Solved

SAM and SYSTEM hive

Posted on 2011-09-08
7
772 Views
Last Modified: 2012-05-12
With local  ladmin rights - can the admin copy the SAM and SYSTEM registry hives from a windows server? If not how can copies be obtained?
0
Comment
Question by:pma111
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 200 total points
ID: 36504894
I believe these files are not able to be copied while windows is running. I think you can access these files with a bootable linux CD or you may also be able to copy them using a tool like NT Offline.

http://www.pogostick.net/~pnh/ntpasswd/
0
 
LVL 3

Author Comment

by:pma111
ID: 36504907
I wondered if ntbackup would work
0
 
LVL 9

Assisted Solution

by:Ashok Dewan
Ashok Dewan earned 150 total points
ID: 36504938
you can copy only registry hives but not sam file. Download any mini windows live cd or any linux live cd.
1. Ubuntu
2. knoppix
these are bootable live cd's
http://www.ubuntu.com/download/ubuntu/download
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 9

Expert Comment

by:Ashok Dewan
ID: 36504947
sorry you also cannot copy registry hives.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 36504960
Another option you can try is this.

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.

Original posting here.
http://www.firewall.cx/ftopicp-21828.html
0
 
LVL 92

Assisted Solution

by:nobus
nobus earned 150 total points
ID: 36508670
or hook the drive to a working pc to copy the files
0
 
LVL 3

Author Comment

by:pma111
ID: 36508732
Its a live (v important server) so powering it down is out the equation or taking drives out.

I am suprised you cant just ntbackup the config folder :( then access them from a restored backup
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is an article about Leadership and accepting and adapting to new challenges. It focuses mostly on upgrading to Windows 10.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question