#43410 [Opn]: SNMP cause "PHP has encountered an Access Violation" when wrong IP or CommStr
| From: | andy_wolk at mail dot ru | Date: | Wed, 20 Feb 2008 14:06:16 +0000 |
| Subject: | #43410 [Opn]: SNMP cause "PHP has encountered an Access Violation" when wrong IP or CommStr | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-122501@lists.php.net to get a copy of this message | ||
ID: 43410
User updated by: andy_wolk at mail dot ru
Reported By: andy_wolk at mail dot ru
Status: Open
Bug Type: SNMP related
Operating System: Windows 2003 Server Enterprise
PHP Version: 5.2.5
New Comment:
<link rel=STYLESHEET type=text/css href=res/default.css title=default>
<!-- Begin Analysis Summary Section -->
<table border=0 cellpadding=0 cellspacing=0 class=mycustomContainer>
<tr>
<td valign=top width=50% style=padding-left:5px; padding-right:5px;>
<table border=0 cellpadding=2 cellspacing=2 class=mycustomTable>
<tr class=mycustomHeader>
<td>
<table border=0 cellpadding=2 cellspacing=0 bgcolor=#818181>
<tr>
<td><img id=Icon_Results src=res/bulletpoint.gif></td>
</tr>
</table>
</td>
<td width=100% style=padding-left:5px;> Analysis Summary </td>
</tr>
<tr id=Table_Results>
<td width=15 class=mycustomText> </td>
<td class=row>
<table border=1 class=mycustomTable>
<tr class=mycustomText>
<th>Type</th>
<th>Description</th>
<th>Recommendation</th>
</tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/error.png width=16 height=16> Error</td><td
class=mycustomText>In
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
the assembly instruction at
<b>ntdll!ExpInterlockedPopEntrySListFault</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x20657355</b> on thread
<a
href='#4516:5910Thread3228'><b>10</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#4516:5910196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value:
<b>0x0</b></td><td class=mycustomText>An access violation exception
thrown by a heap memory manager function indicates <b>heap
corruption</b>. Please follow the steps outlined in the following
Knowledge Base article: <br> <a target='_blank'
href='http://support.microsoft.com/?id=300966'>
300966 Howto debug heap
corruption issues in Internet Information Services (IIS) </a></td></tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/error.png width=16 height=16> Error</td><td
class=mycustomText>In
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
the assembly instruction at <b>ntdll!RtlAllocateHeap+579</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x00000000</b> on thread
<a
href='#7844:31129Thread1536'><b>54</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#7844:31129196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value:
<b>0x0</b></td><td class=mycustomText>An access violation exception
thrown by a heap memory manager function indicates <b>heap
corruption</b>. Please follow the steps outlined in the following
Knowledge Base article: <br> <a target='_blank'
href='http://support.microsoft.com/?id=300966'>
300966 Howto debug heap
corruption issues in Internet Information Services (IIS) </a></td></tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/error.png width=16 height=16> Error</td><td
class=mycustomText>In
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
the assembly instruction at
<b>ntdll!ExpInterlockedPopEntrySListFault</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x64006f00</b> on thread
<a
href='#3460:3810Thread4592'><b>2</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#3460:3810196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value:
<b>0x0</b></td><td class=mycustomText>An access violation exception
thrown by a heap memory manager function indicates <b>heap
corruption</b>. Please follow the steps outlined in the following
Knowledge Base article: <br> <a target='_blank'
href='http://support.microsoft.com/?id=300966'>
300966 Howto debug heap
corruption issues in Internet Information Services (IIS) </a></td></tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/information.png width=16 height=16>
Information</td><td class=mycustomText>DebugDiag determined that this
dump file
(w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable <b>combined crash and hang analysis</b> for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the <b>g_DoCombinedAnalysis</b> constant to <font
color='Red'><b>True</b></font>.</td><td
class=mycustomText> </td></tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/information.png width=16 height=16>
Information</td><td class=mycustomText>DebugDiag determined that this
dump file
(w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable <b>combined crash and hang analysis</b> for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the <b>g_DoCombinedAnalysis</b> constant to <font
color='Red'><b>True</b></font>.</td><td
class=mycustomText> </td></tr>
<tr><td class=mycustomText align=center valign=middle nowrap><img
border=0 src=res/information.png width=16 height=16>
Information</td><td class=mycustomText>DebugDiag determined that this
dump file
(w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable <b>combined crash and hang analysis</b> for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the <b>g_DoCombinedAnalysis</b> constant to <font
color='Red'><b>True</b></font>.</td><td
class=mycustomText> </td></tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
<!-- End Analysis Summary Section -->
<br>
<!-- Begin Analysis Details Section -->
<table border=0 cellpadding=0 cellspacing=0 class=mycustomContainer>
<tr>
<td valign=top width=50% style=padding-left:5px; padding-right:5px;>
<table border=0 cellpadding=2 cellspacing=2 class=mycustomTable>
<tr class=mycustomHeader>
<td>
<table border=0 cellpadding=2 cellspacing=0 bgcolor=#818181>
<tr>
<td><img id=Icon_Data src=res/bulletpoint.gif></td>
</tr>
</table>
</td>
<td width=100% style=padding-left:5px;> Analysis Details </td>
</tr>
<tr id=Table_Data>
<td width=15 class=mycustomText> </td>
<td class=row>
<script for=window event=onload language='JavaScript'>
// initially collapse all 'ToggleStartCollapsed' sections
for(i=0; i < document.anchors.length; i++)
{
var elem = document.anchors[i];
if (elem.className.toUpperCase() == "TOGGLESTARTCOLLAPSED")
doToggle2(elem);
}
// invoke any additional togglers
var togglers = (new VBArray(g_Togglers.Items())).toArray();
for (i in togglers)
window.execScript(togglers[i] + '();', 'JScript');
</script>
<script language="JavaScript">
var g_Togglers = new ActiveXObject("Scripting.Dictionary");
function AddToggler(togglerFunctionName)
{
g_Togglers.Add(togglerFunctionName, togglerFunctionName);
}
function doToggle()
{
var srcElement = window.event.srcElement;
doToggle2(srcElement);
}
function doToggle2(srcElement)
{
var img, a, div, base
if(srcElement == null)
return;
if (srcElement.className.substr(0, 6).toUpperCase() == "TOGGLE")
{
try
{
base = srcElement.id.substr(0, srcElement.id.length - 1);
a = document.all(base + "t");
img = document.all(base + "i");
div = document.all(base + "s");
if (div != null)
{
if (div.style.display == "none")
{
div.style.display = "block";
if (img != null)
{
img.src = "res/up.png";
}
}
else
{
div.style.display = "none";
if (img != null)
{
img.src = "res/down.png";
}
}
}
}
catch(Ex){}
}
}
</script>
<b><a onclick='javascript:doToggle();return false;' id='ScriptOff-t'
class='ToggleStartCollapsed' style='cursor:hand; '>
</a></b><br><div
id='ScriptOff-s' style='DISPLAY: block'><br>
<table cellpadding=5 cellspacing=0 class=myCustomText><tr><td><img
src='res/information.png'></td><td><font color='red'>Your
browser
settings are currently prohibiting this report's scripts from
running.</font><br> This is preventing some features of this analysis
report from displaying properly. To enable scripts to run, right-click
the security warning above and choose "Allow Blocked Content..." or
enable the "Allow active content to run in files on My Computer*"
setting on the Advanced tab of your "Internet Options" dialog to avoid
being prompted in the future</td></tr></table><br><br></div>
<h4>Table Of Contents</h4><a
href='#Dump3460:3810-t'><b>w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp</b></a><br> <a
href='#3460:3810Thread4592'><b>Faulting
Thread</b></a><br> <a
href='#3460:3810Module'><b>Faulting Module
Information</b></a><br><br><a
href='#Dump7844:31129-t'><b>w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp</b></a><br> <a
href='#7844:31129Thread1536'><b>Faulting
Thread</b></a><br> <a
href='#7844:31129Module'><b>Faulting Module
Information</b></a><br><br><a
href='#Dump4516:5910-t'><b>w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp</b></a><br> <a
href='#4516:5910Thread3228'><b>Faulting
Thread</b></a><br> <a
href='#4516:5910Module'><b>Faulting Module
Information</b></a><br><br><b><a
onclick='javascript:doToggle();return
false;' id='Dump3460:3810-t' class='ToggleStartExpanded'
style='cursor:hand; '><IMG class='ToggleStartExpanded'
align='bottom'
src='res/up.png' id='Dump3460:3810-i'> Report for
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp</a></b><br><div
id='Dump3460:3810-s' style='DISPLAY: block'><br>
<h1>Report for
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp</h1>
<table cellpadding=0 cellspacing=0 border=0
class=myCustomText ID="Table1">
<tr><td>Type of Analysis
Performed</td><td> <b>Crash
Analysis</b></td></tr>
<tr><td>Machine
Name</td><td> <b>INETVPNSERVER</b></td></tr>
<tr><td>Operating
System</td><td> <b>Windows
Server 2003 Service Pack 2</b></td></tr>
<tr><td>Number Of
Processors</td><td> <b>8</b></td></tr>
<tr><td>Process
ID</td><td> <b>3460</b></td></tr>
<tr><td>Process
Image</td><td> <b>c:\WINDOWS\system32\inetsrv\w3wp.exe</b></td></tr>
<tr><td>System
Up-Time</td><td> <b>61 day(s)
11:20:36</b></td></tr>
<tr><td>Process
Up-Time</td><td> <b>01:03:30</b></td></tr>
</table>
<p class="myCustomText">
<h4><a name='3460:3810Thread4592'>Thread 2 - System ID
4592</a></h4>
<table border=0 cellpadding=0 cellspacing=0
class=myCustomText><tr><td>Entry
point</td><td> <b>ntdll!RtlpWorkerThread</b></td></tr><tr><td>Create
time</td><td> <b>20.02.2008
15:53:09</b></td></tr><tr><td>Time spent in user
mode</td><td> <b>0 Days
0:0:0.0</b></td></tr><tr><td>Time
spent in kernel mode</td><td> <b>0 Days
0:0:0.0</b></td></tr></table><br><br>
</p>
<table border=0 cellpadding=0 cellspacing=0 class=mycustomText>
<tr>
<th>Function</th>
<th> Arg 1</th>
<th> Arg 2</th>
<th> Arg 3</th>
<th> Source</th>
</tr>
<tr>
<td nowrap>ntdll!ExpInterlockedPopEntrySListFault</td>
<td nowrap> <font
face = "courier new">00030718</font></td>
<td nowrap> <font
face = "courier new">00d0fde4</font></td>
<td nowrap> <font
face = "courier new">7c82a0b8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpAllocateFromHeapLookaside+13</td>
<td nowrap> <font
face = "courier new">00030718</font></td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlAllocateHeap+1dd</td>
<td nowrap> <font
face = "courier new">00030000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>msvcrt!_heap_alloc+26</td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>msvcrt!operator new+24</td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td
nowrap>iisutil!IPM_MESSAGE_IMP::AllocateDataLength+12</td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">000391d8</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>iisutil!IPM_MESSAGE_PIPE::ReadMessage+9b</td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> <font
face = "courier new">64710045</font></td>
<td nowrap> </td>
</tr>
<tr>
<td
nowrap>iisutil!IPM_MESSAGE_PIPE::MessagePipeCompletion+31d</td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> <font
face = "courier new">000e1b00</font></td>
<td nowrap> <font
face = "courier new">000e1b90</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpWaitOrTimerCallout+74</td>
<td nowrap> <font
face = "courier new">64710045</font></td>
<td nowrap> <font
face = "courier new">000392b8</font></td>
<td nowrap> <font
face = "courier new">000e1b00</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpAsyncWaitCallbackCompletion+37</td>
<td nowrap> <font
face = "courier new">000e1b90</font></td>
<td nowrap> <font
face = "courier new">7c889080</font></td>
<td nowrap> <font
face = "courier new">00093d20</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpWorkerCallout+71</td>
<td nowrap> <font
face = "courier new">7c83ca2b</font></td>
<td nowrap> <font
face = "courier new">000e1b90</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpExecuteWorkerRequest+4f</td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">000e1b90</font></td>
<td nowrap> <font
face = "courier new">00093d20</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpApcCallout+11</td>
<td nowrap> <font
face = "courier new">7c83a9ca</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">000e1b90</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpWorkerThread+61</td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>kernel32!BaseThreadStart+34</td>
<td nowrap> <font
face = "courier new">7c839efb</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
</table>
<br><br>
NTDLL!EXPINTERLOCKEDPOPENTRYSLISTFAULT
<br><br>
<h4>Detailed Info For Corrupt Heap</h4>
<h4>
<a name='#3460:3810196608'>
Heap 3 - 0x00030000
</a>
</h4>
<table class=myCustomText ID="Table1">
<tr>
<td><b>Heap Name</b></td>
<td><b> msvcrt!_crtheap</b></td>
</tr>
<tr>
<td><b>Heap Description</b></td>
<td><b> This heap is used by msvcrt</b></td>
</tr>
<tr>
<td><b>Reserved memory</b></td>
<td><b> <font color=SaddleBrown>7,06
MBytes</font></b></td>
</tr>
<tr>
<td><b>Committed memory</b></td>
<td><b> <font color=SaddleBrown>4,75 MBytes</font>
(67,26% of reserved)
</b></td>
</tr>
<tr>
<td><b>Uncommitted memory</b></td>
<td><b> <font color=SaddleBrown>2,31 MBytes</font>
(32,74% of reserved)
</b></td>
</tr>
<tr>
<td><b>Number of heap segments</b></td>
<td><b> 4 segments</b></td>
</tr>
<tr>
<td>Number of uncommitted ranges</td>
<td> 1 range(s)</td>
</tr>
<tr>
<td>Size of largest uncommitted range</td>
<td> <font color=SaddleBrown>2,31 MBytes</font></td>
</tr>
<tr>
<td>Calculated heap fragmentation</td>
<td> 0,00%</td>
</tr>
</table>
<br><br>
<h5>Segment Information</h5>
<table class=myCustomText cellspacing=3 ID="Table2">
<tr>
<th>Base Address</th>
<th>Reserved Size</th>
<th>Committed Size</th>
<th>Uncommitted Size</th>
<th>Number of uncommitted ranges</th>
<th>Largest uncommitted block</th>
<th>Calculated heap fragmentation</th>
</tr>
<tr>
<td>0x00030640</td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x01c80000</td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x02c00000</td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x03510000</td>
<td><font color=SaddleBrown>4,00 MBytes</font></td>
<td><font color=SaddleBrown>1,69 MBytes</font></td>
<td><font color=SaddleBrown>2,31 MBytes</font></td>
<td>1</td>
<td><font color=SaddleBrown>2,31 MBytes</font></td>
<td>0,00%</td>
</tr>
</table>
<br><br>
<h5>Top 5 allocations by size</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 584</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 56</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 308</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=15> </td>
<td colspan=85> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=11> </td>
<td colspan=89> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=8> </td>
<td colspan=92> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=6> </td>
<td colspan=94> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>1,61 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>253,09 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>187,06 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>125,89 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>99,56 KBytes</font></td></tr>
</table></td></tr></table>
<h5>Top 5 allocations by count</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 56</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 12</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 47</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=67> </td>
<td colspan=33> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=19> </td>
<td colspan=81> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=15> </td>
<td colspan=85> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=15> </td>
<td colspan=85> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
12064 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
8099 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
2302 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
1757 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
1756 allocation(s)</td></tr>
</table></td></tr></table>
<a href='#'>Back to Top</a>
<br><br><br><br>
In
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
the assembly instruction at
<b>ntdll!ExpInterlockedPopEntrySListFault</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x64006f00</b> on thread
<a
href='#3460:3810Thread4592'><b>2</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#3460:3810196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value: <b>0x0</b>
<table cellpadding=0 cellspacing=0 border=0 class='myCustomText'
ID="Table2">
<tr>
<td><h2><a name='3460:3810Module'>Module
Information</a></h2></td>
</tr>
<TR>
<TD><b>Image Name:</b></TD>
<td>C:\WINDOWS\system32\ntdll.dll</td>
<TD> <b>Symbol Type:</b> </TD>
<td>PDB</td>
</TR>
<TR>
<TD><b>Base address:</b></TD>
<td>0x7c800000</td>
<TD> <b>Time Stamp:</b> </TD>
<td>Sat Feb 17 17:02:00 2007
</td>
</TR>
<TR>
<TD><b>Checksum:</b></TD>
<td>0x000bd6f9</td>
<TD> <b>Comments:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>COM DLL:</b></TD>
<td>False</td>
<TD> <b>Company Name:</b> </TD>
<td>Microsoft Corporation</td>
</TR>
<TR>
<TD><b>ISAPIExtension:</b></TD>
<td>False</td>
<TD> <b>File Description:</b> </TD>
<td>NT Layer DLL</td>
</TR>
<TR>
<TD><b>ISAPIFilter:</b></TD>
<td>False</td>
<TD> <b>File Version:</b> </TD>
<td>5.2.3790.3959 (srv03_sp2_rtm.070216-1710)</td>
</TR>
<TR>
<TD><b>Managed DLL:</b></TD>
<td>False</td>
<TD> <b>Internal Name:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>VB DLL:</b></TD>
<td>False</td>
<TD> <b>Legal Copyright:</b> </TD>
<td>é Microsoft Corporation. All rights reserved.</td>
</TR>
<TR>
<TD><b>Loaded Image Name:</b> </TD>
<td>ntdll.dll</td>
<TD> <b>Legal Trademarks:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Mapped Image Name:</b> </TD>
<td></td>
<TD> <b>Original filename:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>Module name:</b> </TD>
<td>ntdll</td>
<TD> <b>Private Build:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Single Threaded:</b> </TD>
<td>False</td>
<TD> <b>Product Name:</b> </TD>
<td>Microsoftî Windowsî Operating System</td>
</TR>
<TR>
<TD><b>Module Size:</b> </TD>
<td><font color=DarkGreen>768,00 KBytes</font></td>
<TD> <b>Product Version:</b> </TD>
<td>5.2.3790.3959</td>
</TR>
<TR>
<TD><b>Symbol File Name:</b> </TD>
<td>c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb</td>
<TD> <b>Special Build:</b> </TD>
<td>&</td>
</TR>
</table>
<br><br>
</div>
<b><a onclick='javascript:doToggle();return false;'
id='Dump7844:31129-t' class='ToggleStartExpanded' style='cursor:hand;
'><IMG class='ToggleStartExpanded' align='bottom'
src='res/up.png'
id='Dump7844:31129-i'> Report for
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp</a></b><br><div
id='Dump7844:31129-s' style='DISPLAY: block'><br>
<h1>Report for
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp</h1>
<table cellpadding=0 cellspacing=0 border=0
class=myCustomText ID="Table1">
<tr><td>Type of Analysis
Performed</td><td> <b>Crash
Analysis</b></td></tr>
<tr><td>Machine
Name</td><td> <b>INETVPNSERVER</b></td></tr>
<tr><td>Operating
System</td><td> <b>Windows
Server 2003 Service Pack 2</b></td></tr>
<tr><td>Number Of
Processors</td><td> <b>8</b></td></tr>
<tr><td>Process
ID</td><td> <b>7844</b></td></tr>
<tr><td>Process
Image</td><td> <b>c:\WINDOWS\system32\inetsrv\w3wp.exe</b></td></tr>
<tr><td>System
Up-Time</td><td> <b>59 day(s)
14:12:49</b></td></tr>
<tr><td>Process
Up-Time</td><td> <b>08:38:49</b></td></tr>
</table>
<p class="myCustomText">
<h4><a name='7844:31129Thread1536'>Thread 54 - System ID
1536</a></h4>
<table border=0 cellpadding=0 cellspacing=0
class=myCustomText><tr><td>Entry
point</td><td> <b>w3tp!THREAD_MANAGER::ThreadManagerThread</b></td></tr><tr><td>Create
time</td><td> <b>18.02.2008
19:37:07</b></td></tr><tr><td>Time spent in user
mode</td><td> <b>0 Days
0:0:0.0</b></td></tr><tr><td>Time
spent in kernel mode</td><td> <b>0 Days
0:0:2.515</b></td></tr></table><br><br>
</p>
<table border=0 cellpadding=0 cellspacing=0 class=mycustomText>
<tr>
<th>Function</th>
<th> Arg 1</th>
<th> Arg 2</th>
<th> Arg 3</th>
<th> Source</th>
</tr>
<tr>
<td nowrap>ntdll!RtlAllocateHeap+579</td>
<td nowrap> <font
face = "courier new">00030000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000084</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>msvcrt!malloc+6c</td>
<td nowrap> <font
face = "courier new">00000084</font></td>
<td nowrap> <font
face = "courier new">00000010</font></td>
<td nowrap> <font
face = "courier new">083bf910</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>php5ts!ts_resource_ex+103</td>
<td nowrap> <font
face = "courier new">056359ec</font></td>
<td nowrap> <font
face = "courier new">00000600</font></td>
<td nowrap> <font
face = "courier new">1093f9c8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>php5ts!ts_resource_ex+c4</td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000600</font></td>
<td nowrap> <font
face = "courier new">083bf910</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>php5isapi!HttpFilterProc+b</td>
<td nowrap> <font
face = "courier new">1093fa1c</font></td>
<td nowrap> <font
face = "courier new">00004000</font></td>
<td nowrap> <font
face = "courier new">083bf910</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>w3core!W3_MAIN_CONTEXT::NotifyFilters+e0</td>
<td nowrap> <font
face = "courier new">a1000001</font></td>
<td nowrap> <font
face = "courier new">5a3de000</font></td>
<td nowrap> <font
face = "courier new">145d8b53</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x28ec81ec</td>
<td nowrap> <font
face = "courier new">8bfc4589</font></td>
<td nowrap> <font
face = "courier new">8b571045</font></td>
<td nowrap> <font
face = "courier new">8589087d</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x0c758b56</td>
<td nowrap> <font
