When using a VM, I use these steps to inspect changes to the registry:
- Using 7-Zip, open the vdi/vhd/vmdk file and extract the folder C:\Windows\System32\config
- Run OfflineRegistryView to convert the registry to plaintext
- Set the 'Config Folder' to the folder you extracted
- Set the 'Base Key' to
HKLM\SYSTEM
or HKLM\SOFTWARE
- Set the 'Subkey Depth' to 'Unlimited'
- Press the 'Go' button
Now use your favourite diff program to compare the 'before' and 'after' snapshots.