Compare bounded registry exports by typed value
Compare two selected V5.00 UTF-16LE exports, preserve both complete typed snapshots, and review every key or value change.
Choose a bounded comparison and establish direction
A user asked for two exports to be compared by key/property. Separately, GeekLevel9000 described order changes hiding equivalence in selected exports. T313 accepts the already exported files and delivers a complete typed comparison.
Select exactly two Registry Editor V5.00 UTF-16LE BOM files. The first queue entry is before; the second is after. Check the list and use its up/down arrows before running, because operating-system selection order is not an intent label. Reversing entries reverses added and removed change kinds.
- Use selected complete subkey exports that fit the declared budgets; this tool does not take a live registry snapshot.
- The tool never launches commands, imports a file, creates an apply patch or modifies a source export.
Keep type identity alongside the value
Names use an explicit ASCII case-insensitive rule. Source order and spelling stay in the snapshots but do not alone cause changes. Unicode scalar string values are accepted; non-ASCII key/value names are outside this profile rather than silently compared with a different Windows rule.
| Type | Accepted export form | Complete JSON value |
|---|---|---|
| REG_SZ | Quoted string with supported quote/backslash escapes | Exact scalar string |
| REG_DWORD | dword: plus exactly eight hex digits | Unsigned decimal string |
| REG_QWORD | hex(b): exactly eight little-endian bytes | Exact unsigned decimal string; rawHex |
| REG_BINARY | hex: byte list | Hex string and rawHex |
| REG_EXPAND_SZ | hex(2): terminated UTF-16LE | Literal text; no environment expansion |
| REG_MULTI_SZ | hex(7): terminated nonempty members or empty list | Ordered exact member array and rawHex |
Read the checked example
The example has two key sections and ten typed values in each source. Three existing values change: Enabled from DWORD 1 to 2, Label from old to new, and Type from string 2 to DWORD 2. BeforeOnly is removed and AfterOnly is added. Reversing the declarations does not add another change. Complete reports contain five changes, four original sections and twenty original typed values.
The QWORD value 18446744073709551615 remains an exact decimal string, not a rounded JavaScript number. Binary 00010203ff includes a continued source line, and the MULTI_SZ value [a,b] preserves member order. The empty-list boundary produces [], while malformed interior empty members are refused.
Apply all budgets together
Counts apply to all original sections and values in both sources before comparison. Duplicate case-insensitive keys or values are ambiguous and reject the complete comparison; they are never collapsed to reduce a count. Correctly supported exports can still produce reports beyond the output budget.
| Dimension | Published bound |
|---|---|
| Selected originals | Exactly 2; each ≤ 10 MiB; together ≤ 20 MiB |
| Original key sections / typed values | 100,000 / 200,000 across both |
| Selected source name | 512 UTF-16 units |
| Complete JSON and CSV | Together ≤ 32 MiB; whole comparison or refusal |
| Visible table | 200 changes, 2,000 UTF-16 units per cell |
Use the complete audit downloads
registry-diff.json includes both complete typed snapshots, original spelling/order, raw hex for hex types, SHA256 and every change. A whole-key addition or removal carries every value of that key. registry-changes.csv includes every change with complete before/after key or value JSON. No change may disappear because the preview shows only its first 200 rows.
CSV adds an apostrophe to formula-leading literal cells. The boundary value name =literal stays exact in JSON; its CSV cell becomes protected. Compare identity in JSON, keep source exports for comments and original text, and consider which path/value context should be shared.
The actual native proofs read all 100,000 key sections and 200,000 values, an exact 32 MiB report and every first excess. Real unfinished parse progress can cancel; a fresh Worker restores the same originals. These proofs support the implementation and do not replace the final browser interaction checks.
References
- GeekLevel9000 first-person order problem
Answer and original question read in full on 2026-10-07. The answerer describes reordered selected exports; the original live-registry request and large full-machine dump remain outside this tool.
- User task: compare two exported registry files by key/property
Full question and author follow-up read on 2026-10-07. Comparison matches this task; creating and applying a third .reg file is an explicit remaining gap.
- Microsoft registry value types
Type table and string termination section read on 2026-10-07. This format reference defines type distinctions; it is not counted as user demand.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
Compare typed registry exportsCompare two local .reg exports by ASCII key and typed value, preserving both complete snapshots, original SHA256 and every change in JSON/CSV.
Select exactly two complete Registry Editor V5.00 UTF-16LE BOM exports. Put the before export first and after export second with the queue arrows. Compare key and value identities while ignoring source ordering and ASCII letter case; review complete typed changes without accessing the live registry.
Steps
- Select the before and after exports, then use queue arrows to verify first = before and second = after.
- Compare the supported exports and check source names, SHA256, key/value totals and change kinds.
- Download registry-diff.json and registry-changes.csv for both complete typed snapshots and every change.
- Review values in JSON; keep the original exports for context. No importable .reg patch is generated.
Capabilities and limits
- Exactly two original files, each ≤ 10 MiB and combined ≤ 20 MiB. Source names ≤ 512 UTF-16 units. Both size limits apply before decoding. The combined ceiling is implied by two files at the individual ceiling; it is a protective guard, not another independent capacity. Filename suffix does not establish content; the original BOM, header and typed syntax are checked.
- At most 100,000 original key sections and 200,000 original typed values across both exports, counted before comparison. ASCII key/value names only; Unicode scalar string values are supported. Names use ASCII case folding, not Windows Unicode ordinal equivalence, hive-alias resolution or environment expansion.
- Supported strict types: quoted REG_SZ, eight-hex-digit DWORD, eight-byte little-endian hex(b) QWORD, hex: BINARY, terminated UTF-16LE hex(2) EXPAND_SZ and hex(7) MULTI_SZ. Standard supported HKEY roots, semicolon comments, source ordering and hex continuation are accepted. Duplicate identities, non-ASCII names, deletion/import commands, unknown types, malformed UTF-16 and unsupported export profiles refuse the complete comparison.
- Complete JSON and formula-protected CSV together ≤ 32 MiB, with no partial success. JSON includes every typed key/value in both snapshots, raw hex for hex types, original spelling/order, file SHA256 and all key/value additions, removals and changes. QWORD values are exact decimal strings. CSV includes every complete change; formula-leading literal cells gain an apostrophe, and exact literals remain in JSON.
- Preview: at most 200 change rows and 2,000 UTF-16 units per cell. The copied text is a labelled summary; complete snapshots and changes are in the downloads. This tool never reads a live hive, executes source, imports, applies a patch, or modifies originals. Full-machine dumps of 25 or 850 MB are outside this bounded task.