face = "courier new">8b571045</font></td>
<td nowrap> <font
face = "courier new">8589087d</font></td>
<td nowrap> <font
face = "courier new">fffffed8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x80000000`00000000</td>
<td nowrap> <font
face = "courier new">8589087d</font></td>
<td nowrap> <font
face = "courier new">fffffed8</font></td>
<td nowrap> <font
face = "courier new">00008068</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x80000000`00000000</td>
<td nowrap> <font
face = "courier new">fffffed8</font></td>
<td nowrap> <font
face = "courier new">00008068</font></td>
<td nowrap> <font
face = "courier new">3c858d00</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x80000000`00000000</td>
<td nowrap> <font
face = "courier new">00008068</font></td>
<td nowrap> <font
face = "courier new">3c858d00</font></td>
<td nowrap> <font
face = "courier new">50ffffff</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>0x80000000`00000000</td>
<td nowrap> <font
face = "courier new">3c858d00</font></td>
<td nowrap> <font
face = "courier new">50ffffff</font></td>
<td nowrap> <font
face = "courier new">ff0c8d8d</font></td>
<td nowrap> </td>
</tr>
</table>
<br><br>
NTDLL!RTLALLOCATEHEAP+579
<br><br>
<h4>Detailed Info For Corrupt Heap</h4>
<h4>
<a name='#7844:31129196608'>
Heap 3 - 0x00030000
</a>
</h4>
<table class=myCustomText ID="Table1">
<tr>
<td><b>Heap Name</b></td>
<td><b> msvcrt!_crtheap</b></td>
</tr>
<tr>
<td><b>Heap Description</b></td>
<td><b> This heap is used by msvcrt</b></td>
</tr>
<tr>
<td><b>Reserved memory</b></td>
<td><b> <font color=SaddleBrown>63,06
MBytes</font></b></td>
</tr>
<tr>
<td><b>Committed memory</b></td>
<td><b> <font color=SaddleBrown>39,68 MBytes</font>
(62,92% of reserved)
</b></td>
</tr>
<tr>
<td><b>Uncommitted memory</b></td>
<td><b> <font color=SaddleBrown>23,39 MBytes</font>
(37,08% of reserved)
</b></td>
</tr>
<tr>
<td><b>Number of heap segments</b></td>
<td><b> 7 segments</b></td>
</tr>
<tr>
<td>Number of uncommitted ranges</td>
<td> 1 range(s)</td>
</tr>
<tr>
<td>Size of largest uncommitted range</td>
<td> <font color=SaddleBrown>23,39 MBytes</font></td>
</tr>
<tr>
<td>Calculated heap fragmentation</td>
<td> 0,00%</td>
</tr>
</table>
<br><br>
<h5>Segment Information</h5>
<table class=myCustomText cellspacing=3 ID="Table2">
<tr>
<th>Base Address</th>
<th>Reserved Size</th>
<th>Committed Size</th>
<th>Uncommitted Size</th>
<th>Number of uncommitted ranges</th>
<th>Largest uncommitted block</th>
<th>Calculated heap fragmentation</th>
</tr>
<tr>
<td>0x00030640</td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x01c80000</td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x02c00000</td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x03640000</td>
<td><font color=SaddleBrown>4,00 MBytes</font></td>
<td><font color=SaddleBrown>4,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x055a0000</td>
<td><font color=SaddleBrown>8,00 MBytes</font></td>
<td><font color=SaddleBrown>8,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x08680000</td>
<td><font color=SaddleBrown>16,00 MBytes</font></td>
<td><font color=SaddleBrown>16,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x0d430000</td>
<td><font color=SaddleBrown>32,00 MBytes</font></td>
<td><font color=SaddleBrown>8,61 MBytes</font></td>
<td><font color=SaddleBrown>23,39 MBytes</font></td>
<td>1</td>
<td><font color=SaddleBrown>23,39 MBytes</font></td>
<td>0,00%</td>
</tr>
</table>
<br><br>
<h5>Top 5 allocations by size</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 584</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 308</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 56</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=57> </td>
<td colspan=43> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=51> </td>
<td colspan=49> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=8> </td>
<td colspan=92> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=4> </td>
<td colspan=96> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>13,24 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>7,60 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>6,74 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>1,08 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>568,42 KBytes</font></td></tr>
</table></td></tr></table>
<h5>Top 5 allocations by count</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 12</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 308</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 584</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=70> </td>
<td colspan=30> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=53> </td>
<td colspan=47> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=51> </td>
<td colspan=49> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=47> </td>
<td colspan=53> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
50503 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
35387 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
26779 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
25874 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
23765 allocation(s)</td></tr>
</table></td></tr></table>
<a href='#'>Back to Top</a>
<br><br><br><br>
In
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
the assembly instruction at <b>ntdll!RtlAllocateHeap+579</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x00000000</b> on thread
<a
href='#7844:31129Thread1536'><b>54</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#7844:31129196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value: <b>0x0</b>
<table cellpadding=0 cellspacing=0 border=0 class='myCustomText'
ID="Table2">
<tr>
<td><h2><a name='7844:31129Module'>Module
Information</a></h2></td>
</tr>
<TR>
<TD><b>Image Name:</b></TD>
<td>C:\WINDOWS\system32\ntdll.dll</td>
<TD> <b>Symbol Type:</b> </TD>
<td>PDB</td>
</TR>
<TR>
<TD><b>Base address:</b></TD>
<td>0x7c800000</td>
<TD> <b>Time Stamp:</b> </TD>
<td>Sat Feb 17 17:02:00 2007
</td>
</TR>
<TR>
<TD><b>Checksum:</b></TD>
<td>0x000bd6f9</td>
<TD> <b>Comments:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>COM DLL:</b></TD>
<td>False</td>
<TD> <b>Company Name:</b> </TD>
<td>Microsoft Corporation</td>
</TR>
<TR>
<TD><b>ISAPIExtension:</b></TD>
<td>False</td>
<TD> <b>File Description:</b> </TD>
<td>NT Layer DLL</td>
</TR>
<TR>
<TD><b>ISAPIFilter:</b></TD>
<td>False</td>
<TD> <b>File Version:</b> </TD>
<td>5.2.3790.3959 (srv03_sp2_rtm.070216-1710)</td>
</TR>
<TR>
<TD><b>Managed DLL:</b></TD>
<td>False</td>
<TD> <b>Internal Name:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>VB DLL:</b></TD>
<td>False</td>
<TD> <b>Legal Copyright:</b> </TD>
<td>é Microsoft Corporation. All rights reserved.</td>
</TR>
<TR>
<TD><b>Loaded Image Name:</b> </TD>
<td>ntdll.dll</td>
<TD> <b>Legal Trademarks:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Mapped Image Name:</b> </TD>
<td></td>
<TD> <b>Original filename:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>Module name:</b> </TD>
<td>ntdll</td>
<TD> <b>Private Build:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Single Threaded:</b> </TD>
<td>False</td>
<TD> <b>Product Name:</b> </TD>
<td>Microsoftî Windowsî Operating System</td>
</TR>
<TR>
<TD><b>Module Size:</b> </TD>
<td><font color=DarkGreen>768,00 KBytes</font></td>
<TD> <b>Product Version:</b> </TD>
<td>5.2.3790.3959</td>
</TR>
<TR>
<TD><b>Symbol File Name:</b> </TD>
