Solved

File Server

Posted on 2012-12-26
4
311 Views
Last Modified: 2012-12-28
I am monitoring my files server for anyone deleting file but I don't know why user User: NT AUTHORITY\SYSTEM keeps showing deleting  files sqlserv.exe and copy.exe. I ran my virus and it came up clean


26 Dec 2012 05:57:44 PM Computer: [KFSH-CL-FLPD-02] Monitor: [Watch F:\] Description: The following activities have occurred:
Op: Deleted
File: F:\KFSHHomeFolders\MedApp\mimages\sqlserv.exe
User: NT AUTHORITY\SYSTEM
App: System or Network

Op: Deleted
File: F:\KFSHHomeFolders\MedApp\mimages\copy.exe
User: NT AUTHORITY\SYSTEM
App: System or Network
0
Comment
Question by:YRMC_Infrastructure
4 Comments
 
LVL 18

Expert Comment

by:Sushil Sonawane
ID: 38721405
run the anitvirus scan on the system in safe mode then check
0
 

Author Comment

by:YRMC_Infrastructure
ID: 38721466
I ran it in safe and normal mode
0
 
LVL 27

Accepted Solution

by:
davorin earned 500 total points
ID: 38721500
This is happening in the same folder (I guess) of some medical imaging application.
Is it possible that this is normal behavior for this application?
Application when needed creates/copies this two files and when the procedure is finished the files are deleted.

You can try to use process monitor to get some more details on which process is playing with this two files.
http://technet.microsoft.com/en-us/sysinternals/bb896645
0
 
LVL 5

Expert Comment

by:Imran Saeed
ID: 38723473
Can you attach the files here to analyze?
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question