This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Virus" that "creates" local Administrator account in

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I encountered this "virus"-looking problem today. (kevinf80 advised another user at another forum on the same problem, on Feb 3, 2017, here: https://forums.malwarebytes.com/topic/195593-local-administrator-account-created/ )

 

My system booted very slowly and then showed two user accounts: a new "Administrator" account beside my usual user account in Windows 8.1, instead of simply going to my account directly and asking its password. Thankfully my normal (local) user account is also an administrator account (and password protected).

 

However, upon rebooting, the system now only went to this "new" Administrator account, without a password, and which was very slow to respond to mouse clicks and events. Eventually getting to its desktop, it showed only three icons, including a "Removed Apps" icon that was a HTML link to somewhere… Very suspicious.

 

Rebooting only took me back to this "unwanted" account, which turned out to be the built-in Administrator account that was somehow "hijacked" for this weirdness. Using BIOS/boot routines, pressing F10 and F12 at startup, I could get into my usual account using Safe Mode, but that didn't allow me to connect to the internet, etc.

 

After the initial panic subsided, my solution was to use Windows 8's System Restore function to restore to the most recent "restore point" of a week ago. The restore point option was offered as an advanced option in a boot manager. (I was considering installing Windows 7 or Ubuntu, which made the dual-boot manager appear at startup, for this drastic solution.) Windows 8's System Restore seemed to solve the problem, and then I ran MalwareBytes which quarantined and removed a bunch of adware/malware/other junk.

 

Was this some kind of one-off malware attack? I think I picked it up from an unclean USB the day before.

Hello alyssa__808 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • click on Start Scan
  • when it has finished, click on Open Report
  • click on Export Txt and save the file on your Desktop as RKreport.txt
  • copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

Logs to include with next post:

AdwCleaner log
RKreport.txt


Thanks

Satchfan

 

Hi alyssa__808

It has been 3 days since I replied to your request for help with your computer problems.

Please let me know if you are having problems and still need help.

If I do not hear from you within 24 hours I'll close this topic.

Satchfan

hey satchfan: thanks for your advice.

 

unfortunately, i'm very suspicious of installing unknown software, and after using windows 8's system restore function, as well as a quick clean with malwarebytes, i felt the problem was solved.

 

clearly some malware gained administrator access on my machine, which is worrying, but generally i'm quite careful!

~take care ^-^

Hello alyssa__808

 

I would strongly suggest that you run the tools I suggested as a system restore and Malwarebytes alone won't clean everything. What I asked you to run are safe programmes that are recommended and safely used by all of the malware removal teams on the top respected forums. If you'd rather not and are happy to close this, please let me know.

 

Thanks

 

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI