIOEventsWrapper+0x9
06 0200ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
07 0200ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
08 0200ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 12
System Thread ID: a68
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0204fec8 77f4372d SharedUserData!SystemCallStub+0x4
01 0204fecc 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 0204ff74 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
03 0204ff8c 69532430 kernel32!WaitForMultipleObjects+0x17
04 0204ffb8 77e4a990 exstrace!RegNotifyThread+0x68
05 0204ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 13
System Thread ID: a6c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0208fecc 77f4372d SharedUserData!SystemCallStub+0x4
01 0208fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 0208ff78 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
03 0208ff90 695319c0 kernel32!WaitForMultipleObjects+0x17
04 0208ffb8 77e4a990 exstrace!WriteTraceThread+0x2f
05 0208ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 14
System Thread ID: a78
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 0228ff18 77f43741 SharedUserData!SystemCallStub+0x4
01 0228ff1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
02 0228ff8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
03 0228ff9c 01a88673 kernel32!WaitForSingleObject+0xf
04 0228ffb8 77e4a990 FCACHDLL!CScheduleThread::ScheduleThread+0x60
05 0228ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 15
System Thread ID: a7c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: Other
# ChildEBP RetAddr
00 0240fecc 77f4372d SharedUserData!SystemCallStub+0x4
01 0240fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 0240ff78 6930882e kernel32!WaitForMultipleObjectsEx+0x11a
03 0240ffb0 77f4308b ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc+0x32
04 0240ffb8 77e4a990 ntdll!NtRegisterThreadTerminatePort+0xc
05 0240ffc4 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 16
System Thread ID: a80
Kernel Time: 0:0:0.156
User Time: 0:0:0.171
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 0244fe20 77f4313f SharedUserData!SystemCallStub+0x4
01 0244fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 0244ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 0244ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 0244ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 0244ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 0244ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 17
System Thread ID: a84
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 023cfec0 77f4372d SharedUserData!SystemCallStub+0x4
01 023cfec4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 023cff6c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
03 023cff84 6b78b1f6 kernel32!WaitForMultipleObjects+0x17
04 023cffb8 77e4a990 SMTPSVC!TcpRegNotifyThread+0xdc
05 023cffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 18
System Thread ID: a8c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 0248ff20 77f43741 SharedUserData!SystemCallStub+0x4
01 0248ff24 77e41817 ntdll!ZwWaitForSingleObject+0xc
02 0248ff94 77e4168f kernel32!WaitForSingleObjectEx+0xac
03 0248ffa4 6b78b09a kernel32!WaitForSingleObject+0xf
04 0248ffb8 77e4a990 SMTPSVC!FreeLibThread+0x2c
05 0248ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 19
System Thread ID: b20
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 02b7fe38 77f43741 SharedUserData!SystemCallStub+0x4
01 02b7fe3c 71b23ac3 ntdll!ZwWaitForSingleObject+0xc
02 02b7fe78 71b239d1 mswsock!SockWaitForSingleObject+0x19b
03 02b7ff3c 71c016c9 mswsock!WSPSelect+0x229
04 02b7ff8c 63ec4696 WS2_32!select+0xb9
05 02b7ffb4 63ec4700 ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
06 02b7ffb8 77e4a990 ISATQ!BmonThreadFunc+0x9
07 02b7ffc4 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 20
System Thread ID: b24
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 02c3fe20 77f4313f SharedUserData!SystemCallStub+0x4
01 02c3fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 02c3ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 02c3ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 02c3ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 02c3ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 02c3ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 21
System Thread ID: b30
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 02c7fe20 77f4313f SharedUserData!SystemCallStub+0x4
01 02c7fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 02c7ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 02c7ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 02c7ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 02c7ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 02c7ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 22
System Thread ID: b34
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 02cbff10 77f43741 SharedUserData!SystemCallStub+0x4
01 02cbff14 77e41817 ntdll!ZwWaitForSingleObject+0xc
02 02cbff84 77e4168f kernel32!WaitForSingleObjectEx+0xac
03 02cbff94 02bbd064 kernel32!WaitForSingleObject+0xf
04 02cbffb8 77e4a990 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xc1
05 02cbffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 23
System Thread ID: b3c
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Status: Thread is in a WAIT state.
Thread Type: SMTP Service Worker Thread
# ChildEBP RetAddr
00 02cffe84 77f4372d SharedUserData!SystemCallStub+0x4
01 02cffe88 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
02 02cfff30 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
03 02cfff48 02b9c648 kernel32!WaitForMultipleObjects+0x17
04 02cfffa4 6b77e7ce aqueue!CConnMgr::GetNextConnection+0x1e1
05 02cfffb8 77e4a990 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x21
06 02cfffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 24
System Thread ID: f54
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00abff70 77f430c7 SharedUserData!SystemCallStub+0x4
01 00abff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
02 00abffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
03 00abffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 25
System Thread ID: 258
Kernel Time: 0:0:0.0
User Time: 0:0:0.15
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 00ecfe20 77f4313f SharedUserData!SystemCallStub+0x4
01 00ecfe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 00ecff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 00ecff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 00ecffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 00ecffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 00ecffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 26
System Thread ID: d7c
Kernel Time: 0:0:0.0
User Time: 0:0:0.46
Thread Type: Possible ASP page. Possible DCOM activity
Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
Continuing with other analysis.

No remote call being made

# ChildEBP RetAddr
00 00e8fe20 77f4313f SharedUserData!SystemCallStub+0x4
01 00e8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
02 00e8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
03 00e8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
04 00e8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
05 00e8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
06 00e8ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 27
System Thread ID: ea8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: HTTP Listener
# ChildEBP RetAddr
00 00f6ff50 77f430c7 SharedUserData!SystemCallStub+0x4
01 00f6ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
02 00f6ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
03 00f6ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
04 00f6ffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 28
System Thread ID: ee8
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00faff7c 77f430c7 SharedUserData!SystemCallStub+0x4
01 00faff80 71b246f7 ntdll!ZwRemoveIoCompletion+0xc
02 00faffb8 77e4a990 mswsock!SockAsyncThread+0x67
03 00faffec 00000000 kernel32!BaseThreadStart+0x34




Thread ID: 29
System Thread ID: 354
Kernel Time: 0:0:0.0
User Time: 0:0:0.0
Thread Type: Other
# ChildEBP RetAddr
00 00f0ff70 77f430c7 SharedUserData!SystemCallStub+0x4
01 00f0ff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
02 00f0ffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
03 00f0ffec 00000000 kernel32!BaseThreadStart+0x34

*****

Dump name is formatted as: PID-Timestamp.dmp

Creating C:\iisstate\output\252-1102684642.dmp - mini user dump

*****

Closing open log file C:\iisstate\output\IISState-252.log

Re: IIS State Log Analysis by Pat

Pat
Fri Dec 10 11:38:19 CST 2004

On 2003, you need to run IISState against the w3wp.exe process(es).


Pat

"Ozzie" <none@none.com> wrote in message
news:%23PxQK4r3EHA.3452@TK2MSFTNGP14.phx.gbl...
> This is the first time I ran this awaiting a hang. The threads were
> recorded shortly after running the program and the server did not hang
> so........ here are the results. Any insight would be appreciated.
>
> Opened log file 'C:\iisstate\output\IISState-252.log'
>
> ***********************
> Starting new log output
> IISState version 3.3.1
>
> Fri Dec 10 08:16:04 2004
>
> OS = Windows 2003 Server
> Executable: inetinfo.exe
> PID = 252
>
> Note: Thread times are formatted as HH:MM:SS.ms
>
> ***********************
>
>
>
>
> Thread ID: 0
> System Thread ID: 100
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.15
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0006f9a8 77f4303b SharedUserData!SystemCallStub+0x4
> 01 0006f9ac 77e4905d ntdll!NtReadFile+0xc
> 02 0006fa14 77db51f1 kernel32!ReadFile+0x16c
> 03 0006fa40 77db5297 ADVAPI32!ScGetPipeInput+0x28
> 04 0006fab0 77dfa7f1 ADVAPI32!ScDispatcherLoop+0x4c
> 05 0006fcec 01002655 ADVAPI32!StartServiceCtrlDispatcherA+0x91
> 06 0006fe1c 010027ea inetinfo!StartDispatchTable+0x214
> 07 0006ff44 01003160 inetinfo!main+0x104
> 08 0006ffc0 77e4f38c inetinfo!mainCRTStartup+0x12f
> 09 0006fff0 00000000 kernel32!BaseProcessStart+0x23
>
>
>
>
> Thread ID: 1
> System Thread ID: f8
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0083fe18 77f43741 SharedUserData!SystemCallStub+0x4
> 01 0083fe1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
> 02 0083fe8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
> 03 0083fe9c 01002cf9 kernel32!WaitForSingleObject+0xf
> 04 0083ffb8 77e4a990 inetinfo!W3SVCThreadEntry+0x3b
> 05 0083ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 2
> System Thread ID: 11c
> Kernel Time: 0:0:0.62
> User Time: 0:0:0.78
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0087fcc4 77f43741 SharedUserData!SystemCallStub+0x4
> 01 0087fcc8 77e41817 ntdll!ZwWaitForSingleObject+0xc
> 02 0087fd38 77e4168f kernel32!WaitForSingleObjectEx+0xac
> 03 0087fd48 649f24ac kernel32!WaitForSingleObject+0xf
> 04 0087fd70 010023b6 iisadmin!ServiceEntry+0x214
> 05 0087ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
> 06 0087ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
> 07 0087ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 3
> System Thread ID: 118
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00a7ff9c 77f4262b SharedUserData!SystemCallStub+0x4
> 01 00a7ffa0 77f6b5b2 ntdll!NtDelayExecution+0xc
> 02 00a7ffb8 77e4a990 ntdll!RtlpTimerThread+0x45
> 03 00a7ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 4
> System Thread ID: 138
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00b8feb0 77f4372d SharedUserData!SystemCallStub+0x4
> 01 00b8feb4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 00b8ff5c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 00b8ff74 6e0b377a kernel32!WaitForMultipleObjects+0x17
> 04 00b8ffa0 6e0b6012 COADMIN!NOTIFY_CONTEXT::GetNextContext+0x68
> 05 00b8ffb8 77e4a990 COADMIN!NOTIFY_CONTEXT::NotifyThreadProc+0x62
> 06 00b8ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 5
> System Thread ID: a00
> Kernel Time: 0:0:0.62
> User Time: 0:0:0.46
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0180fbc0 77f4372d SharedUserData!SystemCallStub+0x4
> 01 0180fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 0180fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 0180fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
> 04 0180fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
> 05 0180fd30 6930d973 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
> 06 0180fd70 010023b6 ftpsvc2!ServiceEntry+0xac
> 07 0180ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
> 08 0180ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
> 09 0180ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 6
> System Thread ID: a04
> Kernel Time: 0:0:0.46
> User Time: 0:0:0.78
> Thread Status: Thread is in a WAIT state.
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 0188fbc0 77f4372d SharedUserData!SystemCallStub+0x4
> 01 0188fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 0188fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 0188fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
> 04 0188fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
> 05 0188fd30 6b772f7d INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
> 06 0188fd70 010023b6 SMTPSVC!ServiceEntry+0x129
> 07 0188ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
> 08 0188ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
> 09 0188ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 7
> System Thread ID: a44
> Kernel Time: 0:0:0.203
> User Time: 0:0:0.15
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 01c0ff50 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 01c0ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
> 02 01c0ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
> 03 01c0ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
> 04 01c0ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 8
> System Thread ID: a48
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 01c4ff50 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 01c4ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
> 02 01c4ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
> 03 01c4ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
> 04 01c4ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 9
> System Thread ID: a54
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 01f8fe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 01f8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 01f8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 01f8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 01f8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 01f8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 01f8ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 10
> System Thread ID: a58
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 01fcfcec 77f4372d SharedUserData!SystemCallStub+0x4
> 01 01fcfcf0 77f75297 ntdll!NtWaitForMultipleObjects+0xc
> 02 01fcffb8 77e4a990 ntdll!RtlpWaitThread+0x158
> 03 01fcffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 11
> System Thread ID: a5c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 0200feb4 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 0200feb8 77e430bc ntdll!ZwRemoveIoCompletion+0xc
> 02 0200fee4 77c80bd1 kernel32!GetQueuedCompletionStatus+0x27
> 03 0200ff20 77c80a78 RPCRT4!COMMON_ProcessCalls+0x9f
> 04 0200ff8c 77c58159 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x115
> 05 0200ff90 77c60771 RPCRT4!ProcessIOEventsWrapper+0x9
> 06 0200ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 07 0200ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 08 0200ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 12
> System Thread ID: a68
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0204fec8 77f4372d SharedUserData!SystemCallStub+0x4
> 01 0204fecc 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 0204ff74 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 0204ff8c 69532430 kernel32!WaitForMultipleObjects+0x17
> 04 0204ffb8 77e4a990 exstrace!RegNotifyThread+0x68
> 05 0204ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 13
> System Thread ID: a6c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0208fecc 77f4372d SharedUserData!SystemCallStub+0x4
> 01 0208fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 0208ff78 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 0208ff90 695319c0 kernel32!WaitForMultipleObjects+0x17
> 04 0208ffb8 77e4a990 exstrace!WriteTraceThread+0x2f
> 05 0208ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 14
> System Thread ID: a78
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0228ff18 77f43741 SharedUserData!SystemCallStub+0x4
> 01 0228ff1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
> 02 0228ff8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
> 03 0228ff9c 01a88673 kernel32!WaitForSingleObject+0xf
> 04 0228ffb8 77e4a990 FCACHDLL!CScheduleThread::ScheduleThread+0x60
> 05 0228ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 15
> System Thread ID: a7c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: Other
> # ChildEBP RetAddr
> 00 0240fecc 77f4372d SharedUserData!SystemCallStub+0x4
> 01 0240fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 0240ff78 6930882e kernel32!WaitForMultipleObjectsEx+0x11a
> 03 0240ffb0 77f4308b ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc+0x32
> 04 0240ffb8 77e4a990 ntdll!NtRegisterThreadTerminatePort+0xc
> 05 0240ffc4 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 16
> System Thread ID: a80
> Kernel Time: 0:0:0.156
> User Time: 0:0:0.171
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 0244fe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 0244fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 0244ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 0244ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 0244ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 0244ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 0244ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 17
> System Thread ID: a84
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 023cfec0 77f4372d SharedUserData!SystemCallStub+0x4
> 01 023cfec4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 023cff6c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 023cff84 6b78b1f6 kernel32!WaitForMultipleObjects+0x17
> 04 023cffb8 77e4a990 SMTPSVC!TcpRegNotifyThread+0xdc
> 05 023cffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 18
> System Thread ID: a8c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 0248ff20 77f43741 SharedUserData!SystemCallStub+0x4
> 01 0248ff24 77e41817 ntdll!ZwWaitForSingleObject+0xc
> 02 0248ff94 77e4168f kernel32!WaitForSingleObjectEx+0xac
> 03 0248ffa4 6b78b09a kernel32!WaitForSingleObject+0xf
> 04 0248ffb8 77e4a990 SMTPSVC!FreeLibThread+0x2c
> 05 0248ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 19
> System Thread ID: b20
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 02b7fe38 77f43741 SharedUserData!SystemCallStub+0x4
> 01 02b7fe3c 71b23ac3 ntdll!ZwWaitForSingleObject+0xc
> 02 02b7fe78 71b239d1 mswsock!SockWaitForSingleObject+0x19b
> 03 02b7ff3c 71c016c9 mswsock!WSPSelect+0x229
