Account Unknown(S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176)

Anonymous
2022-10-31T10:36:40+00:00

So recently I updated Windows 11 to its latest 22H2 Version. I noticed that in the properties section of my C Drive, also in the security tab there is a user named "Account Unknown(S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176)

Now, my question is, is this user is associated with current version of windows? Because if I want to delete it, warning dialog occurs. And if this is any other problem, then how can I solve this?

Windows for home | Windows 11 | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

74 answers

Sort by: Most helpful
  1. Anonymous
    2022-10-31T22:39:29+00:00

    sometimes Windows System would look more sus, also its account unknown because it doesn't have a name

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-06-30T18:35:15+00:00

    I've discovered the same account associated with "Special Permissions" on my OS Drive. Just removed it, but in the process made a connection back to a strange occurance around a month ago where the entire size of all of my harddrives were downloaded within two hours on the same day. Here are all of the logs from that day including a picture I took shortly after the discovery. Eventually "MSFT 5.0" masked itself with my Computer Name too.

    It will not allow me to post the raw images on this thread so you can find all related logs in this google share drive.

    Main folder with logs included from Norton Security/Windows/ASUS Router at time of occurance: https://drive.google.com/drive/folders/1DlowoBjYtDrfV7EydHf3lNqYUsj4Zk-5?usp=drive_link

    SSID Before Spoof: https://drive.google.com/file/d/18EZ9NHzZpjISMOF1JHuJvvnOTta8wiPm/view?usp=drive_link

    SSID After Spoof: https://drive.google.com/file/d/1r9JBJyKg67No-jEn61qXZJcAdn5KoU5O/view?usp=drive_link

    You'll notice in the logs that Windows Update and General were the specified downloading applications, a little further digging and diahost.exe was responsible for the 1.3TB+ DL to who knows where.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-05-03T17:42:02+00:00

    hi dave

    why microsoft named it like that,"unknown account" , not something friendly name like "windows background program" or some thing like that,it kind a suspicious for me :V, but thnks god i got the answer before i reset my windows back

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-06-14T18:43:40+00:00

    This has been a plague on me since January to the tune of nearly $300 and a new drive since my system has been just eating its self due to these errors and what not. Not to mention dumping hours into manually scanning through the registry finding hundreds of inf issues and entries that do not belong 😭 Microsoft really does need to fix these issues

    Was this answer helpful?

    10 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-02-01T17:47:12+00:00

    By labelling users this way (or rather "unlabelling" them), Microsoft is normalizing the viewing of information that should make us suspicious, increasing the likelihood of ignoring a real threat in the future. Cybersecurity threats will never be taken truly seriously until someone manages to hack and remotely ignite the launching of a nuclear bomb.

    Was this answer helpful?

    8 people found this answer helpful.
    0 comments No comments