you don't demote the bad server. It looks like it stuffed (technical term!).
you sieze the roles from it using the ndsutil, see Microsoft Technet Article above, and the new server you transfer the roles to becomes the new FSMO, Schema, Domain Naming Master, PDC , RID, Infrastructure, and GC.
once this is done, your AD should be working again correctly, and users should be able to authenticate.
then you shutdown this server and rebuild, in the future, if you need it to be a DC again, use dcpromo etc.
But before you shutdown and rebuild, you need to ensure it doesn't perform any useful roles, like file server, print server, dhcp etc DNS should be running on the other two servers correct?
where are the folders stored and shared?
(interesting we also had the same issue at a school!)