<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx</link><description>One of the best public document which talks about Registry internals is by Mark Russinovich and I will recommend same before you go ahead with this article. http://www.microsoft.com/technet/archive/winntas/tips/winntmag/inreg.mspx?mfr=true Make sure before</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Geek Lectures - Things geeks should know about &amp;raquo; Blog Archive   &amp;raquo;  Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#2713374</link><pubDate>Sat, 05 Jan 2008 21:28:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2713374</guid><dc:creator>Geek Lectures - Things geeks should know about » Blog Archive   »  Internal structures of the Windows Registry</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://geeklectures.info/2008/01/05/internal-structures-of-the-windows-registry/"&gt;http://geeklectures.info/2008/01/05/internal-structures-of-the-windows-registry/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Entenda um pouco mais sobre a estrutura interna do Registro do Windows</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#2713515</link><pubDate>Sat, 05 Jan 2008 22:25:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2713515</guid><dc:creator>Blog do Anderson Thiago (a.k.a Anderson T)</dc:creator><description>&lt;p&gt;Neste artigo, Ganand fala um pouco sobre a estrutura de registro do Windows tomando como base o artigo&lt;/p&gt;
</description></item><item><title>re: Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#3126021</link><pubDate>Fri, 19 Sep 2008 12:30:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126021</guid><dc:creator>PeterN</dc:creator><description>&lt;p&gt;Hi Gaurav ,&lt;/p&gt;
&lt;p&gt;Great article thanks.&lt;/p&gt;
&lt;p&gt;Do you know what the difference is between the BlockAddress and the BinAddress values. From looking at them it seems to me that the BinAddress is either 5 or 1 more than the BlockAddress and the BlockAddress seems to be the address of the hbin.&lt;/p&gt;
&lt;p&gt;I'd be very interested if you could shed some light on this. Thanks.&lt;/p&gt;
</description></item><item><title>re: Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#3215077</link><pubDate>Thu, 19 Mar 2009 11:53:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3215077</guid><dc:creator>kelly</dc:creator><description>&lt;p&gt;Dear Gaurav:&lt;/p&gt;
&lt;p&gt;Thanks a lot for your article.&lt;/p&gt;
&lt;p&gt;I'm looking for some advice as to what I might be doing wrong. &lt;/p&gt;
&lt;p&gt;0: kd&amp;gt; !reg hivelist&lt;/p&gt;
&lt;p&gt;-------------------------------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;| HiveAddr |Stable Length|Stable Map|Volatile Length|Volatile Map|MappedViews|PinnedViews|U(Cnt)| BaseBlock | FileName &lt;/p&gt;
&lt;p&gt;-------------------------------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;| e28b59b8 | &amp;nbsp; &amp;nbsp; &amp;nbsp;1b000 &amp;nbsp;| e28b5a18 | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;| &amp;nbsp;00000000 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e28c3000 &amp;nbsp;| \Microsoft\Windows\UsrClass.dat&lt;/p&gt;
&lt;p&gt;| e28ea008 | &amp;nbsp; &amp;nbsp; 426000 &amp;nbsp;| e28bd000 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 3000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e28ea144 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp;167 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e28b0000 &amp;nbsp;| ttings\Administrator\ntuser.dat&lt;/p&gt;
&lt;p&gt;| e276fb60 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp;| e276fbc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;| &amp;nbsp;00000000 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e27de000 &amp;nbsp;| \Microsoft\Windows\UsrClass.dat&lt;/p&gt;
&lt;p&gt;| e287eb60 | &amp;nbsp; &amp;nbsp; &amp;nbsp;38000 &amp;nbsp;| e287ebc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e287ec9c &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; 15 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e27d3000 &amp;nbsp;| ettings\LocalService\ntuser.dat&lt;/p&gt;