<td>c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb</td>
<TD> <b>Special Build:</b> </TD>
<td>&</td>
</TR>
</table>
<br><br>
</div>
<b><a onclick='javascript:doToggle();return false;'
id='Dump4516:5910-t' class='ToggleStartExpanded' style='cursor:hand;
'><IMG class='ToggleStartExpanded' align='bottom'
src='res/up.png'
id='Dump4516:5910-i'> Report for
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp</a></b><br><div
id='Dump4516:5910-s' style='DISPLAY: block'><br>
<h1>Report for
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp</h1>
<table cellpadding=0 cellspacing=0 border=0
class=myCustomText ID="Table1">
<tr><td>Type of Analysis
Performed</td><td> <b>Crash
Analysis</b></td></tr>
<tr><td>Machine
Name</td><td> <b>INETVPNSERVER</b></td></tr>
<tr><td>Operating
System</td><td> <b>Windows
Server 2003 Service Pack 2</b></td></tr>
<tr><td>Number Of
Processors</td><td> <b>8</b></td></tr>
<tr><td>Process
ID</td><td> <b>4516</b></td></tr>
<tr><td>Process
Image</td><td> <b>c:\WINDOWS\system32\inetsrv\w3wp.exe</b></td></tr>
<tr><td>System
Up-Time</td><td> <b>59 day(s)
15:52:24</b></td></tr>
<tr><td>Process
Up-Time</td><td> <b>01:38:30</b></td></tr>
</table>
<p class="myCustomText">
<h4><a name='4516:5910Thread3228'>Thread 10 - System ID
3228</a></h4>
<table border=0 cellpadding=0 cellspacing=0
class=myCustomText><tr><td>Entry
point</td><td> <b>w3tp!THREAD_MANAGER::ThreadManagerThread</b></td></tr><tr><td>Create
time</td><td> <b>18.02.2008
19:49:57</b></td></tr><tr><td>Time spent in user
mode</td><td> <b>0 Days
0:0:0.281</b></td></tr><tr><td>Time
spent in kernel mode</td><td> <b>0 Days
0:0:0.171</b></td></tr></table><br><br>
</p>
<table border=0 cellpadding=0 cellspacing=0 class=mycustomText>
<tr>
<th>Function</th>
<th> Arg 1</th>
<th> Arg 2</th>
<th> Arg 3</th>
<th> Source</th>
</tr>
<tr>
<td nowrap>ntdll!ExpInterlockedPopEntrySListFault</td>
<td nowrap> <font
face = "courier new">00030838</font></td>
<td nowrap> <font
face = "courier new">0124fed0</font></td>
<td nowrap> <font
face = "courier new">7c82a0b8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlpAllocateFromHeapLookaside+13</td>
<td nowrap> <font
face = "courier new">00030838</font></td>
<td nowrap> <font
face = "courier new">0000003c</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>ntdll!RtlAllocateHeap+1dd</td>
<td nowrap> <font
face = "courier new">00030000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">0000003c</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>msvcrt!_heap_alloc+26</td>
<td nowrap> <font
face = "courier new">0000003c</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>msvcrt!operator new+24</td>
<td nowrap> <font
face = "courier new">0000003c</font></td>
<td nowrap> <font
face = "courier new">5a361d28</font></td>
<td nowrap> <font
face = "courier new">00000008</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>iisutil!IPM_MESSAGE_IMP::CreateMessage+1c</td>
<td nowrap> <font
face = "courier new">0124ff34</font></td>
<td nowrap> <font
face = "courier new">00039238</font></td>
<td nowrap> <font
face = "courier new">5a361d28</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>iisutil!IPM_MESSAGE_PIPE::WriteMessage+5e</td>
<td nowrap> <font
face = "courier new">00000002</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>w3dt!WP_IPM::HandlePing+59</td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00038bb8</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>w3tp!THREAD_POOL_DATA::ThreadPoolThread+73</td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00038b78</font></td>
<td nowrap> <font
face = "courier new">5a300000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>w3tp!THREAD_POOL_DATA::ThreadPoolThread+24</td>
<td nowrap> <font
face = "courier new">00000102</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td
nowrap>w3tp!THREAD_MANAGER::ThreadManagerThread+39</td>
<td nowrap> <font
face = "courier new">00038b78</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
<tr>
<td nowrap>kernel32!BaseThreadStart+34</td>
<td nowrap> <font
face = "courier new">5a301d70</font></td>
<td nowrap> <font
face = "courier new">00038b78</font></td>
<td nowrap> <font
face = "courier new">00000000</font></td>
<td nowrap> </td>
</tr>
</table>
<br><br>
NTDLL!EXPINTERLOCKEDPOPENTRYSLISTFAULT
<br><br>
<h4>Detailed Info For Corrupt Heap</h4>
<h4>
<a name='#4516:5910196608'>
Heap 3 - 0x00030000
</a>
</h4>
<table class=myCustomText ID="Table1">
<tr>
<td><b>Heap Name</b></td>
<td><b> msvcrt!_crtheap</b></td>
</tr>
<tr>
<td><b>Heap Description</b></td>
<td><b> This heap is used by msvcrt</b></td>
</tr>
<tr>
<td><b>Reserved memory</b></td>
<td><b> <font color=SaddleBrown>7,06
MBytes</font></b></td>
</tr>
<tr>
<td><b>Committed memory</b></td>
<td><b> <font color=SaddleBrown>3,89 MBytes</font>
(55,14% of reserved)
</b></td>
</tr>
<tr>
<td><b>Uncommitted memory</b></td>
<td><b> <font color=SaddleBrown>3,17 MBytes</font>
(44,86% of reserved)
</b></td>
</tr>
<tr>
<td><b>Number of heap segments</b></td>
<td><b> 4 segments</b></td>
</tr>
<tr>
<td>Number of uncommitted ranges</td>
<td> 1 range(s)</td>
</tr>
<tr>
<td>Size of largest uncommitted range</td>
<td> <font color=SaddleBrown>3,17 MBytes</font></td>
</tr>
<tr>
<td>Calculated heap fragmentation</td>
<td> 0,00%</td>
</tr>
</table>
<br><br>
<h5>Segment Information</h5>
<table class=myCustomText cellspacing=3 ID="Table2">
<tr>
<th>Base Address</th>
<th>Reserved Size</th>
<th>Committed Size</th>
<th>Uncommitted Size</th>
<th>Number of uncommitted ranges</th>
<th>Largest uncommitted block</th>
<th>Calculated heap fragmentation</th>
</tr>
<tr>
<td>0x00030640</td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td><font color=DarkGreen>64,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x01c80000</td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td><font color=DarkGreen>1à024,00 KBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x02c00000</td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td><font color=SaddleBrown>2,00 MBytes</font></td>
<td>0 Bytes</td>
<td>0</td>
<td>0 Bytes</td>
<td>0,00%</td>
</tr>
<tr>
<td>0x03920000</td>
<td><font color=SaddleBrown>4,00 MBytes</font></td>
<td><font color=DarkGreen>852,00 KBytes</font></td>
<td><font color=SaddleBrown>3,17 MBytes</font></td>
<td>1</td>
<td><font color=SaddleBrown>3,17 MBytes</font></td>
<td>0,00%</td>
</tr>
</table>
<br><br>
<h5>Top 5 allocations by size</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 56</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 584</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 8192</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=15> </td>
<td colspan=85> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=7> </td>
<td colspan=93> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=7> </td>
<td colspan=93> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=6> </td>
<td colspan=94> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
<font color=SaddleBrown>1,32 MBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>205,84 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>101,12 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>97,52 KBytes</font></td></tr>
<tr class=mycustomText><td nowrap>
<font color=DarkGreen>80,00 KBytes</font></td></tr>
</table></td></tr></table>
<h5>Top 5 allocations by count</h5><br><table
border=0><tr><td><table
border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
Allocation Size - 140</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 32</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 56</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 12</td></tr>
<tr class=mycustomText><td nowrap>
Allocation Size - 47</td></tr>
</table></td><td>
<table width=800 border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td bgcolor=#ccccc colspan=100> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ccccff colspan=67> </td>
<td colspan=33> </td>
</tr>
<tr class=mycustomText><td bgcolor=#ffcc00 colspan=19> </td>
<td colspan=81> </td>
</tr>
<tr class=mycustomText><td bgcolor=#cccc00 colspan=15> </td>
<td colspan=85> </td>
</tr>
<tr class=mycustomText><td bgcolor=#33ccff colspan=15> </td>
<td colspan=85> </td>
</tr>
</table></td>
<td><table border=0 cellpadding=0 cellspacing=5>
<tr class=mycustomText><td nowrap>
9895 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
6587 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
1849 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
1498 allocation(s)</td></tr>
<tr class=mycustomText><td nowrap>
1462 allocation(s)</td></tr>
</table></td></tr></table>
<a href='#'>Back to Top</a>
<br><br><br><br>
In
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
the assembly instruction at
<b>ntdll!ExpInterlockedPopEntrySListFault</b> in
<b>C:\WINDOWS\system32\ntdll.dll</b> from <b>Microsoft Corporation</b>
has caused an <b>access violation exception (0xC0000005)</b> when trying
to <b>read from</b></b> memory location <b>0x20657355</b> on thread
<a
href='#4516:5910Thread3228'><b>10</b></a><br><br>Heap
corruption was
detected in heap <b><a href =
'#4516:5910196608'>0x00030000</a></b>,
however pageheap was <b>not</b> enabled in this dump. Please follow the
instructions in the recommendation section for troubleshooting heap
corruption issues.<br><br>Current NTGlobalFlags value: <b>0x0</b>
<table cellpadding=0 cellspacing=0 border=0 class='myCustomText'
ID="Table2">
<tr>
<td><h2><a name='4516:5910Module'>Module
Information</a></h2></td>
</tr>
<TR>
<TD><b>Image Name:</b></TD>
<td>C:\WINDOWS\system32\ntdll.dll</td>
<TD> <b>Symbol Type:</b> </TD>
<td>PDB</td>
</TR>
<TR>
<TD><b>Base address:</b></TD>
<td>0x7c800000</td>
<TD> <b>Time Stamp:</b> </TD>
<td>Sat Feb 17 17:02:00 2007
</td>
</TR>
<TR>
<TD><b>Checksum:</b></TD>
<td>0x000bd6f9</td>
<TD> <b>Comments:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>COM DLL:</b></TD>
<td>False</td>
<TD> <b>Company Name:</b> </TD>
<td>Microsoft Corporation</td>
</TR>
<TR>
<TD><b>ISAPIExtension:</b></TD>
<td>False</td>
<TD> <b>File Description:</b> </TD>
<td>NT Layer DLL</td>
</TR>
<TR>
<TD><b>ISAPIFilter:</b></TD>
<td>False</td>
<TD> <b>File Version:</b> </TD>
<td>5.2.3790.3959 (srv03_sp2_rtm.070216-1710)</td>
</TR>
<TR>
<TD><b>Managed DLL:</b></TD>
<td>False</td>
<TD> <b>Internal Name:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>VB DLL:</b></TD>
<td>False</td>
<TD> <b>Legal Copyright:</b> </TD>
<td>é Microsoft Corporation. All rights reserved.</td>
</TR>
<TR>
<TD><b>Loaded Image Name:</b> </TD>
<td>ntdll.dll</td>
<TD> <b>Legal Trademarks:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Mapped Image Name:</b> </TD>
<td></td>
<TD> <b>Original filename:</b> </TD>
<td>ntdll.dll</td>
</TR>
<TR>
<TD><b>Module name:</b> </TD>
<td>ntdll</td>
<TD> <b>Private Build:</b> </TD>
<td></td>
</TR>
<TR>
<TD><b>Single Threaded:</b> </TD>
<td>False</td>
<TD> <b>Product Name:</b> </TD>
<td>Microsoftî Windowsî Operating System</td>
</TR>
<TR>
<TD><b>Module Size:</b> </TD>
<td><font color=DarkGreen>768,00 KBytes</font></td>
<TD> <b>Product Version:</b> </TD>
<td>5.2.3790.3959</td>
</TR>
<TR>
<TD><b>Symbol File Name:</b> </TD>
<td>c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb</td>
<TD> <b>Special Build:</b> </TD>
<td>&</td>
</TR>
</table>
<br><br>
</div>
<script language='JavaScript'>
AddToggler('doToggleCrashHangAnalysis');
function doToggleCrashHangAnalysis()
{
}
</script>
</td>
</tr>
</table>
</td>
</tr>
</table>
<!-- End Analysis Details Section -->
<br>
<!-- Begin Script Summary Section -->
<table border=0 cellpadding=0 cellspacing=0 class=mycustomContainer>
<tr>
<td valign=top width=50% style=padding-left:5px; padding-right:5px;>
<table border=0 cellpadding=2 cellspacing=2 class=mycustomTable>
<tr class=mycustomHeader>
<td>
<table border=0 cellpadding=2 cellspacing=0 bgcolor=#818181>
<tr><td><img id=Icon_Summary src=res/bulletpoint.gif></td></tr>
</table>
</td>
<td width=100% style=padding-left:5px;> Script Summary </td>
</tr>
<tr id=Table_Summary>
<td width=15 class=mycustomText> </td>
<td class=row>
<table border=1 class=mycustomTable cellpadding=1 cellspacing=1>
<tr class=mycustomText align=left>
<th>Script Name</th>
<th>Status</th>
<th>Error Code</th>
<th>Error Source</th>
<th>Error Description</th>
<th>Source Line</th>
</tr><tr align=left><td
class=mycustomText>CrashHangAnalysis.asp</td><td
class=mycustomText>Completed</td><td class=mycustomText
colspan='4'> </td></tr>
</table>
</td>
</tr>
</td>
</tr>
</table>
<!-- End Script Summary Section -->
Previous Comments:
------------------------------------------------------------------------
[2008-02-20 14:04:36] andy_wolk at mail dot ru
Analysis Summary
Type Description Recommendation
Error In
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!ExpInterlockedPopEntrySListFault in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x20657355 on thread 10
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 An access violation exception thrown
by a heap memory manager function indicates heap corruption. Please
follow the steps outlined in the following Knowledge Base article:
300966 Howto debug heap corruption issues in Internet Information
Services (IIS)
Error In
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!RtlAllocateHeap+579 in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x00000000 on thread 54
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 An access violation exception thrown
by a heap memory manager function indicates heap corruption. Please
follow the steps outlined in the following Knowledge Base article:
300966 Howto debug heap corruption issues in Internet Information
Services (IIS)
Error In
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!ExpInterlockedPopEntrySListFault in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x64006f00 on thread 2
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 An access violation exception thrown
by a heap memory manager function indicates heap corruption. Please
follow the steps outlined in the following Knowledge Base article:
300966 Howto debug heap corruption issues in Internet Information
Services (IIS)
Information DebugDiag determined that this dump file
(w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable combined crash and hang analysis for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the g_DoCombinedAnalysis constant to True.
Information DebugDiag determined that this dump file
(w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable combined crash and hang analysis for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the g_DoCombinedAnalysis constant to True.
Information DebugDiag determined that this dump file
(w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp)
is a crash dump and did not perform any hang analysis. If you wish to
enable combined crash and hang analysis for crash dumps, edit the
CrashHangAnalysis.asp script (located in the DebugDiag\Scripts folder)
and set the g_DoCombinedAnalysis constant to True.
Analysis Details
Your browser settings are currently prohibiting this report's scripts
from running.
This is preventing some features of this analysis report from
displaying properly. To enable scripts to run, right-click the security
warning above and choose "Allow Blocked Content..." or enable the "Allow
active content to run in files on My Computer*" setting on the Advanced
tab of your "Internet Options" dialog to avoid being prompted in the
future
Table Of Contents
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
Faulting Thread
Faulting Module Information
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
Faulting Thread
Faulting Module Information
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
Faulting Thread
Faulting Module Information
Report for
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
Report for
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
Type of Analysis Performed Crash Analysis
Machine Name INETVPNSERVER
Operating System Windows Server 2003 Service Pack 2
Number Of Processors 8
Process ID 3460
Process Image c:\WINDOWS\system32\inetsrv\w3wp.exe
System Up-Time 61 day(s) 11:20:36
Process Up-Time 01:03:30
Thread 2 - System ID 4592
Entry point ntdll!RtlpWorkerThread
Create time 20.02.2008 15:53:09
Time spent in user mode 0 Days 0:0:0.0
Time spent in kernel mode 0 Days 0:0:0.0
Function Arg 1 Arg 2 Arg 3 Source
ntdll!ExpInterlockedPopEntrySListFault 00030718 00d0fde4
7c82a0b8
ntdll!RtlpAllocateFromHeapLookaside+13 00030718 00000010
000392b8
ntdll!RtlAllocateHeap+1dd 00030000 00000000 00000010
msvcrt!_heap_alloc+26 00000010 00000010 000392b8
msvcrt!operator new+24 00000010 00000000 000392b8
iisutil!IPM_MESSAGE_IMP::AllocateDataLength+12 00000010
000391d8 00000000
iisutil!IPM_MESSAGE_PIPE::ReadMessage+9b 00000010 000392b8
64710045
iisutil!IPM_MESSAGE_PIPE::MessagePipeCompletion+31d 000392b8
000e1b00 000e1b90
ntdll!RtlpWaitOrTimerCallout+74 64710045 000392b8 000e1b00
ntdll!RtlpAsyncWaitCallbackCompletion+37 000e1b90 7c889080
00093d20
ntdll!RtlpWorkerCallout+71 7c83ca2b 000e1b90 00000000
ntdll!RtlpExecuteWorkerRequest+4f 00000000 000e1b90
00093d20
ntdll!RtlpApcCallout+11 7c83a9ca 00000000 000e1b90
ntdll!RtlpWorkerThread+61 00000000 00000000 00000000
kernel32!BaseThreadStart+34 7c839efb 00000000 00000000
NTDLL!EXPINTERLOCKEDPOPENTRYSLISTFAULT
Detailed Info For Corrupt Heap
Heap 3 - 0x00030000
Heap Name msvcrt!_crtheap
Heap Description This heap is used by msvcrt
Reserved memory 7,06 MBytes
Committed memory 4,75 MBytes (67,26% of reserved)
Uncommitted memory 2,31 MBytes (32,74% of reserved)
Number of heap segments 4 segments
Number of uncommitted ranges 1 range(s)
Size of largest uncommitted range 2,31 MBytes
Calculated heap fragmentation 0,00%
Segment Information
Base Address Reserved Size Committed Size Uncommitted Size Number of
uncommitted ranges Largest uncommitted block Calculated heap
fragmentation
0x00030640 64,00 KBytes 64,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x01c80000 1 024,00 KBytes 1 024,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x02c00000 2,00 MBytes 2,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x03510000 4,00 MBytes 1,69 MBytes 2,31 MBytes 1 2,31 MBytes 0,00%
Top 5 allocations by size
Allocation Size - 140
Allocation Size - 32
Allocation Size - 584
Allocation Size - 56
Allocation Size - 308
1,61 MBytes
253,09 KBytes
187,06 KBytes
125,89 KBytes
99,56 KBytes
Top 5 allocations by count
Allocation Size - 140
Allocation Size - 32
Allocation Size - 56
Allocation Size - 12
Allocation Size - 47
12064 allocation(s)
8099 allocation(s)
2302 allocation(s)
1757 allocation(s)
1756 allocation(s)
Back to Top
In
w3wp__PID__3460__Date__02_20_2008__Time_04_56_39PM__556__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!ExpInterlockedPopEntrySListFault in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x64006f00 on thread 2
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 Module Information
Image Name: C:\WINDOWS\system32\ntdll.dll Symbol Type: PDB
Base address: 0x7c800000 Time Stamp: Sat Feb 17 17:02:00 2007
Checksum: 0x000bd6f9 Comments:
COM DLL: False Company Name: Microsoft Corporation
ISAPIExtension: False File Description: NT Layer DLL
ISAPIFilter: False File Version: 5.2.3790.3959
(srv03_sp2_rtm.070216-1710)
Managed DLL: False Internal Name: ntdll.dll
VB DLL: False Legal Copyright: © Microsoft Corporation. All rights
reserved.
Loaded Image Name: ntdll.dll Legal Trademarks:
Mapped Image Name: Original filename: ntdll.dll
Module name: ntdll Private Build:
Single Threaded: False Product Name: Microsoft® Windows® Operating
System
Module Size: 768,00 KBytes Product Version: 5.2.3790.3959
Symbol File Name:
c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb
Special Build: &
Report for
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
Report for
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
Type of Analysis Performed Crash Analysis
Machine Name INETVPNSERVER
Operating System Windows Server 2003 Service Pack 2
Number Of Processors 8
Process ID 7844
Process Image c:\WINDOWS\system32\inetsrv\w3wp.exe
System Up-Time 59 day(s) 14:12:49
Process Up-Time 08:38:49
Thread 54 - System ID 1536
Entry point w3tp!THREAD_MANAGER::ThreadManagerThread
Create time 18.02.2008 19:37:07
Time spent in user mode 0 Days 0:0:0.0
Time spent in kernel mode 0 Days 0:0:2.515
Function Arg 1 Arg 2 Arg 3 Source
ntdll!RtlAllocateHeap+579 00030000 00000000 00000084
msvcrt!malloc+6c 00000084 00000010 083bf910
php5ts!ts_resource_ex+103 056359ec 00000600 1093f9c8
php5ts!ts_resource_ex+c4 00000000 00000600 083bf910
php5isapi!HttpFilterProc+b 1093fa1c 00004000 083bf910
w3core!W3_MAIN_CONTEXT::NotifyFilters+e0 a1000001 5a3de000
145d8b53
0x28ec81ec 8bfc4589 8b571045 8589087d
0x0c758b56 8b571045 8589087d fffffed8
0x80000000`00000000 8589087d fffffed8 00008068
0x80000000`00000000 fffffed8 00008068 3c858d00
0x80000000`00000000 00008068 3c858d00 50ffffff
0x80000000`00000000 3c858d00 50ffffff ff0c8d8d
NTDLL!RTLALLOCATEHEAP+579
Detailed Info For Corrupt Heap
Heap 3 - 0x00030000
Heap Name msvcrt!_crtheap
Heap Description This heap is used by msvcrt
Reserved memory 63,06 MBytes
Committed memory 39,68 MBytes (62,92% of reserved)
Uncommitted memory 23,39 MBytes (37,08% of reserved)
Number of heap segments 7 segments
Number of uncommitted ranges 1 range(s)
Size of largest uncommitted range 23,39 MBytes
Calculated heap fragmentation 0,00%
Segment Information
Base Address Reserved Size Committed Size Uncommitted Size Number of
uncommitted ranges Largest uncommitted block Calculated heap
fragmentation
0x00030640 64,00 KBytes 64,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x01c80000 1 024,00 KBytes 1 024,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x02c00000 2,00 MBytes 2,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x03640000 4,00 MBytes 4,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x055a0000 8,00 MBytes 8,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x08680000 16,00 MBytes 16,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x0d430000 32,00 MBytes 8,61 MBytes 23,39 MBytes 1 23,39 MBytes 0,00%
Top 5 allocations by size
Allocation Size - 584
Allocation Size - 308
Allocation Size - 140
Allocation Size - 32
Allocation Size - 56
13,24 MBytes
7,60 MBytes
6,74 MBytes
1,08 MBytes
568,42 KBytes
Top 5 allocations by count
Allocation Size - 140
Allocation Size - 32
Allocation Size - 12
Allocation Size - 308
Allocation Size - 584
50503 allocation(s)
35387 allocation(s)
26779 allocation(s)
25874 allocation(s)
23765 allocation(s)
Back to Top
In
w3wp__PID__7844__Date__02_18_2008__Time_07_48_46PM__213__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!RtlAllocateHeap+579 in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x00000000 on thread 54
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 Module Information
Image Name: C:\WINDOWS\system32\ntdll.dll Symbol Type: PDB
Base address: 0x7c800000 Time Stamp: Sat Feb 17 17:02:00 2007
Checksum: 0x000bd6f9 Comments:
COM DLL: False Company Name: Microsoft Corporation
ISAPIExtension: False File Description: NT Layer DLL
ISAPIFilter: False File Version: 5.2.3790.3959
(srv03_sp2_rtm.070216-1710)
Managed DLL: False Internal Name: ntdll.dll
VB DLL: False Legal Copyright: © Microsoft Corporation. All rights
reserved.
Loaded Image Name: ntdll.dll Legal Trademarks:
Mapped Image Name: Original filename: ntdll.dll
Module name: ntdll Private Build:
Single Threaded: False Product Name: Microsoft® Windows® Operating
System
Module Size: 768,00 KBytes Product Version: 5.2.3790.3959
Symbol File Name:
c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb
Special Build: &
Report for
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
Report for
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
Type of Analysis Performed Crash Analysis
Machine Name INETVPNSERVER
Operating System Windows Server 2003 Service Pack 2
Number Of Processors 8
Process ID 4516
Process Image c:\WINDOWS\system32\inetsrv\w3wp.exe
System Up-Time 59 day(s) 15:52:24
Process Up-Time 01:38:30
Thread 10 - System ID 3228
Entry point w3tp!THREAD_MANAGER::ThreadManagerThread
Create time 18.02.2008 19:49:57
Time spent in user mode 0 Days 0:0:0.281
Time spent in kernel mode 0 Days 0:0:0.171
Function Arg 1 Arg 2 Arg 3 Source
ntdll!ExpInterlockedPopEntrySListFault 00030838 0124fed0
7c82a0b8
ntdll!RtlpAllocateFromHeapLookaside+13 00030838 0000003c
00000000
ntdll!RtlAllocateHeap+1dd 00030000 00000000 0000003c
msvcrt!_heap_alloc+26 0000003c 00000000 00000000
msvcrt!operator new+24 0000003c 5a361d28 00000008
iisutil!IPM_MESSAGE_IMP::CreateMessage+1c 0124ff34 00039238
5a361d28
iisutil!IPM_MESSAGE_PIPE::WriteMessage+5e 00000002 00000000
00000000
w3dt!WP_IPM::HandlePing+59 00000000 00000000 00038bb8
w3tp!THREAD_POOL_DATA::ThreadPoolThread+73 00000000 00038b78
5a300000
w3tp!THREAD_POOL_DATA::ThreadPoolThread+24 00000102 00000000
00000000
w3tp!THREAD_MANAGER::ThreadManagerThread+39 00038b78 00000000
00000000
kernel32!BaseThreadStart+34 5a301d70 00038b78 00000000
NTDLL!EXPINTERLOCKEDPOPENTRYSLISTFAULT
Detailed Info For Corrupt Heap
Heap 3 - 0x00030000
Heap Name msvcrt!_crtheap
Heap Description This heap is used by msvcrt
Reserved memory 7,06 MBytes
Committed memory 3,89 MBytes (55,14% of reserved)
Uncommitted memory 3,17 MBytes (44,86% of reserved)
Number of heap segments 4 segments
Number of uncommitted ranges 1 range(s)
Size of largest uncommitted range 3,17 MBytes
Calculated heap fragmentation 0,00%
Segment Information
Base Address Reserved Size Committed Size Uncommitted Size Number of
uncommitted ranges Largest uncommitted block Calculated heap
fragmentation
0x00030640 64,00 KBytes 64,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x01c80000 1 024,00 KBytes 1 024,00 KBytes 0 Bytes 0 0 Bytes 0,00%
0x02c00000 2,00 MBytes 2,00 MBytes 0 Bytes 0 0 Bytes 0,00%
0x03920000 4,00 MBytes 852,00 KBytes 3,17 MBytes 1 3,17 MBytes 0,00%
Top 5 allocations by size
Allocation Size - 140
Allocation Size - 32
Allocation Size - 56
Allocation Size - 584
Allocation Size - 8192
1,32 MBytes
205,84 KBytes
101,12 KBytes
97,52 KBytes
80,00 KBytes
Top 5 allocations by count
Allocation Size - 140
Allocation Size - 32
Allocation Size - 56
Allocation Size - 12
Allocation Size - 47
9895 allocation(s)
6587 allocation(s)
1849 allocation(s)
1498 allocation(s)
1462 allocation(s)
Back to Top
In
w3wp__PID__4516__Date__02_18_2008__Time_09_28_27PM__338__Second_Chance_Exception_C0000005.dmp
the assembly instruction at ntdll!ExpInterlockedPopEntrySListFault in
C:\WINDOWS\system32\ntdll.dll from Microsoft Corporation has caused an
access violation exception (0xC0000005) when trying to read from memory
location 0x20657355 on thread 10
Heap corruption was detected in heap 0x00030000, however pageheap was
not enabled in this dump. Please follow the instructions in the
recommendation section for troubleshooting heap corruption issues.
Current NTGlobalFlags value: 0x0 Module Information
Image Name: C:\WINDOWS\system32\ntdll.dll Symbol Type: PDB
Base address: 0x7c800000 Time Stamp: Sat Feb 17 17:02:00 2007
Checksum: 0x000bd6f9 Comments:
COM DLL: False Company Name: Microsoft Corporation
ISAPIExtension: False File Description: NT Layer DLL
ISAPIFilter: False File Version: 5.2.3790.3959
(srv03_sp2_rtm.070216-1710)
Managed DLL: False Internal Name: ntdll.dll
VB DLL: False Legal Copyright: © Microsoft Corporation. All rights
reserved.
Loaded Image Name: ntdll.dll Legal Trademarks:
Mapped Image Name: Original filename: ntdll.dll
Module name: ntdll Private Build:
Single Threaded: False Product Name: Microsoft® Windows® Operating
System
Module Size: 768,00 KBytes Product Version: 5.2.3790.3959
Symbol File Name:
c:\symcache\ntdll.pdb\93E72E109DC84F16AA54797E4DA8C1682\ntdll.pdb
Special Build: &
Script Summary
Script Name Status Error Code Error Source Error Description Source
Line
CrashHangAnalysis.asp Completed
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/43410
--
Edit this bug report at http://bugs.php.net/?id=43410&edit=1