View Single Post
  #5  
Old February 14th 10, 06:14 AM posted to microsoft.public.windowsxp.security_admin
John Wunderlich
external usenet poster
 
Posts: 1,466
Default request recomendation for "offline" registry hive diff utility

=?Utf-8?B?R3JhbmRwYUZlcnJldA==?=
wrote in
:

John, Thank you for giving me the answer so quickly. I have no
problem at all with your approach and understand most of it... I
hope you will do me the favor of a follow up that will clarify
things enough in my mind to allow me to do as you sugested.

Its the "best approach is to individually load each hive into
Regedit (with the same name)" part I am not sure about.

Two point of confusion on my part:

[...]
2) If you loaded the hive along the lines you are suggesting, it
becomes part of the active OS's registry, right? That sounds very
dangerous to the future integrity of the OS install in question.

[...]

Soooo, exactly what did you mean when you said " Probably the best
approach is to individually load each hive into Regedit (with the
same name)"


As you've probably found out, after starting Regedit, you click once
on the HKLM key then do a File-Load Hive. Select your hive then It
will then ask you for a name to mount it as. Give it a random name.
Yes, it will become part of HKLM but since you gave it a random name,
nothing knows to look there. After exporting, you then unload the
hive and you're back to normal.

When you mount the "after" hive, you need to mount it with the same
name you used for the "before" hive because this name becomes part of
the export and a different name will cause everything to mismatch.

-- John

Ads