Solved

Windows 2000 Repair NTDS.dit - Single DC no system backups available.

Posted on 2014-01-13
13
770 Views
Last Modified: 2014-01-25
Hello,

My one and only Windows 2000 DC RAID controller crashed this morning and it seemed to corrupt my AD database since I am not able to log in. Upon windows services loading up I received an Issas error stating to reboot into Directory services mode..

So I did. I looked up all the NTDUTIL.EXE and ESENTUTL.EXE commands in order to repair/recover the ntds.dit db but no luck.

Command outputs generated error such as:

Operation terminated with error -1811 (JET_errFileNotFound, File not found)

Is there any special software or utility that maybe able to successfully repair this?

or am I stuck having to rebuild the server? :\

thx
0
Comment
Question by:tobe1424
13 Comments
 
LVL 34

Assisted Solution

by:Seth Simmons
Seth Simmons earned 250 total points
ID: 39777483
you got a file not found error - did you specify the path/file name correctly?
if you rebuild it you will have to add your systems to the domain and create all user accounts again since you have no backup and starting from scratch
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39777597
If you have attempted to use ESENTDSUtil and this did not fix your ntds.dit database then you are probably out of luck. You could possibly call Microsoft as they have some tools that are not released to the public which might be able to help you.

Microsoft only charges you if they correct the issue. So if you DC is worth fixing at most you would be spending approx $300.00 is Microsoft corrects the issue. If not, then you don't pay.

Out side of that if you do not have any system state backups for your AD environment or a second domain controller then you are out of luck.

Will.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39777650
I don't think even MS will attempt to fix the issue as 2000 is out of support OS

Not sure if premium ticket (A grade) can allow to do this but they will charge $$$ hourly basis most probably

instead I suggest you to rebuild the server from scratch may be with latest OS (Windows 2008 at minimum)

Mahesh
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39777663
Even though 2000 is out of support they should be able to do a "best efforts" attempt. MS ticekts are not hourly they are per incident.

Will.
0
 

Author Comment

by:tobe1424
ID: 39777709
thx for the pointers. I ended up correcting the path to c:\winnt\ntds\ntds.dit and used some other options and the repair process finished..

I opted for a chkdsk upon boot up. Now it's starting back up. let see how it goes..

I will advise shortly. Thanks again
0
 

Accepted Solution

by:
tobe1424 earned 0 total points
ID: 39777748
The syntax below did the trick for me. my DC is now back online.


esentutl /p "c:\winnt\ntds\ntds.dit" /!10240 /8 /v /x /o


t
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39777768
Great to hear!

Will.
0
 

Author Comment

by:tobe1424
ID: 39786916
I've requested that this question be closed as follows:

Accepted answer: 250 points for seth2740's comment #a39777483
Assisted answer: 250 points for Spec01's comment #a39777597
Assisted answer: 0 points for tobe1424's comment #a39777748

for the following reason:

the syntax entered worked correctly
0
 

Author Comment

by:tobe1424
ID: 39786912
i ended up discovering the correct syntax with the help of seth and spec01
0
 

Author Comment

by:tobe1424
ID: 39786917
seth's pointer helped me discover the correct syntax i needed in order to rebuild my AD db.
0
 

Author Comment

by:tobe1424
ID: 39803462
sounds good to me
0

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now