I’m sorry if this should be on SuperUser instead of ServerFault. Please ask me to migrate the question instead of flaming.
I’ve had 2 windows desktops go down on the network in the space of one month, One windows 7 and the other Windows 8 in a network of 6 machines with PDC and another DC in Azure with a few other machines on a virtual Azure network.
The machines are 2 year old Asus I7 4 core 8 processors with 32 gig memory and SSD main disk. The machines are being run in a development shop so everybody got everything installed. The 2 machines that went down are running local sql servers (and one mysql and postgress also).
The first one went down and we blamed the ssd disk for the crash. But some aspects of the crash made a few warning lights go off in my head but being swamped (developer and trying to bang some sense into the network) did nothing.
Ok Then my machine having quite full main system disk (SSD), decided to run the disk cleanup utility to clean up system files. I noticed that I had 192 gig in system files, thought nothing of it and ran it. Few hours later I started getting strange vibes from the machine and started the task manager… file not found error! Went straight into system32 and lo and behold, no files but those locked by the file system where left.
Tried to download virus scanners but it could not install because the UAW exe was gone. Managed to get a malware scanner down (did not need an install) which did not give me any good reason for the situation. I went to another windows 7 machine and managed to copy all the system32 files to my file system. And my intention was to do a save reboot and copy the files manually to system32 and hopefully get it running (Got a deadline staring at me), but of course that did not work, the boot sector was gone.
The shadow copy folders where gone and the restore points where gone too. So I had to clean install it. The disk is not reporting any errors.
I scanned the network and found a hidden service on the PDC (rootkit). But I know of no virus that does this kind of damage.
So finally the question is.
Can a disk crash on a SSD disk behave like this? And if not what kind of virus can do this kind of damage.
Edit
I know the network is compromised and needs to be reinstalled. But the question is are the clients going down because of a virus or can this be a SSD disk crash or a windows update failure (Which is the company owner's answer to it all, and he only wants to remove the rootkit and then continue.)