can I find out which process is deleting a file? file disappears.

holollollol 86 Reputation points
2021-09-27T10:37:42.213+00:00

Hi

I have two windows 2016 DC server as MSCS cluster.

C:\Windows\System32\drivers\etc folder and a few .sys files were deleted sometime.

Both servers had symptoms, so I reinstalled it a few times, but the symptoms reappear after a certain period of time.

There are no related logs in the antivirus.

I reinstalled it, but I'm worried.

how can I find out which process is deleting a file?

help me~~

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2021-09-27T15:23:57.277+00:00

    Procmon should work.
    https://learn.microsoft.com/en-us/sysinternals/downloads/procmon

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Limitless Technology 40,081 Reputation points
    2021-09-30T08:59:33.1+00:00

    Hello,

    Additionally you can view Event viewer and check Audit logs.

    Also you can check Windows update history if it was deleted by Windows update and Windows Task scheduler if there is any Job is affecting to these files and location.


    If the reply was helpful, please don’t forget to upvote or accept as answer.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.