Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Ownership of all files on hard drive suddenly changed

Update your Vista Drivers Update Your Drivers Now!!
Closed Thread
 
Thread Tools Display Modes
Old 01-07-2008   #1 (permalink)
Big Al Mintaka
Guest


 

Ownership of all files on hard drive suddenly changed

Hello Everyone,
I noticed that when I explored an external USB drive that I couldn't see
folders I had been able to see earlier this evening. I checked the ownership
and found that the owner had been set to

S-1-5-21-2311030268-158868070-3690016334-1008

I looked through the Registry for this and found nothing. So, I reset the
ownership of all files on that drive to my account (I am the "real"
administrator).

Just out of curiosity I checked the ownership of some files on my C: drive.
All of my personal folders were now owned by that long ID string above. Now
I am setting the owner back to my account.

Folders like "Program Files" and "Windows" are owned by TrustedInstaller,
which is what they had been set to earlier today. It looks like all of my
personal folders on all hard drives have been hit.

What the.....????? Does anyone know what this means?

Thanks for your time,
Big Al Mintaka



My System SpecsSystem Spec
Old 01-07-2008   #2 (permalink)
Jesper
Guest


 

RE: Ownership of all files on hard drive suddenly changed

S-1-5-21-2311030268-158868070-3690016334-1008 is a security identifier, a
SID. It is the internal identifier for a user account. The part before 1008
is the computer's or domain's SID. 1008 is called the Relative Identifier and
identifies the unique user account in that computer or domain. Even if you
change the name of the user account the SID always stays the same.

There are two typical scenarios when you see the SID instead of the user
account. Both of them stem from the fact that the computer is unable to
resolve the SID to a username.

The first is when you have used this drive on a different computer and an
account from that computer has been given permissions to, or ownership of,
data. You can tell whether this is the case by retrieving the computer SID
for the computer where you have the problem. There are a few ways to do that.
Without installing additional software, and assuming your account is not a
domain account, you can open a command prompt and typing "whoami /user". It
will show your own SID. If everything before the last number (1008 in this
case) matches between your account and the mystery one then the mystery SID
is for a local account. That means you have case 2.

Case 2 is where an account has been deleted. Ownership and permissions are
not reassigned when accounts are deleted. However, since the account no
longer exists, the computer is unable to find the username for it and shows
you the SID instead.

In your case, since it is an external drive, I would be willing to bet that
you used this drive in a different computer and changed ownership on
everything on the drive. If you log on to that computer with whatever account
you used and run whoami /user you should find that SID.

If you care to explore SIDs a bit more, psgetsid is a nice little tool that
can resolve them back and forth:
http://www.microsoft.com/technet/sys.../psgetsid.mspx. If
you want to learn more about them, there is quite technical documentation at
http://technet2.microsoft.com/window....mspx?mfr=true,
and in the forthcoming Windows Server 2008 Security Resource Kit.
---
Your question may already be answered in Windows Vista Security:
http://www.amazon.com/gp/product/047...otectyourwi-20


"Big Al Mintaka" wrote:
Quote:

> Hello Everyone,
> I noticed that when I explored an external USB drive that I couldn't see
> folders I had been able to see earlier this evening. I checked the ownership
> and found that the owner had been set to
>
> S-1-5-21-2311030268-158868070-3690016334-1008
>
> I looked through the Registry for this and found nothing. So, I reset the
> ownership of all files on that drive to my account (I am the "real"
> administrator).
>
> Just out of curiosity I checked the ownership of some files on my C: drive.
> All of my personal folders were now owned by that long ID string above. Now
> I am setting the owner back to my account.
>
> Folders like "Program Files" and "Windows" are owned by TrustedInstaller,
> which is what they had been set to earlier today. It looks like all of my
> personal folders on all hard drives have been hit.
>
> What the.....????? Does anyone know what this means?
>
> Thanks for your time,
> Big Al Mintaka
>
>
My System SpecsSystem Spec
Closed Thread

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista changed Hard Drive icon... NJB General Discussion 7 07-02-2008 05:58 PM
Vista changed my Hard Drive icon.... NJB Vista hardware & devices 0 06-30-2008 12:09 PM
Taking Ownership of a 2nd Hard Drive Rohan Vista security 1 12-09-2007 04:35 AM
Transferring files from Slave XP hard drive to new Vista Hard drive - primary Scootermc50@gmail.com Vista installation & setup 1 05-23-2007 08:46 PM
Changed ownership and indexing =?ISO-8859-1?Q?Erik_Wikstr=F6m?= Vista General 0 09-12-2006 11:43 AM


Update your Vista Drivers Update Your Drivers Now!!

Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008