Strange long numbered user in list of users in security tab of drive properties (XP)

shurato

Platinum Member
Sep 24, 2000
2,398
0
76
I was fiddling around with my windows xp sp1 system and when i clicked on properties for one of my drives and clicked on the security tab and found 2 users S-1-5-21-1177238915-1383384898-1060284298-1003 and *.-1005 listed. What is this? It has an icon of traced persons face with a question mark on it. First username has special permissions checked and second username has all the deny boxes checked but the boxes are faded out and you cant check or uncheck.

What is this? Has my system been comprimised by a trojan? I'm on dialup and have not installed an anti-virus program on my XP system nor a firewall. I know I should since i had both on my previous system before the XP install.

edit: also i do not have these users listed in my user list. just the admin and my account which is also an administrator account is listed in my users list in the computer management snap-in.
 

ProviaFan

Lifer
Mar 17, 2001
14,993
1
0
I've had "ghost" user accounts like this show up when I upgraded from Windows 2000 to Windows XP. Not sure why, or how to get rid of them. If you never upgraded, but rather performed a fresh install, you may have been hacked, so please follow the suggestions of the others about antivirus and firewall programs.
 

shurato

Platinum Member
Sep 24, 2000
2,398
0
76
Thanks...still a little confused but understanding it more. Yeah I have a copy of tiny firewall i am using on my other computer that I will install on my computer and I need to pick up an antivirus program for xp.
 

Woodchuck2000

Golden Member
Jan 20, 2002
1,632
1
0
I've had "ghost" user accounts like this show up when I upgraded from Windows 2000 to Windows XP. Not sure why, or how to get rid of them. If you never upgraded, but rather performed a fresh install, you may have been hacked, so please follow the suggestions of the others about antivirus and firewall programs.
On NTFS drives, permissions are written at a very low level. They are referenced using SIDs to a database of the users on that computer.

If you've installed a new OS onto an existing NTFS partition, old SIDs may still have access to parts of the drive. If XP/2K cannot find a user that relates to a SID, it will simply display the SID. You can simply delete the SID from the security list on that partition to get rid of it.

shurato - Did you perform a fresh install of XP?