Windows update just added a User to my PC, Do I need 2 plus guest?

Page 3 of 4 FirstFirst 1234 LastLast

  1. Posts : 5,656
    Windows 7 Ultimate x64 SP1
       #21

    Torchwood, it is not an additional admin account that was introduced, it has always been there. Problem was it got enabled without user consent.

    I have all Windows updates installed and haven't seen such behavior in my PCs.
      My Computer


  2. Posts : 10,485
    W7 Pro SP1 64bit
       #22

    GokAy said:
    ~~~
    Well, try logging in with the Administrator (now Admin-Bob) and if it works, just disable it and remember the name if ever needed. :) We should be rename it back somehow, maybe others will advice something regarding this.
    Many companies rename the built-in Administrator account as an extra security step. The laptop that I'm on has had that account renamed (and disabled) from day one. This makes it harder for malware that intends to enable/use this built-in Administrator account.

    The link that you provided to the tut for enable/disable built-in admin account has a step that deals with renamed accounts by linking to this tut: Built-in Administrator Account - Change Name

    Bottom-line...
    ...renaming that built-in account is a good thing
    ...disabling that built-in account is a good thing


    BobKoz,
    Most users don't bother renaming the built-in admin account. It is fine if you want to leave that account with its default name. As far as using a admin:user account vs. an standard:user account for day to day use: Yes, the using a standard:user account is safer; however, it can be hard to do/understand certain actions, so it is probably not worth changing to a standard:user account. Just keep the User Account Control turned on when using your current admin:user account.
      My Computer


  3. Posts : 5,656
    Windows 7 Ultimate x64 SP1
       #23

    UNI, you are of course 100% right. I was trying to comment on BobKoz's way of trying to deal with the issue. And to be honest almost forgotten of that best practice :)
      My Computer


  4. Posts : 31
    Windows 7 Premium 64 Bit
    Thread Starter
       #24

    Your right GokkAy

    Standard is greyed out - no problem, you've helped enough :)
      My Computer


  5. Posts : 5,656
    Windows 7 Ultimate x64 SP1
       #25

    Bob, can you try one thing please:

    - Run: eventvwr.msc
    - Expand Windows Logs - Security
    - On right pane - filter current log
    - Enter 4722 (just the number) in the box where it writes <All Event IDs>
    - It will now show which account enabled which account and a bit more info

    See if you can spot something at the day of issue
      My Computer


  6. Posts : 31
    Windows 7 Premium 64 Bit
    Thread Starter
       #26

    I had to post here, tried 3 x after your last question:

    I just typed in a lot of info but got logged out and lost it..

    I added 4722 and displayed the event, it says it happened on 9/9/15 11:02:57 AM which is probably when I turned the PC on.
    I can't capture this sys window with my software - Under subject it says BOBS-PC\BobsPC, and under Target account it says BOBS-PC\Administrator........ But I didn't create anything?

    Also on bootup it said it was completing update installation before opening Windows. This was the first time I had to choose '
    admin' or 'my user'

    About renaming Administrator again : if I do this it won't match the folder called Administrator in C:\Users > is this OK? Or should I remame the folder to match?
      My Computer


  7. Posts : 10,485
    W7 Pro SP1 64bit
       #27

    BobKoz,
    As you have noted - your problem is solved and your computer logs you directly onto your desktop. (This happens by default when Windows see only one enabled account and that account has no password.)

    If you have the time and the interest, GokAy will help you try to figure out why this happened. My rambling below are just to try and answer some of the questions that you asked. Some may have already been answered... so I might be repeating stuff:


    BobKoz said:
    I worked on the extra user issue all day yesterday and so far I have not found a solution.
    Computers can sure take up a lot of time :-(



    BobKoz said:
    I don't believe Malware/Virus caused this unless it was picked up with the 25 Windows updates. I have a lot of protection on my PC (as shown above), but anything is possible! Aso my wife's computer did the same thing after the 25 up-dates, her computer is exactly the same as mine and we are not Network Connected.
    As you noted, we are not seeing any other people mention this happening to them.
    Wild (and unlikely) guess here:
    It could be that your antivirus app prevented some update from doing its thing and the update enabled the built-in admin account to complete the task. (I'm guessing that you and your wife use the same antivirus app.)



    BobKoz said:
    A new user was created on my PC during the Windows update named "Administrator" (with administrator rights).
    As noted elsewhere, the built-in account was enabled, not created. While this is a minor distinction, it would be really scary if a new admin account had been created. As it is, the event is still a mystery, but slightly less scary.



