Neatbo.

Separate registry order from value changes

A registry comparison needs explicit name rules, exact value types and a complete audit trail before anyone considers applying changes.

Order can obscure a value question

GeekLevel9000 reported reordered selected exports that looked different as text. A separate user wanted key/property comparison and then an apply step. T313 addresses the comparison of supplied exports; applying a change remains a separate decision.

Make direction and identity visible

A two-file difference has a direction. The first queue entry is before, the second is after, and the result names both originals. Review this before using added or removed labels. The selected filenames do not establish which export was earlier; you supply that meaning.

ASCII letter case is ignored for supported names, while value text and member order remain exact. The tool declines non-ASCII names because an approximation to Windows name equivalence could create false matches. This narrow rule is visible in every full report.

Keep the type, not just a display string

String 2 and DWORD 2 have different types and produce a change. A QWORD can exceed the exact integer range of common floating-point displays, so JSON stores exact decimal text. Binary and encoded string types retain original bytes as rawHex alongside their decoded typed value. EXPAND_SZ text stays literal; reading a comparison never expands an environment variable.

Checked distinctions
BeforeAfterResult
DWORD 00000001DWORD 00000002value-changed
REG_SZ "2"DWORD 00000002value-changed (type)
Same binary bytes, lowercase hexSame binary bytes, uppercase hexNo value change
Same values in another declaration orderSame ASCII identities and typesNo value change; both source orders preserved

Keep the full record separate from the preview

A 200-row preview is a reading aid. Both complete snapshots and every change remain in JSON; every complete change remains in CSV. A whole-key removal includes the key’s full typed values, so the count of changed keys is not a substitute for that record.

  • Use JSON for exact literals; CSV formula protection intentionally changes the cell presentation.
  • Keep original exports for comments and text syntax. SHA256 links a report to the supplied original bytes.
  • An unsupported profile or budget refusal is atomic. Correct both original inputs and rerun instead of treating a partial list as complete.
  • The bounded task accepts two files ≤ 10 MiB each; an 850 MB full-machine dump needs another workflow.
  • No live registry read, import patch, command execution or automatic application follows a successful comparison.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

Compare typed registry exportsCompare two local .reg exports by ASCII key and typed value, preserving both complete snapshots, original SHA256 and every change in JSON/CSV.

Select exactly two complete Registry Editor V5.00 UTF-16LE BOM exports. Put the before export first and after export second with the queue arrows. Compare key and value identities while ignoring source ordering and ASCII letter case; review complete typed changes without accessing the live registry.

Steps

  1. Select the before and after exports, then use queue arrows to verify first = before and second = after.
  2. Compare the supported exports and check source names, SHA256, key/value totals and change kinds.
  3. Download registry-diff.json and registry-changes.csv for both complete typed snapshots and every change.
  4. Review values in JSON; keep the original exports for context. No importable .reg patch is generated.

Capabilities and limits

  • Exactly two original files, each ≤ 10 MiB and combined ≤ 20 MiB. Source names ≤ 512 UTF-16 units. Both size limits apply before decoding. The combined ceiling is implied by two files at the individual ceiling; it is a protective guard, not another independent capacity. Filename suffix does not establish content; the original BOM, header and typed syntax are checked.
  • At most 100,000 original key sections and 200,000 original typed values across both exports, counted before comparison. ASCII key/value names only; Unicode scalar string values are supported. Names use ASCII case folding, not Windows Unicode ordinal equivalence, hive-alias resolution or environment expansion.
  • Supported strict types: quoted REG_SZ, eight-hex-digit DWORD, eight-byte little-endian hex(b) QWORD, hex: BINARY, terminated UTF-16LE hex(2) EXPAND_SZ and hex(7) MULTI_SZ. Standard supported HKEY roots, semicolon comments, source ordering and hex continuation are accepted. Duplicate identities, non-ASCII names, deletion/import commands, unknown types, malformed UTF-16 and unsupported export profiles refuse the complete comparison.
  • Complete JSON and formula-protected CSV together ≤ 32 MiB, with no partial success. JSON includes every typed key/value in both snapshots, raw hex for hex types, original spelling/order, file SHA256 and all key/value additions, removals and changes. QWORD values are exact decimal strings. CSV includes every complete change; formula-leading literal cells gain an apostrophe, and exact literals remain in JSON.
  • Preview: at most 200 change rows and 2,000 UTF-16 units per cell. The copied text is a labelled summary; complete snapshots and changes are in the downloads. This tool never reads a live hive, executes source, imports, applies a patch, or modifies originals. Full-machine dumps of 25 or 850 MB are outside this bounded task.
Open Compare typed registry exports →