
by Jerry Honeycutt
Changing the Registry is risky. The worst-case scenario is that Windows 98 will no longer start. The best case scenario is that you won't notice anything different, but on the whole, you'll probably cause certain applications or devices to behave improperly. No damage is irreparable, however, if you back up the Registry using the methods described in this chapter and if you stick to the plan you learn about in this section.
But just to be sure you know the risks, take a look at why editing the Registry using the Registry Editor is dangerous:
You can learn to make changes in the Registry without risking anything, and you can safely experiment with the Registry. After writing three books on the Registry (and through endless tinkering), this author has made only one change that he couldn't safely recover from. You can make sure that your experience with the Registry is just as good by making a plan before you strike out to make changes.
To that end, here's a sample plan that you can change to suit your own needs:
TIP: You wouldn't think the Registry would be in peril when you install a new program because you don't change any Registry settings yourself. Regardless, my experience suggests that you should back up the Registry before you install programs with which you're unfamiliar so that you can easily recover from a wayward Setup program's faux pas.
Windows 98 stores the entire contents of the Registry in two files: SYSTEM.DAT and USER.DAT. These are binary files that you can't view using a text editor (as you can INI files). Windows 98 also turns on the Read-only, System, and Hidden attributes of SYSTEM.DAT and USER.DAT so that you can't accidentally replace, change, or delete these files. SYSTEM.DAT contains configuration data specific to the computer on which you installed Windows 98. USER.DAT contains configuration data specific to the current user.
Take a look. SYSTEM.DAT and USER.DAT are located in C:\Windows. The location of USER.DAT will be different if you've configured the computer to use profiles, though. In that case, Windows would have created a new system folder called C:\WINDOWS\PROFILES, under which you'll find a folder for each user that logs onto the machine. For example, C:\WINDOWS\PROFILES\JERRY contains my configuration data, and C:\WINDOWS\ PROFILES\POMPY contains my dog's configuration data. Each user's profile folder contains an individual copy of USER.DAT. You'll still find a default USER.DAT in C:\WINDOWS, mind you, which Windows uses as a template for new users.
NOTE: Profiles allow multiple users to log onto a single computer with their own familiar settings (Start menu options, desktop configuration, and so on). You enable profiles using the Enable Multi-Users Settings Wizard. To start the wizard, select the Users icon in the Control Panel, or open the Passwords Properties dialog box by selecting the Passwords icon in the Control Panel. [dagger]
Take a look at Figure 19.1. This Figure shows you how the Windows 98 Registry looks when viewed in the Registry Editor. In the left-hand pane, you see all the Registry's keys. In the right-hand pane, you see all the configuration data for the key that's selected in the left pane. Each group of configuration data in the Registry is called a key. Keys are very much like sections in INI files. They have names and can contain one or more bits of configuration data. Key names can be made up of any combination of alphabetical, numeric, and symbol characters, as well as spaces.
FIG. 19.1 The Registry Editor is a simple program that packs a lot of power.
The most important difference between the Registry's keys and an INI file's sections is that a Registry key can contain other keys. That's the origin of the Registry's hierarchy. You can think of it as stuffing a bunch of file folders inside another file folder. At the top of Figure 19.1, you see My Computer. This just represents the computer whose Registry you're viewing (you can view remote computers, too). Below My Computer, you see a handful of root keys. Each root key contains a number of subkeys.
TIP: This chapter uses the terms key and subkey interchangeably. In reality, when referring to a child key (a key underneath the key being discussed), you should call it a subkey.
Below subkeys are value entries, where Windows stores the actual configuration data. Each key can contain one or more value entries, and each value entry has three parts:
| Type | Description |
| String | Text, words, or phrases. The Registry always displays strings within quotes. |
| Binary | Binary values of unlimited size, represented as hexadecimal. (These are similar to DWORDs except they're not limited to four bytes.) |
| DWORD | 32-bit binary values in hexadecimal format (double words). The Registry displays a DWORD as an 8-digit (four bytes) hexadecimal number. |
NOTE: Every key contains at least one value entry, called (Default). This chapter just calls it the default value entry for a key. The default value entry is always a string value. Windows provides it for compatibility with the Windows 3.1 Registry and older 16-bit applications. In many cases, the default value entry doesn't contain anything at all. In other cases, a program needs to store only one value, so the default value entry is the only data stored in that key.[dagger]
You'll find six root keys in the Windows 98 Registry (take another look at Figure 19.1). HKEY_LOCAL_MACHINE and HKEY_USERS are real Registry keys; the others are aliases. Aliases are just shortcuts to branches within HKEY_LOCAL_MACHINE or HKEY_USERS that make accessing a particular set of configuration data easier for programmers and users. Take a look at the real keys first (we'll cover the aliases in a bit).
HKEY_LOCAL_MACHINE contains configuration data that describes the hardware and software installed on the computer, such as device drivers, security data, and computer-specific software settings (uninstall information, for example). This information is specific to the computer itself instead of to any one user who logs on to it. The following list describes the contents of each subkey immediately under HKEY_LOCAL_MACHINE:
NOTE: The single largest branch in the Registry is HKEY_LOCAL_MACHINE\Software\Classes. This subkey describes all the associations between documents and programs, as well as information about COM objects; thus, it is very large. You can also get to this branch through the root key HKEY_CLASSES_ROOT, which is an alias for HKEY_LOCAL_MACHINE\Software\Classes.[dagger]
The Windows 98 Configuration ManagerThe Configuration Manager is the heart of Plug and Play. It is responsible for managing the configuration process on the computer. It identifies each bus on your computer (PCI, SCSI, ISA) and all the devices on each bus. It also notes the configuration of each device, making sure that each device is using unique resources (IRQ and I/O address).
The Configuration Manager works with three key components to make all of this happen: bus enumerators, arbitrators, and device drivers. Here's a summary of the purpose of each component:
| Bus enumerators |
Bus enumerators are responsible for building the hardware tree. They query each device or each device driver for configuration information. |
| Arbitrators |
Arbitrators assign resources to each device in the hardware tree. That is, they dole out IRQs, I/O addresses, and such to each device. |
| Device drivers |
The Configuration Manager loads a device driver for each device in the hardware tree and communicates the device's configuration to the driver. |
HKEY_USERS contains all of the user-specific configuration data for the computer. That is, Windows stores configuration data for each user that logs on to the computer in a subkey under HKEY_USERS. If you haven't configured the computer to use profiles, all you'll find is a single subkey called .DEFAULT. The following list describes what you'll find in HKEY_USERS\.DEFAULT or within each user's subkey:
NOTE: The Registry has an order of precedence. Often, Windows or other programs will store duplicate data in both HKEY_USERS and HKEY_LOCAL_MACHINE. In such cases, the configuration data stored in HKEY_USERS has precedence over the data stored in HKEY_LOCAL_MACHINE. Windows does this so that individual user preferences will override computer-specific settings.[dagger]
Even though the Registry Editor does show six root keys, there are really only two: HKEY_LOCAL_MACHINE and HKEY_USERS. The remaining root keys are really just aliases that refer to branches (entire portions of the Registry beginning with a particular key) within the other two root keys. In other words, aliases are a bit like shortcuts in Explorer: If you change a value in one of the aliases, that value is actually changed in either HKEY_LOCAL_MACHINE or HKEY_USERS.
Here's more information about each alias:
NOTE: When you export the Registry to a REG file, the file contains entries found only in HKEY_LOCAL_MACHINE and HKEY_USERS. That's because it is redundant to export the aliases.[dagger]
Abbreviations for Root KeysYou'll frequently see abbreviations for the root keys used in publications (but not this one). The following table gives the abbreviation used for each root key:
| Root Key | Abbreviation |
| HKEY_CLASSES_ROOT | HKCR |
| HKEY_CURRENT_USER | HKCU |
| HKEY_LOCAL_MACHINE | HKLM |
| HKEY_USERS | HKU |
| HKEY_CURRENT_CONFIG | HKCC |
| HKEY_DYN_DATA | HKDD |
REGEDIT might not be on your Start menu, but it is probably in your Windows folder (C:\WINDOWS). The file name is REGEDIT.EXE. To open it, choose Start, Programs, Run. Then type regedit and click OK. The REGEDIT window pops up. If you want, you can drag REGEDIT.EXE from your Windows folder to the Start button to create a shortcut to it.
TROUBLESHOOTING:I see REGEDIT.EXE in my Windows folder, but either I can't run it or it won't let me change anything in the Registry. If you're using a computer in a networked environment, your system administrator might have disabled it. You'll have to plead your case to the system administrator for access to REGEDIT.EXE. Note that the system administrator can also prevent REGEDIT.EXE from being installed on your computer if you're installing Windows from the network or doing a custom installation.
CAUTION: Preventing user access to the Registry Editor requires the cooperation of the program that the user is using to edit the Registry. REGEDIT cooperates. Other programs probably won't. Thus, in Windows 98, you can't be sure that a user doesn't have access to the Registry.
When you search the Registry, REGEDIT looks for keys, value names, and value data that match the text you specify. In other words, it searches using the name of each key, the name of each value entry, and the actual data from each value entry. You can use the search feature to find entries relating to a specific product, to find all the entries that contain a reference to a file on your computer, or to locate entries related to a particular hardware device.
Here's how to search the Registry:
FIG. 19.2 Use these options to search for an item in the Registry.
TIP: If you select any item in REGEDIT's left-hand pane and start typing the name of a Registry key, REGEDIT moves to the key that best matches what you've typed thus far. For example, expand HKEY_CLASSES_ROOT. Then press ., and REGEDIT selects .386; press b, and REGEDIT selects .bat; press m, and REGEDIT selects .bmp. Note that if you pause between keystrokes, REGEDIT starts your incremental search over with the next key you type.
TIP: If the left-hand pane isn't big enough to easily tell which key REGEDIT found, look at REGEDIT's status bar to see the full name of the key. Alternatively, you can drag the window divider to the right to make more space in the left-hand pane.
Sometimes you have a really good reason to rename a key or value entry: to hide an entry from Windows while you test out a change. Well that's easy enough. Renaming a key or value entry in REGEDIT is similar to renaming a file in Windows Explorer except that you can't rename it by clicking on the name. Instead, you select the key or value entry that you want to rename, choose Edit, Rename, type over the name or change it, and then press Enter.
TIP: You can also rename a key or value entry by selecting it and pressing F2.
As a user, changing a value entry's setting is probably the number one activity you'll do with REGEDIT. You might want to personalize your desktop, for example, or you might need to adjust a TCP/IP setting to work better with your network.
Here's how to change a value entry:
FIG. 19.3 The Edit String dialog box shows you the original data before you start editing.
FIG. 19.4 Choose Decimal if your hexadecimal math is a bit rusty.
FIG. 19.5 You can use the Windows calculator (in Scientific mode) to convert decimal values to hexadecimal values for use in this dialog box.
TIP: Protect yourself when changing value data. Note the name of the value entry that you want to change and then rename it using some obscure name that Windows won't recognize such as MyValue. Then create a new Registry key with the name you assigned (as described in the next section) and set its value to what you want. This way, you can always restore the original setting by deleting the value entry you created and renaming the value entry you saved with its original name.
Changes that you make to the Registry might not be reflected immediately in Windows or the programs that are currently running. The only way to make sure is to close REGEDIT and restart Windows or the affected program.
To restart Windows 98 quickly, choose Shut Down from the Start menu. In the Shut Down Windows dialog box, select Restart the Computer and then hold down the Shift key and click OK. Windows 98 restarts without rebooting your computer.
Creating a new key or value entry is generally harmless--and equally useless unless, of course, you know for sure that either Windows or another program will use your new key. For example, the Microsoft Knowledge Base might instruct you to create a new Registry key to fix a problem. That's useful. Creating a new key out of thin air is pretty useless, however.
To create a new key or value entry, do one of the following:
Be very careful about deleting keys and value entries from your Registry. You'll likely prevent Windows from working properly if you carelessly delete keys or value entries from the Registry. If you don't know for sure what will happen or if you haven't been instructed to do so, don't delete anything. However, if you do need to delete a key or value entry, use these steps:
TIP: Before deleting a key, rename it with some obscure name such as MyNukedKey. This hides it from Windows and your applications. Then restart your computer and try it out. If everything works okay, go ahead and delete the key.
