LSASS.exe在我的SBS2003 DC上使用100%的CPU使用率。
对于我的生活,我无法弄清楚是什么原因造成的。 我检查了事件日志,发现了一些事情。 我看不出有什么关系。 除了ActiveSync错误(很久以前,在发生此问题之前启动)之外,没有任何内容会定期login。
有几个日志,
Event Type: Warning Event Source: MSDTC Event Category: SVC Event ID: 53258 Date: 02.05.2013 Time: 5:43:20 pm User: N/A Computer: SERVER Description: MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: %1 For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
和
Event Type: Error Event Source: MSExchangeSA Event Category: RFR Interface Event ID: 9143 Date: 02.05.2013 Time: 5:42:58 pm User: N/A Computer: SERVER Description: Referral Interface cannot contact any Global Catalog that supports the NSPI Service. Clients making RFR requests will fail to connect until a Global Catalog becomes available again. After a Domain Controller is promoted to a Global Catalog, it must be rebooted to support MAPI Clients. For more information, click http://www.microsoft.com/contentredirect.asp.
还有一些MSExchangeAL错误;
Event Type: Error Event Source: MSExchangeAL Event Category: LDAP Operations Event ID: 8026 Date: 02.05.2013 Time: 5:31:32 pm User: N/A Computer: SERVER Description: LDAP Bind was unsuccessful on directory SERVER.etcetera.local for distinguished name ''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.
和
Event Type: Error Event Source: MSExchangeAL Event Category: Service Control Event ID: 8250 Date: 02.05.2013 Time: 5:31:19 pm User: N/A Computer: SERVER Description: The Win32 API call 'DsGetDCNameW' returned error code [0x862] The specified component could not be found in the configuration information. The service could not be initialized. Make sure that the operating system was installed properly. For more information, click http://www.microsoft.com/contentredirect.asp.
和
Event Type: Error Event Source: MSExchangeAL Event Category: LDAP Operations Event ID: 8026 Date: 02.05.2013 Time: 5:31:19 pm User: N/A Computer: SERVER Description: LDAP Bind was unsuccessful on directory SERVER.etcetera.local for distinguished name ''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.
这是这个域中唯一的服务器。 那么我假设,这个问题是来自这台机器的,所以我一直在关注这个部分。
http://blogs.technet.com/b/askds/archive/2007/08/23/troubleshooting-high-lsass-cpu-utilization-on-a-domain-controller-part-2-of-2.aspx
我已经尝试了几个我见过的选项。 我在“RASSFM KDCSVC WDIGEST scecli dsrestor”的HKLM \ System \ CurrentControlSet \ Control \ LSA中的Notification Packages中有条目。 我读过这里的标准条目不包括dsrestor条目,虽然我很犹豫,说这是问题(我有一个中断时间今晚testing删除这个+重新启动)。
任何人有任何想法,我可以尝试?
谢谢! -Ewan
好的,我发现了这个问题。 傻我 – 我没有注意到有一个重复的LSASS.exe。 原来这是恶意软件挖掘BitCoins,因此CPU使用率很高。