This is a read-only archive. No new posts or registrations. Privacy Page
Software

Registry Root Keys

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Three of the root keys in the registry are there for ease of navigation and do not exist as a file on the hard drive. They are derived keys. The two keys that actually exist on the hard drive are: HKEY_LOCAL_MACHINE (HKLM is the short name) HKEY_USERS (HKU is the short name) HKEY_CLASSES_ROOT is a link to HKLM\Software\Classes [external image: user posted image] HKEY_CURRENT_USER is a link to HKU\ where sid is a security identifier which is the number you see under HKU that starts with "s-1-#-etc" where # is from 0-5 and etc is too complicated to explain here but can have to do with root domain and other factors, local system accounts have a number here generated by the operating system when the account is created. .[external image: user posted image] HKEY_CURRENT_CONFIG is a subkey of HKLM\System\CurrentControlSet\Hardware Profiles\Current [external image: user posted image] Where are the actual files (hives) that HKLM and HKU are stored in? The hive files that have been loaded are shown in: HKLM\System\CurrentControlSet\Control\hivelist Here is what mine looks like
CODE
REGEDIT4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist] "\\REGISTRY\\MACHINE\\HARDWARE"="" "\\REGISTRY\\MACHINE\\SECURITY"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SECURITY" "\\REGISTRY\\MACHINE\\SOFTWARE"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\software" "\\REGISTRY\\MACHINE\\SYSTEM"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\system" "\\REGISTRY\\USER\\.DEFAULT"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\default" "\\REGISTRY\\MACHINE\\SAM"="\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SAM" "\\REGISTRY\\USER\\S-1-5-20"="\\Device\\HarddiskVolume1\\Documents and Settings\\NetworkService\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-20_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\NetworkService\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat" "\\REGISTRY\\USER\\S-1-5-21-1234567890-123456789-123456789-1234"="\\Device\\HarddiskVolume1\\Documents and Settings\\bleh\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-21-1234567890-123456789-123456789-1234_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\bleh\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat" "\\REGISTRY\\USER\\S-1-5-19"="\\Device\\HarddiskVolume1\\Documents and Settings\\LocalService\\NTUSER.DAT" "\\REGISTRY\\USER\\S-1-5-19_Classes"="\\Device\\HarddiskVolume1\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat"
For the local registry (the one on your machine) you can think of "REGISTRY" as HKEY and "MACHINE" as "LOCAL_MACHINE" so "\\REGISTRY\\MACHINE\\HARDWARE" would be HKEY_LOCAL_MACHINEM\Hardware. Also, for a local registry, "\Device\\HarddiskVolume1" translates to the active partition, normally "c:". The rest is the path to the actual hive. so "\\Device\\HarddiskVolume1\\WINDOWS\\system32\\config\\SAM" is C:\Windows\system32\config\SAM. As you can see, HKLM hives are stored in %SystemRoot%\system32\config\. If you look in that config directory you will see files with no extension, those are the hives. The other files are copies, backups and logs of changes. As would be expected, HKU hives are stored under "Documents and Settings\" except for .default which is in the config directory with the HKLM hives.. Whether you make a change in a key or its mirror, the new data is reflected in both. In other words, if you delete HKEY_CLASSES_ROOT\SomeKey then HKLM\Software\Classes\SomeKey will also be gone. It follows that if you make a registry file to delete some keys, like this: REGEDIT 4 [-HKEY_CLASSES_ROOT\SomeKey] [-HKLM\Software\Classes\SomeKey] the second line is not necessary. Remeber that we are actually only dealing with one entry in a hive file, not two. Some helpful links: http://www.akadia.com/services/windows_reg…y_tutorial.html http://www.winguides.com/article.php?id=1&guide=registry
I have been researching registry issues for awhile now and need some information. Firstly what does it mean when a key has no value? such as in the following example form a start up log. "Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found*" Also I see a number fo keys that point to folder that contain no files. Are these keys orphans? Appreciate some info. Thanks FM
QUOTE
I have been researching registry issues for awhile now and need some information. Firstly what does it mean when a key has no value? such as in the following example form a start up log. "Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found*"
By default, that key does not exist. It can be created and then windows will use it. Here is a little list of some areas that windows checks for startup items and a google search of "CurrentVersion\policies\Explorer\Run".
QUOTE
Also I see a number fo keys that point to folder that contain no files. Are these keys orphans?
If the key points to a folder and the folder exists then the key is not an orphan. Orphan keys point to things that no longer exist. You need to determine if the folder is necessary. If it is not then you can remove it and most likely the key pointing to it. Don't delete anything in the registry you are unsure of. It takes allot of clutter to actually slow down system performance but deleting just one wrong key can adversly affect the system or even cripple it.
Thanks for the info. So would it be safe to say that a key is nolonger necessary if the folder that it points to nolonger exists? To determine if the folder is there I can search for it, and if I have the radial button for "show all hidden files and folders" active, and the check box for "Display the contents of system folders" checked, and "Hide protected operating system files" unchecked, then I should be able to see any valid file or folder that is pointed at in the registry. The utilities for changing the hidden attribute that are linked to in the tools section I presume will do this, but will it make a difference when using these tools which version of Windows is being used? Aside of having a non-valid file name will there be any cases with the view options described above that a file will still remain hidden? FM
If you are showing hidden files/folders and the contents of system folders AND you do the search "by hand" rather than relying on the search assistant then you can be 99% sure that the folder does not exist. Some files/folders can still be hidden under those conditions but I am not aware of any legitimate purpose for doing so. I do not recommend deleting keys from the registry unless you are absolutley sure of what you are doing. There would have to be hundreds, if not thousands, of unnecessary keys to cause a noticeable slowdown in the system. Problems are, by far, more often caused by something missing than by something that is there. This is especially true for NT based systems.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI