The registry has two halves, and one follows you
The machine half lives in C:\Windows\System32\config — the SYSTEM, SOFTWARE, SAM and SECURITY hives behind HKEY_LOCAL_MACHINE and its siblings. The user half is NTUSER.DAT, one file per account, riding inside the profile folder itself. At logon the kernel mounts it into the registry tree as HKEY_CURRENT_USER; at logoff, if nothing keeps it loaded, it unloads cleanly and everything you changed this session stays in that file.
Two sibling files, NTUSER.DAT.LOG1 and NTUSER.DAT.LOG2, are the hive's transaction logs: they capture in-flight writes so a power cut mid-save cannot corrupt the hive. Together with the file itself they are most of what a "Windows profile" actually is — a folder of data plus a private registry graft that the system attaches to you at sign-in. That is also why profiles can "break" in ways a folder of documents never would.
What is actually inside
Almost nothing in there looks like "the registry" to a user — it is per-user state, and almost all of it is settings you want to keep. A healthy hive measures 3 to 30 MB. When one misbehaving application starts writing megabytes of keys every session, the file grows and logons slow down, because the whole hive loads into memory at sign-in.
- HKCU\Software — per-application settings for everything you run, by far the biggest chunk of the hive
- HKCU\Environment — your personal PATH and variables, which is where setx writes when you omit the /M switch
- Per-user autostart: the Run and RunOnce keys under HKCU\Software\Microsoft\Windows\CurrentVersion\Run launch your tray utilities at every logon
- File associations you have set by hand — the UserChoice entries under Explorer\FileExts that "Open with" creates
- Explorer's own memory: taskbar layout, Quick Access pins, Run-dialog history, typed paths
- Mapped network drives marked "reconnect at sign-in", which live under HKCU\Network
Why nobody can "clean" it
The file is exclusively locked from logon until logoff — you cannot copy, open or edit your own NTUSER.DAT while signed in, and neither can any cleaner. Tools that promise to "compact" it either work offline or export and re-import the registry, which loses data and fixes nothing measurable on a modern, indexed hive. A bloated hive is a symptom: the thing to treat is the application writing junk into it, not the file to vacuum.
The failure mode everyone eventually meets: if the hive cannot load at logon — corruption, or another process holding it busy — Windows signs you into a temporary profile with a warning, and the desktop looks factory-reset. The fix is never to delete NTUSER.DAT, because that makes the reset permanent. The fix is to release whatever keeps the hive loaded, or to repair it offline from another administrator account with the Registry Editor's Load Hive command.
Questions and Answers
Is it safe to delete NTUSER.DAT?
No — it is your settings, not a cache: delete it and Windows builds you a fresh, empty profile with default application settings, an empty desktop and a new taskbar layout.
Why can't I copy my own NTUSER.DAT?
The kernel holds the hive exclusively locked from logon to logoff. Copy it from another admin account with the profile logged off, or export HKCU with reg export while signed in.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]