Questions

W3WP.EXE faulting NTDLL.DLL

+
0 Votes
Locked

W3WP.EXE faulting NTDLL.DLL

jordan
Every hour on a Windows server 2008 x64 we get a error with W3WP.EXE.

Faulting application w3wp.exe, version 7.0.6002.18005, time stamp 0x49e023cf, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03824, exception code 0xc0000374, fault offset 0x000ab0bf, process id 0x1880, application start time 0x01ca9a66195b85b9.

I did a dump and got this info. I really need some help here.


--------------------------------
Report for w3wp.DMP
Type of Analysis Performed Hang Analysis
Machine Name
Operating System Windows Vista Service Pack 2
Number Of Processors 8
Process ID 6444
Process Image C:\Windows\SysWOW64\inetsrv\w3wp.exe
System Up-Time 3 day(s) 16:21:04
Process Up-Time 00:04:05


Top 5 Threads by CPU time
Note - Times include both user mode and kernel mode for each thread Thread ID: 37 Total CPU Time: 00:00:21.309 Entry Point for Thread: ntdll!LdrInitializeThunk+e
Thread ID: 45 Total CPU Time: 00:00:20.138 Entry Point for Thread: ntdll!LdrInitializeThunk+e
Thread ID: 42 Total CPU Time: 00:00:19.078 Entry Point for Thread: ntdll!LdrInitializeThunk+e
Thread ID: 36 Total CPU Time: 00:00:17.222 Entry Point for Thread: ntdll!LdrInitializeThunk+e
Thread ID: 44 Total CPU Time: 00:00:14.757 Entry Point for Thread: ntdll!LdrInitializeThunk+e


Thread report

Thread 0 - System ID 6376
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.015
Time spent in kernel mode 0 Days 00:00:00.046


Function
wow64cpu!CpupSyscallStub+9
wow64cpu!Thunk0ArgReloadState+1a
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll!LdrpInitializeProcess+1568
ntdll! ?? ::FNODOBFM::`string'+20959
ntdll!LdrInitializeThunk+e


Back to Top


Thread 1 - System ID 5344
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.00
Time spent in kernel mode 0 Days 00:00:00.00


Function
wow64cpu!RemoveIoCompletionFault+41
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e


Back to Top


Thread 2 - System ID 6608
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.00
Time spent in kernel mode 0 Days 00:00:00.00


Function
wow64cpu!WaitForMultipleObjects32+3a
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e


Back to Top


Thread 3 - System ID 6736
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.00
Time spent in kernel mode 0 Days 00:00:00.00


Function
ntdll!NtWaitForWorkViaWorkerFactory+a
wow64!whNtWaitForWorkViaWorkerFactory+23
wow64!Wow64SystemServiceEx+ca
wow64cpu!ServiceNoTurbo+28
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e


Back to Top


Thread 4 - System ID 6624
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.078
Time spent in kernel mode 0 Days 00:00:00.00


Function
wow64cpu!RemoveIoCompletionFault+41
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e


Back to Top


Thread 5 - System ID 1996
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.639
Time spent in kernel mode 0 Days 00:00:00.015


Function
wow64cpu!RemoveIoCompletionFault+41
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e


Back to Top


Thread 6 - System ID 6164
Entry point ntdll!LdrInitializeThunk+e
Create time 1/28/2010 4:19:16 PM
Time spent in user mode 0 Days 00:00:00.577
Time spent in kernel mode 0 Days 00:00:00.015


Function
wow64cpu!RemoveIoCompletionFault+41
wow64!RunCpuSimulation+a
wow64!Wow64LdrpInitialize+4b4
ntdll! ?? ::FNODOBFM::`string'+20aa1
ntdll!LdrInitializeThunk+e