21-06-2013, 01:32 PM
I have a person who thinks their computer has been hacked into.

I have updated their internet security program (BitDefender Internet Security 2013) & scanned (37 threats detected so far)

I am going to change their security key on their wireless adsl router

is there anything else that I should do:
1] to detect whether or not they have been hacked into
2] to prevent further hacking?

Thank you

21-06-2013, 01:44 PM
is there anyway of identifying if the computer has been hacked into (she wants proof)

Speedy Gonzales
21-06-2013, 01:47 PM
Look in its logs and see if it blocked anything. What are the threats?

21-06-2013, 01:54 PM
will get back to you on that when the scan is completed.

Alex B
21-06-2013, 02:03 PM
Why does she think it has been hacked, and what information does she think has been accessed.

21-06-2013, 02:08 PM
Good question and it was hard for me to pin her down as she was quite vague
but she said setting seemed to have been changed
windows would open up & then close & she wouldn't be able to find them.
she took pictures of some of the windows - but I couldn't make out enough of the details to know what they were reflecting.
she has very little data if any - only uses the laptop for skype & emails

21-06-2013, 02:20 PM
here is the results of the scan:
Speedy Gonzales
21-06-2013, 02:29 PM
Well the 1st lot are cookies. I wouldnt worry about those. Did she make the backup files?? If not delete them. It looks like SP59624.exe is an HP setup file

I would disable system restore, use ccleaner to remove temp files/cookies. Then turn system restore back on

21-06-2013, 02:31 PM
Yep I agree, I wasn't too worried about the cookies.
Will run CCleaner after Malwarebytes finishes it's scan


Speedy Gonzales
21-06-2013, 02:34 PM
Post a HJT log . We'll see whats in it

21-06-2013, 02:38 PM
Thank you:

Speedy Gonzales
21-06-2013, 03:07 PM
Does she used McAfee endpoint Encryption agent, If she doesnt I would uninstall it. Does this support dual graphics? Since it looks like its got Intel and ATI video drivers on it?

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

There's a few things in there that you dont really need.

HP Software Framework ,HPConnectionManager, HPQuickWebProxy, HP ProtectTools, HP Support Assistant. The netbook I have here has downloads for these. But I wont be installing them.. All they do is take up space on the hdd. And I dont even know what they do anyway. But, it runs fine without them

21-06-2013, 03:10 PM
I agree - I feel HP overloads their systems with stuff the user doesn't need or want.
Cheers - will make the suggested changes.

Speedy Gonzales
21-06-2013, 03:14 PM
Sweet no probs. Yup most branded PC's you'll get a lot of junk on them lol. One reason I build my own. None of this crap gets installed on it lol

21-06-2013, 03:38 PM
Malwarebytes found:
Files Detected: 2
D:\OWNER-PC\Backup Set 2012-04-09 185240\Backup Files 2012-04-22 202938\Backup files 2.zip (Rogue.Installer.SFXGen1)
D:\OWNER-PC\Backup Set 2012-04-09 185240\Backup Files 2012-05-27 195526\Backup files 2.zip (Rogue.Installer.SFXGen1)

Speedy Gonzales
21-06-2013, 03:47 PM
You may have to send a sample to them (http://forums.malwarebytes.org/index.php?showtopic=102160). To see if it is a rogue installer, or a false +. Or do this (http://forums.malwarebytes.org/index.php?showtopic=3228)

If you scanned the same files with bitdefender, what does that say?

21-06-2013, 04:01 PM
I find it very annoying that tracking cookies are portrayed as serious security risks by some anti-virus applications.

21-06-2013, 04:47 PM
Thank you.
Have to follow up on this Tues - have an extended weekend :)

21-06-2013, 05:21 PM
Which is the reason we often get comments" AV-scanner'A' found nothing, yet Wizbang.AVScanner found 25 "serious threats" (ie cookies)!!!!! So AV-scanner'A' is useless.

21-06-2013, 07:09 PM
That depends on who is saying the AV is not that good. Personally I dont include cookies as part of the "infections" that's because I run two programs first, 1. Ccleaner and 2. TFC cleaner ( cleans out items ccleaner misses) So all cookies are removed beforehand.