New
#1
New user accounts being created daily by something, help please
For the last 3 days I have gone to log on to my PC and there is a new user account created. Once every day for 3 days now. It appears to be Windows Mail but I do not use that, at all. Nor do I use Exchange.
Here are the 3 events in the event viewer:
Audit Success 9/17/2014 12:40:47 PM Microsoft Windows security auditing. 4720 User Account Management
Audit Success 9/16/2014 10:29:29 PM Microsoft Windows security auditing. 4720 User Account Management
Audit Success 9/15/2014 10:11:53 PM Microsoft Windows security auditing. 4720 User Account Management
Now one thing I noticed is the two of the user accounts had admin rights, one was a normal account. The two with admin rights had corresponding app activity in the application log. Here is a snippet of the application event log for the 9/17 occurrence where user "x1x2x3" was created:
Information 9/17/2014 12:41:49 PM ESENT 102 General
WinMail (15752) WindowsMail0: The database engine (6.01.7601.0000) started a new instance (0).
Information 9/17/2014 12:41:50 PM ESENT 210 Logging/Recovery
WinMail (15752) WindowsMail0: A full backup is starting.
Information 9/17/2014 12:41:50 PM ESENT 220 Logging/Recovery
WinMail (15752) WindowsMail0: Beginning the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore (size 2 Mb).
Information 9/17/2014 12:41:50 PM ESENT 221 Logging/Recovery
WinMail (15752) WindowsMail0: Ending the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.
Information 9/17/2014 12:41:51 PM ESENT 223 Logging/Recovery
WinMail (15752) WindowsMail0: Starting the backup of log files (range C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log - C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log).
Information 9/17/2014 12:41:51 PM ESENT 222 Logging/Recovery
WinMail (15752) WindowsMail0: Ending the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log. Not all data in the file has been read (read 0 bytes out of 2097152 bytes).
Error 9/17/2014 12:41:51 PM ESENT 215 Logging/Recovery
WinMail (15752) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
Information 9/17/2014 12:41:51 PM ESENT 103 General
WinMail (15752) WindowsMail0: The database engine stopped the instance (0).
I believe it errored because I logged on to the machine at this time. The previous occurrence had no error. I couldnt find much help online. I did run Microsoft Security Essentials and the latest version of Malwarebytes which is found just 4 PUP instances and quarantined them. That was yesterday and as you can see it didnt stop the issue.
Please let me know what this could be, how to stop it, and what else I can provide for analysis.
Thanks