Solved

Windows 2000 Repair NTDS.dit - Single DC no system backups available.

Posted on 2014-01-13
13
781 Views
Last Modified: 2014-01-25
Hello,

My one and only Windows 2000 DC RAID controller crashed this morning and it seemed to corrupt my AD database since I am not able to log in. Upon windows services loading up I received an Issas error stating to reboot into Directory services mode..

So I did. I looked up all the NTDUTIL.EXE and ESENTUTL.EXE commands in order to repair/recover the ntds.dit db but no luck.

Command outputs generated error such as:

Operation terminated with error -1811 (JET_errFileNotFound, File not found)

Is there any special software or utility that maybe able to successfully repair this?

or am I stuck having to rebuild the server? :\

thx
0
Comment
Question by:tobe1424
13 Comments
 
LVL 34

Assisted Solution

by:Seth Simmons
Seth Simmons earned 250 total points
ID: 39777483
you got a file not found error - did you specify the path/file name correctly?
if you rebuild it you will have to add your systems to the domain and create all user accounts again since you have no backup and starting from scratch
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39777597
If you have attempted to use ESENTDSUtil and this did not fix your ntds.dit database then you are probably out of luck. You could possibly call Microsoft as they have some tools that are not released to the public which might be able to help you.

Microsoft only charges you if they correct the issue. So if you DC is worth fixing at most you would be spending approx $300.00 is Microsoft corrects the issue. If not, then you don't pay.

Out side of that if you do not have any system state backups for your AD environment or a second domain controller then you are out of luck.

Will.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39777650
I don't think even MS will attempt to fix the issue as 2000 is out of support OS

Not sure if premium ticket (A grade) can allow to do this but they will charge $$$ hourly basis most probably

instead I suggest you to rebuild the server from scratch may be with latest OS (Windows 2008 at minimum)

Mahesh
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39777663
Even though 2000 is out of support they should be able to do a "best efforts" attempt. MS ticekts are not hourly they are per incident.

Will.
0
 

Author Comment

by:tobe1424
ID: 39777709
thx for the pointers. I ended up correcting the path to c:\winnt\ntds\ntds.dit and used some other options and the repair process finished..

I opted for a chkdsk upon boot up. Now it's starting back up. let see how it goes..

I will advise shortly. Thanks again
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Accepted Solution

by:
tobe1424 earned 0 total points
ID: 39777748
The syntax below did the trick for me. my DC is now back online.


esentutl /p "c:\winnt\ntds\ntds.dit" /!10240 /8 /v /x /o


t
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39777768
Great to hear!

Will.
0
 

Author Comment

by:tobe1424
ID: 39786916
I've requested that this question be closed as follows:

Accepted answer: 250 points for seth2740's comment #a39777483
Assisted answer: 250 points for Spec01's comment #a39777597
Assisted answer: 0 points for tobe1424's comment #a39777748

for the following reason:

the syntax entered worked correctly
0
 

Author Comment

by:tobe1424
ID: 39786912
i ended up discovering the correct syntax with the help of seth and spec01
0
 

Author Comment

by:tobe1424
ID: 39786917
seth's pointer helped me discover the correct syntax i needed in order to rebuild my AD db.
0
 

Author Comment

by:tobe1424
ID: 39803462
sounds good to me
0

Featured Post

The curse of the end user strikes again      

You’ve updated all your end user’s email signatures. Hooray! But guess what? They’re playing around with the HTML, adding stupid taglines and ruining the imagery. Find out how you can save your signatures from end users today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now