Step 1: Sign in to your own admin account
Step 2: Inspect the suspicious account before deleting
C:\Users\<suspicious-account-name> in File Explorer. If it contains files you actually want to keep, copy them to your own user folder first.Step 3: Demote then delete
Important
Step 4: Reset your own password
Step 5: If your own account was demoted
net localgroup administrators <your-username> /add.Important
Step 6: Run a malware sweep
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers