need to identify users nis 2011

I am running windows 7 home premium. I bought the computer new. The OS and nis 2010 were already installed. I have renewed my norton subscription twice before it expired, so now I have nis 2011. My question is,

 

When my computer starts up, there are three profiles that I can select to log on to. One administator and two standard, all password protected.

 

If I go to C:\users, there are 6 different profiles listed the names I have given to the user accounts I have set up don't appear to let me at least verify which 3 are mine. There is also a default user file. In addition another profile called "default APPOOL" showed up and I don't know why. When I look at security tab properties there are a lot of user entries recieving permissions and one says C;\users(pc users) which is covered up with a s-1-5-21xxxxxxxxx when I click the security tab, but it disappears quickly and displays C:\users(pcusers) again. When I look at the registry entries for users, I am usuming the s-1-5-17 thru s-1-5-20 are my three accounts. The s-1-5-21xxxxxxxx has two entries, the second one has classes at the end.

 

How do I identify where each account came from or who it belongs to. I am suspiscious about the s-1-5-21 profile, 1) because I don't know what it is and 2) it is the common denominator in reading my error logs. If I open that profile it has the same folders as the other profiles and when I open its documents folder there are many files including files that are filetypes like .RRR .xml that I can't read or cant access. All files normally display in black, Some files in this profile display in blue. What does that mean.? Every tother folder in that profile is either empty or displays a list of sounds in blue. (Chime, ding, calligraphy,.

 

Can someone tell me if this has something to do with Norton? Each profile has in the app data folder a local, localow, and a roaming profile.

 

I am just a single computer. My internet provider is comcast. I am not connected to other computers. I feel like there has been some remote activity and I unchecked the remote access box but it doesn.t stay that way. I need to identify and clean up my user accounts and their permissions to a normal setting for a single computer with one adm. and two standard accts.

I know this probably can be better explained. Sound familiar to anyone?