> 04 02b7ff8c 63ec4696 WS2_32!select+0xb9
> 05 02b7ffb4 63ec4700 ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
> 06 02b7ffb8 77e4a990 ISATQ!BmonThreadFunc+0x9
> 07 02b7ffc4 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 20
> System Thread ID: b24
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 02c3fe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 02c3fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 02c3ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 02c3ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 02c3ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 02c3ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 02c3ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 21
> System Thread ID: b30
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 02c7fe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 02c7fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 02c7ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 02c7ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 02c7ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 02c7ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 02c7ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 22
> System Thread ID: b34
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 02cbff10 77f43741 SharedUserData!SystemCallStub+0x4
> 01 02cbff14 77e41817 ntdll!ZwWaitForSingleObject+0xc
> 02 02cbff84 77e4168f kernel32!WaitForSingleObjectEx+0xac
> 03 02cbff94 02bbd064 kernel32!WaitForSingleObject+0xf
> 04 02cbffb8 77e4a990 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xc1
> 05 02cbffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 23
> System Thread ID: b3c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Status: Thread is in a WAIT state.
> Thread Type: SMTP Service Worker Thread
> # ChildEBP RetAddr
> 00 02cffe84 77f4372d SharedUserData!SystemCallStub+0x4
> 01 02cffe88 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
> 02 02cfff30 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
> 03 02cfff48 02b9c648 kernel32!WaitForMultipleObjects+0x17
> 04 02cfffa4 6b77e7ce aqueue!CConnMgr::GetNextConnection+0x1e1
> 05 02cfffb8 77e4a990 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x21
> 06 02cfffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 24
> System Thread ID: f54
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00abff70 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 00abff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
> 02 00abffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
> 03 00abffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 25
> System Thread ID: 258
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.15
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 00ecfe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 00ecfe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 00ecff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 00ecff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 00ecffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 00ecffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 00ecffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 26
> System Thread ID: d7c
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.46
> Thread Type: Possible ASP page. Possible DCOM activity
> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
> Continuing with other analysis.
>
> No remote call being made
>
> # ChildEBP RetAddr
> 00 00e8fe20 77f4313f SharedUserData!SystemCallStub+0x4
> 01 00e8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
> 02 00e8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
> 03 00e8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
> 04 00e8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
> 05 00e8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
> 06 00e8ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 27
> System Thread ID: ea8
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: HTTP Listener
> # ChildEBP RetAddr
> 00 00f6ff50 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 00f6ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
> 02 00f6ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
> 03 00f6ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
> 04 00f6ffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 28
> System Thread ID: ee8
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00faff7c 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 00faff80 71b246f7 ntdll!ZwRemoveIoCompletion+0xc
> 02 00faffb8 77e4a990 mswsock!SockAsyncThread+0x67
> 03 00faffec 00000000 kernel32!BaseThreadStart+0x34
>
>
>
>
> Thread ID: 29
> System Thread ID: 354
> Kernel Time: 0:0:0.0
> User Time: 0:0:0.0
> Thread Type: Other
> # ChildEBP RetAddr
> 00 00f0ff70 77f430c7 SharedUserData!SystemCallStub+0x4
> 01 00f0ff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
> 02 00f0ffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
> 03 00f0ffec 00000000 kernel32!BaseThreadStart+0x34
>
> *****
>
> Dump name is formatted as: PID-Timestamp.dmp
>
> Creating C:\iisstate\output\252-1102684642.dmp - mini user dump
>
> *****
>
> Closing open log file C:\iisstate\output\IISState-252.log
>
>



Re: IIS State Log Analysis by Pat

Pat
Mon Dec 13 14:57:04 CST 2004

There was no activity at the time the log was taken. It looks idle.


Pat

"Ozzie" <none@none.com> wrote in message
news:%23Nyf40Q4EHA.708@TK2MSFTNGP11.phx.gbl...
> Attached is iisstate run against w3wp.exe My server was hanging about
> 3:30 PM every day. I have worker processes to recycle after 12 hrs of
> inactivity and 3 AM every day. The server has not hung after changing the
> recycling processes. I also downloaded the Access Jet driver fix but have
> not installed it yet awaiting all my other debugging efforts. IISCHAgent
> has not recorded any hangs. So based on these latest results, I am trying
> to determine if I have an app failing or is this nothing more than a bad
> driver. Thanks
>
> Ozzie
>
>
> "Pat [MSFT]" <patfilot@online.microsoft.com> wrote in message
> news:%23S6tK8t3EHA.1976@TK2MSFTNGP09.phx.gbl...
>> On 2003, you need to run IISState against the w3wp.exe process(es).
>>
>>
>> Pat
>>
>> "Ozzie" <none@none.com> wrote in message
>> news:%23PxQK4r3EHA.3452@TK2MSFTNGP14.phx.gbl...
>>> This is the first time I ran this awaiting a hang. The threads were
>>> recorded shortly after running the program and the server did not hang
>>> so........ here are the results. Any insight would be appreciated.
>>>
>>> Opened log file 'C:\iisstate\output\IISState-252.log'
>>>
>>> ***********************
>>> Starting new log output
>>> IISState version 3.3.1
>>>
>>> Fri Dec 10 08:16:04 2004
>>>
>>> OS = Windows 2003 Server
>>> Executable: inetinfo.exe
>>> PID = 252
>>>
>>> Note: Thread times are formatted as HH:MM:SS.ms
>>>
>>> ***********************
>>>
>>>
>>>
>>>
>>> Thread ID: 0
>>> System Thread ID: 100
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.15
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0006f9a8 77f4303b SharedUserData!SystemCallStub+0x4
>>> 01 0006f9ac 77e4905d ntdll!NtReadFile+0xc
>>> 02 0006fa14 77db51f1 kernel32!ReadFile+0x16c
>>> 03 0006fa40 77db5297 ADVAPI32!ScGetPipeInput+0x28
>>> 04 0006fab0 77dfa7f1 ADVAPI32!ScDispatcherLoop+0x4c
>>> 05 0006fcec 01002655 ADVAPI32!StartServiceCtrlDispatcherA+0x91
>>> 06 0006fe1c 010027ea inetinfo!StartDispatchTable+0x214
>>> 07 0006ff44 01003160 inetinfo!main+0x104
>>> 08 0006ffc0 77e4f38c inetinfo!mainCRTStartup+0x12f
>>> 09 0006fff0 00000000 kernel32!BaseProcessStart+0x23
>>>
>>>
>>>
>>>
>>> Thread ID: 1
>>> System Thread ID: f8
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0083fe18 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 0083fe1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
>>> 02 0083fe8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
>>> 03 0083fe9c 01002cf9 kernel32!WaitForSingleObject+0xf
>>> 04 0083ffb8 77e4a990 inetinfo!W3SVCThreadEntry+0x3b
>>> 05 0083ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 2
>>> System Thread ID: 11c
>>> Kernel Time: 0:0:0.62
>>> User Time: 0:0:0.78
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0087fcc4 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 0087fcc8 77e41817 ntdll!ZwWaitForSingleObject+0xc
>>> 02 0087fd38 77e4168f kernel32!WaitForSingleObjectEx+0xac
>>> 03 0087fd48 649f24ac kernel32!WaitForSingleObject+0xf
>>> 04 0087fd70 010023b6 iisadmin!ServiceEntry+0x214
>>> 05 0087ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
>>> 06 0087ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
>>> 07 0087ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 3
>>> System Thread ID: 118
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 00a7ff9c 77f4262b SharedUserData!SystemCallStub+0x4
>>> 01 00a7ffa0 77f6b5b2 ntdll!NtDelayExecution+0xc
>>> 02 00a7ffb8 77e4a990 ntdll!RtlpTimerThread+0x45
>>> 03 00a7ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 4
>>> System Thread ID: 138
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 00b8feb0 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 00b8feb4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 00b8ff5c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 00b8ff74 6e0b377a kernel32!WaitForMultipleObjects+0x17
>>> 04 00b8ffa0 6e0b6012 COADMIN!NOTIFY_CONTEXT::GetNextContext+0x68
>>> 05 00b8ffb8 77e4a990 COADMIN!NOTIFY_CONTEXT::NotifyThreadProc+0x62
>>> 06 00b8ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 5
>>> System Thread ID: a00
>>> Kernel Time: 0:0:0.62
>>> User Time: 0:0:0.46
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0180fbc0 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 0180fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 0180fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 0180fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
>>> 04 0180fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
>>> 05 0180fd30 6930d973 INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
>>> 06 0180fd70 010023b6 ftpsvc2!ServiceEntry+0xac
>>> 07 0180ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
>>> 08 0180ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
>>> 09 0180ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 6
>>> System Thread ID: a04
>>> Kernel Time: 0:0:0.46
>>> User Time: 0:0:0.78
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: SMTP Service Worker Thread
>>> # ChildEBP RetAddr
>>> 00 0188fbc0 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 0188fbc4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 0188fc6c 77d076f5 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 0188fcc8 77d077f5 USER32!RealMsgWaitForMultipleObjectsEx+0x13f
>>> 04 0188fce4 643f5723 USER32!MsgWaitForMultipleObjects+0x1d
>>> 05 0188fd30 6b772f7d INFOCOMM!IIS_SERVICE::StartServiceOperation+0x22f
>>> 06 0188fd70 010023b6 SMTPSVC!ServiceEntry+0x129
>>> 07 0188ffa8 77db571b inetinfo!InetinfoStartService+0x2a6
