can I find out which process is deleting a file? file disappears.

holollollol 86 Reputation points
2021-09-27T10:37:42.213+00:00

Hi

I have two windows 2016 DC server as MSCS cluster.

C:\Windows\System32\drivers\etc folder and a few .sys files were deleted sometime.

Both servers had symptoms, so I reinstalled it a few times, but the symptoms reappear after a certain period of time.

There are no related logs in the antivirus.

I reinstalled it, but I'm worried.

how can I find out which process is deleting a file?

help me~~

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,389 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-09-27T15:23:57.277+00:00

    Procmon should work.
    https://learn.microsoft.com/en-us/sysinternals/downloads/procmon

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Limitless Technology 39,396 Reputation points
    2021-09-30T08:59:33.1+00:00

    Hello,

    Additionally you can view Event viewer and check Audit logs.

    Also you can check Windows update history if it was deleted by Windows update and Windows Task scheduler if there is any Job is affecting to these files and location.


    If the reply was helpful, please don’t forget to upvote or accept as answer.

    0 comments No comments