Hello,
Can anyone gleam any info from these windbg info on crash dumps

We have two specific crashes that are happening often. On the busier servers
they happen every minute

=================================================

Microsoft (R) Windows Debugger Version 6.2.0013.1

Copyright (c) Microsoft Corporation. All rights reserved.



Loading Dump File
[C:\IISDebugTools\logs\20030922-132444\Process_Shut_Down--5784_w3wp_gardeniu
m.com.tr.dmp]

User Mini Dump File with Full Memory: Only application data is available

Comment: 'Generated by IISDBG'

Windows Server 2003 Version 3790 UP Free x86 compatible

Product: Server, suite: TerminalServer

Debug session time: Mon Sep 22 13:32:09 2003

System Uptime: 3 days 3:34:08.676

Process Uptime: 0 days 0:16:11.000

Symbol search path is: C:\WINDOWS\Symbols

Executable search path is:

........................................................

eax=000000c0 ebx=00000100 ecx=00000000 edx=00000000 esi=000830a8
edi=00000000

eip=7ffe0304 esp=0333fe24 ebp=0333ff8c iopl=0 nv up ei pl zr na po nc

cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

SharedUserData!SystemCallStub+0x4:

7ffe0304 c3 ret

0:000> kb

ChildEBP RetAddr Args to Child

0333fe20 77f4313f 77c57b25 0000010c 0333ff7c
SharedUserData!SystemCallStub+0x4

*** ERROR: Symbol file could not be found. Defaulted to export symbols for
rpcrt4.dll -

0333fe24 77c57b25 0000010c 0333ff7c 00000000
ntdll!NtReplyWaitReceivePortEx+0xc

WARNING: Stack unwind information not available. Following frames may be
wrong.

0333ff8c 77c696a9 77c695f1 000830a8 00000000
rpcrt4!NdrServerInitializeNew+0x1d5

0333ffb0 77c696d7 0008a1e0 77e4a990 000be218
rpcrt4!I_RpcBindingIsClientLocal+0x799

0333ffec 00000000 77c696c0 000be218 00000000
rpcrt4!I_RpcBindingIsClientLocal+0x7c7

0:000> ~*kb

. 0 Id: 1698.1f6c Suspend: -1 Teb: 7ff9b000 Unfrozen

ChildEBP RetAddr Args to Child

0333fe20 77f4313f 77c57b25 0000010c 0333ff7c
SharedUserData!SystemCallStub+0x4

0333fe24 77c57b25 0000010c 0333ff7c 00000000
ntdll!NtReplyWaitReceivePortEx+0xc

WARNING: Stack unwind information not available. Following frames may be
wrong.

0333ff8c 77c696a9 77c695f1 000830a8 00000000
rpcrt4!NdrServerInitializeNew+0x1d5

0333ffb0 77c696d7 0008a1e0 77e4a990 000be218
rpcrt4!I_RpcBindingIsClientLocal+0x799

0333ffec 00000000 77c696c0 000be218 00000000
rpcrt4!I_RpcBindingIsClientLocal+0x7c7

============================================================================
======


The other common one is

Windows Server 2003 Version 3790 UP Free x86 compatible

Product: Server, suite: TerminalServer

Debug session time: Mon Sep 22 13:52:52 2003

System Uptime: 3 days 3:54:52.739

Process Uptime: 0 days 0:28:15.000

Symbol search path is: C:\WINDOWS\Symbols

Executable search path is:

............................................................................
..

eax=00000000 ebx=00000000 ecx=0006fda4 edx=00000000 esi=77f4360b
edi=fffffffe

eip=7ffe0304 esp=0006fdf0 ebp=0006fee0 iopl=0 nv up ei pl zr na po nc

cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

SharedUserData!SystemCallStub+0x4:

7ffe0304 c3 ret

0:000> kb

ChildEBP RetAddr Args to Child

0006fdec 77f43617 77e4f257 ffffffff fffffffe
SharedUserData!SystemCallStub+0x4

0006fdf0 77e4f257 ffffffff fffffffe 00000000 ntdll!NtTerminateProcess+0xc

0006fee0 77e4f1f6 fffffffe 77e8f3b0 ffffffff kernel32!_ExitProcess+0x57

0006fef4 7921d0ea fffffffe 0006ff18 792124fe kernel32!TerminateProcess

0006ff00 792124fe fffffffe 791bd8c8 79230a34 mscorwks!SafeExitProcess+0x38

0006ff18 791795b7 fffffffe 791b0000 0006ff60 mscorwks!IsComPlusWrapper+0x15

0006ff28 77bc8b3b fffffffe 77bc8c40 fffffffe mscoree!CorExitProcess+0x46

0006ff30 77bc8c40 fffffffe 00000000 fffffffe msvcrt!__crtExitProcess+0x25

0006ff60 77bc8c88 fffffffe 00000000 00000000 msvcrt!_cinit+0xce

0006ff70 01001973 fffffffe 00000000 00000000 msvcrt!exit+0xd

0006ffc0 77e4f38c 00000000 00000000 7ffdf000 w3wp!wmainCRTStartup+0x144

0006fff0 00000000 0100182f 00000000 78746341 kernel32!BaseProcessStart+0x23

0:000> ~*kb

. 0 Id: b50.19c0 Suspend: -1 Teb: 7ffde000 Unfrozen

ChildEBP RetAddr Args to Child

0006fdec 77f43617 77e4f257 ffffffff fffffffe
SharedUserData!SystemCallStub+0x4

0006fdf0 77e4f257 ffffffff fffffffe 00000000 ntdll!NtTerminateProcess+0xc

0006fee0 77e4f1f6 fffffffe 77e8f3b0 ffffffff kernel32!_ExitProcess+0x57

0006fef4 7921d0ea fffffffe 0006ff18 792124fe kernel32!TerminateProcess

0006ff00 792124fe fffffffe 791bd8c8 79230a34 mscorwks!SafeExitProcess+0x38

0006ff18 791795b7 fffffffe 791b0000 0006ff60 mscorwks!IsComPlusWrapper+0x15

0006ff28 77bc8b3b fffffffe 77bc8c40 fffffffe mscoree!CorExitProcess+0x46

0006ff30 77bc8c40 fffffffe 00000000 fffffffe msvcrt!__crtExitProcess+0x25

0006ff60 77bc8c88 fffffffe 00000000 00000000 msvcrt!_cinit+0xce

0006ff70 01001973 fffffffe 00000000 00000000 msvcrt!exit+0xd

0006ffc0 77e4f38c 00000000 00000000 7ffdf000 w3wp!wmainCRTStartup+0x144

0006fff0 00000000 0100182f 00000000 78746341 kernel32!BaseProcessStart+0x23

RE: process pools terminating by timcof

timcof
Tue Sep 30 02:53:51 CDT 2003

You will want to open a debug case with MS support, and they will want all of the files generated; mainly the .dmp files; you can load these in windbg (load
symbols) anf get more useful information.

Thank you. I hope this information is helpful.

Tim Coffey [MSFT]

This posting is provided ?AS IS? with no warranties, and confers no rights. You assume all risk for your use. © 2001 Microsoft Corporation. All rights reserved.
--------------------
| From: "Robbie Wallis" <robbie.wallis@virgin.net>
| Subject: process pools terminating
| Date: Wed, 24 Sep 2003 03:41:52 +0100
| Lines: 194
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
| Message-ID: <#7GXsVkgDHA.3204@TK2MSFTNGP11.phx.gbl>
| Newsgroups: microsoft.public.inetserver.iis
| NNTP-Posting-Host: wal18b2s.gotadsl.co.uk 62.3.237.110
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.inetserver.iis:276849
| X-Tomcat-NG: microsoft.public.inetserver.iis
|
| Hello,
| Can anyone gleam any info from these windbg info on crash dumps
|
| We have two specific crashes that are happening often. On the busier servers
| they happen every minute
|
| =================================================
|
| Microsoft (R) Windows Debugger Version 6.2.0013.1
|
| Copyright (c) Microsoft Corporation. All rights reserved.
|
|
|
| Loading Dump File
| [C:\IISDebugTools\logs\20030922-132444\Process_Shut_Down--5784_w3wp_gardeniu
| m.com.tr.dmp]
|
| User Mini Dump File with Full Memory: Only application data is available
|
| Comment: 'Generated by IISDBG'
|
| Windows Server 2003 Version 3790 UP Free x86 compatible
|
| Product: Server, suite: TerminalServer
|
| Debug session time: Mon Sep 22 13:32:09 2003
|
| System Uptime: 3 days 3:34:08.676
|
| Process Uptime: 0 days 0:16:11.000
|
| Symbol search path is: C:\WINDOWS\Symbols
|
| Executable search path is:
|
| ........................................................
|
| eax=000000c0 ebx=00000100 ecx=00000000 edx=00000000 esi=000830a8
| edi=00000000
|
| eip=7ffe0304 esp=0333fe24 ebp=0333ff8c iopl=0 nv up ei pl zr na po nc
|
| cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
| SharedUserData!SystemCallStub+0x4:
|
| 7ffe0304 c3 ret
|
| 0:000> kb
|
| ChildEBP RetAddr Args to Child
|
| 0333fe20 77f4313f 77c57b25 0000010c 0333ff7c
| SharedUserData!SystemCallStub+0x4
|
| *** ERROR: Symbol file could not be found. Defaulted to export symbols for
| rpcrt4.dll -
|
| 0333fe24 77c57b25 0000010c 0333ff7c 00000000
| ntdll!NtReplyWaitReceivePortEx+0xc
|
| WARNING: Stack unwind information not available. Following frames may be
| wrong.
|
| 0333ff8c 77c696a9 77c695f1 000830a8 00000000
| rpcrt4!NdrServerInitializeNew+0x1d5
|
| 0333ffb0 77c696d7 0008a1e0 77e4a990 000be218
| rpcrt4!I_RpcBindingIsClientLocal+0x799
|
| 0333ffec 00000000