Solved

SAM and SYSTEM hive

Posted on 2011-09-08
7
767 Views
Last Modified: 2012-05-12
With local  ladmin rights - can the admin copy the SAM and SYSTEM registry hives from a windows server? If not how can copies be obtained?
0
Comment
Question by:pma111
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 200 total points
ID: 36504894
I believe these files are not able to be copied while windows is running. I think you can access these files with a bootable linux CD or you may also be able to copy them using a tool like NT Offline.

http://www.pogostick.net/~pnh/ntpasswd/
0
 
LVL 3

Author Comment

by:pma111
ID: 36504907
I wondered if ntbackup would work
0
 
LVL 9

Assisted Solution

by:Ashok Dewan
Ashok Dewan earned 150 total points
ID: 36504938
you can copy only registry hives but not sam file. Download any mini windows live cd or any linux live cd.
1. Ubuntu
2. knoppix
these are bootable live cd's
http://www.ubuntu.com/download/ubuntu/download
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 9

Expert Comment

by:Ashok Dewan
ID: 36504947
sorry you also cannot copy registry hives.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 36504960
Another option you can try is this.

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.

Original posting here.
http://www.firewall.cx/ftopicp-21828.html
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 150 total points
ID: 36508670
or hook the drive to a working pc to copy the files
0
 
LVL 3

Author Comment

by:pma111
ID: 36508732
Its a live (v important server) so powering it down is out the equation or taking drives out.

I am suprised you cant just ntbackup the config folder :( then access them from a restored backup
0

Featured Post

[Webinar] Disaster Recovery and Cloud Management

Learn from Unigma and CloudBerry industry veterans which providers are best for certain use cases and how to lower cloud costs, how to grow your Managed Services practice in IaaS clouds, and how to utilize public cloud for Disaster Recovery

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Dual boot for S.O 7 35
Windows IPv6 DHCP server 8 38
Auto-indent certain lines in Notepad++ 10 35
BOSD APC_INDEX_MISMATCH - who's the culprit ? 4 30
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Know what services you can and cannot, should and should not combine on your server.
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now