Microsoft KB Archive/267578

= Access Violation in Lsass.exe in a Windows 2000 Domain =

Article ID: 267578

Article Last Modified on 11/1/2006

-

APPLIES TO


 * Microsoft Windows 2000 Service Pack 1
 * Microsoft Windows 2000 Service Pack 2
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Advanced Server

-



This article was previously published under Q267578



IMPORTANT: This article contains information about modifying the registry. Before you modify the registry, make sure to back it up and make sure that you understand how to restore the registry if a problem occurs. For information about how to back up, restore, and edit the registry, click the following article number to view the article in the Microsoft Knowledge Base:

256986 Description of the Microsoft Windows Registry



SYMPTOMS
You may receive a Dr. Watson error message in Lsass.exe on a Windows 2000-based server in a Microsoft Windows 2000-based domain.



CAUSE
There is a problem in Lsass.exe performing security ID (SID) to name lookups in a Windows 2000-based domain which causes heap corruption. The problem occurs in some circumstances when a deleted domain SID is the first in a list of permissions or local groups on a member server and there is an Lsa Lookup SID to Name request to the Windows 2000 Domain Controller and the SID no longer exists in the Domain.



RESOLUTION
WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

To resolve this problem, obtain the latest service pack for Windows 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:

260910 How to Obtain the Latest Windows 2000 Service Pack

The English version of this fix should have the following file attributes or later:   Date         Time       Version        Size       File name --  5/31/2001    11:13p    5.0.2195.3663  501,520    Lsasrv.dll (56-bit) 5/31/2001   03:30p    5.0.2195.3649  354,576    Advapi32.dll 5/31/2001   03:37p    5.0.2195.3649  519,440    Instlsa5.dll 5/31/2001   03:31p    5.0.2195.3649  142,608    Kdcsvc.dll 5/30/2001   02:55p    5.0.2195.3649  209,008    Kerberos.dll 5/29/2001   09:26a    5.0.2195.3649   69,456    Ksecdd.sys 5/29/2001   09:26a    5.0.2195.3649  501,520    Lsasrv.dll 5/29/2001   09:26a    5.0.2195.3649   33,552    Lsass.exe 5/31/2001   03:31p    5.0.2195.3652  908,560    Ntdsa.dll 5/31/2001   03:31p    5.0.2195.3649  382,736    Samsrv.dll

You should install the Windows 2000 hotfix only on the domain controllers. To implement this fix, install the hotfix and add the following value in the registry on the Windows 2000-based domain controllers.  Start Registry Editor (Regedt32.exe). Locate the following key in the registry:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA

 On the Edit menu, click Add Value, and then add the following registry value:

Value name: LsaLookupReturnSidTypeDeleted

Data type: REG_DWORD

Radix: Hexidecimal

Value: 1

 Quit Registry Editor and reboot the computer.

For additional information about how to install Windows 2000 and Windows 2000 hotfixes at the same time, click the article number below to view the article in the Microsoft Knowledge Base:

249149 Installing Microsoft Windows 2000 and Windows 2000 Hotfixes

<div class="status_section">

STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Windows 2000 Service Pack 3.

Additional query words: master resource account trust missing dropdown box

Keywords: kbbug kbfix kbqfe kbwin2000sp3fix kbsecurity kbhotfixserver KB267578

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.