We have a Server 2003 Std machine that is getting files deleted. All of the users are denying any responsibility and in both instances someone has been in an excel file, gone to close/save it and received a message saying the file no longer exists. A quick search reveals that the file does indeed no longer exist. File recovery tools have been unable to retreive the file.
My understanding has always been that when you open a spreadsheet, whether it be local, accross the LAN or even the WAN you effectivly open a copy of the file. You work on the copy only leaving the original untouched until such a time as you save your changes (to the same file in the the same location with the same name).
If network connectivity were an issue then the original file would not be deleted but there is no trace anywhere on the network of even the temp file.
I am looking for some kind of logging software at the moment that will monitor this particular folder and let me know if a file is deleted and by whom. Until I find such an application though I would like to know if there is a way to maintain all current permissions but remove the ability to actually delete the file.
Virus and malware scans have turned up no infections and the deleted files seem fairly targeted, I would expect viral causes to be more random and widespread.
Can anyone offer any solutions?