New
#11
Here you go.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\ProfileList" /S
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users
Default REG_EXPAND_SZ %SystemDrive%\Users\Default
Public REG_EXPAND_SZ %SystemDrive%\Users\Public
ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-1895224422-1809919336-1963888058-1000
ProfileImagePath REG_EXPAND_SZ C:\Users\TEMP.Wotaken
Flags REG_DWORD 0x0
State REG_DWORD 0x4a04
Sid REG_BINARY 01050000000000051500000066D4F670682DE16BBA8D0E75E803000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-1895224422-1809919336-1963888058-1000.bak
ProfileImagePath REG_EXPAND_SZ C:\Users\Jew.Wotaken
Flags REG_DWORD 0x0
State REG_DWORD 0x8000
Sid REG_BINARY 01050000000000051500000066D4F670682DE16BBA8D0E75E803000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-1895224422-1809919336-1963888058-1003
ProfileImagePath REG_EXPAND_SZ C:\Users\Joseph
Flags REG_DWORD 0x0
State REG_DWORD 0x0
Sid REG_BINARY 01050000000000051500000066D4F670682DE16BBA8D0E75EB03000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
C:\Windows\system32>