DNS server has encountered a critical error from the Active Directory

Hello -
I am trying to help troubleshoot some issues on a small office network with MS 2003 Small Business Server and  Win 2000 clients. We've had sporadic Internet / file sharing problems and then on Monday, one user lost his H:\ (home) mapped drive and then later his S:\ (shared ) netwqork drive letters which are mapped to the server. I'll paste in entries that seem related from the Event Viewer. Can anyone make heads or tails? I'm not a DNS or A.D. expert but it all seems to boil down to one or both of those is misconfigured. Here are the events:

=========================
Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4015
Date:            11/15/2004
Time:            3:25:03 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly.

The extended error debug information (which may be empty) is "". The event data contains the error.

For more information, see

Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 51 00 00 00               Q...    


=================

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
Date:            11/15/2004
Time:            3:25:03 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
The DNS server was unable to complete directory service enumeration of zone _msdcs.[server].local.  This DNS server is configured

to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the Active

Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is

"". The event data contains the error.

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00               *#..    


===========================

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
Date:            11/15/2004
Time:            3:25:03 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
The DNS server was unable to complete directory service enumeration of zone 1.168.192.in-addr.arpa.  This DNS server is

configured to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the

Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be

empty) is "". The event data contains the error.

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00               *#..    


===========================

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
Date:            11/15/2004
Time:            3:25:03 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
The DNS server was unable to complete directory service enumeration of zone 7.168.192.in-addr.arpa.  This DNS server is

configured to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the

Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be

empty) is "". The event data contains the error.

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00               *#..    


================================

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
Date:            11/15/2004
Time:            3:25:03 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
The DNS server was unable to complete directory service enumeration of zone [SERVER].local.  This DNS server is configured to

use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the Active

Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is

"". The event data contains the error.

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00               *#..    

=======================

Event Type:      Warning
Event Source:      NTDS ISAM
Event Category:      Performance
Event ID:      507
Date:            11/15/2004
Time:            10:58:08 PM
User:            N/A
Computer:      [SERVER-NAME-HERE]
Description:
NTDS (556) NTDSA: A request to read from the file "C:\WINDOWS\NTDS\ntds.dit" at offset 9969664 (0x0000000000982000) for

8192 (0x00002000) bytes succeeded, but took an abnormally long time (104 seconds) to be serviced by the OS. This problem is

likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

For more

information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

RickNCNAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

WeHeCommented:
looks like a corrupted AD (ntds.dit file).
try to repair, booted into Directory Service Restore Mode, with ntdsutil
if you dont know your DSRM password, you can set it with ntdsutil from any other client (ntdsutil -> set dsrm password).
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
RickNCNAuthor Commented:
Would the DSRM password just be the Administrator's password?
0
WeHeCommented:
no. it is the password you entered while doing dcpromo.
dcpromo process asks you for a DSRM Password.
Administrator is not avail because a DC does not have any local accounts (only DSRM)
0
Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

RickNCNAuthor Commented:
I'm not sure what dcpromo is. I have a vague understanding, but don't think I "did" dcpromo. Would I have done that during server OS installation? I'm not quite following.
0
WeHeCommented:
I forgot the SBS Version of W2K3.
It should be the administrator password, yes.
0
RickNCNAuthor Commented:
I haven't tried this yet, and may not get to it soon, so am awarding the points because it seems very likely to be the problem/solution. Thank you.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.