Server Compromised??? Missing 100Gb!!!
Dell Server
Xeon 3.06GHz 1Gb Ram
2x PERC LD PERCRAID SCSI Drives
Disk 0 Basic NTFS 33.86 Gb
3x Partitions
31Mb (EISA Configuration)
15.01Gb C:
18.82Gb D:
Disk 1 Basic NTFS 169.33 Gb
169.33Gb E:
The problem is the E: drive, it has 2 visible and 2 hidden directories:-
E:\Microsoft SQL Server\ (Size On Disk 328,167,424 bytes)
E:\RECYCLER\ (Size On Disk 8,192 bytes)
E:\System Volume Information (Size On Disk 0 bytes)
E:\WUTemp (Size On Disk 0 bytes)
All of which add up to 328,175,616 bytes.
However when I look at the properties for the drive I get this:
Used space : 108,066,578,432 bytes 100Gb
Free space : 73,753,202,688 bytes 68.6Gb
Capacity : 181,819,781,120 bytes 169Gb
WHEREs THAT 100Gb GONE TO!!!!??????
I believe it may have been compromised as it was accidently left outside the firewall for a time and I understand the network logs showing it having some 10Mb/sec traffic with protocols indicating it may have been streaming video/music/etc... (I don't personnally have access to these logs btw).
However, the fact remains theres 100Gb disapeared and I cant see it. Is there someway for me to see this data and verifywhat it is AND where it is and possibly if theres anymore hidden on the other partitions and, god forbid, any other server.
So, pleasepleasepleasepleasepleasepleaseplease heeeelllllllpp Thanking you in advance
Dave