Solved

Network Administrator

Posted on 2009-05-15
3
878 Views
Last Modified: 2012-05-07
We have a domain controller that is a DC, GC and print server. We noticed that the CPU usage is very high. It goes up to 100 % then it drops down to 20% then back to 85%...etc.  The file that is consuming the most CPU is LSASS.exe.

Any help would be appriciated.
0
Comment
Question by:rogermendieta
3 Comments
 
LVL 6

Expert Comment

by:0791882310
Comment Utility
lsass.exe is a security manager for windows (I.E... windows logons and what not)... so it shouldn't be taking up any resources... unless your running a terminal server.... in other cases lsass.exe is a trojan... make sure where the file in running from... the file location should be [root drive]\[windows root]\system32\...

i would recommend doing some virus scans and what not
0
 
LVL 18

Accepted Solution

by:
Andrej Pirman earned 500 total points
Comment Utility
Here is what Microsoft says about it and provides a hotfix:
http://support.microsoft.com/kb/842382

It is also very likely that your AD is corrupted. You may try to restore it from backup, or try some AD repair tools available, like "ntdsutil".
0
 
LVL 1

Expert Comment

by:rwetmore
Comment Utility
You might want to try checking out this blog from MS.  It also has some good tips on troubleshooting LSASS.exe high CPU utilization.

http://blogs.technet.com/askds/archive/2009/04/16/conficker-causes-lsass-to-consume-cpu-time-on-domain-controllers.aspx

Hopefully your client don't have Confiker.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

My previous article  (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_4466-A-beginners-guide-to-installing-SCCM2007-on-Windows-2008-R2-Server.html)detailed one possible method to get SCCM 2007 installed an…
Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

5 Experts available now in Live!

Get 1:1 Help Now