{"id":7463,"date":"2016-08-07T05:08:34","date_gmt":"2016-08-07T05:08:34","guid":{"rendered":"http:\/\/www.top-password.com\/blog\/?p=7463"},"modified":"2016-08-07T05:08:34","modified_gmt":"2016-08-07T05:08:34","slug":"edit-offline-windows-registry-from-winpe","status":"publish","type":"post","link":"https:\/\/www.top-password.com\/blog\/edit-offline-windows-registry-from-winpe\/","title":{"rendered":"How to Edit Offline Windows Registry from WinPE"},"content":{"rendered":"<p>When your computer no longer boots up or you&#8217;re unable to login to Windows, a registry hack might fix your problem. To access the registry for an unbootable Windows installation, you should use a WinPE bootdisk. In this tutorial we&#8217;ll walk you through the steps to load \/ edit offline registry hive from WinPE.<\/p>\n<p>Before get started, we need to know the locations of Windows registry hives:<\/p>\n<p><strong>HKEY_LOCAL_MACHINE\\SYSTEM:<\/strong> %windir%\\system32\\config\\SYSTEM<br \/>\n<strong>HKEY_LOCAL_MACHINE\\SAM:<\/strong> %windir%\\system32\\config\\SAM<br \/>\n<strong>HKEY_LOCAL_MACHINE\\SECURITY:<\/strong> %windir%\\system32\\config\\SECURITY<br \/>\n<strong>HKEY_LOCAL_MACHINE\\SOFTWARE:<\/strong> %windir%\\system32\\config\\SOFTWARE<br \/>\n<strong>HKEY_USERS\\.DEFAULT:<\/strong> %windir%\\system32\\config\\DEFAULT<\/p>\n<p><strong>How to Edit Offline Windows Registry from WinPE?<\/strong><\/p>\n<ol>\n<li>Boot your computer into WinPE. Open a Command Prompt and run <strong>regedit.exe<\/strong> to open the Registry Editor.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/command-prompt-from-winpe.png\" alt=\"command-prompt-from-winpe\" width=\"600\" height=\"236\" class=\"alignnone size-full wp-image-7466\" \/><\/p>\n<\/li>\n<li>In the left pane of Registry Editor, highlight the <strong>HKEY_LOCAL_MACHINE<\/strong> hive (or HKEY_USERS).\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/highlight-registry-key.png\" alt=\"highlight-registry-key\" width=\"550\" height=\"304\" class=\"alignnone size-full wp-image-7467\" \/><\/p>\n<\/li>\n<li>Click the <strong>File<\/strong> menu and select <strong>Load Hive<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/load-hive.png\" alt=\"load-hive\" width=\"550\" height=\"304\" class=\"alignnone size-full wp-image-7468\" \/><\/p>\n<\/li>\n<li>Browse to your Windows partition and select the registry hive which you wish to load. In my example, the registry hives are located in the directory <em>D:\\Windows\\System32\\Config<\/em>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/select-registry-hive.png\" alt=\"select-registry-hive\" width=\"571\" height=\"424\" class=\"alignnone size-full wp-image-7469\" \/><\/p>\n<\/li>\n<li>Type a key name whatever you like (e.g. &#8220;<em>OfflineReg<\/em>&#8220;) and click <strong>OK<\/strong>. The name will be used to create a new node in the tree so one can browser the offline registry.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/enter-key-name-for-loading.png\" alt=\"enter-key-name-for-loading\" width=\"550\" height=\"304\" class=\"alignnone size-full wp-image-7470\" \/><\/p>\n<\/li>\n<li>Now under the <strong>HKEY_LOCAL_MACHINE<\/strong> key, you should see a new key named after the name you typed previously.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/offline-registry.png\" alt=\"offline-registry\" width=\"550\" height=\"339\" class=\"alignnone size-full wp-image-7471\" \/><\/p>\n<\/li>\n<li>Expand the new key, browse to the desired key or value for editing. In my example, I browse to <em>OfflineReg\\Software\\Microsoft\\IdentityCRL\\StoredIdentities<\/em> and delete its subkey.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/modify-offline-registry.png\" alt=\"modify-offline-registry\" width=\"600\" height=\"455\" class=\"alignnone size-full wp-image-7472\" \/><\/p>\n<\/li>\n<li>When you finish with the modifications, highlight the key you created previously (e.g. &#8220;<em>OfflineReg<\/em>&#8220;). Click the <strong>File<\/strong> menu and select <strong>Unload Hive<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/08\/unload-hive.png\" alt=\"unload-hive\" width=\"550\" height=\"339\" class=\"alignnone size-full wp-image-7473\" \/><\/p>\n<\/li>\n<li>This will unload the hive and all changes made will be saved to the offline registry.\n<\/li>\n<\/ol>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>When your computer no longer boots up or you&#8217;re unable to login to Windows, a registry hack might fix your problem. To access the registry for an unbootable Windows installation, you should use a WinPE bootdisk. In this tutorial we&#8217;ll walk you through the steps to load \/ edit offline registry hive from WinPE. Before [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,10,1894,3,39,5,4],"tags":[2881,2879,2880,2882],"class_list":["post-7463","post","type-post","status-publish","format-standard","hentry","category-others","category-tips-tricks","category-windows-10","category-windows-7","category-windows-8","category-windows-vista","category-windows-xp","tag-access-windows-registry-offline","tag-edit-offline-registry-hive","tag-load-windows-registry-offline","tag-offline-windows-registry-editor"],"_links":{"self":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/7463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/comments?post=7463"}],"version-history":[{"count":6,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/7463\/revisions"}],"predecessor-version":[{"id":7477,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/7463\/revisions\/7477"}],"wp:attachment":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/media?parent=7463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/categories?post=7463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/tags?post=7463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}