RE: SceSrv - 1003 by sjhari
sjhari
Wed Aug 11 16:15:25 CDT 2004
Hi,
Event ID: 1003
Description:
Policy change from LSA/SAM can't be saved in the policy storage. Error 5 to
save policy change for account S-1-1-0 in the default GPOs. For more
debugging information, please look security\logs\scepol.log under Windows
root.
Event ID: 1
Description:
The FireDaemon service has started.
CAUSE
This behavior may occur when a virus that uses the FireDaemon program to
run as a Windows service infects your computer. The virus changes the
default domain controller security policy so that no users have the Access
this computer from the network security policy setting in User Rights
Assignment.
RESOLUTION
To resolve this behavior, disable the FireDaemon services on your computer.
To disable the FireDaemon services, follow these steps:
Right-click My Computer, and then click Manage.
Expand Services and Applications, and then click Services.
Right-click any unwanted FireDaemon service, and then click Properties.
Note This issue has been reported for the following services:
FireDaemon Service: scvhost
FireDaemon Service: scvhostlog
FireDaemon Service: secure
In the Startup type box, click Disabled, and then click OK.
Thanks,
sjhari@online.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no rights.