Windows 10: The mysterious unknown account: Threat or harmless bug?

Discus and support The mysterious unknown account: Threat or harmless bug? in User Accounts and Family Safety to solve the problem; In the process of performing the usual necessary cleanup after installing FCU (fixing the various DCOM errors due to improper permission settings) I... Discussion in 'User Accounts and Family Safety' started by Pirx, Oct 29, 2017.

  1. Pirx Win User

    The mysterious unknown account: Threat or harmless bug?


    In the process of performing the usual necessary cleanup after installing FCU (fixing the various DCOM errors due to improper permission settings) I was reminded of this particular situation again. I was hoping that perhaps the collected expertise in this forum could shed some light on this potentially serious problem.

    In a nutshell, it appears that for certain hardware configurations (see below), there is an unusual SID that is being created which the system does not recognize, so it is listed as an "Unknown Account". This could be a minor nuisance, except for the fact that this SID is assigned permissions at top-level registry keys and then propagates down to a vast number of system objects. As a consequence, this unknown account has permissions to a large number of objects and processes, including the permission to launch and activate almost any DCOM object on the system.

    The SID of this account is S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681, and there is some indication (from two posts by Sonya here and here) that these security entries are created during the installation of NVidia video drivers. Now, like I said, this could just be a minor cosmetic nuisance, except it may not be.

    First of all, the SID above does not look like a standard, properly formed SID. Second, I have seen some references that Windows allows processes to generate SIDs of that kind "on the fly" for special purposes, such as sandboxing: You create an SID for a non-existent account for a process, which means that such a process does not have access to any of the regular system objects except those with permissions for "Everyone", I think.
    If that is correct, and if a process can create such SIDs freely, then the issue we have with this NVidia-generated SID is that it cracks our systems wide open to any process that can generate this SID for itself. In other words, we would be looking at a catastrophic security hole. Indeed, the poster I have quoted above (Sonya) reports that NVidia software seems to be starting all sorts of processes using just this mechanism, including remote connections of all sorts. In one of her posts she goes as far as referring to this as "theft ware".

    So, here are my questions:
    • Can we confirm that this SID indeed "belongs" to NVidia? Does everyone with NVidia drivers have these? Do others not have them? Also, as far as I can tell this SID is only generated on Windows 10 systems.
    • Since the SID in question is defined for top-level registry keys and propagates down from there, it could be fairly easy to get rid of it: Simply remove those permissions from HKLM, HKCU, etc., and the offending permissions should be (almost?) all gone. The question is, will that have any adverse consequences? Note that, since the SID in question is illegal, once I remove those permissions I cannot recreate them. If removing them breaks something, then I'm looking at a reinstall...
    • Are my concerns above valid? Perhaps they're not, and other than a cosmetic issue those permissions for the offending SID don't really matter. If Sonya is correct, however, this may not be the case.

    Here's hoping somebody knows more about this...

    :)
     

  2. Basic issues in Lumia 950 xl

    I also get that little red dot on the top left of my screen on reboot. It harmless and I figured its where we normally would see the T-Mobile logo but since its unlocked we get a mysterious red dot instead The mysterious unknown account: Threat or harmless bug? :)
     
    markeboyle, Oct 29, 2017
    #2
  3. receiving threats

    How to block or report threats from unknown gamer tags
     
    lordgoatykinz45, Oct 29, 2017
    #3
  4. Pirx Win User

    The mysterious unknown account: Threat or harmless bug?

    I forgot one additional possibility: Perhaps permissions for that mysterious SID are in fact somehow needed (at least on systems with NVidia drivers?). In that case it would of course be unwise to delete these permissions. Of course, the question still remains if indeed only NVidia-based systems use that entry. Unfortunately the only Windows 10 systems I can get my hands on right now do have NVidia cards, so I cannot check that hypothesis.
     
  5. lx07 Win User
    I have that SID in registry (values and permissions) and only have Intel HD so it is not to do with NVidea.

    I read some speculation that it was due to leftovers from defaultuser0 not being deleted correctly during install. I don't know whether it is a bug or deliberate - it seems unclear.


    The mysterious unknown account: Threat or harmless bug? [​IMG]
     
  6. Pirx Win User
    Interesting. So it's not an NVidia thing. Thanks!
     
  7. Bree New Member
    You can get the same leftover (an unknown SID with permissions here, there and everywhere) if you ever created another local user account, then deleted it later. I have often done this, so I see a lot of 'unknown users'.

