Spyware Adware Virus Hijack Removal Forums - Malware Crypt  

Go Back   Spyware Adware Virus Hijack Removal Forums - Malware Crypt > Computer Help > Computer Help and Repairs

Computer Help and Repairs Post your requests here for assistance for all computer problems and issues not related to malware/infection.

Reply
 
Thread Tools Display Modes
  #1  
Old 01-06-2010, 01:55 AM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default User accounts

In my friends' computer, there is an HP_Administrator Account showing up in the Users area. If an account is created for him and another for her, the HP_Administrator Account will also show up when you log in.

Could the HP_Administrator Account be renamed to his name, or would it be best to leave it alone and just create an account for her?

Thanks for the help!
Reply With Quote
  #2  
Old 01-06-2010, 04:47 PM
jintan's Avatar
jintan jintan is offline
MalwareCrypt Guy
 
Join Date: Sep 2008
Posts: 2,782
Default

You can run a check to verify all the accounts on the system, then decide after that. The actual computer Administrator account does not normally show as a user account at login (only is presented when accessing Safe Mode), but can if a person at some point chose to use it for their regular account.

Click Here and download Bobbi Flekman's SWWhoAmI (swwhoami.exe) to your Desktop (important you save it to your desktop).

Then go to Go to Start > Run and type

cmd

and OK. At the prompt copy/paste the following (Enter after).

"%userprofile%\desktop\swwhoami.exe" /listusers >c:\userlook.txt & start notepad c:\userlook.txt

Once the scan completes a textbox will open (the file can be found at C:\userlook.txt). You can post that back here for us to review, or just review it with your friends and provide them with the tips on what to select.
Reply With Quote
  #3  
Old 01-07-2010, 02:24 AM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default

Thanks for the info, Jin!

Took the computer back to them this morning, but, I'll go back to their home in the next week or so, and check out the info you provided.


Is there an advantage to having the HP_Administrator account, plus an account for him and another for her (both of the last two with Administrative privileges)?

Last edited by Aaflac; 01-07-2010 at 02:29 AM.
Reply With Quote
  #4  
Old 01-07-2010, 02:40 AM
jintan's Avatar
jintan jintan is offline
MalwareCrypt Guy
 
Join Date: Sep 2008
Posts: 2,782
Default

I am pretty sure the "HP_Administrator" account is akin to the owner account, and is not the actual computer Administrator account. If you get a chance you can verify that with Bobbi Flekman's SWWhoAmI, which makes the point moot, unless they don't like the name and would like their individualized own account names. Then just copy over the things like the Favorites and bookmarks folders files and go with the new user account. Ultimately the backup and problem solver account will always be the Administrator account.
Reply With Quote
  #5  
Old 01-07-2010, 02:54 AM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default

Thanks, Jin.

Will do some checking with SWWhoAmI, see what it shows, and take it from there.
Reply With Quote
  #6  
Old 01-07-2010, 04:48 PM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default

These are the results:

Users on this computer:
Is Admin? | Username
------------------
Yes | Administrator
| ASPNET
| Guest (Disabled)
| HelpAssistant (Disabled)
| IUSR_NMPR
| rayandcandace
| SUPPORT_388945a0 (Disabled)

Don't know how ASPNET, HelpAssistant (Disabled), IUSR_NMPR, and SUPPORT_388945a0 (Disabled) got there.

Rayandcandace was the only account created...
Reply With Quote
  #7  
Old 01-07-2010, 04:59 PM
jintan's Avatar
jintan jintan is offline
MalwareCrypt Guy
 
Join Date: Sep 2008
Posts: 2,782
Default

Those others are system accounts created for special needs, like Support accounts to use for network access, and Windows system accounts like ASPNET.

I might have been incorrect about the status of that HP_Admin account though. If they log in under that account name, then again run SWWhoAmI using this command:

"%userprofile%\desktop\swwhoami.exe" >c:\userlook1.txt & start notepad c:\userlook1.txt

It will verify just that user account.
Reply With Quote
  #8  
Old 01-09-2010, 01:59 AM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default

To get to the Administrator account, these friends blank out their account, and replace it with Administrator. Then, they type in the password. They do not go into Safe Mode or to control panel.

Have never heard of blanking out an account and then replacing it with Administrator. Has anybody?
Reply With Quote
  #9  
Old 01-09-2010, 02:54 AM
jintan's Avatar
jintan jintan is offline
MalwareCrypt Guy
 
Join Date: Sep 2008
Posts: 2,782
Default

That makes more sense of the situation now, and I am sure you already would know it. They have more than one account, and it and the Administrator account is passworded, and they have "Use Welcome screen" unchecked in Control Panel - User Accounts. So they change the user name here:



(Photo from technosid.files.wordpress.com)
Reply With Quote
  #10  
Old 01-09-2010, 03:03 AM
Aaflac's Avatar
Aaflac Aaflac is offline
Malware Removal Person
 
Join Date: Jan 2009
Location: Illinois USA
Posts: 301
Default

Quote:
and I am sure you already would know it
My brain is fried...

How do they get to the prompt you show above, blank out their account, and replace it with Administrator?
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:24 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2008 MalwareCrypt.com