Hacked?? Full recovery but acitivty on event log w/PICS

dinomite

Commendable
Mar 8, 2016
2
0
1,510
so i recently did a full recovery on my laptop to delete everything and reinstall windows 8 on march 4th during the day. i had to go through the initial setup So i figured i would do that after the weekend. so i shut down my laptop and left it in my room with the doors locked. i come home march 7th around 7pm to go through the setup. i thought my laptop was hacked before which is why i did the reinstall. so after making my admin and user account and messing with some settings i decide to check the event log. on the log it shows a bunch of activity with requests for bluetooth passwords, user accounts privileges & changes, special logons, etc. the blocks of time when it starts & ends, always end with an event for the laptop set to sleep. theres also 4 events that show up as 2015 for some reason not sure how that happened but the events show computer name to be TC-W. can someone view my saved event log to verify this? and if so what im suppose to do cause i was running bitdefender before & that didnt seem to help. it seem both my laptops and my store cctv system seems to have been hacked.


FileDownloadHandler.ashx




FileDownloadHandler.ashx
 
Solution
Are you sure that you didn't just name the computer TC-W when you first ran it?

Also , full recovery as in clean install or something else? If you think you may have been "hacked", you need to do a clean install

dinomite

Commendable
Mar 8, 2016
2
0
1,510


i went to update and recovery and selected the "delete everything & reinstall windows" option. by clean install, do yo mean formatting the hdd and installing with windows cd? my laptop didnt come with a cd.

and im positive i didnt name my laptop tc-w. it was named dinomite. i never got a chance to go through the setup after i reinstalled windows so i never named my laptop anyting until after the weekend which was dmz. and it doesnt explain how event viewer is showing all these events over the weekend while i was gone and my laptop was turned off.
 


1) That sounds like you have not clean installed, so it's quite possible that the old name was TC-W at some time and just carried over when you reverted.
2) As for the events showing up, you have one of two main possibilities:
a) Your clock is wrong
b) You didn't actually turn it off, simply put it to sleep
3) A third, but rare, possibility is that you have another computer on your network that is transmitting logs.