Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Windows\system32>REG QUERY HKU
HKEY_USERS\.DEFAULT
HKEY_USERS\S-1-5-19
HKEY_USERS\S-1-5-20
HKEY_USERS\S-1-5-21-1864999921-4217884488-1375275430-1000
HKEY_USERS\S-1-5-21-1864999921-4217884488-1375275430-1000_Classes
HKEY_USERS\S-1-5-18
C:\Windows\system32>REG QUERY HKU\S-1-5-20
HKEY_USERS\S-1-5-20
(Default) REG_SZ Empty
HKEY_USERS\S-1-5-20\AppEvents
HKEY_USERS\S-1-5-20\Console
HKEY_USERS\S-1-5-20\Control Panel
HKEY_USERS\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\EUDC
HKEY_USERS\S-1-5-20\Keyboard Layout
HKEY_USERS\S-1-5-20\Network
HKEY_USERS\S-1-5-20\Printers
HKEY_USERS\S-1-5-20\Software
C:\Windows\system32>REG QUERY HKU\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\Environment
TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\ProfileList\S-1-5-20"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-20
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkSer
vice
Flags REG_DWORD 0x0
State REG_DWORD 0x0
C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService
C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM

OI)(CI)(F)
BUILTIN\Administrators

OI)(CI)(F)
NT AUTHORITY\NETWORK SERVICE

OI)(CI)(
F)
Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT TOSHIBA\user1

I)(F)
NT AUTHORITY\SYSTEM

I)(F)
BUILTIN\Administrators

I)(
F)
Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService /as
Volume in drive C is SQ004393V04
Volume Serial Number is DAA2-4ABD
Directory of C:\Windows\ServiceProfiles\NetworkService
02/03/2012 04:56 PM 65,536 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TM.blf
02/03/2012 04:56 PM 524,288 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
12/13/2011 01:40 PM 524,288 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
12/10/2011 08:59 PM 65,536 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TM.blf
12/10/2011 08:59 PM 524,288 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TMContainer00000000000000000001.regtrans-ms
11/02/2006 05:57 AM 524,288 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TMContainer00000000000000000002.regtrans-ms
07/15/2012 12:05 PM 65,536 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TM.blf
07/15/2012 12:05 PM 524,288 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
04/01/2012 06:03 PM 524,288 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
04/01/2012 05:29 PM 65,536 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TM.blf
04/01/2012 05:29 PM 524,288 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
02/14/2012 08:29 PM 524,288 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
02/14/2012 06:53 PM 65,536 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TM.blf
02/14/2012 06:53 PM 524,288 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
02/03/2012 08:22 PM 524,288 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
15 File(s) 5,570,560 bytes
0 Dir(s) 147,797,721,088 bytes free
C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService /ah
Volume in drive C is SQ004393V04
Volume Serial Number is DAA2-4ABD
Directory of C:\Windows\ServiceProfiles\NetworkService
10/24/2011 09:34 PM <DIR> AppData
11/02/2006 08:28 AM 1,024 NTUSER.DAT.LOG
07/15/2012 03:18 PM 262,144 ntuser.dat.LOG1
11/02/2006 05:47 AM 0 ntuser.dat.LOG2
02/03/2012 04:56 PM 65,536 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TM.blf
02/03/2012 04:56 PM 524,288 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
12/13/2011 01:40 PM 524,288 NTUSER.DAT{2fca40a8-23ac-11e1-bb4b-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
12/10/2011 08:59 PM 65,536 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TM.blf
12/10/2011 08:59 PM 524,288 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TMContainer00000000000000000001.regtrans-ms
11/02/2006 05:57 AM 524,288 NTUSER.DAT{3a539865-6a70-11db-887c-d362bd
253390}.TMContainer00000000000000000002.regtrans-ms
07/15/2012 12:05 PM 65,536 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TM.blf
07/15/2012 12:05 PM 524,288 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
04/01/2012 06:03 PM 524,288 NTUSER.DAT{7d6c0128-7c5a-11e1-99e5-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
04/01/2012 05:29 PM 65,536 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TM.blf
04/01/2012 05:29 PM 524,288 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
02/14/2012 08:29 PM 524,288 NTUSER.DAT{80d5d8cf-5777-11e1-ac0f-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
02/14/2012 06:53 PM 65,536 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TM.blf
02/14/2012 06:53 PM 524,288 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
02/03/2012 08:22 PM 524,288 NTUSER.DAT{c22de7ea-4ec1-11e1-bf62-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
18 File(s) 5,833,728 bytes
1 Dir(s) 147,796,836,352 bytes free
C:\Windows\system32> THANK YOU!!!!!!