MiTeC Windows Registry Recovery MiTeC
winget install --id=MiTeC.RegistryRecovery -e
This application allows to read files containing Windows 9x,NT,2K,XP,2K3,7,8,10 and 11 registry hives. It extracts many useful information about configuration and windows installation settings of host machine. Registry hive can be exported into REGEDIT4 format. Here are described individual explorers: - In this explorer you can see basic file properties and checksums. - Displays all security records used in registry. Usage counter, owner SID, group SID, list of affected keys and list of SACL and DACL is displayed for every record with flags and permissions enumerated. This explorer is available only for NT based system registry hives. - Displays Machine SID and part of SYSKEY. Enumerates local user and group accounts and some of their properties. This explorer is available only for NT based system registry SAM hive. - Displays Windows name, ID and key, install date and user registration info. Enumerates installed software with descriptions and install date and list of installed hotfixes wih description. This explorer is available only SOFTWARE registry hive (Product ID and key are extracted in SYSTEM hive too). Last boot and shutdown datetimes are extracted only from SYSTEM hive. Also displays user and machine name and tree based Start menu for selected USER hive. This explorer is available for USER registry hive. - Displays quick overview (CPU, Monitors, Video and Sound card and Network cards) and full device map of configured devices that worked on host machine. They are displayed in “Device Manager-like” tree with some properties. This explorer is available for SYSTEM registry hive. - Enumerates applications that are registered to be run after startup. This explorer is available for SOFTWARE registry hive. - Enumerates all installed services and drivers with properties. This explorer is available only for NT based system registry SYSTEM hive. - Displays all installed network clients, protocols and services. Enumerates all defined network connections with its TCP/IP configuration. This explorer is available only for NT based system registry SYSTEM hive. - Displays settings (rules) for Windows Firewall. This explorer is available only for NT based system registry SYSTEM hive. - Displays all environment variables. This explorer is available only for NT based system registry SYSTEM hive. - This explorer displays whole registry in known tree format. Contains powerful searching and data interpreter.