QUOTE(cwtien @ Oct 28 2006, 09:14 PM)
If you're running NTFS, you can just turn on auditing on the folder (Security/Advanced/Auditing).
That shuold enable you to see who's deleting the files. It's logged into the security event log.
Second that. The security log will show who delete what file at what time. That's the best evidence. Then send a personal email to the culprit with the screenshot attached, says "dont ever mess with your system administrator". That shuold enable you to see who's deleting the files. It's logged into the security event log.
Oct 29 2006, 07:26 PM

Quote
0.0169sec
0.71
6 queries
GZIP Disabled