File Server

YRMC_Infrastructure
YRMC_Infrastructure used Ask the Experts™
on
I am monitoring my files server for anyone deleting file but I don't know why user User: NT AUTHORITY\SYSTEM keeps showing deleting  files sqlserv.exe and copy.exe. I ran my virus and it came up clean


26 Dec 2012 05:57:44 PM Computer: [KFSH-CL-FLPD-02] Monitor: [Watch F:\] Description: The following activities have occurred:
Op: Deleted
File: F:\KFSHHomeFolders\MedApp\mimages\sqlserv.exe
User: NT AUTHORITY\SYSTEM
App: System or Network

Op: Deleted
File: F:\KFSHHomeFolders\MedApp\mimages\copy.exe
User: NT AUTHORITY\SYSTEM
App: System or Network
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
run the anitvirus scan on the system in safe mode then check

Author

Commented:
I ran it in safe and normal mode
This is happening in the same folder (I guess) of some medical imaging application.
Is it possible that this is normal behavior for this application?
Application when needed creates/copies this two files and when the procedure is finished the files are deleted.

You can try to use process monitor to get some more details on which process is playing with this two files.
http://technet.microsoft.com/en-us/sysinternals/bb896645
Imran SaeedIT Technical Director

Commented:
Can you attach the files here to analyze?

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial