Mysterious, Native "A" Registry Key with Path: Registry\A Mysterious, Native "A" Registry Key with Path: Registry\A windows windows

Mysterious, Native "A" Registry Key with Path: Registry\A


Here is the comment from one of our driver writers: "DISCACHE.sys driver seems to be caching system file attributes and using \REGISTRY\A in an undocumented way. This driver is part of the kernel so it can load any hive wherever it wants."


Interesting...

The key indeed can be opened with a relative path, but not with an absolute path.

And it seems to contain information about all file systems and whatnot. Looks mysterious, indeed...