Solved New user accounts being created daily by something, help please

Viper41086

New member
Local time
10:14 AM
Messages
7
For the last 3 days I have gone to log on to my PC and there is a new user account created. Once every day for 3 days now. It appears to be Windows Mail but I do not use that, at all. Nor do I use Exchange.

Here are the 3 events in the event viewer:

Audit Success 9/17/2014 12:40:47 PM Microsoft Windows security auditing. 4720 User Account Management
Audit Success 9/16/2014 10:29:29 PM Microsoft Windows security auditing. 4720 User Account Management
Audit Success 9/15/2014 10:11:53 PM Microsoft Windows security auditing. 4720 User Account Management

Now one thing I noticed is the two of the user accounts had admin rights, one was a normal account. The two with admin rights had corresponding app activity in the application log. Here is a snippet of the application event log for the 9/17 occurrence where user "x1x2x3" was created:

Information 9/17/2014 12:41:49 PM ESENT 102 General
WinMail (15752) WindowsMail0: The database engine (6.01.7601.0000) started a new instance (0).

Information 9/17/2014 12:41:50 PM ESENT 210 Logging/Recovery
WinMail (15752) WindowsMail0: A full backup is starting.

Information 9/17/2014 12:41:50 PM ESENT 220 Logging/Recovery
WinMail (15752) WindowsMail0: Beginning the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore (size 2 Mb).

Information 9/17/2014 12:41:50 PM ESENT 221 Logging/Recovery
WinMail (15752) WindowsMail0: Ending the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.

Information 9/17/2014 12:41:51 PM ESENT 223 Logging/Recovery
WinMail (15752) WindowsMail0: Starting the backup of log files (range C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log - C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log).

Information 9/17/2014 12:41:51 PM ESENT 222 Logging/Recovery
WinMail (15752) WindowsMail0: Ending the backup of the file C:\Users\x1x2x3\AppData\Local\Microsoft\Windows Mail\edb00001.log. Not all data in the file has been read (read 0 bytes out of 2097152 bytes).

Error 9/17/2014 12:41:51 PM ESENT 215 Logging/Recovery
WinMail (15752) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

Information 9/17/2014 12:41:51 PM ESENT 103 General
WinMail (15752) WindowsMail0: The database engine stopped the instance (0).


I believe it errored because I logged on to the machine at this time. The previous occurrence had no error. I couldnt find much help online. I did run Microsoft Security Essentials and the latest version of Malwarebytes which is found just 4 PUP instances and quarantined them. That was yesterday and as you can see it didnt stop the issue.

Please let me know what this could be, how to stop it, and what else I can provide for analysis.

Thanks
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Hello and welcome Viper mate run hese scans as well

http://www.superantispyware.com/


http://www.bleepingcomputer.com/download/adwcleaner/

download from bleeping computer – delete any rubbishthese find.

http://www.emsisoft.com.au/en/software/eek/ I only use the Emergency and Command line scans as a matter of course.
If the problem still persist then use this
http://support.kaspersky.com/4162 This will run from power up and not involves Windows

you can also use this if necessary Utilities < the top link TDSS Killer
Then I suggest these

http://www.sevenforums.com/tutorials/1538-sfc-scannow-command-system-file-checker.html

http://www.sevenforums.com/tutorials/433-disk-check.html < use the /f option in Option 2 ifnecessary





 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Thank you. I will need a couple of days to do all of this and see if it comes back. Stand by...
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Not a problem mate I am not going anywhere :)
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Ok, so far I have done all of these except for the disk check and
Download Kaspersky Rescue Disk 10

I am running the sfc scan now.

It did happen again at 3:41 this morning making it now 4 days in a row. I am deleting the user account that is created each day and its user folder.

Would it be worth trying a a restore point before the 15th?

Thanks
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Mate you can restore back to whenever you like you will not lose data - you only go back to older settings basically.
To look for older setting if you are not sure see my pic.
 

Attachments

  • RESTORE 2.PNG
    RESTORE 2.PNG
    20.3 KB · Views: 41

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Ok, I have done all of these and barely anything was found and fixed. It is still happening. This morning an account was created with the name ASPNET... I am actually beginning to think someone is hacking my PC. After this account was created the event viewer shows a logon at 1:14 AM, one minute after the account was created. And in the network information details I see this:

Network Information:
Workstation Name: JOHN-PC
Source Network Address: -
Source Port: -

I have no idea what JOHN-PC is. My PC and laptop are named something very different. After finding this I did a search for JOHN_PC and sure enough the very first occurrence where account name APACHA was created there was a logon from JOHN-PC as well.

So how do I go about fixing this issue if I am being hacked?

Edit: Actually, I have continued doing research. I have HFS and leave it on regularly as I share files with friends and myself from other PC's. I do secure everything with passwords of course and I log every IP address. Strangely, there was a connection through HFS at the same time the account was created and the IP address was logged. I dont think that the time in the event viewer of the account being created and the time of an external connection being logged through HFS and the fact that the event viewer network information shows a workstation name that is unknown to me is all coincidence. I am nearly 100% sure I am being hacked.

That said, I have updated HFS to the newest version as there were apparently some security issues with older version (but not the one I had actually). I also set bans and basically banned everyone EXCEPT for a specific list of IP addresses. I tested this to make sure it worked. If it happens again, I will simply stop using HFS all together and see if that fixes it. Im not sure they were getting in through a vulnerability in HFS or if HFS just happened to log incoming IP addresses period. However my laptop is on the same network and I do not have HFS running on it and there have been no issue with that. Then again, its been in sleep mode and my PC is always on... :-/

Im really hoping its a vulnerability in HFS and that by updating and banning all IP's except a small list will fix the issue.

Any other thoughts?

Thanks
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Ok mate I think first up you should run the Kaspersky rescue disk it will run from power up and doesn't need Windows at all it will scour through everything.

The other malware scans run them and then it may be an idea to run a rookit scan -
http://support.kaspersky.com/viruses/utility run the TDSSKiller it is the best one and most used of the rootkit scans that are available.

Another good scan to use is this http://www.emsisoft.com.au/en/software/eek/ I only usually use the Emergency and Command line scans

I would be very surprised if these do not pick something up and I am now thinking something is afoot as my machines are all John-PC:huh:

I would also check on your security settings too not just the machine but also the modem / router.
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Icit2lol. I have actually already run all of the programs you suggested. Literally every program came back clean except for the first one or two and they just found 2 PUPs each. Not too bad. Im really pretty diligent with my computers and keeping them clean. I build my own PC's and I am a programmer so I would say I am an intermediate PC user at a minimum. Would not say I am hacker level or anything though, cause if I were I would not need help from the forums. lol.

What do you mean your PC's all say John-PC? You are showing the same thing in your event viewer? Is anyone? Jacee???

Anyhow, right now its a waiting game I think. Just waiting to see if my changes will work, and if not I simply have to take more drastic measures and start turning my PC off when I leave it. :(
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
No mate my name is John and I set them all to John when setting them up or installing:) Me I am just an RN and do this for a hobby so I am not really as good at this as you are it is only what I have picked up from folks on this site.

I never had done a build until I came here and the rest is history:)
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Hmm, thinking out loud...


  • Your system is open to a select group of users in order to share files.
  • Your logs show a backup activity for a commonly used mail program/service but one you do not use (however, it is installed by default with Windows).
  • This backup activity occured during a login connection with one of the remote group members.
  • The backup activities occur around the same time of day.

Based on the above, maybe one of the remote members has their backup service configured to:

  • Run at a specific time (or when first logged in after the scheduled time)
  • Backup based on their network not just the local workstation - you are part of their network (as a share)
  • Backup service scans the entire network (includes you) and backs up programs/files based on their configuration settings

Thus that system tries to backup your mail directory.

How have you configured your share rights?

Just thinking out loud...

Regards,
GEWB
 

My Computer My Computer

At a glance

Linux Mint / XP / Win7 Home, Pro, Ultimate / ...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
(7 different computers booting up to 10 systems)
OS
Linux Mint / XP / Win7 Home, Pro, Ultimate / Win8.1 / Win10
Other Info
Four desktops, two laptops, one notebook and one tablet
Well, that is true that I have my laptop set up to run backups, however I never leave it on. So it only runs the backup when I manually run it. That is all of the PC's in my house and again none with the workstation named JOHN-PC.

I will just say that since updating HFS, adding rules to ban all IP addresses using an exception list, and adding rules to block the IP address in question, the issue has not occurred again. So, knock on wood, with any luck, I think the issue may be resolved. I am going to continue to monitor obviously.

Thanks guys.
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Good! keep us informed :)
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It has been about two weeks now and no more occurrences. I am going to go ahead and say this is resolved with the steps I put in place.

Thanks for your support
 

My Computer My Computer

At a glance

Windows 7 Pro x64
Computer type
PC/Desktop
OS
Windows 7 Pro x64
Back
Top