You have to cope with how tenacious root hints are.
The copy in AD is loaded preferentially either from the DomainDNSZones application partition or from the domain partition (as above).
If the copy from AD fails to load "cache.dns" is loaded.
Only if both copies in AD, and cache.dns are deleted (or renamed), and only after the DNS service is restarted will any change become apparent.
Chris