User folder owned by unknown user on new Thinkpad

Performance, hardware, software, general buying and gaming discussion..
Post Reply
Message
Author
ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

User folder owned by unknown user on new Thinkpad

#1 Post by ikarus » Tue Mar 27, 2007 3:55 pm

I have had my new Z61t with Vista for a few days now and I just observed that there is a user directory with a cryptic name on it. Properties show access permissions for a user "Account unknown". File creation date is 2006/11/02. My theory is that either one of these must be the cause of this:

1) There is a rootkit on my machine. I find that hard to believe since Vista is relatively new, the machine hasn't been online much and one of the first things I did was installing Firefox and Thunderbird.

2) This is the remnant of some remote service run by Lenovo. I somehow remember having agreed to remote servicing when I powered up the machine the first time.

3) I got a refurbished machine and they forgot to clean up the account they were using for doing some clean-up work. This may add cause to me returning the laptop because of the bent LCD frame issue (see my recent posting in Z series forum).

Can anyone shed some light on this?

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

#2 Post by ikarus » Tue Mar 27, 2007 5:39 pm

Another theory... it may also be that this folder was created automatically when I experimented with hooking up my old XP machine to the Thinkpad via Ethernet. Geez, those are the days when I wish myself back onto Linux. :?

jdhurst
Admin
Admin
Posts: 5831
Joined: Thu Apr 29, 2004 6:49 am
Location: Toronto, Canada

#3 Post by jdhurst » Tue Mar 27, 2007 6:17 pm

ikarus wrote:Another theory... it may also be that this folder was created automatically when I experimented with hooking up my old XP machine to the Thinkpad via Ethernet. Geez, those are the days when I wish myself back onto Linux. :?
Not likely. Networking two machines does not create user folders on its own. No different than Linux in this respect. ... JDH

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

#4 Post by ikarus » Wed Apr 04, 2007 12:29 pm

It's odd. A few reboots later, the user folder is back. This time, its name is kdbhpmBNIWEL. Total tree size is 22MB, 15.5 being in C:\Users\kdbhpmBNIWEL\AppData\Local\Microsoft\Windows Mail alone. It is owned by "Account Unknown (S1-5-21-<long number>). If noone else has this, I'm starting to think I really got a refurbished laptop and that some start-up process is restoring some old data.

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

#5 Post by ikarus » Wed Apr 04, 2007 1:42 pm

Actually, I believe I did a BIOS update around the time of the user folder creation timestamp. Could this be a clue?

jdhurst
Admin
Admin
Posts: 5831
Joined: Thu Apr 29, 2004 6:49 am
Location: Toronto, Canada

#6 Post by jdhurst » Wed Apr 04, 2007 1:45 pm

At no time have I seen an NT-based computer create a user on its own that cannot be identified. I have Local Service and Network Service user folders but they are identifiable. Additionally there are Microsoft and VMware users on my system but no user folders for them.

So yes, you apparently did not get a new TP out of the box.
... JDH

RealBlackStuff
Admin
Admin
Posts: 17519
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

#7 Post by RealBlackStuff » Wed Apr 04, 2007 6:12 pm

They may have given you a 'demonstrator', which would explain the odd account.
They may also have loaded a Sony music CD on that laptop, which could explain the rootkit.
All in all, that's definitely NOT a new machine. I'd get it exchanged if I were you.
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

Talon88
Sophomore Member
Posts: 170
Joined: Thu Jan 12, 2006 11:22 pm
Location: Toronto & HK

#8 Post by Talon88 » Wed Apr 04, 2007 10:06 pm

:::

Have you or you friends ever put an Audio or Movie
CD/DVD into your system. This will automatically
inplant the rootkit to you system by these stupid
copyright org....!

:::
--
~ Talon88 ~ IBM Z60t 14" WS ThinkPad ~

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

#9 Post by ikarus » Wed Apr 04, 2007 11:10 pm

I ran a rootkit tool on the machine and that didn't find anything. I still need to figure out when these folders are created, but it's definitely not after every regular shutdown. My current prime suspect is the Thinkpad tool responsible for installing the BIOS update.

RealBlackStuff
Admin
Admin
Posts: 17519
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

#10 Post by RealBlackStuff » Thu Apr 05, 2007 1:50 am

Let this online-scanner check your laptop. TrendMicro's Housecall does a very thorough job
http://housecall.trendmicro.com/
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

Gotcha!

#11 Post by ikarus » Thu Apr 05, 2007 11:17 am

Apparently, these user folders are created on Vista when you start the Thinkvantage System Update as a user without admin rights. I don't have the "true" Administrator account enabled, so this might not happen if it is. It's strange I should be the only one who has run across this issue. Could someone else try and let me know? Thanks!

hoplite
Freshman Member
Posts: 95
Joined: Thu Mar 15, 2007 11:21 pm
Location: New York, NY

#12 Post by hoplite » Thu Apr 05, 2007 12:19 pm

Happened to me too. I thought it was my cisco VPN connection that created it. I couldn't figure it out what it was. I'll test it later now that you came up with a cause and see if I can reproduce your results.
W510 - 4318-CTO (15.6" FHD, i7-820, 8GB DD3, 500GB)
T60P - 8744-J2U (LG 15.4" WSXGA+, 2.0GHz, 4GB DDR2, 500GB 7200RPM, FireGL 256MB, Vista Business)
T60 - (15.4" - WSXGA - 2.0GHz, 2GB DDR2, 320GB)
R40 - 2681 (15" XGA, 2.2GHz, 1GB RAM, 40GB)

ikarus
Posts: 16
Joined: Sat Mar 24, 2007 1:24 pm
Location: Mountain View, CA

#13 Post by ikarus » Fri Apr 06, 2007 1:28 pm

hoplite wrote:I'll test it later now that you came up with a cause and see if I can reproduce your results.
Thanks, please let me know what you find. My next question would be how to let Lenovo know about it so that they can provide a fix.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Thinkpad - General HARDWARE/SOFTWARE questions”

Who is online

Users browsing this forum: No registered users and 6 guests