Technical Discussion
  >> Windows Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User cheshire_man
(experienced) Wed 21-Jul-10 18:36:26
Print Post

What is user named DRAWDE


[link to this post]
 
When I booted my PC (XP SP3) this morning it took 3 to 4 times longer than usual to get going. Once going it seemed ok.

Tried it again, the same.

Started in Safe mode and to my surprise it came up with User login screen, myself (the only user on the PC) and one called DRAWDE. I had no idea what DRAWDE was so when the PC had started looked in Control Panel / Users, no sign of an alien user. Searched the Registry for DRAWDE, no sign.

So becoming somewhat bemused I went into Control Panel / Administrative Tools / Computer Management. Under Local Users and Groups I found 'drawde' (together with my own account, Guest, ASPNET, SUPPORT_388945a0, HelpAssistant - the last 2 were disabled). The description for 'drawde' said 'Built-in account for administering the computer/domain'. Being somewhat bemused, rather than deleting the user I disabled it and then rebooted.

It started fine and has been ok all day, including a reboot just now, to check.

It occurred to me that DRAWDE is an anagram of ADWARE and made we wonder whether it's crept in by some unwanted activity. I ran Superantispyware and Malwarebytes. The first found Adware tracking cookies, which it deleted but these are "usually" harmless. Malwarebytes reported two registry key infections:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
Any thoughts on what may be going on?

For background I rebuilt the complete system last December and have been the only user.

Tony
Standard User deleted
(deleted) Wed 21-Jul-10 18:45:52
Print Post

Re: What is user named DRAWDE


[re: cheshire_man] [link to this post]
 
In reply to a post by cheshire_man:
It occurred to me that DRAWDE is an anagram of ADWARE
Oh no it isn't.
Standard User cheshire_man
(experienced) Wed 21-Jul-10 18:53:26
Print Post

Re: What is user named DRAWDE


[re: deleted] [link to this post]
 
So it isn't, must get a new dictionary blush

Tony


Register (or login) on our website and you will not see this ad.

Standard User cheshire_man
(experienced) Thu 22-Jul-10 23:01:14
Print Post

Re: What is user named DRAWDE


[re: cheshire_man] [link to this post]
 
I decided to rebuld my PC.

No sign of that user now so I'd guess it's from some rogue source.

Tony
Standard User deleted
(deleted) Fri 23-Jul-10 20:20:10
Print Post

Re: What is user named DRAWDE


[re: cheshire_man] [link to this post]
 
Wow thank your lucky stars it wasn't ALUCARD laugh

but seriously, something did appear to create a 'hidden' Admin user account - definitely worrying.
would have been interesting to have done a file search to see if any other files or folders were created at the same time.

and really, always safer to user standard 'User' account for most things..
  Print Thread

Jump to