Svchost.exe causing CPU usage to go up and down


sorry if have posted in wrong forum ever post here.  have run issue unable find assistance on.  on of our domain controllers (3) running server 2008 x64 see cpu spiking , down.  the cpu will start out next nothing jumps 100% second, returns next nothing second, jumps 100% second.... , on.  using process explorer found out svchost process runs dhcp client, tcp/ip netbios helper, , windows event log services.  if kill process can start services without issues except windows event log service.  start windows event log service cpu starts spiking , down again.  there not seem unusual # of events being logged , don't have auditing turned on not sure going on.  able gather procdump have posted below.  continue investigate wondering if offer insight?

 

*******************************************************************************

*                                                                             *

*                        exception analysis                                   *

*                                                                             *

*******************************************************************************

getpageurldata failed, server returned http status 404

url requested: http://watson.microsoft.com/stageone/svchost_exe/6_0_6001_18000/47919291/unknown/0_0_0_0/bbbbbbb4/80000003/00000000.htm?retriage=1

faulting_ip:

+70de990

00000000`00000000 ??              ???

exception_record:  ffffffffffffffff -- (.exr 0xffffffffffffffff)

exceptionaddress: 0000000000000000

   exceptioncode: 80000003 (break instruction exception)

  exceptionflags: 00000000

numberparameters: 0

faulting_thread:  00000000000003d8

default_bucket_id:  status_breakpoint

process_name:  svchost.exe

error_code: (ntstatus) 0x80000003 - {exception}  breakpoint  breakpoint has been reached.

exception_code: (hresult) 0x80000003 (2147483651) - 1 or more arguments invalid

mod_list: <analysis/>

ntglobalflag:  0

application_verifier_flags:  0

primary_problem_class:  status_breakpoint

bugcheck_str:  application_fault_status_breakpoint

last_control_transfer:  000000007740616a 0000000077636eda

stack_text: 

00000000`0010f2f8 00000000`7740616a : 00000000`00000010 00000000`0010f150 00000000`00000000 0000990d`354adee0 : ntdll!zwreadfile+0xa

00000000`0010f300 000007fe`ff30fc9a : 00000000`0010f3c0 00000000`00246f28 00000000`0010f430 00000000`0010f3f8 : kernel32!readfile+0x8a

00000000`0010f390 000007fe`ff30fa3b : 00000000`00246f28 00000000`00000000 00000000`00000000 00000000`00000000 : advapi32!scgetpipeinput+0x3a

00000000`0010f3e0 000007fe`ff30e00d : 00000000`0000003c 00000000`00000000 00000000`00000000 00000000`000004d3 : advapi32!scdispatcherloop+0x9a

00000000`0010f4e0 00000000`ffa81dca : 00000000`00245310 00000000`00000000 00000000`00000024 00000000`00000000 : advapi32!startservicectrldispatcherw+0x176

00000000`0010f780 00000000`ffa824b2 : 00000000`00000000 00000000`ffa85490 01ce990d`38280236 00000000`0d72c90f : svchost!wmain+0x110

00000000`0010f7b0 00000000`7740b22d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : svchost!sccreatewellknownsids+0x301

00000000`0010f7f0 00000000`77616861 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!basethreadinitthunk+0xd

00000000`0010f820 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!rtluserthreadstart+0x1d

 

stack_command:  ~0s; .ecxr ; kb

followup_ip:

svchost!wmain+110

00000000`ffa81dca 33c9            xor     ecx,ecx

symbol_stack_index:  5

symbol_name:  svchost!wmain+110

followup_name:  machineowner

module_name: svchost

image_name:  svchost.exe

debug_flr_image_timestamp:  47919291

failure_bucket_id:  status_breakpoint_80000003_svchost.exe!wmain

bucket_id:  x64_application_fault_status_breakpoint_svchost!wmain+110

watson_stageone_url:  http://watson.microsoft.com/stageone/svchost_exe/6_0_6001_18000/47919291/unknown/0_0_0_0/bbbbbbb4/80000003/00000000.htm?retriage=1

followup: machineowner

---------

i figured out issue... event log being overloaded windows security audits new firewall brought online without knowledge.   firewall had ldap feature turned on resolve ip hostnames.  if come across cpu spikes described in thread, make sure (or else) didn't add sw/hw points dc.  



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file