The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.
Windows API functions that query and manipulate registry values
Hives
HKEY_LOCAL_MACHINE ---> HKEY_CURRENT_USER
HKEY_CLASSES_ROOT (HKCR) ---> HKCU\Software\Classes
file associations
HKEY_CURRENT_USER (HKCU)
NTUSER.DAT and USRCLASS.DAT
HKEY_CLASSES_ROOT
".擴展名"