rand1038
Topic Starter
Three of the root keys in the registry are there for ease of navigation and do not exist as a file on the hard drive. They are derived keys.
The two keys that actually exist on the hard drive are:
HKEY_LOCAL_MACHINE (HKLM is the short name)
HKEY_USERS (HKU is the short name)
HKEY_CLASSES_ROOT is a link to HKLM\Software\Classes
[external image: user posted image]
HKEY_CURRENT_USER is a link to HKU\ where sid is a security identifier which is the number you see under HKU that starts with "s-1-#-etc" where # is from 0-5 and etc is too complicated to explain here but can have to do with root domain and other factors, local system accounts have a number here generated by the operating system when the account is created.
.[external image: user posted image]
HKEY_CURRENT_CONFIG is a subkey of HKLM\System\CurrentControlSet\Hardware Profiles\Current
[external image: user posted image]
Where are the actual files (hives) that HKLM and HKU are stored in?
The hive files that have been loaded are shown in:
HKLM\System\CurrentControlSet\Control\hivelist
Here is what mine looks like
| CODE |
| REGEDIT4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist] "\\REGISTRY\\MACHINE\\HARDWARE"="" "\\REGISTRY\\MACHINE\\SECURITY"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SECURITY" "\\REGISTRY\\MACHINE\\SOFTWARE"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\software" "\\REGISTRY\\MACHINE\\SYSTEM"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\system" "\\REGISTRY\\USER\\.DEFAULT"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\default" "\\REGISTRY\\MACHINE\\SAM"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SAM" "\\REGISTRY\\USER\\S-1-5-20"="\\Device\\HarddiskVolume1\\Documents and Settings\\NetworkService\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-20_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\NetworkService\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat" "\\REGISTRY\\USER\\S-1-5-21-1234567890-123456789-123456789-1234"="\\Device\\HarddiskVolume1\\Documents and Settings\\bleh\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-21-1234567890-123456789-123456789-1234_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\bleh\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat" "\\REGISTRY\\USER\\S-1-5-19"="\\Device\\HarddiskVolume1\\Documents and Settings\\LocalService\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-19_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat" |
For the local registry (the one on your machine) you can think of "REGISTRY" as HKEY and "MACHINE" as "LOCAL_MACHINE" so "\\REGISTRY\\MACHINE\\HARDWARE" would be HKEY_LOCAL_MACHINEM\Hardware.
Also, for a local registry, "\Device\\HarddiskVolume1" translates to the active partition, normally "c:". The rest is the path to the actual hive. so "\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SAM" is C:\Windows\system32\config\SAM.
As you can see, HKLM hives are stored in %SystemRoot%\system32\config\. If you look in that config directory you will see files with no extension, those are the hives. The other files are copies, backups and logs of changes. As would be expected, HKU hives are stored under "Documents and Settings\" except for .default which is in the config directory with the HKLM hives..
Whether you make a change in a key or its mirror, the new data is reflected in both. In other words, if you delete
HKEY_CLASSES_ROOT\SomeKey
then HKLM\Software\Classes\SomeKey will also be gone. It follows that if you make a registry file to delete some keys, like this:
REGEDIT 4
[-HKEY_CLASSES_ROOT\SomeKey]
[-HKLM\Software\Classes\SomeKey]
the second line is not necessary. Remeber that we are actually only dealing with one entry in a hive file, not two.
Some helpful links:
http://www.akadia.com/services/windows_reg…y_tutorial.html
http://www.winguides.com/article.php?id=1&guide=registry