>>> 08 0188ffb8 77e4a990 ADVAPI32!ScSvcctrlThreadA+0xe
>>> 09 0188ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 7
>>> System Thread ID: a44
>>> Kernel Time: 0:0:0.203
>>> User Time: 0:0:0.15
>>> Thread Type: HTTP Listener
>>> # ChildEBP RetAddr
>>> 00 01c0ff50 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 01c0ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
>>> 02 01c0ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
>>> 03 01c0ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
>>> 04 01c0ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 8
>>> System Thread ID: a48
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: HTTP Listener
>>> # ChildEBP RetAddr
>>> 00 01c4ff50 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 01c4ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
>>> 02 01c4ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
>>> 03 01c4ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
>>> 04 01c4ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 9
>>> System Thread ID: a54
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 01f8fe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 01f8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 01f8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 01f8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 01f8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 01f8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 01f8ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 10
>>> System Thread ID: a58
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 01fcfcec 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 01fcfcf0 77f75297 ntdll!NtWaitForMultipleObjects+0xc
>>> 02 01fcffb8 77e4a990 ntdll!RtlpWaitThread+0x158
>>> 03 01fcffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 11
>>> System Thread ID: a5c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 0200feb4 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 0200feb8 77e430bc ntdll!ZwRemoveIoCompletion+0xc
>>> 02 0200fee4 77c80bd1 kernel32!GetQueuedCompletionStatus+0x27
>>> 03 0200ff20 77c80a78 RPCRT4!COMMON_ProcessCalls+0x9f
>>> 04 0200ff8c 77c58159 RPCRT4!LOADABLE_TRANSPORT::ProcessIOEvents+0x115
>>> 05 0200ff90 77c60771 RPCRT4!ProcessIOEventsWrapper+0x9
>>> 06 0200ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 07 0200ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 08 0200ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 12
>>> System Thread ID: a68
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0204fec8 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 0204fecc 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 0204ff74 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 0204ff8c 69532430 kernel32!WaitForMultipleObjects+0x17
>>> 04 0204ffb8 77e4a990 exstrace!RegNotifyThread+0x68
>>> 05 0204ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 13
>>> System Thread ID: a6c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0208fecc 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 0208fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 0208ff78 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 0208ff90 695319c0 kernel32!WaitForMultipleObjects+0x17
>>> 04 0208ffb8 77e4a990 exstrace!WriteTraceThread+0x2f
>>> 05 0208ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 14
>>> System Thread ID: a78
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0228ff18 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 0228ff1c 77e41817 ntdll!ZwWaitForSingleObject+0xc
>>> 02 0228ff8c 77e4168f kernel32!WaitForSingleObjectEx+0xac
>>> 03 0228ff9c 01a88673 kernel32!WaitForSingleObject+0xf
>>> 04 0228ffb8 77e4a990 FCACHDLL!CScheduleThread::ScheduleThread+0x60
>>> 05 0228ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 15
>>> System Thread ID: a7c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 0240fecc 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 0240fed0 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 0240ff78 6930882e kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 0240ffb0 77f4308b ftpsvc2!PASV_ACCEPT_CONTEXT::AcceptThreadFunc+0x32
>>> 04 0240ffb8 77e4a990 ntdll!NtRegisterThreadTerminatePort+0xc
>>> 05 0240ffc4 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 16
>>> System Thread ID: a80
>>> Kernel Time: 0:0:0.156
>>> User Time: 0:0:0.171
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 0244fe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 0244fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 0244ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 0244ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 0244ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 0244ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 0244ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 17
>>> System Thread ID: a84
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: SMTP Service Worker Thread
>>> # ChildEBP RetAddr
>>> 00 023cfec0 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 023cfec4 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 023cff6c 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 023cff84 6b78b1f6 kernel32!WaitForMultipleObjects+0x17
>>> 04 023cffb8 77e4a990 SMTPSVC!TcpRegNotifyThread+0xdc
>>> 05 023cffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 18
>>> System Thread ID: a8c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: SMTP Service Worker Thread
>>> # ChildEBP RetAddr
>>> 00 0248ff20 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 0248ff24 77e41817 ntdll!ZwWaitForSingleObject+0xc
>>> 02 0248ff94 77e4168f kernel32!WaitForSingleObjectEx+0xac
>>> 03 0248ffa4 6b78b09a kernel32!WaitForSingleObject+0xf
>>> 04 0248ffb8 77e4a990 SMTPSVC!FreeLibThread+0x2c
>>> 05 0248ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 19
>>> System Thread ID: b20
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: HTTP Listener
>>> # ChildEBP RetAddr
>>> 00 02b7fe38 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 02b7fe3c 71b23ac3 ntdll!ZwWaitForSingleObject+0xc
>>> 02 02b7fe78 71b239d1 mswsock!SockWaitForSingleObject+0x19b
>>> 03 02b7ff3c 71c016c9 mswsock!WSPSelect+0x229
>>> 04 02b7ff8c 63ec4696 WS2_32!select+0xb9
>>> 05 02b7ffb4 63ec4700 ISATQ!ATQ_BMON_SET::BmonThreadFunc+0x22
>>> 06 02b7ffb8 77e4a990 ISATQ!BmonThreadFunc+0x9
>>> 07 02b7ffc4 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 20
>>> System Thread ID: b24
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 02c3fe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 02c3fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 02c3ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 02c3ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 02c3ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 02c3ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 02c3ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 21
>>> System Thread ID: b30
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 02c7fe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 02c7fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 02c7ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 02c7ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 02c7ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 02c7ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 02c7ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 22
>>> System Thread ID: b34
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 02cbff10 77f43741 SharedUserData!SystemCallStub+0x4
>>> 01 02cbff14 77e41817 ntdll!ZwWaitForSingleObject+0xc
>>> 02 02cbff84 77e4168f kernel32!WaitForSingleObjectEx+0xac
>>> 03 02cbff94 02bbd064 kernel32!WaitForSingleObject+0xf
>>> 04 02cbffb8 77e4a990 aqueue!CSMTP_RETRY_HANDLER::RetryThreadRoutine+0xc1
>>> 05 02cbffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 23
>>> System Thread ID: b3c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Status: Thread is in a WAIT state.
>>> Thread Type: SMTP Service Worker Thread
>>> # ChildEBP RetAddr
>>> 00 02cffe84 77f4372d SharedUserData!SystemCallStub+0x4
>>> 01 02cffe88 77e41bfa ntdll!NtWaitForMultipleObjects+0xc
>>> 02 02cfff30 77e4b0e4 kernel32!WaitForMultipleObjectsEx+0x11a
>>> 03 02cfff48 02b9c648 kernel32!WaitForMultipleObjects+0x17
>>> 04 02cfffa4 6b77e7ce aqueue!CConnMgr::GetNextConnection+0x1e1
>>> 05 02cfffb8 77e4a990 SMTPSVC!PERSIST_QUEUE::QueueThreadRoutine+0x21
>>> 06 02cfffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 24
>>> System Thread ID: f54
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 00abff70 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 00abff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
>>> 02 00abffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
>>> 03 00abffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 25
>>> System Thread ID: 258
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.15
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 00ecfe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 00ecfe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 00ecff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 00ecff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 00ecffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 00ecffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 00ecffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 26
>>> System Thread ID: d7c
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.46
>>> Thread Type: Possible ASP page. Possible DCOM activity
>>> Executing Page: ASP.dll symbols not found. Unable to locate ASP page.
>>> Continuing with other analysis.
>>>
>>> No remote call being made
>>>
>>> # ChildEBP RetAddr
>>> 00 00e8fe20 77f4313f SharedUserData!SystemCallStub+0x4
>>> 01 00e8fe24 77c57b85 ntdll!NtReplyWaitReceivePortEx+0xc
>>> 02 00e8ff8c 77c60829 RPCRT4!LRPC_ADDRESS::ReceiveLotsaCalls+0x193
>>> 03 00e8ff90 77c60771 RPCRT4!RecvLotsaCallsWrapper+0x9
>>> 04 00e8ffb0 77c60857 RPCRT4!BaseCachedThreadRoutine+0x9c
>>> 05 00e8ffb8 77e4a990 RPCRT4!ThreadStartRoutine+0x17
>>> 06 00e8ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 27
>>> System Thread ID: ea8
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: HTTP Listener
>>> # ChildEBP RetAddr
>>> 00 00f6ff50 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 00f6ff54 77e430bc ntdll!ZwRemoveIoCompletion+0xc
>>> 02 00f6ff80 63ec7235 kernel32!GetQueuedCompletionStatus+0x27
>>> 03 00f6ffb8 77e4a990 ISATQ!AtqPoolThread+0x40
>>> 04 00f6ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 28
>>> System Thread ID: ee8
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 00faff7c 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 00faff80 71b246f7 ntdll!ZwRemoveIoCompletion+0xc
>>> 02 00faffb8 77e4a990 mswsock!SockAsyncThread+0x67
>>> 03 00faffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>>
>>>
>>>
>>> Thread ID: 29
>>> System Thread ID: 354
>>> Kernel Time: 0:0:0.0
>>> User Time: 0:0:0.0
>>> Thread Type: Other
>>> # ChildEBP RetAddr
>>> 00 00f0ff70 77f430c7 SharedUserData!SystemCallStub+0x4
>>> 01 00f0ff74 77f7e6ae ntdll!ZwRemoveIoCompletion+0xc
>>> 02 00f0ffb8 77e4a990 ntdll!RtlpWorkerThread+0x3b
>>> 03 00f0ffec 00000000 kernel32!BaseThreadStart+0x34
>>>
>>> *****
>>>
>>> Dump name is formatted as: PID-Timestamp.dmp
>>>
>>> Creating C:\iisstate\output\252-1102684642.dmp - mini user dump
>>>
>>> *****
>>>
>>> Closing open log file C:\iisstate\output\IISState-252.log
>>>
>>>
>>
>>
>
>
>