Skip to content

Instantly share code, notes, and snippets.

@warewolf
Created July 5, 2017 04:04
Show Gist options
  • Select an option

  • Save warewolf/eb9f376269a5e7d4555996277e22d715 to your computer and use it in GitHub Desktop.

Select an option

Save warewolf/eb9f376269a5e7d4555996277e22d715 to your computer and use it in GitHub Desktop.
registry diff of the same win7 VM booting 2x
--- /tmp/left-bA3uU/left-system-reg-l5GJd.tmp 2017-07-04 23:48:10.086963908 -0400
+++ /tmp/right-3nTJO/right-system-reg-ydUqH.tmp 2017-07-04 23:48:10.086963908 -0400
@@ -101,20 +101,20 @@
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\SqmData]
"AvgCountDiff"=dword:000001f6
"AvgFileCount"=dword:000001f6
-"CMFLastStartTime"=hex(b):05,ff,f9,48,41,04,ca,01
-"CMFStartTime"=hex(b):c0,b2,bb,72,d6,f4,d2,01
+"CMFLastStartTime"=hex(b):c0,b2,bb,72,d6,f4,d2,01
+"CMFStartTime"=hex(b):c0,87,57,23,41,f5,d2,01
"FileCountDiff"=dword:000001f6
"LastFileCount"=dword:000001f6
-"SystemLastStartTime"=hex(b):40,73,af,20,ef,f4,d2,01
-"SystemStartTime"=hex(b):a0,7d,d0,7b,ef,f4,d2,01
+"SystemLastStartTime"=hex(b):a0,7d,d0,7b,ef,f4,d2,01
+"SystemStartTime"=hex(b):c0,7c,44,23,41,f5,d2,01
"TotalCMFSize"=dword:0000000e
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\SqmData\BootLanguages]
-"en-US"=dword:00000004
+"en-US"=dword:00000005
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management\PrefetchParameters]
-"BaseTime"=dword:1e51c6f4
-"BootId"=dword:00000004
+"BaseTime"=dword:1e524cbe
+"BootId"=dword:00000005
"EnableBootTrace"=dword:00000000
"EnablePrefetcher"=dword:00000003
"EnableSuperfetch"=dword:00000003
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\AITEventLog]
"BufferSize"=dword:00000001
"ClockType"=dword:00000001
-"FileCounter"=dword:00000004
+"FileCounter"=dword:00000005
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SQMLogger]
"BufferSize"=dword:00000010
"FileCount"=dword:00000000
-"FileCounter"=dword:00000004
+"FileCounter"=dword:00000005
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\WdiContextLog]
"BufferSize"=dword:00000010
-"FileCounter"=dword:00000001
+"FileCounter"=dword:00000002
@@ -34185,11 +34185,11 @@
"ComponentizedBuild"=dword:00000001
"Directory"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,00,00
"ErrorMode"=dword:00000000
"NoInteractiveServices"=dword:00000000
"ShellErrorMode"=dword:00000001
-"ShutdownTime"=hex(3):30,a8,a8,01,d7,f4,d2,01
+"ShutdownTime"=hex(3):20,b0,58,44,41,f5,d2,01
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Epoch]
-"Epoch"=dword:000000b9
+"Epoch"=dword:000000bf
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Epoch2]
-"Epoch"=dword:0000000b
+"Epoch"=dword:0000000f
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CMF\SqmData\BootLanguages]
-"en-US"=dword:00000004
+"en-US"=dword:00000005
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters]
-"BaseTime"=dword:1e51c6f4
-"BootId"=dword:00000004
+"BaseTime"=dword:1e524cbe
+"BootId"=dword:00000005
"EnableBootTrace"=dword:00000000
"EnablePrefetcher"=dword:00000003
"EnableSuperfetch"=dword:00000003
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment