Эврика !!!! Задача была успешно решена !!!
Итак, приехал на участок, имею 3 контроллера домена в одной сети, на 2х из них терминальные службы в режиме удаленного администрирования, на 3м - в режиме сервера приложений.
В результате кривого лечения от Sasser (как это и сам местный админ объяснить не может ) получили ситуацию сабджевого топика - отказ присоединения терминального клиента к серверам. На всех в диспетчере сервера терминалов отсутствовал т.н. "Слушатель RDP". Установка и удаление терминаьных служб результатов не приносила.
Мне помог (на всех 3 контроллерах) следующий ход:
1) Удаление ветки HKLM\SYSTEM\CCC\Control\Terminal Server\
2) Импорт ветки с заведомо рабочего сервака с работающими службами терминалов (на всякий случай вот этот reg)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server]
"DeleteTempDirsOnExit"=dword:00000001
"FirstCountMsgQPeeksSleepBadApp"=dword:0000000f
"Modems With Bad DSR"=hex(7):4d,00,75,00,6c,00,74,00,69,00,54,00,65,00,63,00,\
68,00,20,00,4d,00,75,00,6c,00,74,00,69,00,4d,00,6f,00,64,00,65,00,6d,00,20,\
00,4d,00,54,00,32,00,38,00,33,00,34,00,00,00,4d,00,75,00,6c,00,74,00,69,00,\
54,00,65,00,63,00,68,00,20,00,4d,00,75,00,6c,00,74,00,69,00,4d,00,6f,00,64,\
00,65,00,6d,00,20,00,4d,00,54,00,32,00,38,00,33,00,34,00,5a,00,44,00,58,00,\
00,00,4d,00,75,00,6c,00,74,00,69,00,54,00,65,00,63,00,68,00,20,00,4d,00,54,\
00,32,00,38,00,33,00,34,00,00,00,4d,00,75,00,6c,00,74,00,69,00,54,00,65,00,\
63,00,68,00,20,00,4d,00,54,00,32,00,38,00,33,00,34,00,5a,00,44,00,58,00,00,\
00,4d,00,75,00,6c,00,74,00,69,00,54,00,65,00,63,00,68,00,20,00,32,00,38,00,\
33,00,34,00,00,00,4d,00,75,00,6c,00,74,00,69,00,54,00,65,00,63,00,68,00,20,\
00,32,00,38,00,33,00,34,00,5a,00,44,00,58,00,00,00,00,00
"MsgQBadAppSleepTimeInMillisec"=dword:00000001
"NthCountMsgQPeeksSleepBadApp"=dword:00000005
"PerSessionTempDir"=dword:00000001
"ProductVersion"="5.0"
"TSEnabled"=dword:00000001
"IdleWinStationPoolCount"=dword:00000000
"TSAppCompat"=dword:00000000
"TSUserEnabled"=dword:00000000
"IAT"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Clip Redirector]
"Name"="RDPClip"
"Type"=dword:00000003
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Terminal Server Redirector]
"Name"="\\Device\\RdpDr"
"Type"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\AuthorizedApplications]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration]
"Callback"=dword:00000000
"CallbackNumber"=""
"Domain"=""
"InitialProgram"=""
"KeyboardLayout"=dword:00000000
"MaxConnectionTime"=dword:00000000
"MaxDisconnectionTime"=dword:00000000
"MaxIdleTime"=dword:00000000
"NWLogonServer"=""
"Password"=""
"Shadow"=dword:00000001
"UserName"=""
"WorkDirectory"=""
"fInheritAutoLogon"=dword:00000001
"fInheritCallback"=dword:00000000
"fInheritCallbackNumber"=dword:00000000
"fInheritInitialProgram"=dword:00000001
"fInheritMaxDisconnectionTime"=dword:00000000
"fInheritMaxIdleTime"=dword:00000000
"fInheritMaxSessionTime"=dword:00000000
"fInheritReconnectSame"=dword:00000000
"fInheritResetBroken"=dword:00000000
"fInheritShadow"=dword:00000000
"fLogonDisabled"=dword:00000000
"fPromptForPassword"=dword:00000001
"fReconnectSame"=dword:00000000
"fResetBroken"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Dos]
"KbdIdleBusymsAllowed"=dword:0000003c
"KbdIdleDetectAbsolute"=dword:00000001
"KbdIdleDetectProbationCount"=dword:00000050
"KbdIdleInProbationCount"=dword:00000023
"KbdIdlemsAllowed"=dword:00000000
"KbdIdlemsGoodProbationEnd"=dword:000009c4
"KbdIdlemsProbationTrial"=dword:000009c4
"KbdIdlemsSleep"=dword:00000064
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\KeyboardType Mapping]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\KeyboardType Mapping\JPN]
"00000000"="kbd101.dll"
"00000001"="kbdax2.dll"
"00000002"="kbd106.dll"
"00000003"="kbdibm02.dll"
"00010D01"="kbdnec95.dll"
"000000000017"="kbdlk41a.dll"
"000000020015"="kbdnecAT.dll"
"000000020017"="kbdlk41j.dll"
"00000D01"="kbdnecNT.dll"
"00000D04"="kbdnecNT.dll"
"00010002"="kbd106n.dll"
"00010D04"="kbdnec95.dll"
"00020002"="f3ahvoas.dll"
"00020D01"="kbdnecAT.dll"
"00020D04"="kbdnecAT.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\KeyboardType Mapping\KOR]
"00000003"="kbd101a.dll"
"00000004"="kbd101b.dll"
"00000005"="kbd101c.dll"
"00000006"="kbd103.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Utilities]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Utilities\change]
"logon"=hex(7):30,00,00,00,31,00,00,00,4c,00,4f,00,47,00,4f,00,4e,00,00,00,63,\
00,68,00,67,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,00,\
00,00
"port"=hex(7):30,00,00,00,31,00,00,00,50,00,4f,00,52,00,54,00,00,00,63,00,68,\
00,67,00,70,00,6f,00,72,00,74,00,2e,00,65,00,78,00,65,00,00,00,00,00
"user"=hex(7):30,00,00,00,31,00,00,00,55,00,53,00,45,00,52,00,00,00,63,00,68,\
00,67,00,75,00,73,00,72,00,2e,00,65,00,78,00,65,00,00,00,00,00
"winsta"=hex(7):31,00,00,00,31,00,00,00,57,00,49,00,4e,00,53,00,54,00,41,00,00,\
00,63,00,68,00,67,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,\
00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Utilities\query]
"appserver"=hex(7):30,00,00,00,32,00,00,00,54,00,45,00,52,00,4d,00,53,00,45,00,\
52,00,56,00,45,00,52,00,00,00,71,00,61,00,70,00,70,00,73,00,72,00,76,00,2e,\
00,65,00,78,00,65,00,00,00,00,00
"process"=hex(7):30,00,00,00,31,00,00,00,50,00,52,00,4f,00,43,00,45,00,53,00,\
53,00,00,00,71,00,70,00,72,00,6f,00,63,00,65,00,73,00,73,00,2e,00,65,00,78,\
00,65,00,00,00,00,00
"session"=hex(7):30,00,00,00,31,00,00,00,53,00,45,00,53,00,53,00,49,00,4f,00,\
4e,00,00,00,71,00,77,00,69,00,6e,00,73,00,74,00,61,00,2e,00,65,00,78,00,65,\
00,00,00,00,00
"user"=hex(7):30,00,00,00,31,00,00,00,55,00,53,00,45,00,52,00,00,00,71,00,75,\
00,73,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,00,00
"winsta"=hex(7):31,00,00,00,31,00,00,00,57,00,49,00,4e,00,53,00,54,00,41,00,00,\
00,71,00,77,00,69,00,6e,00,73,00,74,00,61,00,2e,00,65,00,78,00,65,00,00,00,\
00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Utilities\reset]
"session"=hex(7):30,00,00,00,31,00,00,00,53,00,45,00,53,00,53,00,49,00,4f,00,\
4e,00,00,00,72,00,77,00,69,00,6e,00,73,00,74,00,61,00,2e,00,65,00,78,00,65,\
00,00,00,00,00
"winsta"=hex(7):31,00,00,00,31,00,00,00,57,00,49,00,4e,00,53,00,54,00,41,00,00,\
00,72,00,77,00,69,00,6e,00,73,00,74,00,61,00,2e,00,65,00,78,00,65,00,00,00,\
00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\VIDEO]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\VIDEO\rdpdd]
"VgaCompatible"="\\Device\\Video0"
"\\Device\\Video0"="\\REGISTRY\\Machine\\System\\CurrentControlSet\\Services\\RDPDD\\Device0"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd]
"BaudRate"=dword:0000e100
"ByteSize"=dword:00000008
"CfgDll"="RDPCFGEX.DLL"
"ConnectType"=dword:00000001
"DeviceName"=""
"FlowHardwareRx"=dword:00000001
"FlowHardwareTx"=dword:00000001
"FlowType"=dword:00000001
"InputBufferLength"=dword:00000800
"MinEncryptionLevel"=dword:00000002
"Parity"=dword:00000000
"StopBits"=dword:00000000
"WdDLL"="rdpwd"
"WdPrefix"="RDP"
"WsxDLL"="rdpwsx"
"XoffChar"=dword:00000013
"XonChar"=dword:00000011
"fAutoClientDrives"=dword:00000000
"fAutoClientLpts"=dword:00000001
"fDisableCam"=dword:00000001
"fDisableCcm"=dword:00000001
"fDisableCdm"=dword:00000001
"fDisableEncryption"=dword:00000001
"fEnableBreakDisconnect"=dword:00000000
"fEnableDTR"=dword:00000001
"fEnableDsrSensitivity"=dword:00000000
"fEnableRTS"=dword:00000001
"fFlowSoftwareRx"=dword:00000001
"fFlowSoftwareTx"=dword:00000001
"fForceClientLptDef"=dword:00000001
"StartupPrograms"="rdpclip"
"WdFlag"=dword:00000036
"WdName"="Microsoft RDP 5.0"
"fDisableClip"=dword:00000000
"fDisableCpm"=dword:00000000
"fDisableLPT"=dword:00000000
"fInheritAutoClient"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\Tds]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\Tds\tcp]
"OutBufCount"=dword:00000006
"OutBufDelay"=dword:00000064
"OutBufLength"=dword:00000212
"PdClass"=dword:00000002
"PdDLL"="tdtcp"
"PdFlag"=dword:0000004e
"PdName"="tcp"
"PortNumber"=dword:00000d3d
"ServiceName"="tcpip"
"InteractiveDelay"=dword:0000000a
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations]
"Anonymous"=hex:01,00,04,80,a0,00,00,00,ac,00,00,00,00,00,00,00,14,00,00,00,02,\
00,8c,00,05,00,00,00,00,00,18,00,ff,03,0f,00,01,01,00,00,00,00,00,05,12,00,\
00,00,74,00,6c,00,00,00,1c,00,ff,03,0f,00,01,02,00,00,00,00,00,05,20,00,00,\
00,20,02,00,00,00,00,65,78,00,00,1c,00,a1,01,00,00,01,02,00,00,00,00,00,05,\
20,00,00,00,21,02,00,00,00,00,65,78,00,00,1c,00,20,00,00,00,01,02,00,00,00,\
00,00,05,20,00,00,00,22,02,00,00,00,00,65,78,00,00,18,00,20,00,00,00,01,01,\
00,00,00,00,00,01,00,00,00,00,22,02,00,00,01,01,00,00,00,00,00,05,12,00,00,\
00,01,01,00,00,00,00,00,05,12,00,00,00
"AppServer"=hex:01,00,04,81,60,00,00,00,6c,00,00,00,00,00,00,00,14,00,00,00,02,\
00,4c,00,03,00,00,00,00,00,14,00,ff,03,0f,00,01,01,00,00,00,00,00,05,12,00,\
00,00,00,00,18,00,ff,03,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,\
00,00,00,18,00,a1,01,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,\
01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
"RemoteAdmin"=hex:01,00,04,80,50,00,00,00,5c,00,00,00,00,00,00,00,14,00,00,00,\
02,00,3c,00,02,00,00,00,00,00,18,00,ff,03,0f,00,01,01,00,00,00,00,00,05,12,\
00,00,00,00,00,00,00,00,00,1c,00,ff,03,0f,00,01,02,00,00,00,00,00,05,20,00,\
00,00,20,02,00,00,00,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00
"DefaultSecurity"=hex:01,00,04,80,50,00,00,00,5c,00,00,00,00,00,00,00,14,00,00,\
00,02,00,3c,00,02,00,00,00,00,00,18,00,ff,03,0f,00,01,01,00,00,00,00,00,05,\
12,00,00,00,00,00,00,00,00,00,1c,00,ff,03,0f,00,01,02,00,00,00,00,00,05,20,\
00,00,00,20,02,00,00,00,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\Console]
"Callback"=dword:00000000
"CallbackNumber"=""
"Comment"="System Console"
"Domain"=""
"InitialProgram"=""
"InputBufferLength"=dword:00000000
"KeyboardLayout"=dword:00000000
"KeyboardName"="\\REGISTRY\\Machine\\System\\CurrentControlSet\\Services\\Kbdclass"
"MaxConnectionTime"=dword:00000000
"MaxDisconnectionTime"=dword:00000000
"MaxIdleTime"=dword:00000000
"MouseName"="\\REGISTRY\\Machine\\System\\CurrentControlSet\\Services\\Mouclass"
"OutBufCount"=dword:00000000
"OutBufDelay"=dword:00000000
"OutBufLength"=dword:00000000
"Password"=""
"PdClass"=dword:00000001
"PdDll"=""
"PdFlag"=dword:0000001e
"PdName"="console"
"Shadow"=dword:00000000
"UserName"=""
"WdDll"="wdcon"
"WdFlag"=dword:00000000
"WdName"="Console"
"WorkDirectory"=""
"fEnableWinStation"=dword:00000001
"fInheritAutoLogon"=dword:00000000
"fInheritCallback"=dword:00000000
"fInheritCallbackNumber"=dword:00000000
"fInheritInitialProgram"=dword:00000000
"fInheritMaxDisconnectionTime"=dword:00000000
"fInheritMaxIdleTime"=dword:00000000
"fInheritMaxSessionTime"=dword:00000000
"fInheritReconnectSame"=dword:00000000
"fInheritResetBroken"=dword:00000000
"fInheritShadow"=dword:00000000
"fLogonDisabled"=dword:00000000
"fPromptForPassword"=dword:00000001
"fReconnectSame"=dword:00000000
"fResetBroken"=dword:00000000
"fUseDefaultGina"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]
"CfgDll"="RDPCFGEX.DLL"
"fEnableWinStation"=dword:00000001
"MaxInstanceCount"=dword:ffffffff
"PdName"="tcp"
"PdClass"=dword:00000002
"PdDLL"="tdtcp"
"PdFlag"=dword:0000004e
"OutBufLength"=dword:00000212
"OutBufCount"=dword:00000006
"OutBufDelay"=dword:00000064
"InteractiveDelay"=dword:00000032
"PortNumber"=dword:00000d3d
"KeepAliveTimeout"=dword:00000000
"LanAdapter"=dword:00000000
"WdName"="Microsoft RDP 5.0"
"WdDLL"="rdpwd"
"WsxDLL"="rdpwsx"
"WdFlag"=dword:00000036
"InputBufferLength"=dword:00000800
"CdClass"=dword:00000000
"CdName"=""
"CdDLL"=""
"CdFlag"=dword:00000000
"Comment"=""
"fInheritAutoLogon"=dword:00000001
"fInheritResetBroken"=dword:00000001
"fInheritReconnectSame"=dword:00000001
"fInheritInitialProgram"=dword:00000001
"fInheritCallback"=dword:00000000
"fInheritCallbackNumber"=dword:00000001
"fInheritShadow"=dword:00000001
"fInheritMaxSessionTime"=dword:00000001
"fInheritMaxDisconnectionTime"=dword:00000001
"fInheritMaxIdleTime"=dword:00000001
"fInheritAutoClient"=dword:00000001
"fInheritSecurity"=dword:00000000
"fPromptForPassword"=dword:00000001
"fResetBroken"=dword:00000000
"fReconnectSame"=dword:00000000
"fLogonDisabled"=dword:00000000
"fAutoClientDrives"=dword:00000000
"fAutoClientLpts"=dword:00000001
"fForceClientLptDef"=dword:00000001
"fDisableEncryption"=dword:00000001
"fHomeDirectoryMapRoot"=dword:00000000
"fUseDefaultGina"=dword:00000000
"fDisableCpm"=dword:00000000
"fDisableCdm"=dword:00000001
"fDisableCcm"=dword:00000001
"fDisableLPT"=dword:00000000
"fDisableClip"=dword:00000000
"fDisableExe"=dword:00000000
"fDisableCam"=dword:00000001
"Username"=""
"Domain"=""
"Password"=""
"WorkDirectory"=""
"InitialProgram"=""
"CallbackNumber"=""
"Callback"=dword:00000000
"Shadow"=dword:00000001
"MaxConnectionTime"=dword:00000000
"MaxDisconnectionTime"=dword:00000000
"MaxIdleTime"=dword:00000000
"KeyboardLayout"=dword:00000000
"MinEncryptionLevel"=dword:00000002
"NWLogonServer"=""
"WFProfilePath"=""
"WdPrefix"="RDP"
"TraceEnable"=dword:00000000
"TraceDebugger"=dword:00000000
"TraceClass"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\UserOverride]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\UserOverride\Control Panel]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\UserOverride\Control Panel\Desktop]
"Wallpaper"="(none)"
3) После чего следовала перезагрузка сервера (в одном из случаев я потом получил сообщение о сбое службы терминалов, помогла переустановка терминальных служб). После чего слушатель RDP-появился и подключение к удаленному рабочему столу (терминальный режим) заработали.
В результате сравнения существующего на момент аварии и импортируемого reg-файла выявило следующие отличия:
В "битом" реестре присутствовали строки, (отсутствовавшие в рабочем):
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\lanatable]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\lanatable\{F3AE46EA-07CD-43CE-824C-6175CCA53DA7}]
"LanaId"=dword:00000002
"Security"=hex:01,00,04,80,74,00,00,00,80,00,00,00,00,00,00,00,14,00,00,00,02,\
00,60,00,04,00,00,00,00,00,14,00,ff,03,0f,00,01,01,00,00,00,00,00,05,12,00,\
00,00,00,00,18,00,ff,03,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,\
00,00,00,14,00,ff,03,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,00,00,18,00,\
ff,03,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,\
00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
В рабочем реестре присутствовали строки:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\VIDEO\rdpdd]
"VgaCompatible"="\\Device\\Video0"
"\\Device\\Video0"="\\REGISTRY\\Machine\\System\\CurrentControlSet\\Services\\RDPDD\\Device0"
Кроме того найденные отличия в одинаковых ветках:
рабочая - "TSEnabled"=dword:00000001
битая - "TSEnabled"=dword:00000000
vBulletin v3.6.4, Copyright ©2000-2025, Jelsoft Enterprises Ltd.