Link to home
Start Free TrialLog in
Avatar of syseng007
syseng007

asked on

Server 2003 Shutdown Unexpectedly Due to LSASS

One of our server 2003 domain controller shutdown unexpected due to LSASS. Can someone please provide guidance what this means? Thanks!


1.      LSASS crashed:
Event Type:           Error
Event Source:       Winlogon
Description:
A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code c0000005.  The machine must now be restarted.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

2.      This caused winlogon to restart server:
Event Type:           Information
Event Source:       USER32
Event Category:    None
Event ID:                1074
User:                      NT AUTHORITY\SYSTEM
Description:
The process winlogon.exe has initiated the restart of computer <server> on behalf of user for the following reason: No title for this reason could be found
Reason Code: 0x50006
Shutdown Type: restart
Comment: The system process 'C:\WINDOWS\system32\lsass.exe' terminated unexpectedly with status code -1073741819.  The system will now shut down and restart.


3.      No memory dump file generated
4.      Dr Watson Dump generated. c:\windows\debug\user.dmp Extract detailed below
Comment: 'Dr. Watson generated MiniDump'
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path.           *
* Use .symfix to have the debugger choose a symbol path.                   *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
Windows Server 2003 Version 3790 (Service Pack 2) MP (24 procs) Free x64
Product: LanManNt, suite: TerminalServer SingleUserTS
System Uptime: not available
................................................................
.........................................
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(204.1664): Access violation - code c0000005 (first/second chance not available)
Unable to load image C:\WINDOWS\system32\rpcrt4.dll, Win32 error 0n2
*** WARNING: Unable to verify timestamp for rpcrt4.dll
*** ERROR: Module load completed but symbols could not be loaded for rpcrt4.dll
rpcrt4+0x170e5:
000007ff`7fd470e5 8b4008          mov     eax,dword ptr [rax+8] ds:00000000`000097f4=????????

5.      Currently LSASS is running under PID 516 and has the below DLLs loaded
ntdll.dll,kernel32.dll,ADVAPI32.dll,RPCRT4.dll,Secur32.dll,LSASRV.dll,msvcrt.dll,USER32.dll,GDI32.dll,SAMSRV.dll,cryptdll.dll,DNSAPI.dll,WS2_32.dll,WS2HELP.dll,MSASN1.dll,NETAPI32.dll,SAMLIB.dll,MPR.dll,NTDSAPI.dll,WLDAP32.dll,msprivs.dll,kerberos.dll,msv1_0.dll,iphlpapi.dll,PSAPI.DLL,netlogon.dll,w32time.dll,msvcp60.dll,USERENV.dll,AUTHZ.dll,schannel.dll,CRYPT32.dll,wdigest.dll,rsaenh.dll,TivoliAP.dll,ole32.dll,OLEAUT32.dll,NTDSA.dll,NTDSATQ.dll,MSWSOCK.dll,ESENT.dll,setupapi.dll,ntdsmsg.dll,ws03res.dll,ntdsbsrv.dll,WSOCK32.dll,VSSAPI.DLL,ATL.DLL,KDCSVC.dll,RASSFM.dll,scecli.dll,BOAPwdFilter.dll,ACTIVEDS.dll,adsldpc.dll,credui.dll,SHELL32.dll,SHLWAPI.dll,comctl32.dll,PCNSFLT.dll,WINTRUST.dll,imagehlp.dll,hnetcfg.dll,wshtcpip.dll,cryptnet.dll,SensApi.dll,pwdssp.dll,NTDSKCC.dll,W32TOPL.dll,winrnr.dll,netman.dll,netshell.dll,rtutils.dll,CLUSAPI.dll,MPRAPI.dll,RASAPI32.dll,rasman.dll,TAPI32.dll,
WINMM.dll,WZCSvc.DLL,WMI.dll,DHCPCSVC.DLL,WTSAPI32.dll,WINSTA.dll,WININET.dll,WZCSAPI.DLL,rasadhlp.dll,w3ssl.dll,strmfilt.dll,HTTPAPI.dll,pstorsvc.dll,psbase.dll,xpsp2res.dll,CLBCatQ.DLL,COMRes.dll,VERSION.dll,es.dll,adsldp.dll,SXS.DLL,dssenh.dll,WINHTTP.dll
ASKER CERTIFIED SOLUTION
Avatar of Member_2_6492660_1
Member_2_6492660_1
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial