Solved

Server not configured for transactions

Posted on 2004-08-22
14
2,912 Views
Last Modified: 2010-03-18
Hi All.

The famous error again. I have 40+ clients running under a Win2000 Server. From the last few days almost 5-10 clients, when im trying to access them from Network Neighbourhood is showing me an error message 'SERVER NOT CONFIGURED FOR TRANSACTIONS'. All the default administrattive shares are lost not even IPC$ on these clients . All the shares are ther on my Server. Gradually these PCs cannot connect to my Email server nor any of the network actions is taking place. I have Symantec Corporate. It didnt find any virus. My mail server had few viruses and i deleted all those files.
I followed all the previous posts on the same problem from Experts Exchange but no luck. Neither microsoft solution works - for example changing the AutoShareServer value in the registry. Day by day one by one PC is falling into this category.
Im in a real TEMPEST ... ANy help pls...
- Seige
0
Comment
Question by:kelpere
  • 5
  • 5
  • 4
14 Comments
 
LVL 41

Expert Comment

by:stevenlewis
ID: 11863776
0
 
LVL 20

Assisted Solution

by:Debsyl99
Debsyl99 earned 65 total points
ID: 11863780
Hi
Have a look at this, it sounds like you still have a virus problem, and with these trojans Symantec is just not picking them up - my fully update symantec av missed 7 trojans on my pc that trend online picked up. I suggest you start by running some of the online scanners against your machines, cleaning them up and then running the fix again,
PAQ on : Server not configured for transactions
http:Q_21010475.html
Collection of pest removal tools and advice
http:Q_20975384.html

Deb :))
0
 
LVL 41

Expert Comment

by:stevenlewis
ID: 11863785
0
 

Author Comment

by:kelpere
ID: 11863858
Stevenlewis and Debis!! i tried all the expert-exchange links yu gave me already but no solution at all. I re-installed one of OS of an infected PC. All the $ shares were there till i installed MS-Office. But once office 2000/2003 is installed these shares are gone.

StevenLewis! i can create $ shares but it is getting disappeared after 10 minutes or so. I tried to Put 'net share IPC $' as a BAT file on startup but still no luck,
One thing i noticed is that after 2-3 days few of these machines stops accessing the network. I cannot access shared folders on other machines nor i can browse the net or i can connect to the exchange server.

The exchange server had lot of viruse which i cleaned and deleted from the BADMAIL directory. Theres no trojans....
ALso none of my Registry entries has anything called AUTOSHAREWKS or AUTOSHARESERVER. These entries are coming only after I install POLEDIT. So registry dealings never helped.
Im having sleepless nights as i have 45 PCs and im the only one to run around :(
The count of machines showing this error is gradually increasing.

Pls pls pls..help me
0
 
LVL 41

Accepted Solution

by:
stevenlewis earned 60 total points
ID: 11863903
>>The count of machines showing this error is gradually increasing
an indication that this is viral/trojan
run ad-aware  ( www.lavasoft.de ) on these machines, and then run a free online virus scan
http://housecall.trendmicro.com/

http://security.symantec.com/

http://www.pandasoftware.com/activescan/com/activescan_principal.htm


0
 
LVL 20

Expert Comment

by:Debsyl99
ID: 11863914
Hi
Stevenlewis is correct I believe - you still have an infection and you need to track it down, disable it and remove it or the shares will not stay,
Have a look at the discussion here:
http://www.annoyances.org/exec/forum/win2000/t1031760762

Deb :))
0
 

Author Comment

by:kelpere
ID: 11867910
Hey guys...Great Thanks for the opinions.
Im running an Online Scan from TrendMicro and lot of Trojan Variants have been caught on many machines. An unwanted service SVCHOSTC.EXE is running on all these infected machines. I deleted this file and removed its reference from the Registry too (HKLM and HKCU)

The shares are not yet restored. I think i need to wait for that. I noted one more interesting thing. Yesterday on one of the infected PCs i re-installed the LAN card. After the re-install, much of my surprise the machine was able to be accessed from the network. It is not showing 'Server not configured for Txn' Error msg.
I got a svchostc removal tool from spyware. Im installing it on my nodes.
Im really disappointed why Symantec couldnt catch it:(

Another interesting thing is that today morning on one of the PC the display is totally upside down... Im really shocked and weird friends!!!!
What a hectic situation!!!!   Keep me posted and i will update yu guys too..
Thanks once again.... Let me see if the shares can be restored!!
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 

Author Comment

by:kelpere
ID: 11873086
Guys!! one more update.
I used TrendMicro to scan and delete the svchostc.exe . All the $ shares were restored. I did the same on almost 8 machines. I finished the 6th machine and when i checked back the 1st machine..... guess what!!! that blooded SVCHOSTC.EXE is running again and the registry entry is also restored.

Just for your information, i formatted one PC with Win 2K and when i put that on the network and installed MS-office on that machine all the $ shares just disappeared.

I really doubt that the virus is on the network... How shud i overcome or solve that... Just any ideas will be highly appreciated. I scanned the servers but no attacks there at all..
Pls advise...
0
 
LVL 20

Expert Comment

by:Debsyl99
ID: 11873198
Hi

You need to find what's spawning it - and that can really be trial and error - did you get a name for it or them or was it svchost.exe?
You could try donwloading msconfig for windows xp from here - see at the bottom of the page -(works with 2000)
http://www.thetechguide.com/downloads.html

After installing it you can run it from start-run- msconfig and use it to disable all unnecessay startup files and services - it can help you narrow down what's causing this particular svchost
Alternatively you could try posting a hijackthis logfile from the affected machine to start with,

Also exactly what did you do to get rid of it?

Deb :))

0
 
LVL 41

Expert Comment

by:stevenlewis
ID: 11876849
pull each machine off the network, clean it, and don't plug it back in untill all machines are cleaned (tedious, I know, but this way you will eliminate it)
0
 

Author Comment

by:kelpere
ID: 11880960
Stevenlewis!!! yu are giving me a tough time... 45 PCs and pulling out them one by one drives me crazy.
The worm is shown by trend Micro as WORM.RBOT.IF
Mind me its very dangerous. But still few PCs, the registry entries are coming back once i plug them on to network. Also the services are running.

On XP machines an exe is getting executed for the service to start . It is in C:\WINDOWS\CONFIG\mt.exe . I tried to delete the config folder, recreate a dummy mt.exe, delete the exe but still when i reboot the exe is created by default.

Deb! I used trend-micro to delete those files.  I tried SPYHUNTER but it is asking for money to clean the file. Adaware is good but i hvae to get the results yet.

Im bit relieved but still the worm is  alive on my network.....
More sleepless nights to come..... Any help guys
Seige
0
 
LVL 20

Expert Comment

by:Debsyl99
ID: 11881059
Hi
Some manual removal instructions here that will hopefully work - follow them exactly - if using win xp, you must both disable system restore first, then reboot insafe mode: (can't find worm.rbot.if so assume you meant the worm below)
Worm.RBot.af
http://www.pestpatrol.com/PestInfo/w/worm_rbot_af.asp#Detection%20and%20Removal

Also if you seriously want to remove this nasty little pain I strongly suggest you follow Stevenlewis' advice and disconnect each one from the network prior to cleaning and only plug them back in when you are happy that it's gone. A pain but has to be better than all these constantly disappearing shares eh?

Deb :))
0
 

Author Comment

by:kelpere
ID: 11919474
VOILA guys!!!!!!!

Everything is fine now. AFter the recent update now Symantec has detected and quarantined the culprit . It was W32.SPYBOT . Anyway as per yu guys advise, i unplugged each and every PC, detected and cleaned it using Trend Micro House Call and once 80% job is over Symantec started detecting it :)

Many many many thanks Deb and StevenLewis. I really dunno how to express my gratitude to you guys. I dont have any support here and thats why i depend on you guys.

Now im confused. I want to give points to both of you? Is it possible anyway? Once again many thanks guys for making my LAN up and running fine again.

Rgds
Seige
0
 
LVL 20

Expert Comment

by:Debsyl99
ID: 11920472
Hi

If you look at the bottom you'll see split points option, just click that and off you go - Glad we helped,

Deb :))
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Downtime reduced, data recovered by utilizing an Experts Exchange Business Account Challenge The United States Marine Corps employs more than 200,000 active-duty Marines with operations in four continents, all requiring complex networking system…
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now