Account Unknown (S-1-5-21-547018398-3866267173-42692509597-1000) and Administrator with "x" icon.

ty94728

Posts: 7   +0
After wiping the computer with random method using DBAN and reinstalling Windows 10, I try to reinstall Google Chrome but the download was "moved or deleted".
I am wondering what is this unknown account relating to. I have been experiencing these account unknown only associated with the non-Microsoft apps downloaded from third party.
 
Past History: I once used a well-known HP Printer 8600 Pro that was once said on the internet to be vulnerable to malware infections, etc. Also I have had issues with slow internet speed and DNS server not being found on popular sites. In Gmail, emails are sent to me using my gmail email address. Background tabs in Chrome never stop loading. At one point, only a few keyboard keys were functional but later fixed after wiping the computer. I also have seen the entire page filled with of "update windows drivers" and "windows 10 repair tool" ads on regular sites I visit
 
Whenever I have a problem with a browser I switch to an alternative. In my case I've just moved form Firefox which I've always favoured in the past to Opera. Although you were thorough in wiping the hard drive I'd run some intensive security programs to re-check for infection. SAS Free and Malwarebytes are often recommended. Maybe rethink your security software and certainly post on here what it is that you are using. Scour through the software that you have installed since Windows 10 and research that it is not the problem. Ditch any wondrous all singing and dancing tune up or driver finder utilities that may have been installed. It's always advisable to select Custom installs so that you can decline bundled extras which in some cases are malware. I've had some very annoying battles with Toolbars that defy most efforts to remove them so am very cautious when installing anything.
 
Accounts that only appear as an SID usually refer to deleted accounts. Wouldn't worry too much about it.
 
Get a cmd prompt and enter
wmic useraccount
fourth column of the result reports disable/enabled as false/true
 
I am quite stuck on this problem to be honest because I did not delete any accounts after reinstalling Windows. I compared various "c:\windows" subfolders and only find that the start menu has "unknown account" security permissions. Please let me know what this could be? Thanks.
 
I am quite stuck on this problem to be honest because I did not delete any accounts after reinstalling Windows. I compared various "c:\windows" subfolders and only find that the start menu has "unknown account" security permissions. Please let me know what this could be? Thanks.
Forget Subfolders, and you're even in the wrong place.
The xxx-1000 SID is the first USER account created

try this
WMIC USERACCOUNT LIST BRIEF​
look for the SID on the right, find the corresponding name in the fourth column
 
Which problem are you seeking a solution; the SID xx-1000 or find that the start menu has "unknown account" security permissions.
 
I have been trying to remove the unknown account from foreign places like downloaded files or somewhere from internet. I do not know where is this coming from. Attached is the cmd result for "wmic useraccount". Thanks for your guys' asistance.
 

Attachments

  • screenshot for wmic useraccount.jpg
    screenshot for wmic useraccount.jpg
    148.4 KB · Views: 8
HMM; the issue is Status=Degraded for all accounts. Now WHY and how to reset to OK?
 
You've been infected; Report the above comment with your original post into the Virus Removal Forum
 
I have some issues that I do not know what to do with it. Attached below is a system health report. Thank you.
 

Attachments

  • windows system health report.PNG
    windows system health report.PNG
    67.6 KB · Views: 5
I'm not a hardware person and I only posted here to let you know that there is no infection issue, so you'll have to wait for others to reply here.
Good luck :)
 
Back