&lt;p&gt;| e2318b60 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp;| e2318bc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;| &amp;nbsp;00000000 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e2319000 &amp;nbsp;| \Microsoft\Windows\UsrClass.dat&lt;/p&gt;
&lt;p&gt;| e2310b60 | &amp;nbsp; &amp;nbsp; &amp;nbsp;37000 &amp;nbsp;| e2310bc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e2310c9c &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; 14 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e2312000 &amp;nbsp;| tings\NetworkService\ntuser.dat&lt;/p&gt;
&lt;p&gt;| e1dd3638 | &amp;nbsp; &amp;nbsp;1492000 &amp;nbsp;| e1dea000 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 7000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e1dd3774 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp;256 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1dd6000 &amp;nbsp;| emRoot\System32\Config\SOFTWARE&lt;/p&gt;
&lt;p&gt;| e1dc3b60 | &amp;nbsp; &amp;nbsp; &amp;nbsp;3b000 &amp;nbsp;| e1dc3bc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;| &amp;nbsp;00000000 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; 15 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1dcb000 &amp;nbsp;| temRoot\System32\Config\DEFAULT&lt;/p&gt;
&lt;p&gt;| e1dc5008 | &amp;nbsp; &amp;nbsp; &amp;nbsp; c000 &amp;nbsp;| e1dc5068 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e1dc5144 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1dc6000 &amp;nbsp;| emRoot\System32\Config\SECURITY&lt;/p&gt;
&lt;p&gt;| e1dc7b60 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 6000 &amp;nbsp;| e1dc7bc0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;| &amp;nbsp;00000000 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1dcd000 &amp;nbsp;| \SystemRoot\System32\Config\SAM&lt;/p&gt;
&lt;p&gt;| e13a9840 | &amp;nbsp; &amp;nbsp; &amp;nbsp; e000 &amp;nbsp;| e13a98a0 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 4000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e13a997c &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e13ac000 &amp;nbsp;| &amp;lt;NONAME&amp;gt;&lt;/p&gt;
&lt;p&gt;| e1024758 | &amp;nbsp; &amp;nbsp; 365000 &amp;nbsp;| e1038000 | &amp;nbsp; &amp;nbsp; &amp;nbsp;22000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e1024894 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp;164 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1037000 &amp;nbsp;| SYSTEM&lt;/p&gt;
&lt;p&gt;| e102f008 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp;| e102f068 | &amp;nbsp; &amp;nbsp; &amp;nbsp; 1000 &amp;nbsp; &amp;nbsp;| &amp;nbsp;e102f144 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp;| &amp;nbsp; &amp;nbsp; 0| e1030000 &amp;nbsp;| &amp;lt;NONAME&amp;gt;&lt;/p&gt;
&lt;p&gt;-------------------------------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;0: kd&amp;gt; dt nt!hhive e1024758&lt;/p&gt;
&lt;p&gt;Symbol nt!hhive not found.&lt;/p&gt;
&lt;p&gt;0: kd&amp;gt; dt nt!cmhive e1024758&lt;/p&gt;
&lt;p&gt;Symbol nt!cmhive not found.&lt;/p&gt;
&lt;p&gt;Please help me. My email is snowy_1207@163.com.&lt;/p&gt;
&lt;p&gt;Thanks a lot.&lt;/p&gt;
</description></item><item><title>re: Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#3244466</link><pubDate>Fri, 22 May 2009 13:16:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3244466</guid><dc:creator>Artur Carvalho</dc:creator><description>&lt;p&gt;you're missing the _&lt;/p&gt;
&lt;p&gt;dt nt!_hhive&lt;/p&gt;
&lt;p&gt;you could search for it using dt nt!*hive&lt;/p&gt;
&lt;p&gt;in my machine i get&lt;/p&gt;
&lt;p&gt;ntkrpamp!_CMHIVE&lt;/p&gt;
&lt;p&gt;ntkrpamp!_HHIVE&lt;/p&gt;
&lt;p&gt;i use a dual core processor&lt;/p&gt;
&lt;p&gt;hope this helps&lt;/p&gt;
</description></item><item><title>re: Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx#3258968</link><pubDate>Fri, 26 Jun 2009 16:05:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3258968</guid><dc:creator>SP</dc:creator><description>&lt;p&gt;I am looking to access HKEY_CLass_root from kernel.. Howz that possible...&lt;/p&gt;
</description></item></channel></rss>