Windows 10: Suspicious account owning C:/ and OneDriveTemp file named after an SID

Discus and support Suspicious account owning C:/ and OneDriveTemp file named after an SID in Windows 10 Gaming to solve the problem; Hi,I have had a few alerts regarding a Trojan program in my computer. I have identified a folder in OneDriveTemp named :... Discussion in 'Windows 10 Gaming' started by Yanis Dufour, Oct 25, 2024.

  1. Suspicious account owning C:/ and OneDriveTemp file named after an SID


    Hi,I have had a few alerts regarding a Trojan program in my computer. I have identified a folder in OneDriveTemp named : C:\OneDriveTemp\S-1-5-21-2566854302-1957120293-848769299-1001which looks very suspicious. This folder contains a 0kb file named : a6f896e07d0445b18f7874bfbbf5bad8-Personal.I've also seen, after looking at similar issues people had, that the C:/ respository is owned by an unknown user with a different SID starting with S-1-15-3-65536. From what I could read, it seems to be a legit user but I'm not sure I understand fully why does it exist and how is it not dangerous if it cou

    :)
     
    Yanis Dufour, Oct 25, 2024
    #1
  2. Ramesh Srinivasan, Oct 25, 2024
    #2
  3. Try3 Win User
    Lost myWin10 User Partition Name  

    Stu, I do not understand:- 1 The "USER" account appears in many places in Admin 2 bootable user - you've used this term before but it is not a defined term and I don't know what you mean. I can take you through a series of commands to check exactly what each user account thinks is its user folder path. It's going to get too confusing with aliases such as "USER" so, if you are willing, perhaps you can post the results of the checks in PMs to me and I'll be careful to avoid using real usernames in posts here. Step 0 In all steps, ignore user 'accounts' called DefaultAccount, defaultuser0/1/…, Guest, WDAGUtilityAccount Step 1 Run this command Code:
    This tells you the SID for each username. Step 2 Run RegEdit, go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList Step 3 For each of the SIDs in the Registry SubKeys beginning S-1-5-21, select it and look at its ProfileImagePath entry. Step 4 Step 3 tells you the ProfileImagePath [user folder path] for each SID and you can then look up which user name it relates to using the results of Step 1. So now you can see which user folder path Windows thinks it should use for each username. Please post [here or in a PM to me] the list of usernames, SIDs, user folder paths. Please confirm that those user folder paths get shown in File explorer, C:\Users. Denis
     
  4. Vesao Win User

    Suspicious account owning C:/ and OneDriveTemp file named after an SID

    Remove account

    I suggest you backup your personalized files first before removing the account.
    To delete an account, follow these steps:
    1. Press WIN + X keys and click Command Prompt (Admin) from the menu.
    2. Type the following command and press Enter. Replace test with the name of your sister's account. Code:
     
    Vesao, Oct 25, 2024
    #4
Thema:

Suspicious account owning C:/ and OneDriveTemp file named after an SID

Loading...
  1. Suspicious account owning C:/ and OneDriveTemp file named after an SID - Similar Threads - Suspicious account owning

  2. Suspicious account owning C:/ and OneDriveTemp file named after an SID

    in Windows 10 Software and Apps
    Suspicious account owning C:/ and OneDriveTemp file named after an SID: Hi,I have had a few alerts regarding a Trojan program in my computer. I have identified a folder in OneDriveTemp named : C:\OneDriveTemp\S-1-5-21-2566854302-1957120293-848769299-1001which looks very suspicious. This folder contains a 0kb file named :...
  3. 4625 Event ID shows own pc name as the account name and security ID on Null SID

    in Windows 10 Gaming
    4625 Event ID shows own pc name as the account name and security ID on Null SID: Can anyone shed light as I'm getting the error below, on a pattern, every 7 PM daily and 8 AM weekly on one of our *servers ?. No scripts running, and no task/s scheduled to run. I do get that it is coming somewhere remotely as it has a logon type of 3 but the IP is coming...
  4. 4625 Event ID shows own pc name as the account name and security ID on Null SID

    in Windows 10 Software and Apps
    4625 Event ID shows own pc name as the account name and security ID on Null SID: Can anyone shed light as I'm getting the error below, on a pattern, every 7 PM daily and 8 AM weekly on one of our *servers ?. No scripts running, and no task/s scheduled to run. I do get that it is coming somewhere remotely as it has a logon type of 3 but the IP is coming...
  5. 4625 Event ID shows own pc name as the account name and security ID on Null SID

    in AntiVirus, Firewalls and System Security
    4625 Event ID shows own pc name as the account name and security ID on Null SID: Can anyone shed light as I'm getting the error below, on a pattern, every 7 PM daily and 8 AM weekly on one of our *servers ?. No scripts running, and no task/s scheduled to run. I do get that it is coming somewhere remotely as it has a logon type of 3 but the IP is coming...
  6. Files w/ suspicious names undetected by malware scan?

    in Windows 10 Gaming
    Files w/ suspicious names undetected by malware scan?: I was doing a malware scan on my laptop and found files named the...
  7. Files w/ suspicious names undetected by malware scan?

    in Windows 10 Software and Apps
    Files w/ suspicious names undetected by malware scan?: I was doing a malware scan on my laptop and found files named the...
  8. How do files get into OneDriveTemp?

    in Windows 10 Network and Sharing
    How do files get into OneDriveTemp?: I have a folder on C:\ which contains almost all of my personal work. Today I noticed that the whole folder had been moved from c:\ to c:\OneDriveTemp. This happened at least before last night, because an altered file was not saved in the backup set that saves everything in...
  9. OneDriveTemp file

    in Windows 10 Network and Sharing
    OneDriveTemp file: I have the location of OneDrive in my D drive. Also there is a OneDriveTemp folder. The OneDriveTemp folder fails to back up in my external hard drive. When I try to open the OneDriveTemp folder a phantom drive is created in "This PC" Sometimes it is a Drive G:, sometimes...
  10. OneDriveTemp Hidden file on C:\...vhdx

    in Windows 10 Network and Sharing
    OneDriveTemp Hidden file on C:\...vhdx: Hi, I noticed there is a hidden file named; OneDriveTemp Hidden file on C:\ It's also shown that is a .vhdx The strange is when I tried to mount this .vhdx to check what is inside it, I got message says; this locked by bitlocker, to open it you must enter the USB, etc, I...