Possible to extract registry backup from restore point?

Azzip

New member
Local time
11:40 PM
Messages
2
Hi everybody, I was wondering if it is possible to extract the registry backup from a System Restore Point? In Windows XP the restore points were plain folders within the System Volume Information, but in Windows 7 they appear to be compressed into files like "{c09132a3-4131-11df-b9d7-002017c00008}{8807474b-c356-7e49-b2ae-03046e4cc752}". Is there a way to open these? I read the tutorial about extracting files from the system image vhd files in the WindowsImageBackup folder, but I think this is a different situation unless the system restore points are also vhd files?

(Background: I have a truecrypt system encryption which renders windows' own recovery function useless in the case of boot failure. So I ended up replacing the registry files manually by mounting my drive with a linux live cd w/ truecrypt. The only problem was to get hand on a working backup, so for the next time I'd like to know if I can extract the registry files from my old restore points).
 

My Computer My Computer

At a glance

Windows 7 Pro x64
OS
Windows 7 Pro x64
The easiest way to handle this is to install ERUNT and have it auto start when the system boots. It will make a complete backup of your registry and store it in date named folders under \Windows\ERDNT\AutoBackup.

The reg files are easily restored by running the appropriate erdnt.exe file from the date named folder you want.

Worked well with XP and Vista and now works with Win 7.
 

My Computer My Computer

At a glance

Windows 10 Pro X64Intel Quad Core i7-4770 @ 3.4Ghz16.0GB PC3-12800 DDR3 SDRAM 1600 MHzIntel Integrated HD Graphics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo IdeaCenter 450
OS
Windows 10 Pro X64
CPU
Intel Quad Core i7-4770 @ 3.4Ghz
Memory
16.0GB PC3-12800 DDR3 SDRAM 1600 MHz
Graphics Card(s)
Intel Integrated HD Graphics
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
250GB Samsung EVO SATA-3 SSD
2TB Seagate ST2000DM001 SATA-2
1.5TB Seagate ST3150041AS SATA
Keyboard
Dell USB
Mouse
Lenovo USB
Internet Speed
Cable via Road Runner 3MB Upload, 30MB Download
Antivirus
Windows Defender, MBAM Pro, MBAE
Browser
Seamonkey
Other Info
UEFI/GPT
PLDS DVD-RW DH16AERSH
The easiest way to handle this is to install ERUNT and have it auto start when the system boots. It will make a complete backup of your registry and store it in date named folders under \Windows\ERDNT\AutoBackup.

The reg files are easily restored by running the appropriate erdnt.exe file from the date named folder you want.

Worked well with XP and Vista and now works with Win 7.

Thank you for your nice workaround! Still I'm curious if I can get into those System Restore point files. Any idea?
 

My Computer My Computer

At a glance

Windows 7 Pro x64
OS
Windows 7 Pro x64
No, sorry. I'd like to see some ideas as well.
 

My Computer My Computer

At a glance

Windows 10 Pro X64Intel Quad Core i7-4770 @ 3.4Ghz16.0GB PC3-12800 DDR3 SDRAM 1600 MHzIntel Integrated HD Graphics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo IdeaCenter 450
OS
Windows 10 Pro X64
CPU
Intel Quad Core i7-4770 @ 3.4Ghz
Memory
16.0GB PC3-12800 DDR3 SDRAM 1600 MHz
Graphics Card(s)
Intel Integrated HD Graphics
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
250GB Samsung EVO SATA-3 SSD
2TB Seagate ST2000DM001 SATA-2
1.5TB Seagate ST3150041AS SATA
Keyboard
Dell USB
Mouse
Lenovo USB
Internet Speed
Cable via Road Runner 3MB Upload, 30MB Download
Antivirus
Windows Defender, MBAM Pro, MBAE
Browser
Seamonkey
Other Info
UEFI/GPT
PLDS DVD-RW DH16AERSH
The author of this program might be willing to give a clue:

ShadowExplorer.com - About

He digs out the file backups or shadow copies from restore point sets. I use the program and it's worked well for me. Perhaps a donation might get the author to provide a few clues. I don't think it's open source. But you might be surprised. Sometimes these programmer types will email you back if you ask a question tangential to one of their applications. :)
 

My Computer My Computer

At a glance

Windows 7 32 bitAMD 5200+ dual core2 GBNVidia GeForce 6150SE 128 MB
Computer Manufacturer/Model Number
HP Media Center
OS
Windows 7 32 bit
CPU
AMD 5200+ dual core
Memory
2 GB
Graphics Card(s)
NVidia GeForce 6150SE 128 MB
Monitor(s) Displays
CRT
Screen Resolution
1280x1024
Hard Drives
500 GB Sata internal :

SIIG USB 3.0 docking stations w/WD Caviar Black 6 Gb/s drives
Keyboard
PS/2
Mouse
PS/2 Wheel Mouse
Other Info
SIIG USB 3.0 PCIexpress card.
You can copy the hives from shadow copies with Shadow Explorer.
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
You can copy the hives from shadow copies with Shadow Explorer.
Works well in Vista, but does probably not work in XP. This is what the program desciption says: " ShadowExplorer allows you to browse the shadow copies created by the Windows® VistaTM Volume Shadow Copy Service. "
 

My Computer My Computer

At a glance

Vista, Windows7, Mint Mate, Zorin, Windows 8from 1.6GHz Duo to i7
Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Back
Top