Windows Server - SBS 2003 Event ID 7011 is freezing the network

Asked By Andy on 08-Mar-11 10:21 AM
We have a network of 11 computers with Small Business Server 2003 running on a HP ML350 G3

This error is created in the event log but there was no other entry for over an hour before

How can we diagnose this issue?

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7011
Date:  08/03/2011
Time:  13:58:02
User:  N/A
Computer: SERVER
Description:
Timeout (30000 milliseconds) waiting for a transaction response from the NtFrs service.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Mike Manny replied to Andy on 08-Mar-11 10:59 AM
You can change the time out and see if this resolves the issue: 
Although, microsoft calls it a "fix" i call it a "workaround" until a fix can be found, lets be honest here.
This can be from a lack of resources on the server, which i Highly suspect.  What does the server do? 
How much Memory is installed?  Is the CPU constanly maxed? Is the Memory paging constantly?  Does this even coincide with a virus scan or virus update?  a backup of SQL.   etc etc..

To figure out exactly what is causing it, give as many details as you can.   What exactly does the small business server do that is.  What kind of hardware does the HP ML350 g3 have inside. 



Event ID 7011 — Basic Service Operations

Updated: December 11, 2025

Applies To: Windows Server 2008

red

Service Control Manager transmits control requests to running services and driver services. It also maintains status information about those services, and reports configuration changes and state changes.

Event Details

Product: Windows Operating System
ID: 7011
Source: Service Control Manager
Version: 6.0
Symbolic Name: EVENT_TRANSACT_TIMEOUT
Message: Timeout (%1 milliseconds) waiting for a transaction response from the %2 service.

Resolve

Increase the service timeout period

The Service Control Manager will generate an event if a service does not respond within the defined timeout period (the default timeout period is 30000 milliseconds). To resolve this problem, use the Registry Editor to change the default timeout value for all services.

To perform this procedure, you must have membership in Administrators, or you must have been delegated the appropriate authority.

Caution: Incorrectly editing the registry may severely damage your system. Before making changes to the registry, you should back up any valued data.

To change the service timeout period:

  1. Click the Start button, then click Run, type regedit, and click OK.
  2. In the Registry Editor, click the registry subkey HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control.
  3. In the details pane, locate the ServicesPipeTimeout entry, right-click that entry and then select Modify.

    Note: If the ServicesPipeTimeout entry does not exist, you must create it by selecting New on the Edit menu, followed by the DWORD Value, then typing ServicesPipeTimeout, and clicking Enter.

  4. Click Decimal, enter the new timeout value in milliseconds, and then click OK.
  5. Restart the computer.

Verify

To perform this procedure, you must have membership in Administrators, or you must have been delegated the appropriate authority.

To verify the state in which a service is operating:

  1. Click the Start button, Run, then type cmd to open a command prompt.
  2. Type sc interrogate service_name (where service_name is the name of the service) at the command prompt to update the status of that service in Service Control Manager.
  3. Type sc qc service_name at the command prompt to display the configuration status of the service.
  4. Type sc queryex service_name at the command prompt to display the extended status of the service. This command will provide the following information about a service: SERVICE_NAME (the service's registry subkey name), TYPE (the type of service, for example, shared process, interactive), STATE (for example, running, paused, and the states that are not available), WIN32_EXIT_CODE (the Windows exit error code), SERVICE_EXIT_CODE (the service exit code), CHECKPOINT, WAIT_HINT (the time period the SCM waits before reporting a service failure), PID (ID of the process running the service), and FLAGS. If the service was started successfully, the WIN32_EXIT_CODE field should contain a zero (0). If the service failed to start when an attempt was made, this field should contain an exit code provided by the service when it could not start.
  5. Type net helpmsg exit_code (where exit_code is the 4 digit number of the error code) at the command prompt to display the meaning of the exit code.

Andy replied to Mike Manny on 08-Mar-11 11:25 AM
Thanks for such a quick reply...
Just before I make this change, I notice that it says that "applies to Windows Server 2008"

Is this registry change the same as SBS 2003?

Thanks
Andy replied to Mike Manny on 08-Mar-11 11:59 AM
The server is an old ML350 G3
Xeon 3.0Ghz processor
3GB Ram
Smart Array 641 controller
2x 1000rpm scsi drives in a mirrored raid

SBS 2003 is just being used as a file server.

Trend Micro WFBS-A - The messaging security agent is not installed as they don't use Exchange (just local PST's)

Backup was backup exec but we have removed that and now using remote backup.

Aparently this issue has been there for over a year!

Shadow copy seems to trigger the error but the error can appear without an event before it

Monitoring and reporting also seemed to trigger the event hourly
Mike Manny replied to Andy on 08-Mar-11 12:20 PM
What is your update A/V policy?  Is there any scheduled re-accurring task that is accuring.  YOu say it happens alot with VSS.  Is it possible to install a nother small internal hard drive and move VSS to that disk?  It could be from a large number of I/O to one disk.  It sounds like you have everything hitting the same disk for all server operations.  Backup exec has it's own shadow copy providers, as does microsoft, as does vm ware.  You can do a VSadmin list Providers to see all VS writers, please list them for me.

here is the 2003 one for changing that value, same thing looks like, sorry about that (or similar)
http://support.microsoft.com/kb/922918
To work around this problem, modify the registry to increase the default time-out value for the service control manager. To increase this value to 60 seconds, follow these steps:
  1. Click Start, click Run, type regedit, and then click OK.
  2. Locate and then click the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
  3. In the right pane, locate the ServicesPipeTimeout entry.

    Note If the ServicesPipeTimeout entry does not exist, you must create it. To do this, follow these steps:
    1. On the Edit menu, point to New, and then click DWORD Value.
    2. Type ServicesPipeTimeout, and then press ENTER.
  4. Right-click ServicesPipeTimeout, and then click Modify.
  5. Click Decimal, type 60000, and then click OK.

    This value represents the time in milliseconds before a service times out.
  6. Restart the computer.
Note This workaround may resolve the problem where the service does not start. However, we recommend that you research this problem to determine whether it is a symptom of another problem.
Andy replied to Mike Manny on 08-Mar-11 01:05 PM
AV is updating regular but it doesn't seem to be that...
Shadow copy is the only scheduled task

I could install another hdd but this server really has such little use, I can't believe that it is overworked!

C:\Documents and Settings\Administrator>VSSadmin list Providers
vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001 Microsoft Corp.

Provider name: 'Microsoft Software Shadow Copy provider 1.0'
   Provider type: System
   Provider Id: {b5946137-7b9f-4925-af80-51abd60b20d5}
   Version: 1.0.0.7



Thanks
Andy replied to Mike Manny on 08-Mar-11 03:03 PM
This error is after changing timeout to 60000...

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7011
Date:  08/03/2011
Time:  19:40:07
User:  N/A
Computer: DILSERVER
Description:
Timeout (60000 milliseconds) waiting for a transaction response from the NtFrs service.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Mike Manny replied to Andy on 08-Mar-11 03:32 PM
How often do you have VSS kicking off?  If VSS kicks off to often it can also cause this issue. We have it set on ours to once a hour. that seems to be fine.  IF multiple things are trying to leverage VSS you could see this, such as shadow copy and a backup at the same time. 

Another thing, is you A/V running any scans during the day? 

Ironically, i found another post with someone who seems to have teh same hardware as you, and very similar cercumstances..http://forums.techarena.in/small-business-server/393794.htm

Doing another google search (http://www.google.com/search?hl=en&q=HP+ML350+ntfrs&aq=f&aqi=&aql=&oq=f
It scares me to see this happen on so many of your server setups.  I'm guessing there could be a bios update that will fix the issue...

Looking at this post http://social.technet.microsoft.com/Forums/en-US/smallbusinessserver/thread/13a94af4-a32c-417c-bed7-452b296a4ba1  on your server, it was the way this persons A/V was recording logs that caused their issue.

http://support.microsoft.com/kb/932755 HP Advisory also had suggested installing this update on ProLiant ML servers. 
 
We'll start with these, i'm confident it's an issue that is caused by your server and something very fixable.


Andy replied to Mike Manny on 10-Mar-11 02:33 PM
I set vss to twice per day,,, if it was every hour Mike - no one would get any work done!

I disabled the AV for 1 day but still had the issue...

I've also seen this issue all over the web but no one seems to have posted the answer!

Maybe I should install every possible HP update and see if that works - then go for the Microsoft update!

I can't do it until the weekend so I will post back with any news

Any other suggestions are welcome

Thanks Andy