This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

lsass.exe application error

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I booted up yesterday and got this message: (Win XP Pro, SP 2 I'm almost certain)

lsass.exe Application Error
The instruction at ."0x7574ce634" referenced memory at 0x000d5004.
The memory could not be "read."
Click on "OK" to terminate the program.
Click on "Cancel' to debug.

When I clicked on "OK," I got the next message:

NT Authorization System
System Shutdown 1073741819
and it counts down to re-boot.

If I click on "Cancel," at the first message, the compuer boots to a completely empty and non-functioning desktop - there is the wallpaper picture and nothing else. I cannot right-click or get to Task Manager or any toolbars.

I can boot into safe mode, and safe mode with networking. All my programs seem to be there and functioning. I have a laptop that I have connected, so I can use a flash drive to download stuff onto this laptop and then from the drive onto the PC. I have run Stinger, and the Microsoft Malicious Software tool, and neither of these found a virus/worm.

I have cable, that is supposed to be firewalled through the provider, I have NAV that has auto update and I scan weekly, I have Ad-Aware, Spybot, Spyware Blaster, and have run all of those in safe mode with no results. I have Stop-zilla too.

When I search RegEdit I do find a registry value called "avserve.exe" which seems to be located in a folder called "Search Assistant." Sub-folder "ACMru," which contains 2 files, "5603," and "5604." I have tried to delete avserve.exe through Regedit but it doesn't go away. Listed along with that folder are 3 instances of lsass.exe.

Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 5:56:11 PM, on 1/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINXPPRO\System32\smss.exe
C:\WINXPPRO\system32\winlogon.exe
C:\WINXPPRO\system32\services.exe
C:\WINXPPRO\system32\lsass.exe
C:\WINXPPRO\system32\svchost.exe
C:\WINXPPRO\system32\svchost.exe
C:\WINXPPRO\Explorer.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?p=1153521247
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: VizController Class - {0F9CECE1-0306-4BB0-8BEF-C9EA3841E38A} - C:\Program Files\Vyooh\DiskView\VizBHO.dll
O2 - BHO: ZILLAbar BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\ZB2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {6A882320-BDD0-4ff4-BE3A-D8BAF82668E9} - (no file)
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\ZB2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINXPPRO\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXPPRO\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: Add to EverNote - res://C:\Program Files\EverNote\EverNote\enbar.dll/2000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {010136FD-5E80-11D8-9E86-0007E96C65AE} (SprtWMIControl Class) - http://supportcenter.rr.com/sdccommon/down…/sprtctlwmi.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143394812968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160076845843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://ib.dancik.com/ib/download/actimage40930.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugi…NetOpPlugin.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINXPPRO\system32\WPDShServiceObj.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINXPPRO\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe
O23 - Service: NsEngine - Unknown owner - C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXPPRO\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINXPPRO\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

I forgot to add that I cannot disable System Restore because I can't log in as administrator. I can't remember my password, if I ever set one. I think sys restore was already turned off before this started happening, but not sure. Is there a way to get into that setting another way? I don't know if the virus, if it is one, turned off that log-in ability, that would be a neat little trick to get itself re-installed every time the computer boots.

Thank you for your help.
Is no one able to help me at all? I cannot get this computer to boot up except in Safe Mode or Safe with networking. Should I even try to go on the internet in Safe mode/ I have NAV and I think it's running… I have now stopped system restore, although the System Restore tab never showed up in the System screens….will that help in any way? Ihave tried every tool I can find, PLEASE HELP ME!
Hello Juliane and welcome to the TomCoyote Forums! :wavey:

We apologize for the delay in replying. We are swamped with requests and some topics do occasionally get overlooked. Especially if you "bump" the topic. Our helpers often look for posts with no replies, which is why we advise to not bump the topic as seen in the Guidelines. I suspect this is why your posts were overlooked.

The lsass error is often because of a virus or malware. lsass.exe itself is a necessary Windows file, and thus should not be removed. Although the most notable virus exploiting lsass.exe was Sasser and Sasser is an old one that is recognized and removed by most if not all anti-virus programs. The problem seems to be that the memory can't be read where lsass is allocated when run in normal mode. It could perhaps be a problem with the file system.

If you still have the problem. Try the following:

Open "My Computer" (You can do this in safe mode) and right click on your C: drive. Choose "Properties"
In the Tools tab, click on the Check Now… button under "Error-Checking".
Put a check in the two boxes. Automatically fix system errors and Scan for and attempt recovery of bad sectors and then click Start.
It should give you a warning that it cannot run because it needs exclusive access to the drive and that Windows prevents it. Should you schedule it to scan on next restart? Click yes.
Restart the machine, it should proceed with Checkdisk. Be warned that checking for bad sectors makes the scan seem to take forever. It can take up to an hour depending on system speed and hard drive size. Do let it finish. It will display some information regarding the scan when it is complete, but the computer often restarts before you can see the info. There are ways to get to the log later, so do not worry about missing the info.

See if that helps.

Another thing you can try is running the System File Checker utility. You may need your Operating System disc though. To run it, go to Start - Run and type in this: sfc /scannow and press enter.
Note the space between the c and the /.
This utility will compare important protected system files and replace any that don't match or are corrupted.

As far as going online while in safe mode, it should not be done unless there is no other way. Safe Mode is used for troubleshooting, and should not be used to get online as most drivers and protection are disabled while in safe mode.

Post back if you need additional help.

Again, sorry for the delay.

Regards,
Thank you for replying. Can you tell me anything about my Hijack This log? I got the machine somewhat straightened out - it's lost that lsass.exe message and I can again access everything in regular boot mode. I uninstalled several suspect programs including Acrobat Reader (which was difficult to remove) and Microsoft Small Business Accounting (which included SQL Server, also difficult to extract). I don't think I ever had the virus, but I did end up getting a couple of messages about the security database parameter being wrong. I haven't found a fix for that yet. If I try to check the security settings, such as logs, the computer freezes and I get that error message. So I just haven't tried to do that. I assume it is something odd like that because I am also told I do not have the proper privilege level to change the date and time (one user should still have all powers). If you see anything weird in my log, please let me know. I've run HT several times now, and used Registry Mechanic, and not much has shown up, compared with others' logs I've seen posted here. Thanks again. Juliane
That log was fine. I don't see anything bad in there…

What fixed the error?

I don't think I ever had the virus, but I did end up getting a couple of messages about the security database parameter being wrong. I haven't found a fix for that yet.


If you get those messages again, write them down. The more actual info we have, the higher the chances at finding out what's wrong. Also please if you can include what exactly you were doing when the error occured would help maybe narrow it down.

I'm not sure I understand which security settings you are referring to.

If I try to check the security settings, such as logs, the computer freezes and I get that error message. So I just haven't tried to do that.


Which logs? And again, the exact error message might help.

I assume it is something odd like that because I am also told I do not have the proper privilege level to change the date and time (one user should still have all powers).

I'll look around and see if I can find a fix for that. Are you sure you are the only user and that you have admin rights? Just making sure.
To ensure your account does have administrative rights, you can go to Control Panel and choose User Accounts. It should list the names of all the accounts and their group under the name.

I'll post back when I have something on that.
I tried to get the message for you and the computer locked up on me! Here it is, typed out. What I do is go to Control Panel, Administrative Tools, then Local Security. If I click on User Controls or whatever, I get this message: "Security Templates. The Group Policy security settings that apply to this machine could nto be determined. The error returned when trying to rettive these settings from the local security policy database (%windir%\security/database/secedit.sdb) was: The parameter is incorrect. All local security settings will be displayed but not indication will be given as to whether or not a give security setting is defended (?)(not sure of my handwriting there) by Group Policy. Any local security setting modified through this User Interface may subsequently be overridden by domain-level policies." Once that message is displayed, the computer hangs, and I get a message that my virtual memory is low and Windows is increasing it. But then it just hangs. Last night all my desktop icons disappeared and I had to re-boot. I increased the pagefile size myself, but on the first screen it still has the same size displayed. My setting is on the second page, the first never changes. I am the sole user when in normal boot mode. Says "Admin." When I boot into safe mode, I can log-in as regular "me," or Administrator, which requires a password, but which still does not allow me to change the date and time, and some icons on the desktop don't show up. This may have happened because we had a hard drive crash and had to slave one drive and do another install on C. There are many duplicate files between the 2 drives now, and an IT guy did this, so perhaps he set up another account at some point. I have disabled Simple File Sharing per XP Annoyances books, but I doubt that is a factor.
I've pointed a few people here who might be able to help you with this problem. Hopefully we can help you fix the problems you are having. Hang on.
OK I think we're on to something here.