There are two ways you can work with the Registry. You can work with it in its current form (SYSTEM.DAT and USER.DAT in Windows 98) using REGEDIT. Or you can export it to a text file (REG file) and edit it with your favorite text editor, such as WordPad (the file is too big for Notepad). If you export your Registry to a text file, you can use your editor's search-and- replace features to make massive changes to it. Be careful doing this, however, because you can inadvertently change a value you don't mean to change.
Aside from editing the Registry with a text editor, exporting the Registry to a text file has a more practical purpose. You're not limited to exporting your entire Registry. You can export a specific key and all its subkeys and value entries (the branch). Thus, you can export a tiny part of the Registry for the following purposes:
To export your entire Registry or just a specific branch, perform the following steps:
FIG. 19.6 You can export a branch of the Registry or the whole thing.
The resulting file looks very much like a classic INI file. To see it, open it in Notepad: Right-click the REG file and choose Edit. (Notepad will offer to open the file in WordPad if it's larger than 64KB.) The first line always contains REGEDIT4, which identifies the file as a REGEDIT file. The remainder of the file contains the keys and value entries REGEDIT exported. Figure 19.7 shows what exported Registry entries look like in a text file.
FIG. 19.7 A Registry export file looks a lot like an INI file.
The file is split into multiple sections, with each Registry key in its own section. The name of the key is shown in brackets. It is the fully qualified name of that key in the Registry file (in other words, you see the entire name of the branch including the name of the root key). Each value entry for a key is listed in that key's section. The value entry's name appears in quotation marks, except for default value entries, which REGEDIT indicates with the at sign (@). The value entry's data looks different depending on its type, as shown in Table 19.2.
| Type | Example |
| String | "This is a string value" |
| DWORD | DWORD:00000001 |
| HEX | HEX:FF 00 FF 00 FF 00 FF 00 FF 00 FF 00 |
After you've made changes to your exported file, you might want to import it back into the Registry. In Windows Explorer, right-click an exported Registry file and choose Mer_ge. Windows updates your Registry.
CAUTION: Be careful not to accidentally double-click a REG file. If you do, Windows automatically merges it with the Registry because merge is the default action for the REG file type.
You'll find comfort in knowing that Windows 98 automatically backs up the Registry for you. Once each day, it uses the Windows Registry Checker (SCANREGW.EXE in C:\Windows) to back up the Registry to CAB files you find in C:\WINDOWS\SYSBCKUP. The first backup is named RB000.CAB, the second is RB001.CAB, and so on. The file with the highest number is the most recent backup file; thus, RB004.CAB is a more recent backup than RB002.CAB.
Right-click one of the CAB files, presumably the most recent, and choose View to examine its contents. You'll find four files in it: SYSTEM.DAT, SYSTEM.INI, USER.DAT, and WIN.INI. By default, Windows Registry Checker keeps only five backup copies of the Registry, but you can increase that by changing the MaxBackupCopies entry in SCANREG.INI to a higher number, perhaps 10.
You can also force Windows Registry Checker to make additional backup copies of the Registry after it has made its daily backup. Here's how:
Windows Registry Checker is the preferred method for backing up the Registry. However, alternative methods might suit your needs better; you'll learn about those methods in the following sections.
Create a Startup DiskIf you're in a pinch and can't start Windows 98, you'll be very glad that you created a startup disk. This disk gets your computer going when it won't start from the hard drive. You'll also find a handful of utilities on the disk that you might be able to use to fix your computer. Here's how to create the startup disk:
1. Double-click the Add/Remove Programs icon in the Control Panel.
2. In the Add/Remove Programs Properties dialog box, click the Startup Disk tab.
3. Click the Create Disk button and follow the onscreen instructions. Windows 98 will likely ask you for your Windows 98 CD-ROM (or disks).
4. When Windows 98 finishes creating your startup disk, click OK to close the Add/Remove Programs Properties dialog box.
5. Label your Emergency Startup Disk and keep it in a safe place just in case you encounter problems starting Windows 98.
Windows 98 doesn't put CD-ROM or network drivers on your startup disk. If you think you might need access to either of these when you start from your startup disk, you'll have to copy the 16-bit DOS drivers to the disk. Then create a CONFIG.SYS and AUTOEXEC.BAT that loads them properly.
The absolute easiest way to back up the contents of the Registry is to copy the files that contain the Registry to a safe place. You can even do this from Windows 98 Explorer, as explained here:
If you'd rather do this more or less automatically, you can create a batch file that does the same thing. Then all you have to do is execute the batch file to copy SYSTEM.DAT and USER.DAT to a safe place.
The following batch file copies both files (SYSTEM.DAT and USER.DAT). It uses the Xcopy command with the /H and /R switches. The /H switch copies files with the Hidden and System attributes. You use this switch in lieu of changing the files' attributes with the attrib command. The /R switch replaces read-only files. That way, Xcopy will be able to write over previous backup copies of the Registry. %WinDir% expands to the location of your Windows folder when the batch file runs.
xcopy %WinDir%\system.dat %WinDir%\Registry\ /H /R xcopy %WinDir%\user.dat %WinDir%\Registry\ /H /R
NOTE: If you configured Windows 98 to use user profiles, you'll need to tweak this batch file to make it correctly back up your USER.DAT and USER.DA0 files. In particular, you need to change the second line so that it copies these files from your profile folder instead of from the Windows folder. You can also enhance this batch file so that it copies USER.DAT and USER.DA0 files for all users on the computer by copying the second line for each user.[dagger]
Windows 98 comes with a tape backup utility that you can use as part of your regular backup strategy. Although Windows 98 Setup doesn't install it by default, you can use the Add/Remove Programs icon in the Control Panel to install the backup utility. After you install it, choose Start, Programs, Accessories, System Tools, Backup to run it.
By default, Microsoft Backup doesn't back up the Registry. Thus, to back up the Windows 98 Registry, you must perform the following steps before starting the backup:
FIG. 19.8 By default, Microsoft Backup doesn't back up the Registry.
As you learned earlier in this chapter, you can export the entire contents of the Registry into a REG file (see "Importing and Exporting Registry Entries," earlier in this chapter).
CAUTION: Don't rely on an exported copy of the Registry as your only backup. Microsoft has recorded problems that have occurred when users attempted to restore a backup using this method. For example, Windows 98 might not correctly update all Registry data.
The best use for this method is to back up only the portion of the Registry in which you're making changes. That way, if something goes wrong while you're editing the Registry, you can easily restore that branch by double-clicking the REG file.
The Emergency Repair Utility (ERU) is a tool that you can use to back up your important configuration files. You can back up those files to a floppy disk or to another folder on your computer. Microsoft preconfigured it to back up your most important configuration files, including:
| AUTOEXEC.BAT | PROTOCOL.INI |
| COMMAND.COM | SYSTEM.DAT |
| CONFIG.SYS | SYSTEM.INI |
| IO.SYS | USER.DAT |
| MSDOS.SYS | WIN.INI |
You'll find ERU on your Windows 98 CD-ROM in \TOOLS\MISC\ERU. Copy all four files to a folder on your computer. Then add a shortcut to your Start menu by dragging ERU.EXE and dropping it on the Start button. After you've copied it to your computer, use these steps to back up your configuration files, including the Registry:
FIG. 19.9 You can specify which files ERU includes in the backup.
As you learned earlier, Windows 98 uses a utility called Windows Registry Checker to back up copies of the Registry to CAB files stored in C:\WINDOWS\SYSBCKUP. You can restore any one of those backups using the real-mode version of this utility named SCANREG.EXE, which you find in C:\WINDOWS\COMMAND. To do so, follow these steps:
Although using Microsoft Registry Checker is the preferred method for restoring the Registry, you can use other methods. The sections that follow describe methods for restoring the alternative backups you learned about in the previous sections.
Did you make a backup copy of SYSTEM.DAT and USER.DAT? If so, you can easily restore those files and continue with business. Here's how:
If you prefer, you can create a batch file that automatically restores your backup copies of SYSTEM.DAT and USER.DAT. Then all you have to do is double-click the batch file to restore them.
The following batch file restores your backup files. It uses the Xcopy command with the /H and /R switches. The /H switch copies hidden and system files. The /R switch replaces read-only files. That way, Xcopy will be able to overwrite the current copy of SYSTEM.DAT and USER.DAT. %WinDir% expands to the location of your Windows folder when the batch file runs.
Xcopy %WinDir%\Registry\System.dat %WinDir%\System.dat /R /H Xcopy %WinDir%\Registry\User.dat %WinDir%\User.dat /R /H
NOTE: If you've configured Windows 98 to for multiple user profiles, you'll need to tweak this batch file to make it correctly restore USER.DAT. In particular, you need to change the second line so that it restores the backup copy into your profile folder.[dagger]
If you used the Windows 98 tape backup utility (Microsoft Backup) to back up the Registry, you can easily (if not quickly) restore the Registry to the state it was in when you last backed up your computer. You must use the following steps to instruct Windows 98 to restore the Registry:
NOTE: Using Microsoft Backup to back up and restore the Registry is a method better suited for a full backup. That is, if you restore the Registry from a backup tape, you should also restore the entire system from the same tape. Doing so ensures that the files on your computer match the settings found in the Registry. If you restore just the Registry from an older tape, chances are good that your computer won't work correctly because the configuration data in the Registry doesn't match the remaining files on your computer.[dagger]
Earlier in this chapter, you learned how to export the Registry into a REG file. You can't import this file while Windows 98 is running, however, because the Registry Editor can't replace keys that are open. You need to start your computer to the DOS prompt, and then use the Registry Editor in real mode to import the Registry. Follow these steps:
NOTE: This method is better suited to restoring backups containing small portions of the Registry. For instance, you can back up a single branch in which you're making changes. If you make a mistake, you can restore that single branch, without affecting other parts of the Registry.[dagger]
The Emergency Repair Utility (ERU) is a tool that backs up all of your important configuration files, including the Registry. You learned how to backup the Registry with the ERU earlier in this chapter. Here's how to restore your configuration files from the backup:
If all else fails, you'll find one more backup copy of the Registry on your computer. SYSTEM.1ST is a read-only, hidden, system file in the root folder of your boot drive. This is a backup copy of SYSTEM.DAT that Windows 98 made after you successfully installed and started Windows 98. It doesn't contain any custom settings, nor does it include any information added by the programs you've installed. The only thing this file does for you is get your machine running again if nothing else works.
Here's how to restore SYSTEM.1ST:
CAUTION: Use this method as a last resort only. Once you've restored SYSTEM.1ST, all the configuration changes you've made to your computer since you first installed Windows 98 will be gone.
The Windows 98 Registry vs. Windows 95 and NTYou will see little or no difference between the Windows 98 and Windows 95 Registries. The organization is the same, and the Registry Editor is the same. Inside the Registry is a different story, however. Microsoft has optimized the code and data structures that implement the Registry so that it performs much faster. The only thing you might notice is how much faster the Registry works.
The Windows 98 and Windows NT 4.0 Registries, in many ways, are very similar. However, there are some pretty huge differences between HKEY_CLASSES_ROOT and HKEY_USERS that you should be aware of:
l Windows NT 4.0 stores the Registry in hives, whereas Windows 95 stores the Registry in two binary files.
- Windows NT 4.0 implements full security for the Registry hives and for each individual key in the Registry. Windows 95 provides little security.
- The structure of HKEY_LOCAL_MACHINE\System is very different in Windows 95 and Windows NT 4.0.
- Windows NT 4.0 provides an additional Registry Editor that takes advantage of security and the different types of data you can store in a value.
To learn more about the differences between the Windows 98 and Windows NT 4.0 Registries, take a look at Macmillan's own Windows 95 and Windows NT 4.0 Registry & Customization Handbook.
© Copyright, Macmillan Computer Publishing. All rights reserved.