I have a Windows XP FAT32 system with a limited use able to access the Administrator user files. I dont see much activity from the limited user but a lot under Administator that I cant explain. Could be limited user be access the Administrator user file and somehow spoof (masquerade) the Administration user.
VulnerabilitiesMicrosoft Legacy OSDigital Forensics