New
#31
I think I got them all
Code:C:\Windows\system32> sc sdshow plugplay D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRR C;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) C:\Windows\system32> REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18" /S HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5 -18 Flags REG_DWORD 0xc State REG_DWORD 0x0 RefCount REG_DWORD 0x1 Sid REG_BINARY 010100000000000512000000 ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofi le C:\Windows\system32> REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19" /S HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5 -19 ProfileImagePath REG_EXPAND_SZ C:\Windows\ServiceProfiles\LocalService Flags REG_DWORD 0x0 State REG_DWORD 0x0 C:\Windows\system32> REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20" /S HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5 -20 ProfileImagePath REG_EXPAND_SZ C:\Windows\ServiceProfiles\NetworkServic e Flags REG_DWORD 0x0 State REG_DWORD 0x0 C:\Windows\system32> net start winmgmt The requested service has already been started. More help is available by typing NET HELPMSG 2182. C:\Windows\system32> SC QC winmgmt [SC] QueryServiceConfig SUCCESS SERVICE_NAME: winmgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\Windows\system32> SC QUERYEX winmgmt SERVICE_NAME: winmgmt TYPE : 20 WIN32_SHARE_PROCESS STATE : 4 RUNNING (STOPPABLE, PAUSABLE, ACCEPTS_SHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0 PID : 624 FLAGS : C:\Windows\system32> REG QUERY HKU HKEY_USERS\.DEFAULT HKEY_USERS\S-1-5-19 HKEY_USERS\S-1-5-20 HKEY_USERS\S-1-5-21-3673603920-1938417040-2204823040-1001 HKEY_USERS\S-1-5-21-3673603920-1938417040-2204823040-1001_Classes HKEY_USERS\S-1-5-18 C:\Windows\system32> REG QUERY HKU\S-1-5-20 HKEY_USERS\S-1-5-20\AppEvents HKEY_USERS\S-1-5-20\Console HKEY_USERS\S-1-5-20\Control Panel HKEY_USERS\S-1-5-20\Environment HKEY_USERS\S-1-5-20\EUDC HKEY_USERS\S-1-5-20\Keyboard Layout HKEY_USERS\S-1-5-20\Network HKEY_USERS\S-1-5-20\Printers HKEY_USERS\S-1-5-20\Software HKEY_USERS\S-1-5-20\System C:\Windows\system32> REG QUERY HKU\S-1-5-20\Environment HKEY_USERS\S-1-5-20\Environment TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp C:\Windows\system32> REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5 -20 ProfileImagePath REG_EXPAND_SZ C:\Windows\ServiceProfiles\NetworkServic e Flags REG_DWORD 0x0 State REG_DWORD 0x0 C:\Windows\system32>