Question
July 17, 2008 at 02:16 AM
akujenga

Windows 2000 Server active directory recovery

by akujenga . Updated 18 years ago

I’ve got a (IBM PII) W2K server that acts as a domain controller for a network of +/-40 Windows PCs. This machine seems to have been attacked by some spyware to a point of giving a blue screen during the startup process. I ran a virus scan using McAfee and a number of viruses were detected and cleaned. We also hooked the drive up as a slave on another machine and some more viruses were detected and cleaned. We’ve tried to repair the Windows installation but now the machine no longer gives the blue screen but simply stops responding during the boot process. If I try to boot into Safe Mode, it stops at the point “…\System32\DRIVERS\agp440.sys”. As if that was not enough, we had to move the drive from the original server because someone misfitted some RAM.

I unfortunately do not have a backup of the Active Directory database as the machine’s main role has been to be a domain controller and I never worried about backing up.

I would like to avoid having to recreate users and rejoin PCs to the domain. My question is: How can I restore things back to normal? Can I copy the Active Directory database if I hook the drive as a slave on another machine such that users can login and use shared resources as before? If not, how can I solve this problem?

Your assistance would be greatly appreciated.

This discussion is locked

All Comments