Where is the exact location of the registry inside install.wim?

tonho888

New Member
sorry sir, maybe my question is a bit basic. where is the location of the registry in install.wim that I can pull/backup manually? like its in c:\\windows\setup which i can pull out using 7zip,thanks
 
There is no single registry file.

Every image has a different group of reg hives, with the extracted folder path proceeded by the image's index number.
ie. image 4 -> "4\Windows\System32\config\..."

HKEY_LOCAL_MACHINE\SYSTEM\Windows\System32\config\SYSTEM
HKEY_LOCAL_MACHINE\SAM\Windows\System32\config\SAM
HKEY_LOCAL_MACHINE\SECURITY\Windows\System32\config\SECURITY
HKEY_LOCAL_MACHINE\SOFTWARE\Windows\System32\config\SOFTWARE
HKEY_USERSuser folder's NTUSER.DAT
HKEY_USERS.DEFAULT\Windows\System32\config\DEFAULT

When you mount an image, NTLite will temporarily load SYSTEM & SOFTWARE hives under HKLM\NLTmp*
 
I wouldn't bother backing up install.wim's registry files. They are "incomplete", because Windows installation adds many new entries which don't exist before your first logon.

If you have a command-line registry snapshot tool, run it from Post-Setup to capture the registry before other apps begin to modify it.
 
“If you have a command-line registry snapshot tool, run it from Post-Setup to capture the registry before other apps begin to modify it” I like the way you explain, really. but how do you catch any registry that has not been changed by other apps, sir?
 
Windows will inject reg updates as part of the install process, and during normal operation. Even if your system is idle, Services are constantly updating the registry with overhead data. Any comparison of the entire registry will show background "noise".

The best way to understand non-Windows changes, is to wait 15-20 min. after your first logon to allow Windows to settle down. Then run any registry capture tool, right before customizing your user profile or installing 3rd-party apps. This will minimize the non-useful changes the registry comparison tool will report.

Otherwise you capture a lot of uninteresting garbage. I use RegistryChangesView for this work.
 
Windows will inject reg updates as part of the install process, and during normal operation. Even if your system is idle, Services are constantly updating the registry with overhead data. Any comparison of the entire registry will show background "noise".

The best way to understand non-Windows changes, is to wait 15-20 min. after your first logon to allow Windows to settle down. Then run any registry capture tool, right before customizing your user profile or installing 3rd-party apps. This will minimize the non-useful changes the registry comparison tool will report.

Otherwise you capture a lot of uninteresting garbage. I use RegistryChangesView for this work.
i tried RegistryChangesView, and i am wondering, why it does not show up any changes ? i have tried changing explorer settings, and driver settings
 
It works, the first-time run "create a snapshot now" vs. "create a [time-named] snapshot process" is a bit confusing. Once you get over that clumsy part, the rest is surprisingly easy and clean. It's probably my favorite NirSoft tool, since it has the most attention to detail.
 
It works, the first-time run "create a snapshot now" vs. "create a [time-named] snapshot process" is a bit confusing. Once you get over that clumsy part, the rest is surprisingly easy and clean. It's probably my favorite NirSoft tool, since it has the most attention to detail.
ah, i thought it was a live tool. thanks
 
NirSoft is a goldmine. Sniffing windows UI stuff with regfromapp can be a pain, use before and after snapshots or what garlin suggested.
 
NirSoft is a goldmine. Sniffing windows UI stuffi with regfromapp can be a pain, use before and after snapshots or what garlin suggested.
i will have to investigate this program more. i am trying to slim my windows install, even more, by finding my AMD gpu registry values, for sharpening, and digital vibrance, and so forth, so i can back them up into a single .reg file, and not have to run the amd software in the background anymore, as i have noticed it uses VRAM as well. and i have all the features turned off. i am a bit of a minimalist :p
 
as an update, im using msi afterburner for clock control and fan control, and msi statistics server for monitoring / other. the CPU thread usage is less, and handles are less, ram usage is less to, and i freed up ~70mb VRAM. i used iobit unlocker to rename the "offending" exe files with a new extension of .old
 
AMD R5 230 gpu - Start RegFromApp 32 and 64bit versions, look for CCC.exe, Catalyst Control Centre, tweak a setting, below is just a sample i grabbed. Radeon settings is cnext.exe, RFA can sniff some of its settings, not all.

Code:
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\ATI\ACE\Settings\Runtime\Graphics\DisplaysColour2]
"LUT_Desktop"="Gamma_Red:1;Gamma_Green:1;Gamma_Blue:1;Brightness_Red:-45;Brightness_Green:-45;Brightness_Blue:-45;Contrast_Red:100;Contrast_Green:100;Contrast_Blue:100;"

[HKEY_CURRENT_USER\Software\ATI\ACE\Settings\Runtime\Graphics\UDID\PCI_VEN_1002&DEV_677B&SUBSYS_30271043&REV_00_4&2DB3ECDA&0&0008A]
"AccessTime"="27/06/2023 00:29:14"

[HKEY_CURRENT_USER\Software\ATI\ACE\Settings\Runtime\Graphics\UDID\PCI_VEN_1002&DEV_677B&SUBSYS_30271043&REV_00_4&2DB3ECDA&0&0008&02A]
"AccessTime"="27/06/2023 00:29:14"
 
Thank you for sharing that, on my system, i dont use CCC.exe, its RadeonSoftware.exe. I checked for those keys you posted anyway, and i dont see them on my system.

The closest i have been able to narrow things down to, regkey wise, is : Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000

I cannot find the digital vibrance settings, or image sharpening settings. The alternative, could set these options, using RadeonSoftware.exe, then rename it to .old , or use the old amd crimson control panel, which is not as bloated, but does not seem to contain the image sharpening function, and other functions are missing. the hunt continues...
 
so far this is my result, on windows 10, 22h2, the cpu speed is wrong though. its a weird bug i have, after turning off intel speedstep. its really 4.2ghz max
rss usage.jpg
 
Back
Top