Windows 10: window NT-AUTHORITY Misuse by hackers

Discus and support window NT-AUTHORITY Misuse by hackers in Windows 10 Customization to solve the problem; What is happening now is window 10 is hijack and no home users is immune to it and microsoft will do nothing because they got nothing to do with home... Discussion in 'Windows 10 Customization' started by Manenogus, Nov 13, 2019.

  1. Manenogus Win User

    window NT-AUTHORITY Misuse by hackers


    What is happening now is window 10 is hijack and no home users is immune to it and microsoft will do nothing because they got nothing to do with home users, it starts with account problems, this is because you are being impersonated and your local account will be hijack by online administrators.

    this is what happened


    When you first set up your pc, you give your pc the Name and you login with Microsoft account.

    Later on, you realise the pc name you gave is not there, you see DESKTOP-C7M62D0

    The User default profile is not you and you can't change it

    what happened is some time back you got infected or you visit pc repeater you don't remember and now, the default migration settings was set on you, even if you buy new window 10, the default migration setting will be applied automatically without you knowing and this will continue as long as you are still using window 10, it is in the memory.

    MigUnit Name =<"WIN-79EM792E6F\Dfault User>\additional_options\additional_options\windows_core_settings\Microsoft-window-win32k-settings(CCSIAgent)


    I manage to lay my hand the setting logs, it say their Group is managed by the system and users are prevented from making system wide changes intentionally or accidentally.

    when you see notification start coming account problem, You are being impersonated, open users, you will see You the person who log into the pc and " public " under you, double click, property and you will see you are being managed by system administrators.

    go to quick access, document, pictures, one Drive, video and then "favorite" you will see who is actually got permission on you.

    "public" this is another users disquest, it also got document, photos, oneDrive favorite and all that you always used, you may think it is a repetition but not, it generate too much temp files and all what you are doing is stored in tmp files and you do not have permission to delete these files, it is not the usual place temporary files, check the property of all and its the users you see in the log sheet NT-Authority and all that you see in the log sheet, the 2 users "Public and You will merge as one account and that is why you will be seeing Microsoft account problems and oneDrive is not log in even if you are login with Microsoft account, the notification keep coming and the local account will be hijack as you are seeing.


    what happened after account is hijacked, another Microsoft window in the container will be overlay over the Window which you install, and now what you see in the sheet log below become reality, keep using the window but never make any changes, you can't even open firewall, that overlay window key log and no problem, no update and no download, no antivirus, although you had antivirus before and you can still see it in the taskbar, you can click and it says everythings is fine but if you manage to open firewall, it says firewall is not using recommended settings. when you open the bios, sometime you will find that, secure boot is disable, hot key is enable and software control is enable, even if you reset it to factory default, it will go back at the start of window, you will not be able to restore window, reset, you do nothing because what you see is in the container and keylog, this controlled window works perfectly if you do not do not touch any setting, if you do touch any settings, the window will crush.

    window NT-AUTHORITY Misuse by hackers [​IMG]


    window NT-AUTHORITY Misuse by hackers [​IMG]

    :)
     
    Manenogus, Nov 13, 2019
    #1
  2. Goatberg Win User

    NT AUTHORITY\Authenticated Users added to Users group upon every restart

    I have a Windows 10 computer that I would only like certain users on a domain to be able to login to. Lets say limit access to only those users in the group named football.

    I have added the football group to the Windows users group. The computer is on a domain and I noticed the following two groups both of which I removed from the Windows users group.

    • NT AUTHORITY\Authenticated Users
    • NT AUTHORITY\Interactive
    I have tested that NT AUTHORITY\Authenticated Users is allowing users outside of the football group to login to the computer and this is not wanted.

    If I remove both of these groups from the Windows users group then they will reappear upon every restart of the computer. This did not have with Windows 7. This seems to be a security problem???
     
    Goatberg, Nov 13, 2019
    #2
  3. NT AUTHORITY/SYSTEM shutdown

    How do I removed this shutdown initiated by NT AUTHORITY/SYSTEM on windows 10?. It keeps showing up on my PC.
     
    mikerozzle, Nov 13, 2019
    #3
  4. Gelo31415 Win User

    window NT-AUTHORITY Misuse by hackers

    EventID 10016 - NT AUTHORITY\SYSTEM - name not found


    Hi all!
    This is the problem I am facing:

    Code:
    Code:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}  and APPID  {F72671A9-012C-4725-9D2F-2A4D32D65169}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
    AND

    Code:
    Code:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {D63B10C5-BB46-4990-A94F-E40B9D520160}  and APPID  {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}  to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
    So far i have tried the solution as described here:

    Error - Event ID DistributedCOM - Microsoft Community
    The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID

    All works fine, until i have to add "NT AUTHORITY\SYSTEM" in the final step. Windows tells me that this name can not be found. Google told me, that NT AUTHORITY\SYSTEM has something to do with SQL so i went ahead and installed from the MS homepage.

    I am running W10Pro (fresh install one week ago) with all the latest updates. All drivers up to date.

    Any ideas of what i could try next? This issue seems to be responsible for crashes every few hours *Mad*Sleepy*Sad
     
    Gelo31415, Nov 13, 2019
    #4
Thema:

window NT-AUTHORITY Misuse by hackers

Loading...
  1. window NT-AUTHORITY Misuse by hackers - Similar Threads - window AUTHORITY Misuse

  2. NT AUTHORITY\SYSTEM ‎powershell‎, New-MailboxExportRequest

    in Windows 10 Gaming
    NT AUTHORITY\SYSTEM ‎powershell‎, New-MailboxExportRequest: Hi Community,I have an exch of 2016 Cu22 and Cu23. All are patched with the latest patches on both CU updates. but recently I have seen a mailbox export request visible on my EAC notification bells. I check and surprise. some exploits RAN a command on the power shell to get a...
  3. NT AUTHORITY\SYSTEM ‎powershell‎, New-MailboxExportRequest

    in Windows 10 Software and Apps
    NT AUTHORITY\SYSTEM ‎powershell‎, New-MailboxExportRequest: Hi Community,I have an exch of 2016 Cu22 and Cu23. All are patched with the latest patches on both CU updates. but recently I have seen a mailbox export request visible on my EAC notification bells. I check and surprise. some exploits RAN a command on the power shell to get a...
  4. Scheduled Tasks being deleted by NT AUTHORITY\System

    in Windows 10 Customization
    Scheduled Tasks being deleted by NT AUTHORITY\System: Good Afternoon, Hoping someone can shed some light on this mystery! In basics, I have two scheduled tasks set by group policy to call upon a .bat script. However, one keeps being deleted by 'NT AUTHORITY\System account for seemingly no reason. This only affects one task...
  5. SSH Connection Refused - nt Authority

    in Windows 10 Network and Sharing
    SSH Connection Refused - nt Authority: I'm trying to get into a win10 box from a linux box. I can get in using a normal user password but when I try to use shh keys I get: debug1: Authentications that can continue: publickey,password,keyboard-interactive debug1: Next authentication method: publickey ED25519...
  6. NT Service\TrustedInstaller & NT authority\system

    in Windows 10 Customization
    NT Service\TrustedInstaller & NT authority\system: is "NT Service\TrustedInstaller" the same thing as "NT Authority\system"? can you log into "NT Athority\system"? i understand that "NT Service\TrustedInstaller" is not a user, i under stand that "NT Service\TrustedInstaller" is just trustedinstaller.exe with a temporary...
  7. NT AUTHORITY\NETWORK SERVICE - Different language

    in Windows 10 Customization
    NT AUTHORITY\NETWORK SERVICE - Different language: Hi What could be the reason for the NT AUTHORITY\NETWORK SERVICE doesn't appear to me in english ? I was having some issues while running some powershell scripts that was searching by the english name. I was only able to find out by the sid. $objSID = New-Object...
  8. NT Authority hijack persistent/embedded

    in AntiVirus, Firewalls and System Security
    NT Authority hijack persistent/embedded: I have a machine that I am not able to do much with other than to wonder whats really goin on at the other end of the constant HDD indicator light, fans spooling up/ down and is all of this to some nefarious end with the 50gb of data activity my router handled today for the...
  9. NT Authority will not give me access !!!!

    in User Accounts and Family Safety
    NT Authority will not give me access !!!!: Hello, I could use some real help here. I have a Dell Inspiron 5775 running Windows 10 Home 1909 up to date, in the past I could go into performance monitor as admin and I could add New Data Sets for GPU and CPU. Now when I tried to add these parameters I keep getting the NT...
  10. NT Authority will not give me access !!!!

    in Windows 10 Support
    NT Authority will not give me access !!!!: Hello, I could use some real help here. I have a Dell Inspiron 5775 running Windows 10 Home 1909 up to date, in the past I could go into performance monitor as admin and I could add New Data Sets for GPU and CPU. Now when I tried to add these parameters I keep getting the NT...

Users found this page by searching for:

  1. nt authority authenticated users HACKING