Solved

SAM and SYSTEM hive

Posted on 2011-09-08
7
762 Views
Last Modified: 2012-05-12
With local  ladmin rights - can the admin copy the SAM and SYSTEM registry hives from a windows server? If not how can copies be obtained?
0
Comment
Question by:pma111
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 200 total points
ID: 36504894
I believe these files are not able to be copied while windows is running. I think you can access these files with a bootable linux CD or you may also be able to copy them using a tool like NT Offline.

http://www.pogostick.net/~pnh/ntpasswd/
0
 
LVL 3

Author Comment

by:pma111
ID: 36504907
I wondered if ntbackup would work
0
 
LVL 9

Assisted Solution

by:Ashok Dewan
Ashok Dewan earned 150 total points
ID: 36504938
you can copy only registry hives but not sam file. Download any mini windows live cd or any linux live cd.
1. Ubuntu
2. knoppix
these are bootable live cd's
http://www.ubuntu.com/download/ubuntu/download
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 9

Expert Comment

by:Ashok Dewan
ID: 36504947
sorry you also cannot copy registry hives.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 36504960
Another option you can try is this.

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.

Original posting here.
http://www.firewall.cx/ftopicp-21828.html
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 150 total points
ID: 36508670
or hook the drive to a working pc to copy the files
0
 
LVL 3

Author Comment

by:pma111
ID: 36508732
Its a live (v important server) so powering it down is out the equation or taking drives out.

I am suprised you cant just ntbackup the config folder :( then access them from a restored backup
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Know what services you can and cannot, should and should not combine on your server.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now