Last week we had a servercrash for the 4th time within 6 months. All four times were exactly the same causes (as for as we think). These are the symptoms:
- the desktop is completely empty and has a gray color.
- The programfolderlist in the startmenu Is totally empty.
- If we open the windows explorer we get a error “acces denied”. This is because all useraccount are deleted.
- If we approach the server from another pc, we see that the system32 folder is completely empty. Round about 75 % off all files are gone.
Things that are still operational (as long as we don’t reboot the server) are things like shares, printers, useraccounts, etc.
People who are working on the server are not awear on whats going one, the can still work.
The configuration on the server is as following:
- Windows NT 4.0 server with servicepack 6a wich acts like a PDC
- Backup Exec 9.1
- Mcafee E-policy Orchestrator
Between the first en the second crash we have changed from servername and IP adres. We also changed the entire server (hardware).
If we scan the harddisk for viruses the scanner doesn’t find anything suspicious. The scanner scans every night.
After the second crash we installed windows nt 4.0 server next to the winnt directoy wich crashed. So we created a winnt2 directory next to the other. At this way we where able to install a un-delete tool wich could tell us at what time al the files were deleted. For example at 12.00 PM exactly.
Lucky for us that this is no critical server. We have al important data and apps stored on the BDC. So everyone can stille continue working. We just really wanna know what the cause of this all is.
I thank you in advance,