syseng007
asked on
Server 2003 Shutdown Unexpectedly Due to LSASS
One of our server 2003 domain controller shutdown unexpected due to LSASS. Can someone please provide guidance what this means? Thanks!
1. LSASS crashed:
Event Type: Error
Event Source: Winlogon
Description:
A critical system process, C:\WINDOWS\system32\lsass. exe, failed with status code c0000005. The machine must now be restarted.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
2. This caused winlogon to restart server:
Event Type: Information
Event Source: USER32
Event Category: None
Event ID: 1074
User: NT AUTHORITY\SYSTEM
Description:
The process winlogon.exe has initiated the restart of computer <server> on behalf of user for the following reason: No title for this reason could be found
Reason Code: 0x50006
Shutdown Type: restart
Comment: The system process 'C:\WINDOWS\system32\lsass .exe' terminated unexpectedly with status code -1073741819. The system will now shut down and restart.
3. No memory dump file generated
4. Dr Watson Dump generated. c:\windows\debug\user.dmp Extract detailed below
Comment: 'Dr. Watson generated MiniDump'
Symbol search path is: *** Invalid ***
************************** ********** ********** ********** ********** **********
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
************************** ********** ********** ********** ********** **********
Executable search path is:
Windows Server 2003 Version 3790 (Service Pack 2) MP (24 procs) Free x64
Product: LanManNt, suite: TerminalServer SingleUserTS
System Uptime: not available
.......................... .......... .......... .......... ........
.......................... .......... .....
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(204.1664): Access violation - code c0000005 (first/second chance not available)
Unable to load image C:\WINDOWS\system32\rpcrt4 .dll, Win32 error 0n2
*** WARNING: Unable to verify timestamp for rpcrt4.dll
*** ERROR: Module load completed but symbols could not be loaded for rpcrt4.dll
rpcrt4+0x170e5:
000007ff`7fd470e5 8b4008 mov eax,dword ptr [rax+8] ds:00000000`000097f4=????? ???
5. Currently LSASS is running under PID 516 and has the below DLLs loaded
ntdll.dll,kernel32.dll,ADV API32.dll, RPCRT4.dll ,Secur32.d ll,LSASRV. dll,msvcrt .dll,USER3 2.dll,GDI3 2.dll,SAMS RV.dll,cry ptdll.dll, DNSAPI.dll ,WS2_32.dl l,WS2HELP. dll,MSASN1 .dll,NETAP I32.dll,SA MLIB.dll,M PR.dll,NTD SAPI.dll,W LDAP32.dll ,msprivs.d ll,kerbero s.dll,msv1 _0.dll,iph lpapi.dll, PSAPI.DLL, netlogon.d ll,w32time .dll,msvcp 60.dll,USE RENV.dll,A UTHZ.dll,s channel.dl l,CRYPT32. dll,wdiges t.dll,rsae nh.dll,Tiv oliAP.dll, ole32.dll, OLEAUT32.d ll,NTDSA.d ll,NTDSATQ .dll,MSWSO CK.dll,ESE NT.dll,set upapi.dll, ntdsmsg.dl l,ws03res. dll,ntdsbs rv.dll,WSO CK32.dll,V SSAPI.DLL, ATL.DLL,KD CSVC.dll,R ASSFM.dll, scecli.dll ,BOAPwdFil ter.dll,AC TIVEDS.dll ,adsldpc.d ll,credui. dll,SHELL3 2.dll,SHLW API.dll,co mctl32.dll ,PCNSFLT.d ll,WINTRUS T.dll,imag ehlp.dll,h netcfg.dll ,wshtcpip. dll,cryptn et.dll,Sen sApi.dll,p wdssp.dll, NTDSKCC.dl l,W32TOPL. dll,winrnr .dll,netma n.dll,nets hell.dll,r tutils.dll ,CLUSAPI.d ll,MPRAPI. dll,RASAPI 32.dll,ras man.dll,TA PI32.dll,
WINMM.dll,WZCSvc.DLL,WMI.d ll,DHCPCSV C.DLL,WTSA PI32.dll,W INSTA.dll, WININET.dl l,WZCSAPI. DLL,rasadh lp.dll,w3s sl.dll,str mfilt.dll, HTTPAPI.dl l,pstorsvc .dll,psbas e.dll,xpsp 2res.dll,C LBCatQ.DLL ,COMRes.dl l,VERSION. dll,es.dll ,adsldp.dl l,SXS.DLL, dssenh.dll ,WINHTTP.d ll
1. LSASS crashed:
Event Type: Error
Event Source: Winlogon
Description:
A critical system process, C:\WINDOWS\system32\lsass.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
2. This caused winlogon to restart server:
Event Type: Information
Event Source: USER32
Event Category: None
Event ID: 1074
User: NT AUTHORITY\SYSTEM
Description:
The process winlogon.exe has initiated the restart of computer <server> on behalf of user for the following reason: No title for this reason could be found
Reason Code: 0x50006
Shutdown Type: restart
Comment: The system process 'C:\WINDOWS\system32\lsass
3. No memory dump file generated
4. Dr Watson Dump generated. c:\windows\debug\user.dmp Extract detailed below
Comment: 'Dr. Watson generated MiniDump'
Symbol search path is: *** Invalid ***
**************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
**************************
Executable search path is:
Windows Server 2003 Version 3790 (Service Pack 2) MP (24 procs) Free x64
Product: LanManNt, suite: TerminalServer SingleUserTS
System Uptime: not available
..........................
..........................
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(204.1664): Access violation - code c0000005 (first/second chance not available)
Unable to load image C:\WINDOWS\system32\rpcrt4
*** WARNING: Unable to verify timestamp for rpcrt4.dll
*** ERROR: Module load completed but symbols could not be loaded for rpcrt4.dll
rpcrt4+0x170e5:
000007ff`7fd470e5 8b4008 mov eax,dword ptr [rax+8] ds:00000000`000097f4=?????
5. Currently LSASS is running under PID 516 and has the below DLLs loaded
ntdll.dll,kernel32.dll,ADV
WINMM.dll,WZCSvc.DLL,WMI.d
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.