Jump to content
multisy

Snapshot slow /w high client CPU

Recommended Posts

The compare took 8 minutes, but creating snapshot took almost 7 hours; using multiserver 7.7.562; with client 7.7.114.

 

This problem also occurs using OEM Professional 7.6.123; with client 7.6.107.

 

This has been an ongoing problem since a Windows Update more than 5 or 6 months ago; on Winodws 7 x86 & x64 clients.

 

 

+ Normal backup using multisy-p at 1/30/2012 12:00 PM (Execution unit 1)

To Backup Set Win 7 x86...

- 1/30/2012 12:00:00 PM: Copying SSD (C:) on multisy-p

File "C:\Boot\BCD": can't read, error -1020 ( sharing violation)

File "C:\Boot\BCD.LOG": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Microsoft Antimalware\IMpService1F383481-F70E-4E7A-8B69-C4B4A23928E3.lock": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpScanCache-1.bin": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb": can't read, error -1020 ( sharing violation)

File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb": can't read, error -1020 ( sharing violation)

File "C:\System Volume Information\Syscache.hve": can't read, error -1020 ( sharing violation)

File "C:\System Volume Information\Syscache.hve.LOG1": can't read, error -1020 ( sharing violation)

File "C:\System Volume Information\Syscache.hve.LOG2": can't read, error -1020 ( sharing violation)

File "C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}": can't read, error -1017 ( insufficient permissions)

File "C:\System Volume Information\{67550f1a-46a5-11e1-9b2c-001742365963}{3808876b-c176-4e48-b7ae-04046e6cc752}": can't read, error -1017 ( insufficient permissions)

File "C:\Users\Boss\NTUSER.DAT": can't read, error -1020 ( sharing violation)

File "C:\Users\Boss\ntuser.dat.LOG1": can't read, error -1020 ( sharing violation)

File "C:\Users\Boss\AppData\Local\Microsoft\Windows\UsrClass.dat": can't read, error -1020 ( sharing violation)

File "C:\Users\Boss\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1": can't read, error -1020 ( sharing violation)

....

 

File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1": can't read, error -1020 ( sharing violation)

File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\config\RegBack\DEFAULT": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\config\RegBack\SAM": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\config\RegBack\SECURITY": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\config\RegBack\SOFTWARE": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\config\RegBack\SYSTEM": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl": can't read, error -1020 ( sharing violation)

File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl": can't read, error -1020 ( sharing violation)

1/30/2012 6:51:07 PM: Snapshot stored, 177.3 MB

 

1/30/2012 6:51:43 PM: Comparing SSD (C:) on multisy-p

File "C:\Program Files\Diskeeper Corporation\Diskeeper\Volume{929BC4AF-8D57-11E0-91AD-806E6F6E6963}.dat": different modify date/time (set: 1/30/2012 1:10:07 PM, vol: 1/30/2012 6:09:38 PM)

File "C:\ProgramData\Microsoft\Microsoft Antimalware\Support\MPLog-12052011-082509.log": different data size (set: 1,061,824, vol: 1,062,380)

File "C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat": different modify date/time (set: 1/30/2012 1:33:09 PM, vol: 1/30/2012 6:52:45 PM)

File "C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat": different modify date/time (set: 1/30/2012 1:33:09 PM, vol: 1/30/2012 6:53:06 PM)

File "C:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM)

File "C:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM)

File "C:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM)

File "C:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:35 PM)

File "C:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 4:04:30 PM)

File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.153.gthr": different data size (set: 2,278, vol: 4,164)

File "C:\Windows\WindowsUpdate.log": different modify date/time (set: 1/30/2012 12:43:03 PM, vol: 1/30/2012 6:14:55 PM)

File "C:\Windows\inf\setupapi.app.log": different modify date/time (set: 1/28/2012 5:15:01 PM, vol: 1/30/2012 6:49:56 PM)

File "C:\Windows\Prefetch\AgGlFaultHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:42 PM)

File "C:\Windows\Prefetch\AgGlFgAppHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:44 PM)

File "C:\Windows\Prefetch\AgGlGlobalHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:40 PM)

File "C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1935655697-179605362-1801674531-1120.db": different modify date/time (set: 1/29/2012 4:35:26 PM, vol: 1/30/2012 3:48:04 PM)

File "C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1935655697-179605362-1801674531-1120.db": different modify date/time (set: 1/29/2012 4:35:26 PM, vol: 1/30/2012 3:47:40 PM)

File "C:\Windows\Prefetch\AgRobust.db": different modify date/time (set: 1/29/2012 6:45:37 AM, vol: 1/30/2012 4:00:39 PM)

File "C:\Windows\Prefetch\CONHOST.EXE-3218E401.pf": different modify date/time (set: 1/30/2012 1:00:01 PM, vol: 1/30/2012 6:12:52 PM)

File "C:\Windows\Prefetch\CSRSS.EXE-8C04D631.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:51:02 PM)

File "C:\Windows\Prefetch\LOGONUI.EXE-1BEE4A84.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:52:20 PM)

File "C:\Windows\Prefetch\LongTermHist.db": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:46 PM)

File "C:\Windows\Prefetch\LongTermHist.db.bt": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:40 PM)

File "C:\Windows\Prefetch\LongTermHist.db.dx": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:45 PM)

File "C:\Windows\Prefetch\MPCMDRUN.EXE-DBF9CB7D.pf": different modify date/time (set: 1/30/2012 10:12:52 AM, vol: 1/30/2012 6:13:02 PM)

File "C:\Windows\Prefetch\RTHLPSVC.EXE-24042594.pf": different modify date/time (set: 1/28/2012 12:23:32 PM, vol: 1/30/2012 1:44:36 PM)

File "C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-AA7A1FDD.pf": different modify date/time (set: 1/30/2012 12:06:09 PM, vol: 1/30/2012 5:29:59 PM)

File "C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-AFAD3EF9.pf": different modify date/time (set: 1/30/2012 12:06:09 PM, vol: 1/30/2012 5:29:57 PM)

File "C:\Windows\Prefetch\SMSS.EXE-1DCD0EB1.pf": different modify date/time (set: 1/29/2012 6:35:14 AM, vol: 1/30/2012 3:50:50 PM)

File "C:\Windows\Prefetch\SVCHOST.EXE-74432B26.pf": different modify date/time (set: 1/29/2012 7:12:56 AM, vol: 1/30/2012 3:45:34 PM)

File "C:\Windows\Prefetch\SVCHOST.EXE-8FD92526.pf": different modify date/time (set: 1/30/2012 12:00:12 AM, vol: 1/30/2012 1:39:30 PM)

File "C:\Windows\Prefetch\TASKHOST.EXE-437C05A8.pf": different modify date/time (set: 1/30/2012 1:10:27 PM, vol: 1/30/2012 6:07:54 PM)

File "C:\Windows\Prefetch\VSSVC.EXE-04D079CC.pf": different modify date/time (set: 1/30/2012 12:00:11 AM, vol: 1/30/2012 1:39:29 PM)

File "C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:51:22 PM)

File "C:\Windows\Prefetch\WISPTIS.EXE-6C347CFA.pf": different modify date/time (set: 1/29/2012 6:08:12 AM, vol: 1/30/2012 3:52:32 PM)

File "C:\Windows\rescache\rc0007\ResCache.hit": different modify date/time (set: 1/30/2012 12:12:53 PM, vol: 1/30/2012 6:07:44 PM)

File "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\MpCmdRun.log": different modify date/time (set: 1/30/2012 10:13:50 AM, vol: 1/30/2012 6:14:56 PM)

File "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:47 PM)

File "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:55 PM)

File "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:56 PM)

File "C:\Windows\System32\LogFiles\Scm\9b75c702-ea13-406a-badb-6c588ee4375b": different modify date/time (set: 1/30/2012 10:07:40 AM, vol: 1/30/2012 6:07:44 PM)

File "C:\Windows\System32\LogFiles\Scm\a1cfa52f-06f2-418d-addb-cd6456d66f43": different modify date/time (set: 1/30/2012 1:10:17 PM, vol: 1/30/2012 6:00:24 PM)

File "C:\Windows\System32\LogFiles\Scm\de8bae53-2809-4f75-85ef-427d364b9b2c": different modify date/time (set: 1/30/2012 10:07:40 AM, vol: 1/30/2012 6:07:42 PM)

File "C:\Windows\System32\wbem\Repository\INDEX.BTR": different modify date/time (set: 1/30/2012 1:18:22 PM, vol: 1/30/2012 3:14:27 PM)

File "C:\Windows\System32\wbem\Repository\MAPPING2.MAP": different modify date/time (set: 1/30/2012 1:36:21 AM, vol: 1/30/2012 3:14:27 PM)

File "C:\Windows\System32\wbem\Repository\OBJECTS.DATA": different modify date/time (set: 1/30/2012 1:18:22 PM, vol: 1/30/2012 3:14:23 PM)

File "C:\Windows\System32\wfp\wfpdiag.etl": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Folder Redirection%4Operational.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NlaSvc%4Operational.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\Security.evtx": didn't compare

File "C:\Windows\System32\winevt\Logs\System.evtx": didn't compare

File "C:\Windows\Temp\MpCmdRun.log": different modify date/time (set: 1/30/2012 10:13:51 AM, vol: 1/30/2012 6:14:55 PM)

1/30/2012 6:59:53 PM: 71 execution errors

Completed: 420 files, 5.2 GB, with 2% compression

Performance: 102.1 MB/minute (55.3 copy, 654.1 compare)

Duration: 06:59:52 (05:16:19 idle/loading/preparing)

Share this post


Link to post
Share on other sites

Building snapshot is when Retrospect backs up the Windows' registry. We had one client that took over three hours to build the snapshot on. The solution was to wipe the hard drive and re-install Windows and the applications.

Share this post


Link to post
Share on other sites

That is not a solution to the problem just a reason to use different backup software.

 

Looking at Process Explorer the pcpds.exe Process moves through files (Handles) very slowly while using high CPU, a fix to pcpds.exe client-side would be a better resolution.

Share this post


Link to post
Share on other sites

That is not a solution to the problem just a reason to use different backup software.

 

Looking at Process Explorer the pcpds.exe Process moves through files (Handles) very slowly while using high CPU, a fix to pcpds.exe client-side would be a better resolution.

Well, pcpds just calls the standard Windows' APIs, just like any other backup software. So i's Microsoft that needs to speed up their registry access.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×