09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 17 Hangs and Sluggish Performance 419<br />

FIGURE 17-26 File open indicated by CreateFileW in frame 50 results in file reads from SRTSP64.SYS.<br />

Sure enough, double-clicking on one of the SRTSP64.SYS lines in the stack displayed the<br />

module’s properties. The dialog box shown in Figure 17-27 confirmed that it was Symantec<br />

AutoProtect that was repeatedly performing on-access virus detection each time Project<br />

opened the file with certain parameters.<br />

FIGURE 17-27 Module Properties dialog box for SRTSP64.SYS.<br />

Typically, administrators configure antivirus on file servers, so there’s no need for clients to<br />

scan files they reference on servers because client-side scanning simply results in duplicative<br />

scans. This led to the support engineer’s second recommendation, which was for the administrator<br />

to set an exclusion filter on their client antivirus deployment for the file share hosting<br />

user profiles.<br />

In less than 15 minutes, the engineer had written up his analysis and recommendations and<br />

sent them back to the customer. The network monitor trace merely served as confirmation of<br />

what he observed in the Procmon trace. The administrator proceeded to implement the suggestions<br />

and, a few days later, confirmed that the user was no longer experiencing long file<br />

loads nor the errors he had reported. Another case closed with Procmon and thread stacks.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!