    BobKoz said:
    ....but no-one has reported this issue as happening on their computer as far as I know?
    Correct*. You are the first*. Lucky you

    *Not that we hear every report of every Windows Update anomaly.



    BobKoz said:
    I deleted the key in my registry for "Administrator" but it did not delete the User "Admin-Bob", I restored the registry with the backup I made. Maybe I should have deleted the C:\ folder in \Users named "Administrator" but I did not. I also searched my computer for "Admin-Bob" and my registry but did not find it anywhere.
    Directions I used to delete registry key: https://support.microsoft.com/en-us/kb/156826
    For future reference...
    ...visit that link again
    ...scroll near the bottom
    ...the info on that web page applies to
    Applies to

    Microsoft Windows Millennium Edition
    Microsoft Windows 98 Second Edition
    Microsoft Windows 98 Standard Edition
    Microsoft Windows 95
    While it is good that you made a backup of the key before deleting it, there are registry keys that cannot easily be restored via backup. In this case, you did no harm. It won't hurt to leave the key there or to delete it.



    BobKoz said:
    GokAy - could not disable Admin account per your link on added user..
    This is just FYI: When working with accounts, it is best to restart the computer and log onto your normal account before doing the steps in that tutorial.




    BobKoz said:
    torchwood - I looked at my System Properties \ User Profiles - (BOBS-PC is name of PC and belongs to a Homegroup - BobsPC is my original user account), I wasn't able to create a screen capture or image but I copied the "User Profiles" results below:

    USER PROFILES
    Profiles shared on this computer:
    ----------------------------------------------------------------------------------------
    BOBS-PC\Administrator 46.9 MB Local Local 9/12/2015 << Questionable?
    BOBS-PC\BobsPC 18.6 MB Local Local 9/12/2015
    Default Profile 1.50 MB Local Local 5/20/2015
    ----------------------------------------------------------------------------------------

    I am still looking for assistance with this issue :
    The added User Account appeared after Windows Update called "Administrator" (with Administrator rights) - I renamed it "Admin-Bob", which is probably connected to the new folder in my C:\
    Drive, in the \Users folder called "Administrator"
    -- I would like to delete this new added user. GokAy, UsernameIssues, torchwood or any members help is appreciated.

    Thank you ,
    Bob
    See pictures
    As has been mentioned: you cannot delete that account. You can (and have) disabled it. If you want, after restarting the computer and logging on with your normal account, you can safely delete that Administrator user folder. You can also leave it there. It really does not matter. About the only impact will be a tiny amount of time added to each full antivirus scan that you do on your computer.





    BobKoz said:
    torchwood said:
    Bob,
    what have you got here.
    Note shorten name field to get all of last modified date.

    Roy
    Hello,

    torchwood - I looked at my System Properties \ User Profiles - (BOBS-PC is name of PC and belongs to a Homegroup - BobsPC is my original user account), I wasn't able to create a screen capture or image but I copied the "User Profiles" results below:

    USER PROFILES
    Profiles shared on this computer:
    ----------------------------------------------------------------------------------------
    BOBS-PC\Administrator 46.9 MB Local Local 9/12/2015 << Questionable?
    BOBS-PC\BobsPC 18.6 MB Local Local 9/12/2015
    Default Profile 1.50 MB Local Local 5/20/2015
    ----------------------------------------------------------------------------------------

    Do you think the one marked "Questionable" is the added User account and deleting it will get rid of the added user?
    What worries me is that I'm going to delete part of my original User account or the PC name?
    And the Date modified is the date of the Windows update when the added User was created - My original User "BobsPC"' was created back in May?

    Thanks,
    As mentioned above and elsewhere, you cannot delete the built-in administrator account. I'm repeating this so that I can also add an assurance that deleting the user folder associated with that built-in administrator account will not impact any other account (not that you expressed that specific concern about the user folder).



    BobKoz said:
    GokAy - your comment:

    Administrator is a default built-in admin account, which is by default disabled.
    Guest is by default disabled and built in also.
    Your own account should be an admin account.

    I never saw the built-in Administrator account before the Windows update, so your saying it somehow got enabled?

    Do you know of anyway I can rename it back to "Administrator"? I'm pissed that I renamed it "Admin-Bob", because now it won't let me rename it back to "Administrator"..

    12 years on WinXP with no issues, this Win7 double administrator thing is kicking me in the butt..
    I am pretty sure that XP has the same built-in administrator account. It is also disabled by default. You probably never had a need to use it.



