Originally posted by: PetePDX
Already mentioned check out root's crontab
See if you can find what is writing to the file lsof, etc
Change the perm on the file to read only and see who complains
Are you running audit ? If so time to learn the ins and outs of audit, go find who created it in the first place
What are the contents of the file ? If not clean text, do a strings on it. The contents can help you get an Idea of what is doing the writing
BTW you have another file (not character device) called /dev/null March 22'd. Do a last and find out who with root access was on then.
Get that person yourself and manager(s) in to a room and discuss your companies termination policy for that person and his manager.