24 ( 11.7 kb/s) \autoexec.bat
10 ( 4.9 kb/s) \config.sys
directory \Documents and Settings\
NT_STATUS_ACCESS_DENIED listing \Documents and Settings\*
directory \enh\
1295 ( 632.3 kb/s) \enh\bginfo-logon.bgi
2678 ( 1307.6 kb/s) \enh\bginfo-support.bgi
1195 ( 61.4 kb/s) \enh\bginfo.bgi
2253 ( 733.4 kb/s) \enh\bginfo.cmd
844648 ( 1922.7 kb/s) \enh\Bginfo.exe
1413 ( 86.2 kb/s) \enh\BGInfo.lnk
2219 ( 1083.5 kb/s) \enh\CDF2ENV.cmd
34816 ( 1307.7 kb/s) \enh\chgcolor.exe
419 ( 136.4 kb/s) \enh\chgcolor.txt
directory \enh\DLLS\
361779 ( 2250.3 kb/s) \enh\DLLS\wbdDD34i.dll
371581 ( 5336.4 kb/s) \enh\DLLS\wbdED44I.dll
102400 ( 3225.8 kb/s) \enh\DLLS\wwctl34i.dll
708 ( 57.6 kb/s) \enh\DomainCheck.cmd
1219 ( 238.1 kb/s) \enh\DomainCheck.vbs
1875 ( 107.7 kb/s) \enh\dynPolLoginRedirect.html
1875 ( 114.4 kb/s) \enh\dynPolLoginRedirect.html.1
directory \enh\FLAGS\
63 ( 61.5 kb/s) \enh\FLAGS\IsInDomain.Yes
42288 ( 2949.8 kb/s) \enh\icons.icc
531968 ( 3002.9 kb/s) \enh\i_view32.exe
1159920 ( 8328.9 kb/s) \enh\LogParser.exe
directory \enh\LOGS\
757 ( 38.9 kb/s) \enh\LOGS\winlicense.log
1821 ( 355.7 kb/s) \enh\LOGS\WSName.log
1704 ( 832.0 kb/s) \enh\LOGS\ZCMBundleActivity.log
tarExtract: Got file './$Recycle.Bin/', mode 040755, size 0, type 5
create d 755 0/0 0 $Recycle.Bin
tarExtract: Got file './$Recycle.Bin/S-1-5-21-1592193973-1859105985-2370942554-1000/', mode 040755, size 0, type 5
create d 755 0/0 0 $Recycle.Bin/S-1-5-21-1592193973-1859105985-2370942554-1000
tarExtract: Got file './$Recycle.Bin/S-1-5-21-1592193973-1859105985-2370942554-1000/desktop.ini', mode 0100644, size 129, type 0
create 644 0/0 129 $Recycle.Bin/S-1-5-21-1592193973-1859105985-2370942554-1000/desktop.ini
tarExtract: Got file './$Recycle.Bin/S-1-5-21-840606294-1342211739-299824548-1008/', mode 040755, size 0, type 5
create d 755 0/0 0 $Recycle.Bin/S-1-5-21-840606294-1342211739-299824548-1008
tarExtract: Got file './$Recycle.Bin/S-1-5-21-840606294-1342211739-299824548-1008/desktop.ini', mode 0100644, size 129, type 0
create 644 0/0 129 $Recycle.Bin/S-1-5-21-840606294-1342211739-299824548-1008/desktop.ini
tarExtract: Got file './autoexec.bat', mode 0100644, size 24, type 0
create 644 0/0 24 autoexec.bat
tarExtract: Got file './config.sys', mode 0100644, size 10, type 0
create 644 0/0 10 config.sys
tarExtract: Got file './Documents and Settings/', mode 040755, size 0, type 5
create d 755 0/0 0 Documents and Settings
tarExtract: Got file './enh/', mode 040755, size 0, type 5
create d 755 0/0 0 enh
tarExtract: Got file './enh/bginfo-logon.bgi', mode 0100644, size 1295, type 0
tarExtract: Got file './enh/LogParser.exe', mode 0100644, size 1.15992e+06, type 0
create 644 0/0 1159920 enh/LogParser.exe
tarExtract: Got file './enh/LOGS/', mode 040755, size 0, type 5
1291941 ( 8524.7 kb/s) \enh\multibakw.exe
869376 ( 6288.9 kb/s) \enh\Printkey2000.exe
391 ( 127.3 kb/s) \enh\procexp.cmd
4777280 ( 6636.3 kb/s) \enh\procexp.exe
1287 ( 83.8 kb/s) \enh\ProfileDirCheck.cmd
tarExtract: Got file './Program Files/Common Files/microsoft shared/ink/el-GR/', mode 040755, size 0, type 5
create d 755 0/0 0 Program Files/Common Files/microsoft shared/ink/el-GR
tarExtract: Got file './Program Files/Common Files/microsoft shared/ink/el-GR/tipresx.dll.mui', mode 0100644, size 4096, type 0
create 644 0/0 4096 Program Files/Common Files/microsoft shared/ink/el-GR/tipresx.dll.mui
31744 ( 6200.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi
33280 ( 8125.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi
62976 (15375.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi
197120 ( 5347.2 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\correct.avi
tarExtract: Got file './Program Files/Common Files/microsoft shared/ink/el-GR/', mode 040755, size 0, type 5
create d 755 0/0 0 Program Files/Common Files/microsoft shared/ink/el-GR
tarExtract: Got file './Program Files/Common Files/microsoft shared/ink/el-GR/tipresx.dll.mui', mode 0100644, size 4096, type 0
create 644 0/0 4096 Program Files/Common Files/microsoft shared/ink/el-GR/tipresx.dll.mui
31744 ( 6200.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi
33280 ( 8125.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi
62976 (15375.0 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi
197120 ( 5347.2 kb/s) \Program Files\Common Files\microsoft shared\ink\en-US\correct.avi
tarExtract: Got file './Users/BKeadle/Favorites/VOP EOP.url', mode 0100644, size 150, type 0
directory \Users\bkeadle.VOP\
directory \Users\bkeadle.VOP\AppData\
directory \Users\bkeadle.VOP\AppData\Local\
directory \Users\bkeadle.VOP\AppData\Local\Application Data\
NT_STATUS_ACCESS_DENIED listing \Users\bkeadle.VOP\AppData\Local\Application Data\*
directory \Users\bkeadle.VOP\AppData\Local\History\
NT_STATUS_ACCESS_DENIED listing \Users\bkeadle.VOP\AppData\Local\History\*
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Credentials\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds\Feeds for United States~\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds Cache\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds Cache\9V1UUSFX\
directory \Users\bkeadle.VOP\AppData\Local\Microsoft\Feeds Cache\BDH5FT81\