    BobKoz said:
    GokAy,

    netplwiz results:

    [X] Users must enter a user name and password to use this computer

    Users for this computer:
    ----------------------------------
    Administrator HomeUsers; Administrators
    BobsPC HomeUsers; Administrators
    HomeGroupUser$ HomeUsers; Administrators

    ---------------------------------

    1) GokAy., I was able to rename the 'Admin-Bob' back to 'Administrator' in netplwiz using properties.

    2) I then Hid the built in Administrator using command prompt > net user administrator /active:no

    3) Built in Administrator is not displayed in Control Panel/User Accounts anymore (fixed)

    4) I tested with a shut down and cold boot and it opens directly into my User Account without any user options


    Looks like you fixed all issues GokAy, thanks for all your help :)

    Is it a security risk to set user account to Administrator, is it a security risk from Hackers (because no-one else physically touches my PC)?

    Sorry for the delay, I wanted to double check everything,
    Bob
    That is an excellent summary.

    I already stated my view on "Is it a security risk to set user account to Administrator"; however, I don't want to discourage you from using the safer Standard account if you want to try it.
    You would need to...
    ...create a user:admin account
    (because you don't want to use the built-in:admin account)
    ...restart the computer
    ...log onto that new user:admin account
    ...demote your normal user account to a standard user account
    ...restart the computer (optional).
    Then use your user:standard account for day to day use.

    Let me offer an example of one difficulty that you might encounter while using a user:standard account:
    We often ask you to do things using an elevated command prompt. If you did option three in this tutorial (SFC /SCANNOW Command - System File Checker), the resulting text file will end up in the desktop folder of the admin account. As long as you know that this is going to happen, then you can deal with it. You can go get the file from there and move it to your desktop.
    Or, you could temporarily make your day to day user account an admin account - then change it back once you are done troubleshooting stuff. There are some things that are impossible to do as a standard user. Using "run as administrator" just will not work for some tasks. While this can be frustrating, you can also look at it as an extra measure of safety. This makes it harder for malware to do those things too





    BobKoz said:
    I'm going to change it to "Standard" until I get more familiar with Win7, big change from XP..

    Netplwiz did actually fix all my issues, I've kept a list of all your directions. I'll mark this thread as solved in a little while.

    Thanks again for all your help, you know your stuff !
    The same advice applies to XP. It was safer to use a non-admin account in XP too.
    Last edited by UsernameIssues; 13 Sep 2015 at 15:51.
      My Computer


  8. Posts : 5,656
    Windows 7 Ultimate x64 SP1
       #28

    It doesn't mean you personally changed it but it was done with your account's privileges.

    Last thing I would check is the Application and System event logs at around the time of the change to see if anything catch my attention.

    If you can't, oh well, issue is solved even though the mystery is not! :)
      My Computer


  9. Posts : 10,485
    W7 Pro SP1 64bit
       #29

    BobKoz said:
    I had to post here, tried 3 x after your last question:

    I just typed in a lot of info but got logged out and lost it..
    Bummer. Thanks for hanging in there.



    BobKoz said:
    I added 4722 and displayed the event, it says it happened on 9/9/15 11:02:57 AM which is probably when I turned the PC on.
    I can't capture this sys window with my software - Under subject it says BOBS-PC\BobsPC, and under Target account it says BOBS-PC\Administrator........ But I didn't create anything?
    What software are you using?




    BobKoz said:
    About renaming Administrator again : if I do this it won't match the folder called Administrator in C:\Users > is this OK? Or should I remame the folder to match?
    For the most part, it will not hurt how Windows operates to have the user folder name differ from the user account name. It mostly just confuses the humans using the computer.

    After you read my previous long/boring post, you will see that you can safely delete this folder. You can rename the built-in administrator account as an added safety measure, but you will need to remember that you have done so. If you are ever instructed to use "net user administrator /active:yes" again you will have to just know to modify those instructions to be "net user renamed /active:yes".

    Again, Windows can handle the renamed account just fine. Its the humans (and malware) that get confused.
      My Computer


  10. Posts : 31
    Windows 7 Premium 64 Bit
    Thread Starter
       #30

    There are 50+ application logs and about the same System logs, on the night of original update an morning I after when I first booted - way to much to type..

    Lets just say the Master Admin somehow got enabled and leave it at that, you helped me solve what I thought was an issue..

    UsernameIssues says:
    "Is it a security risk to set user account to Administrator" ....... By making user Standard.......This makes it harder for malware to do those things too.
    And it's also OK to Delete the C:\Users "Administrator" folder (containing all user subfolders)..

    Do you agree with these also GokAy?
      My Computer


 
Page 3 of 4 FirstFirst 1234 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:53.
Find Us