Ransomware and SYSVOL folder

skak 21 Reputation points
2021-02-23T19:48:27.397+00:00

Hello,

I have an old setup with 4 Domain Controllers 3 Windows Server 2003 and one Windows 2008 R2. Last Week we had a Ransomware attack and it corrupted the SYSVOL folder. I have Recent AD back which I restored in my Lab and copied the clean SYSVOL folder to the existing SYSVOL (deleted the Contents in Sysvol).
Reference Server is build and changed the Registry value to D4 and all other ADC I did D2 after restarting the ntrs and netlogon I see

NtFrs_PreExisting___See_EventLog in the SYSVOL, how can I avoid this ?

https://support.microsoft.com/en-us/help/315457/how-to-rebuild-the-sysvol-tree-and-its-content-in-a-domain

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

8 answers

Sort by: Most helpful
  1. Anonymous
    2021-02-24T00:41:44.957+00:00
    0 comments No comments

  2. skak 21 Reputation points
    2021-02-24T05:31:50.373+00:00

    I have already checked those links but nothing really found. I want to know the root cause of the behavior and also I did a authoritative restore.

    0 comments No comments

  3. Anonymous
    2021-02-24T07:30:29.753+00:00

    Hi,
    Based on my understanding ,when there were d2,or d4 operated, the files within the sysvol on non-authoritative DCs will be placed into the folder pre-existing folder.
    The placement of files in the folder pre-existing on reinitialized members is a safe guard in FRS that is designed to prevent accidental data loss. Any files destined for the replica that exist only in the local pre-existing folder and were replicated after the initial replication may then be copied to the appropriate folder.

    This can't be changed .

    Best Regards,


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.