Microsoft KB Archive/267578

From BetaArchive Wiki
Knowledge Base


Access Violation in Lsass.exe in a Windows 2000 Domain

Article ID: 267578

Article Last Modified on 11/1/2006



APPLIES TO

  • Microsoft Windows 2000 Service Pack 1
  • Microsoft Windows 2000 Service Pack 2
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Advanced Server



This article was previously published under Q267578

IMPORTANT: This article contains information about modifying the registry. Before you modify the registry, make sure to back it up and make sure that you understand how to restore the registry if a problem occurs. For information about how to back up, restore, and edit the registry, click the following article number to view the article in the Microsoft Knowledge Base:

256986 Description of the Microsoft Windows Registry


SYMPTOMS

You may receive a Dr. Watson error message in Lsass.exe on a Windows 2000-based server in a Microsoft Windows 2000-based domain.

CAUSE

There is a problem in Lsass.exe performing security ID (SID) to name lookups in a Windows 2000-based domain which causes heap corruption. The problem occurs in some circumstances when a deleted domain SID is the first in a list of permissions or local groups on a member server and there is an Lsa Lookup SID to Name request to the Windows 2000 Domain Controller and the SID no longer exists in the Domain.

RESOLUTION

WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

To resolve this problem, obtain the latest service pack for Windows 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:

260910 How to Obtain the Latest Windows 2000 Service Pack


The English version of this fix should have the following file attributes or later:

   Date         Time       Version        Size       File name
   --------------------------------------------------------------------------
   5/31/2001    11:13p    5.0.2195.3663  501,520    Lsasrv.dll (56-bit)
   5/31/2001    03:30p    5.0.2195.3649  354,576    Advapi32.dll
   5/31/2001    03:37p    5.0.2195.3649  519,440    Instlsa5.dll
   5/31/2001    03:31p    5.0.2195.3649  142,608    Kdcsvc.dll
   5/30/2001    02:55p    5.0.2195.3649  209,008    Kerberos.dll
   5/29/2001    09:26a    5.0.2195.3649   69,456    Ksecdd.sys
   5/29/2001    09:26a    5.0.2195.3649  501,520    Lsasrv.dll
   5/29/2001    09:26a    5.0.2195.3649   33,552    Lsass.exe
   5/31/2001    03:31p    5.0.2195.3652  908,560    Ntdsa.dll
   5/31/2001    03:31p    5.0.2195.3649  382,736    Samsrv.dll
                




You should install the Windows 2000 hotfix only on the domain controllers. To implement this fix, install the hotfix and add the following value in the registry on the Windows 2000-based domain controllers.

  1. Start Registry Editor (Regedt32.exe).
  2. Locate the following key in the registry:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA

  3. On the Edit menu, click Add Value, and then add the following registry value:

    Value name: LsaLookupReturnSidTypeDeleted
    Data type: REG_DWORD
    Radix: Hexidecimal
    Value: 1

  4. Quit Registry Editor and reboot the computer.

For additional information about how to install Windows 2000 and Windows 2000 hotfixes at the same time, click the article number below to view the article in the Microsoft Knowledge Base:

249149 Installing Microsoft Windows 2000 and Windows 2000 Hotfixes


STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Windows 2000 Service Pack 3.


Additional query words: master resource account trust missing dropdown box

Keywords: kbbug kbfix kbqfe kbwin2000sp3fix kbsecurity kbhotfixserver KB267578