Registry Editor
Registry Editor
1.Safe boot
used to trouble shoot system That has crashed or
failed to boot.it keeps History of boot
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Control\SafeBoot
2.BAM(background activity manager)
The BamUserSettingsInitialize function is used
to create or to open the “UserSettings ”key under
the registry key specified (“returned”) by the
IoOpenDriverRegistryKey () routine (this routine
“returns a handle to a driver-specific registry key
for a particular driver”).
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Services\bam
3.Vss(volume shadow copy service)
VSS coordinates the actions that are required to
create a consistent shadow copy (also known as a
snapshot or a point-in-time copy) of the data that
is to be backed up.
Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\VSS
4.enviorment(os)
you can use environment variables for paths that
are stored in the registry.
These entries require special formatting in order
to be recognized by the operating system as
environment variables.
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Control\Session Manager\
Environment
5.RDP-TCP
What is remote desktop protocol (RDP)? Remote
desktop protocol (RDP) is a secure network
communications protocol developed by Microsoft.
It enables network administrators to remotely
diagnose problems
that individual users encounter and gives users
remote access to their physical work desktop
computer
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Control\Terminal Server\
WinStations\RDP-Tcp
6.bthport(connection port)
Shows previously connected devices through
bluetooth
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Services\BTHPORT\Parameters
7. eventlog
Windows event log is an in-depth record of events
related to the system, security, and application
stored on a Windows operating system. Event logs
can be used to track system and some application
issues and forecast future problems.
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Services\EventLog
8. interfaces
It keeps record of DHCP network and network
plugins and settings
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Services\Tcpip\Parameters\
Interfaces
9. memory management
the process of controlling and coordinating a
computer's main memory. It ensures that
blocks of memory space are properly
managed and allocated so the operating
system (OS),
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Control\Session Manager\Memory
Management
10.additional removable storage info
It keeps record of exeternal removable devices
such as pendrive etc
Computer\HKEY_LOCAL_MACHINE\SYSTEM\
ControlSet001\Control\DeviceClasses\{10497b1b-
ba51-44e5-8318-a65c837b6661}
11.channels(windows event log)
Sink that collects events.events can be written to
event log channels ,event log file, or both a
channel is basically sink that collects events.
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\
Microsoft\Windows\CurrentVersion\WINEVT\
Channels
36.Control Panel
Includes categories and individual items,
including those to not load, unload, etc.
Computer\HKEY_LOCAL_MACHINE\
Microsoft\Windows\CurrentVersion\
Control Panel
37.Still images(Devices ,Web Cam Info )
Microsoft STI makes use of several registry entries, some of which can be modified by
vendor-supplied components.
Computer\HKEY_LOCAL_MACHINE\
SOFTWARE\ControlSet001\Control\Class\
{6bdd1fc6-810f-11d0-bec7-08002be2092f}
38.App Combat Cache
which software are compatible with your
windows Shows
Computer\HKEY_LOCAL_MACHINE\
SYSTEM\ControlSet001\Control\Session
Manager\AppCompatCache
39.Last Shutdown Time
Keeps record of when windows was
shutdown last time
Computer\HKEY_LOCAL_MACHINE\
SYSTEM\ControlSet001\Control\Windows
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.