    Remove the unknown account from the permissions or leave it there, either way it has no impact as the SID doesn't represent an actual account any more.
     
  8. Pirx Win User

    The mysterious unknown account: Threat or harmless bug?

    Well, this one may be different. Notice that this particular SID is not a user account SID, it's what is called an "application SID" in order to specify permissions for application containers. Windows 10 is using these all over the place, which can complicate things considerably. The fact that this is listed as an "Account Unknown" does not necessarily mean that it's not needed. As a matter of fact, in the case of the SID above I have seen reports of people having deleted the SID from permissions, only to end up with a broken system (Edge crashing on launch, etc., etc.) Fixing such a system is possible, but not straightforward, and will require some PowerShell wizardry...
     
  9. Bree New Member
    Apparently an Application SID is used during an install if the install needs to restart an app or sevice after completing.

    https://community.spiceworks.com/top...server-2012-r2
     
    Bree, Apr 5, 2018
    #9
Thema:

The mysterious unknown account: Threat or harmless bug?

Loading...
  1. The mysterious unknown account: Threat or harmless bug? - Similar Threads - mysterious unknown account

  2. Unknown threat found

    in AntiVirus, Firewalls and System Security
    Unknown threat found: Hi everyone. I would very much appreciate it if you can help me. I use Bitdefender free edition as my antivirus and it has found a strange file on my pc and I cannot find anything about it on google. It’s name is pylaspcclife.exe and it’s path is C:\Windows...
  3. Virus & Threat Protection bug.

    in Windows 10 Gaming
    Virus & Threat Protection bug.: Good day,I downloaded a copy of the Kali Linux ISO and saved it on my local drive. Windows Security flagged it as a possible threat. I deleted it immediately but when I run a Windows Security scan it still shows that the Kali ISO is a threat even though I have already deleted...
  4. Administrator Account Mystery

    in Windows 10 Software and Apps
    Administrator Account Mystery: I'm new to Win10.------------------------------------------------------------------------Refurbished HP desktop purchased last weekWindows 10 HomeVersion 21H1 Installed on ‎6/‎29/‎2021 OS build 19043.1288 Experience Windows Feature Experience Pack 120.2212.3920.0...
  5. Administrator Account Mystery

    in Windows 10 Network and Sharing
    Administrator Account Mystery: I'm new to Win10.------------------------------------------------------------------------Refurbished HP desktop purchased last weekWindows 10 HomeVersion 21H1 Installed on ‎6/‎29/‎2021 OS build 19043.1288 Experience Windows Feature Experience Pack 120.2212.3920.0...
  6. Administrator Account Mystery

    in Windows 10 Gaming
    Administrator Account Mystery: I'm new to Win10.------------------------------------------------------------------------Refurbished HP desktop purchased last weekWindows 10 HomeVersion 21H1 Installed on ‎6/‎29/‎2021 OS build 19043.1288 Experience Windows Feature Experience Pack 120.2212.3920.0...
  7. Found an mysterious unknown application in windows 10

    in AntiVirus, Firewalls and System Security
    Found an mysterious unknown application in windows 10: While I was trying to open a photo in windows 10 with one of my photo editor so, I clicked on open with option and then I chose choose another app option and it showed a list of app I can use to open my picture as usual but in that list there was an app named %1 I had not...
  8. Mysterious Account Notification

    in User Accounts and Family Safety
    Mysterious Account Notification: "You need to fix your Microsoft Account. Most likely your password has changed. Click here to fix it in Shared Experiences" I receive the above notification in the Notification Center 2-3 times a week. It is like a normal notification that appears in the bottom right of...
  9. Microsoft Account Mystery

    in User Accounts and Family Safety
    Microsoft Account Mystery: My Windows 10 desktop used to be on my Microsoft account. When version 1803 came out, I wiped the hard drive performing a clean install and I set up the PC using a local account, not the MS account. Since that time, I have not signed into Bing (my homepage on Edge) or any MS...
  10. Mystery Account

    in User Accounts and Family Safety
    Mystery Account: Been using Windows 10 since Aug and really like it. My problem is when turning on my laptop when it gets tothe logon screen, there is a mystery account has showed up that has my account name on it that it defaults to and password doesn't work *Sad but I can't logon with it. I...

Users found this page by searching for:

  1. the mysterious unknown superiors