Solved

Windows 2000 Server

Posted on 2006-06-26
11
220 Views
Last Modified: 2011-09-20
I have a windows 2000 server that allows for remote desktop and is a domain controller.  Sometime over the weekend, a very important directory was deleted somehow.  I really need to find out how this happened.  How can I track down how and who caused this.  It was not a system directory, it was a data folder with crucial information to an in-house application.  As a matter of fact it was on a separate partitian(d:).  What are my options on how to track down what happened????
0
Comment
Question by:gvector1
  • 3
  • 2
  • 2
  • +3
11 Comments
 
LVL 12

Accepted Solution

by:
GinEric earned 500 total points
ID: 16984355
EventViewer, Security, should show all changes of every user.  It might be a little long getting through it.  This assumes you have certain audits on, such as logon success, change permissions, things like that.

The point being, it is most likely somewhere in your logs.

Secondly, it may not actually be gone, or perhaps not fully.  But if you recreate it, it will be gone, replaced by the new creation.

It will take time to track down the event, in any case, but it can be done through the logs.
0
 
LVL 13

Expert Comment

by:Kini pradeep
ID: 16984361
do you have auditing enabled for files and folders, if yes then you could go through the security logs and find out, who did it ( not how it happened) else i dont think there is a way out.
other might know better.

http://www.microsoft.com/technet/security/topics/serversecurity/tcg/tcgch03n.mspx

0
 
LVL 13

Expert Comment

by:itcoza
ID: 16984383
Hi gvector1,

Just one small problem, if you have not set auditing in the past, you may not be able to get this information.

Have a look at the following: http://www.experts-exchange.com/Operating_Systems/Win2000/Q_21310928.html

Regards,
M
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 9

Expert Comment

by:dooleydog
ID: 16984408
Auditing has to have been setup previously. But if not, you can eliminate your admins and users one by one... you will need to question them carefully as to not give away what  you are trying to find out.

Good Luck,

0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 16984420
i agree with itcoza, if you havent enabled auditing, its gone and there is no trace
0
 

Author Comment

by:gvector1
ID: 16984459
Well, unfortunately, auditing was not turned on.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 16984490
:(   not much you can really work with now unless you want to use an undelete software

0
 

Author Comment

by:gvector1
ID: 16984807
Data loss hurts, but I do have a tape backup to restore data from.  Everything is on the tape minus 1 day.  My main desire was to trace the problem to the cause.  But it looks like I am out of luck.  I will leave this post open for a few days in case someone has any suggestions.  I will close and award points at that time.  Thanks for assistance.
0
 
LVL 13

Expert Comment

by:itcoza
ID: 16987669
Do you need more information?  The link I added will give you an Idea of how to setup auditing.

Guidlines for security: http://www.microsoft.com/technet/security/topics/auditingandmonitoring/securitymonitoring/smpgch03.mspx
More on security: http://technet2.microsoft.com/WindowsServer/en/Library/f330f9c6-c1e6-41c2-8295-8427332995f61033.mspx?mfr=true
0
 

Author Comment

by:gvector1
ID: 17050363
I think we have determine what has caused the problem.  Now we have to figure out how it did it.  We believe that it was the Data Replication service that was running.  We have data replication running from 1 server to another server in another building.  I don't know how as of right now but we believe that the replication service had something to do with it, because the same thing happened this past weekend.  We had auditing turned on this time and it did not show to be caused by any user.  It appeared to happen after server reboot also.  Our server is scheduled to reboot over the weekend and it appeared that the data was wiped out or started being wiped out on reboot.  Any insight or suggestions is appreciated.  That is where we stand as of right now.

Thanks,
Kendal
0
 
LVL 12

Expert Comment

by:GinEric
ID: 17064282
Script your reboot to first finish all tasks and to not start any new ones.

Normal reboot for Windows simply times a process and if it isn't finished it just reboots anyway, losing the data, as in replication data.

If the replicator has opened a directory for write, by creating a temp directory then deleting the old one and renaming this new one to the old name, replicator may have a bug in that when a reboot occurs it simply does delete the old one and rename the temp one.  Had you set your reboot script to inspect to see if this was happening and then allowed for it to finish before the actual reboot, you might have saved off the new data.

You probably have to isolate and shut down the replicator before issuing the reboot command.  But you'd also have to disallow new entries, have all users logged off, and pretty much stop all replicating activities.

0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question