Windows 10: Strange Account I found in HKEY_USERS

Discus and support Strange Account I found in HKEY_USERS in AntiVirus, Firewalls and System Security to solve the problem; I recently got a malware attack, luckily nothing bad happen, I resolved it, but when I go to regedit, I found these accounts in... Discussion in 'AntiVirus, Firewalls and System Security' started by TheOneWhoIsntTooTechy, Sep 29, 2021.

  1. Strange Account I found in HKEY_USERS


    I recently got a malware attack, luckily nothing bad happen, I resolved it, but when I go to regedit, I found these accounts in HKEY_USERS:S-1-5-18S-1-5-19S-1-5-20S-1-5-21-1822402108-566194498-1648361893-1001S-1-5-21-1822402108-566194498-1648361893-1001_ClassesThese are very strange, my laptop only have 2 accounts, I don't want to risk my laptop by removing them so I hope you guys can explain it for me,

    :)
     
    TheOneWhoIsntTooTechy, Sep 29, 2021
    #1
  2. Zakin Win User

    Strange Windows 10 User Account issue.

    Unfortunately I had done those steps numerous reboots, it just, reappears for no good reason. The base account isn't even a Microsoft account, it's a local account.

    I haven't quite tried the built in administrator account on W10, but so far in my experience on my own computer, the built in account seemed to have absolutely no more control than I did on my own.

    It's just strange, I go in, it warns me twice about deleting the account, then it's gone. Reboot, and it's back?

    EDIT: Just to specify, both command line and Netplwiz both say only HIS account exists on the computer, it doesn't list this rogue account. This is what I meant in my first post about the fact that even Windows doesn't seem to believe it exists, HALF the time. *Frown Strange Account I found in HKEY_USERS :(
     
    Zakin, Sep 29, 2021
    #2
  3. Vesao Win User
    Remove account

    I suggest you backup your personalized files first before removing the account.
    To delete an account, follow these steps:
    1. Press WIN + X keys and click Command Prompt (Admin) from the menu.
    2. Type the following command and press Enter. Replace test with the name of your sister's account. Code:
     
    Vesao, Sep 29, 2021
    #3
  4. Strange Account I found in HKEY_USERS

    Microsoft account Sign in option under user account is not working

    Hi NAvneet.

    Many thanks for your help. But this didn't work.

    Should I try the below procedure. Someone has suggested this method to similar query in other thread. Pls suggest:

    Please follow the steps to enable the build in administrator and check if it helps:

    • Use the power button on the sign-in screen to Shift+Restart. This will take you to the recovery boot menu.
    • Click Troubleshoot, Advanced options, Startup settings. When given the choice of startup options, try booting the PC in
      Safe Mode with Command Prompt. If you can’t get there, skip to the next major step.
      • If you can get to a CMD window, enable the built-in administrator account:

        net user administrator /active:yes
      • Then restart and sign-in as the Administrator account.
      • Once in the Administrator account, open Regedit
        and go to the following key:

        HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities
      • Save a backup of the key: Export the StoredIdentities key to a .REG file on the desktop.
      • Then continue with step 4 below.
    • Use boot media to access the recovery command prompt.
      • Start Regedit.
      • Select the HKEY_USERS key.
      • Click File, Load Hive. and go up in the file system to This PC. Then browse to this file and then click Open:

        C:\Windows\System32\config\DEFAULT
      • When prompted, name it “def”
      • Select this key:

        HKEY_USERS\def\Software\Microsoft\IdentityCRL\StoredIdentities
      • Save a backup of the key: Export the StoredIdentities key to a .REG file on the C:\ drive.
    • Find the subkey under StoredIdentities that matches the name of the Microsoft Account.
    • Delete the key.
    • If you loaded the offline registry hive, go back up in the tree on the left and select “def”. Then click File,
      Unload hive. This option will only be available if “def” is selected.
    • Restart the PC and test sign-in.
    • Once done, you may need to Verify the account in Settings, Accounts in order for it to be fully usable in Windows again.
    • If you used the built-in Administrator account to resolve the issue, please return it to the default disabled state to help keep the Computer secure. To do so follow the steps:
      net user administrator /active:no
    Please create a new administrator account using the Microsoft Account and check.
     
    Shobhitjain2005, Sep 29, 2021
    #4
Thema:

Strange Account I found in HKEY_USERS

Loading...
  1. Strange Account I found in HKEY_USERS - Similar Threads - Strange Account found

  2. Strange ports are found and TPM is not found

    in Windows 10 Gaming
    Strange ports are found and TPM is not found: Hello FriendsWell i have Windows 11 installed on Asus ROG ,So Here is the thing i have formated my laptop because seems malware bytes found legalhakcer.com suspicious linked to my edge...But some how i see two ports open in my laptop port 1042,1043 afrog so i googled seems...
  3. Strange ports are found and TPM is not found

    in Windows 10 Software and Apps
    Strange ports are found and TPM is not found: Hello FriendsWell i have Windows 11 installed on Asus ROG ,So Here is the thing i have formated my laptop because seems malware bytes found legalhakcer.com suspicious linked to my edge...But some how i see two ports open in my laptop port 1042,1043 afrog so i googled seems...
  4. I was following instructions and found something strange... possibly?

    in Windows 10 Software and Apps
    I was following instructions and found something strange... possibly?: So I went to the eventvwr.exe then to Applications and Service Logs, then to Microsoft, followed by Windows and was supposed to go to Immersive-Shell folder from there.... only problem being... there is no immersive-shell folder. I don't know what to do from here. Help...
  5. Registry Editor - HKEY_USERS

    in Windows 10 Gaming
    Registry Editor - HKEY_USERS: Why there are multiple folders? Is it safe to delete "S-1-5-18" and "S-1-5-19" and "S-1-5-20"? I don't think there's any important stuffs in those folders. They just look like junksEdit : These 3 folders also has the same stuffs...
  6. Registry Editor - HKEY_USERS

    in Windows 10 Software and Apps
    Registry Editor - HKEY_USERS: Why there are multiple folders? Is it safe to delete "S-1-5-18" and "S-1-5-19" and "S-1-5-20"? I don't think there's any important stuffs in those folders. They just look like junksEdit : These 3 folders also has the same stuffs...
  7. Deleted my user in hkey_users

    in Windows 10 Gaming
    Deleted my user in hkey_users: Windows 7. I've deleted a directory in registry with my user in hkey_users. After that a new one was created automatically but I'm having some issues other than just losing a lot of settings and need an advice on how to fix them.Some mouse settings reset after restart. The...
  8. Deleted my user in hkey_users

    in Windows 10 Software and Apps
    Deleted my user in hkey_users: Windows 7. I've deleted a directory in registry with my user in hkey_users. After that a new one was created automatically but I'm having some issues other than just losing a lot of settings and need an advice on how to fix them.Some mouse settings reset after restart. The...
  9. Strange file found

    in Windows 10 Network and Sharing
    Strange file found: The short version is that I found this file about 8 months ago and called windows phone support. No one there had any idea as what it was. All scans have comw up negative for malware. There is no information about it on the web that I could find. I have attached a pic of...
  10. Strange accounts found in registry

    in AntiVirus, Firewalls and System Security
    Strange accounts found in registry: Hello, Recently my virus scanner (Malwarebytes) discovered a registry key that seemed to be associated with a virus that I thought I had gotten rid of a while ago. After doing some digging around in the regsitry editor I found some user keys in HKU that were similar to the...