Share via

How do i fix a computer someone took over as if i was working for a company that he claims to own so now has acess as if im an employee

Gabriela Ibarra 5 Reputation points
2023-07-01T08:08:46.4366667+00:00

C:\ProgramData\Microsoft\Windows\Containers\BaseImages\a526038e-5493-4920-ba0e-5c38331074bb\BaseLayer\Files\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR

DeviceInstanceId SWD\DAFUPNPPROVIDER\UUID:29BBE0E1-1A6E-47F6-8F8D-10C25A70EDAA 
  ClassGuid {62f9c741-b25a-46ce-b54c-9bccce08b6f2} 
  Problem 0x2d 
  Status 0x0 

what is this

Windows for business | Windows Client for IT Pros | User experience | Other
{count} vote

1 answer

Sort by: Most helpful
  1. Jason Nguyen Tran 12,945 Reputation points Independent Advisor
    2026-02-16T10:58:35.0733333+00:00

    Hi Gabriela Ibarra,

    As far as I know, the path you shared under ProgramData\Microsoft\Windows\Containers and the PowerShell output you included are related to Windows container base images and device instance identifiers. These are normal system artifacts used by Windows for virtualization and application isolation, and they do not by themselves indicate that someone has ownership of your computer.

    That said, if you suspect unauthorized access, the most important step is to ensure the integrity and security of your system. I recommend disconnecting the machine from the network until you can verify its state. Next, run a full malware and security scan using Microsoft Defender or another trusted security solution. If you continue to see suspicious behavior, consider performing a clean reinstall of Windows 10 or Windows 11 to ensure that no unauthorized accounts or policies remain.

    Regarding the “Other User” or unexpected account prompts, these can appear if the system was previously joined to a domain or configured with enterprise policies. In such cases, a clean reinstall with a local account setup is the most reliable way to regain control. If you enable the built-in Administrator account using net user administrator /active:yes, the default password is blank unless one was set earlier, so you can usually log in without entering a password.

    In summary, the files and identifiers you listed are part of Windows internals, but the safest course of action when you suspect compromise is to back up your data, reinstall the operating system, and reapply security updates. This ensures you have a trusted baseline.

    I hope this explanation clarifies what you are seeing. If you find this answer helpful, please consider clicking Accept Answer so I know your concern has been resolved.

    Jason.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.