Solved

A Windows 7 Program Event alert is causing me great concern.

Posted on 2010-09-12
2
518 Views
Last Modified: 2013-12-04
Starting a few days ago, I would periodically hear an unfamiliar alert. When I heard the same alert today I was not actively doing anything on the PC. I traced the tone to Program Events related to Windows User Account Control. When I tried to Change User Account Control settings myself, the only option available is to set the conditions that cause a Change User Account Control Settings Program Event alert. When I tried to make a change myself I got that prompt that asks if I wan't to allow a program to make changes to my computer to which I clicked "No". I found that this is the only option under User Accounts that generates the above menioned prompt. The program that wants to run is described as being Microsoft's with a name of UserAccountControlSettings. It's modification date is OK but it's certificate describes it as being used for "Windows Hardware Driver Verification".

I know what I think is going on but want to know how many folks here come to my same conclusion (which I didn't mention on purpose).
0
Comment
Question by:Mister_Rat
2 Comments
 
LVL 2

Expert Comment

by:agengler11
Comment Utility
Try Microsoft Event Viewer.

Control Panel

Administrative Tools

Event Manager
0
 

Accepted Solution

by:
Mister_Rat earned 0 total points
Comment Utility
Yes I did all those things prior to the initial post. After a while of getting nowhere, I checked all the successfull security audit events starting from the date of a suspected malicious event. There I found many network logons (I'm not running a server) for an account that was hidden in terms of how you would normaly view user accounts. I was then able to prevent further network logons for the SOB but am still finding and fixing the problems that were caused.

The moral of the story? When you want to remotely monitor activity on a PC (a laptop in my case) that you own, stay away from Desktop Scout which lures you into trying it with a free 30-day evaluation. Once you run the weird (which I noticed as it briefly ran...too late!) installer, the damage is done.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
OfficeMate Freezes on login or does not load after login credentials are input.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now