Registry Flashcards
4 Root Keys of Registry
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
Offline Registry File Location
\%WINDIR%\system32\config
Hives Contain
Keys - Folders
Values - Data stored in key
5 Hive Files
Default SAM Security System Software
Hive File Location in registry
HKEY_LOCAL_MACHINE
SYSTEM Hive contains
HKEY_LOCAL_MACHINE\SYSTEM hardware config data services config data raw device names for volumes and hard drives raw device names for USB keys
SOFTWARE Hive contains
HKEY_LOCAL_MACHINE\SOFTWARE
applications config data
windows programs/products config data
NTUSER.DAT Hive contains
slew of user activity
config/environment settings
SAM Hive contains
HKEY_LOCAL_MACHINE\SAM
local user and group accounts
SECURITY Hive
password policies
membership and group info
other security information used by SAM and OS
What Systems run RegIdleBackup
Vista
Windows 7
Windows 8
Server 2008
How often does RegIdleBackup run
Every 10 days
What does RegIdleBackup do
Every 10 days, backs up SAM, DEFAULT, SYSTEM SOFTWARE and SECURITY hives
Where does RegIdleBackup store hives
%WinDir%\System32\Config\RegBack
Shadow Copy or RegIdleBackup is disabled usually because of what reasons
Processing
Storage Space
This is not necessary
NTUSER.DAT is stored where on Windows XP file system
c:\Documents and Settings\NTUSER.dat
NTUSER.DAT is stored where on Vista/Win7/Win8 file system
C:\Users\NTUSER.dat