How would I go about finding possible hidden user accounts within NT? I have some audited event log entries which list a password change for “username$”. I know that adding the $ to the end of a folder hides it from view, does the same apply to usernames? When legitimate users change their password, their username appears as is (ie without the $ sign). There is no entry in the User Manager for Domains for “username$”, and I am concerned that network security may have been compromised.