total 40 -rwxrwxrwx 2 root root 0 2008-06-09 05:43 MountPointManagerRemoteDatabase -rwxrwxrwx 1 root root 20480 2008-06-09 10:33 tracking.log drwxrwxrwx 1 root root 8192 2009-05-19 09:23 _restore{1ABB8FC8-42ED-441F-B524-972F0B78A79F}
total 529 drwxrwxrwx 1 root root 4096 2009-05-01 10:29 .. drwxrwxrwx 1 root root 8192 2009-05-01 10:52 RP1 drwxrwxrwx 1 root root 28672 2009-05-01 11:09 RP2 <SNIP>... drwxrwxrwx 1 root root 4096 2009-05-01 11:10 RP35 drwxrwxrwx 1 root root 278528 2009-05-04 14:55 RP36 drwxrwxrwx 1 root root 4096 2009-05-04 19:41 RP37 drwxrwxrwx 1 root root 12288 2009-05-05 12:42 RP38 drwxrwxrwx 1 root root 32768 2009-05-06 12:47 RP39 drwxrwxrwx 1 root root 4096 2009-05-07 13:47 RP40 drwxrwxrwx 1 root root 4096 2009-05-08 01:22 RP41 drwxrwxrwx 1 root root 4096 2009-05-09 01:45 RP42 drwxrwxrwx 1 root root 4096 2009-05-10 01:47 RP43 drwxrwxrwx 1 root root 4096 2009-05-11 02:47 RP44 drwxrwxrwx 1 root root 4096 2009-05-12 00:48 RP45 drwxrwxrwx 1 root root 8192 2009-05-13 01:47 RP46 <SNIP>...Note: we pick a time before the last software update - or a time known to have worked
total 17174 -rwxrwxrwx 1 root root 22988 2009-05-01 10:27 ComDb.Dat -rwxrwxrwx 1 root root 44 2009-05-05 12:42 domain.txt -rwxrwxrwx 1 root root 539 2009-05-19 09:19 reg -rwxrwxrwx 2 root root 28672 2009-05-05 12:42 _REGISTRY_MACHINE_SAM -rwxrwxrwx 2 root root 61440 2009-05-05 12:42 _REGISTRY_MACHINE_SECURITY -rwxrwxrwx 2 root root 23023616 2009-05-05 12:42 _REGISTRY_MACHINE_SOFTWARE -rwxrwxrwx 2 root root 9592832 2009-05-05 12:42 _REGISTRY_MACHINE_SYSTEM -rwxrwxrwx 2 root root 262144 2009-05-05 12:42 _REGISTRY_USER_.DEFAULT -rwxrwxrwx 2 root root 262144 2008-08-28 07:14 _REGISTRY_USER_NTUSER_S-1-5-18 -rwxrwxrwx 2 root root 237568 2009-05-05 12:42 _REGISTRY_USER_NTUSER_S-1-5-19 -rwxrwxrwx 2 root root 237568 2009-05-05 12:42 _REGISTRY_USER_NTUSER_S-1-5-20 -rwxrwxrwx 2 root root 1114112 2009-05-05 12:42 _REGISTRY_USER_NTUSER_S-1-5-21-3240149900-406491170-3688870583-1003 -rwxrwxrwx 2 root root 1048576 2009-05-01 10:28 _REGISTRY_USER_NTUSER_S-1-5-21-3240149900-406491170-3688870583-1004 -rwxrwxrwx 2 root root 1835008 2009-05-04 15:48 _REGISTRY_USER_NTUSER_S-1-5-21-3240149900-406491170-3688870583-500 -rwxrwxrwx 2 root root 1048576 2009-05-04 19:41 _REGISTRY_USER_NTUSER_S-1-5-21-860606365-2559132667-2327032736-5340 -rwxrwxrwx 2 root root 8192 2009-05-05 12:42 _REGISTRY_USER_USRCLASS_S-1-5-19 -rwxrwxrwx 2 root root 8192 2009-05-05 12:42 _REGISTRY_USER_USRCLASS_S-1-5-20 -rwxrwxrwx 2 root root 147456 2009-05-05 12:42 _REGISTRY_USER_USRCLASS_S-1-5-21-3240149900-406491170-3688870583-1003 -rwxrwxrwx 2 root root 262144 2009-05-01 10:25 _REGISTRY_USER_USRCLASS_S-1-5-21-3240149900-406491170-3688870583-1004 -rwxrwxrwx 2 root root 262144 2009-05-01 10:25 _REGISTRY_USER_USRCLASS_S-1-5-21-3240149900-406491170-3688870583-500 -rwxrwxrwx 2 root root 262144 2009-05-04 19:29 _REGISTRY_USER_USRCLASS_S-1-5-21-860606365-2559132667-2327032736-5340 drwxrwxrwx 1 root root 0 2009-05-05 12:42 Repository
REGISTRY=../../../../WINDOWS/system32/config cp _REGISTRY_MACHINE_SAM $REGISTRY/SAM cp _REGISTRY_MACHINE_SECURITY $REGISTRY/SECURITY cp _REGISTRY_MACHINE_SOFTWARE $REGISTRY/software cp _REGISTRY_MACHINE_SYSTEM $REGISTRY/system cp _REGISTRY_USER_.DEFAULT $REGISTRY/default