It appears as though the security policy settings are corrupted.

Here's an MS article that describes how to check the integrity and attempt a repair.
http://www.microsoft.com/resources/documen…n.mspx?mfr=true

Also note this thread where someone had a very similar problem and the fix posted by Doug Knox.

http://www.ureader.com/message/1448150.aspx

I'd suggest you try to do this.

Go to start - run and paste the following in the box.

esentutl /r %windir%\security\database\secedit.sdb

If that fails, try this.

esentutl /p %windir%\security\database\secedit.sdb

See if that clears it. If it succeeds, MS states in the above article that you should clear the log files in the Windows\Security folder.

Let me know how it goes.
Galadriel, the first command brings up a "black box" that only stays for a second, and disappears. No noticeable effect. The second command brings with it a warning, that repair should not be attempted unless I'm prepared to lose data from the log files, etc. or something like it. Should I just ignore that warning and do it anyway? What do I have to lose at this point? (I ask myself.) Thanks a bunch for this.
Just try it and see. They did mention in the article I linked above that the logs would need to be deleted after this step so I assume that's a needed step also. Good luck and hope that fixes the problem.
OK, I just ran that command. My HD is still intact, so I guess it didn't do anything that horrible! Where are these log files located, if you know? So far, nothing looks to be changed, but maybe on re-boot.
Well, I did everything I was supposed to, but still, when I click on "User Policy" in the Security admin. tool, the computer freezes, hangs up. I then cannot get the task manager up at all. Ctrl-Alt-Del does not work. Then it starts its little routine with increasing the virtual memory, and I have to re-boot to stop the cycle. Re-booting works to stop the hang. No error messages when starting and at least I can still get into normal boot mode! Any other ideas?
Hello Juliane,

Galadriel is catching up with some things and has requested assistance with your thread. I am a staff member from the Other Computer Problems forum here at Tom Coyote Forums. I'd like to help you out with the issues you are having.

First of all, let's recap on the situation and what has happened so far (my comments in blue):
  • Galadriel found nothing wrong with your HijackThis log
  • You stopped System Restore because you couldn't disable it
    Do you mean the System Restore Service?
  • lsass.exe Application Error
    • You tried to delete "avserve.exe" from the [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru] registry key
      This registry key stores the values of previous searches in the file system, all this value says is that you have searched for "avserve.exe" in the past. This key and values occur by design.
    • You uninstalled several suspected problematic programs, including Acrobat Reader and Microsoft Small Business Accounting
    • You have since resolved the lsass.exe Application Error
  • You began experiencing the Group Policy security settings error
    • Computer freezes up
    • Windows increases virtual memory
    • Only way to recover is a restart

Here are steps that you have taken to resolve your issues, per Galadriel's advice:
  • You ran the Windows CheckDisk utility
  • You ran the Windows System File Checker (SFC) utility
  • You ran the esentutl /r %windir%\Security\Database\Secedit.sdb command
  • You ran the esentutl /p %windir%\Security\Database\Secedit.sdb command
  • You deleted the log files in C:\WINXPPRO\security\logs
Along with your answer to my question on the second bullet above, please confirm that you have followed all of these steps so that we can proceed.

I look forward to your response,

Ax
Thank you for attempting to help me. Yes, I disabled System Restore long ago, because it can re-install viruses or malware on the computer, and it also takes up a lot of memory. I believe it was disabled before all the problems happened. I had not run the System File Check utility because it would not run in Safe Mode, but I did it just now, and nothing seemed to change because of it, but I haven't tried the security settings yet (don't want to freeze the computer right now). The date and time still says I can't change it because I don't have the proper "privilege level." I will try the security settings in a little while. Everything else on your list has been done at least once. Edit: I checked and the same thing happens. I open Control Panel and go to Administrative Tools, then Local Security Settings, then Local Policies, then User Rights Assignment. When I just click to expand that file, the computer freezes, and after a few minutes, I get that message about template parameters being wrong. Then after a while, while everything just hangs and the windows go blank or flicker, Windows says I don't have enough virtual memory and it is going to increase the pagefile size. Nothing happens after that - except sometimes I lose the desktop icons and all functionality. If you can help me figure this out, I will be very pleased. Thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI