Appearing and Disppearing User Account

blazah99

New member
Local time
12:05 AM
Messages
3
Hi, I have a bit of a strange problem. I encountered a user account on my computer which I didn't recognize (SuperDuperstdw36) and because it was logged in an password protected I couldn't delete it. So I shut down my computer, turned it back on, and it wasn't there. I logged into my user account to check to go delete it but it wasn't there, nor was any user directory for it navigating my drive, all of which has me pretty concerned. I'm not sure how to handle this particular problem as it appears nothing is there, but I fear my computer has been hacked. I'm running on a an old dell with win7 professional 32-bit OS.
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit and a Windows 7...
Computer type
PC/Desktop
OS
Windows 7 Professional 32-bit and a Windows 7 Home Premium 64-bit

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
If there was a new user created there will be an entry for it in the Registry. There is no way they could wipe all tracks of it in time with you shutting down the computer.

This Registry key will have a list of accounts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
 

My Computer My Computer

At a glance

Windows 7 Pro x64i7 2600K 4.7Ghz16GB
OS
Windows 7 Pro x64
CPU
i7 2600K 4.7Ghz
Memory
16GB
Hard Drives
OCZ Vertex 3
RAID 0 SSD
Internet Speed
100Mbps
I ran the 4 anti-spyware/malware programs and cleaned up what they found. However looking at the registry in the ProfileList I see 6 entries in the profileimagepath. I took a look at my other computer to see compare the differences (Both windows 7, first with prob is a 32bit Professional, second is a 64bit Home Premium) and they are as follows:

Win7 Professional 32bit;
%systemroot%\system32\config\systemprofile , C:\Windows\ServiceProfiles\LocalService , C:\Windows\ServiceProfiles\NetworkService , C:\Users\*my account* , C:\Users\*mothers account* , and C:\Users\Administrator .

Win7 Home Premium 64bit;
%systemroot%\system32\config\systemprofile , C:\Windows\ServiceProfiles\LocalService , C:\Windows\ServiceProfiles\NetworkService , C:\Users\*my account* , C:\Users\*account the store put on as it was a floor model when purchase* , and C:\Users\DefaultAppPool .

I exported the ProfileList to a text file because I'm not sure if the other data is relivent or not, however if needed i can dropbox/link the text file here for viewing. I'd also like to completely remove the account the store put on but thats another problem and not critical at the moment.

Also worth noting is when I went to view the registry on the win7 32bit machine the explorer.exe crashed, which isn't normal, and I'm thinking/wondering if its related. I looked at my event logs and saw their was a few special logins today after I had ran the 4 malware removal software.

I took the liberty of saving the most recent event logs from Applications, Security, and Audit beginning from the last startup (both table data and detail data) but the text is quite long and I'm not sure if they would be of use. Should I dropbox the event log text files and link them here for viewing?
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit and a Windows 7...
Computer type
PC/Desktop
OS
Windows 7 Professional 32-bit and a Windows 7 Home Premium 64-bit
I encountered a user account on my computer which I didn't recognize (SuperDuperstdw36) and because it was logged in an password protected I couldn't delete it.
Windows 7 Home Premium 64bit;
%systemroot%\system32\config\systemprofile , C:\Windows\ServiceProfiles\LocalService , C:\Windows\ServiceProfiles\NetworkService , C:\Users\*my account* , C:\Users\*account the store put on as it was a floor model when purchase* , and C:\Users\DefaultAppPool


So in a 'nut-shell' they sold the floor computer to you "as is" and didn't restore the system to it's original settings?
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I encountered a user account on my computer which I didn't recognize (SuperDuperstdw36) and because it was logged in an password protected I couldn't delete it.
Windows 7 Home Premium 64bit;
%systemroot%\system32\config\systemprofile , C:\Windows\ServiceProfiles\LocalService , C:\Windows\ServiceProfiles\NetworkService , C:\Users\*my account* , C:\Users\*account the store put on as it was a floor model when purchase* , and C:\Users\DefaultAppPool


So in a 'nut-shell' they sold the floor computer to you "as is" and didn't restore the system to it's original settings?

That would be correct however that is on my other computer (64bit OS), the one that didn't have SuperDuperstdw36 (the 32bit OS) user account. The 64bit OS machine store's account is "Kiosk" which I've known about for some time but been unable to do anything about it as its hidden and password protected.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Professional 32-bit and a Windows 7...
Computer type
PC/Desktop
OS
Windows 7 Professional 32-bit and a Windows 7 Home Premium 64-bit
Back
Top