What is the REGTRANS-MS file format?
Files with the .regtrans-ms extension store information about changes made to the Windows user registry, used to keep registry edits atomic and crash-safe. .regtrans-ms files work alongside .blf base-log files as part of the Kernel Transaction Manager (KTM) write-ahead log system - together they allow Windows to commit or roll back registry changes cleanly after a crash or power failure. These files are generated automatically by the Common Log File System (CLFS) driver as part of the Transactional Registry (TxR) subsystem, introduced in Windows Vista.
The transaction log processor records all operations that constitute a transaction in these log files. An unfinished or unsuccessful transaction can be reverted to prevent registry corruption. Transaction logs appear alongside registry hive files such as:
NTUSER.DAT- transactions related to the user registry hive;.regtrans-msfiles are saved in the user's profile folder,- System hives (
SYSTEM,SOFTWARE,SAM,SECURITY) - related log files reside in%SystemRoot%\System32\config\.
Files follow the naming pattern {GUID}.TxR.{n}.regtrans-ms (e.g. {3808876b-c176-4e48-b7ae-04046e6cc752}.TxR.0.regtrans-ms).
.regtrans-ms files have the hidden attribute enabled by default. To make them visible, the option to show hidden files must be activated in Windows Explorer. Files for the current session are locked and cannot be edited or deleted while Windows is running. Sometimes, due to errors, .regtrans-ms files may grow unusually large or may not be properly cleaned up by the system. Deleting or editing these files manually risks corrupting the registry hive they protect.
Security & safety
RISK: MEDIUMThe file itself is passive log data and not malware, but it is a PROTECTED system file: it is normally hidden, in use by Windows, and owned by SYSTEM/TrustedInstaller. Do NOT delete, move, or edit .regtrans-ms files - they are part of how Windows keeps the registry crash-safe, and removing them (or the paired .blf base log) can corrupt the registry and stop Windows booting cleanly. Ignore 'cleaner'/'optimizer' guides that tell you to delete them. They are cleaned up and recreated by the OS as needed. (Conversely, a file with this extension showing up in an unexpected, user-writable location could be something masquerading - but in the system registry folders it is exactly what it claims to be.)
Format details
in a nutshellPrograms that open REGTRANS-MS files
Technical details
deep spec| Developer | Microsoft |
| Associated subsystem | Kernel Transaction Manager (KTM) / Transactional Registry (TxR) |
| Underlying format | Common Log File System (CLFS) binary log container |
| Byte order | Little-endian |
| Companion file | .blf base-log file (CLFS base log paired with each .regtrans-ms set) |
| Typical location | User profile folder (alongside NTUSER.DAT) or %SystemRoot%\System32\config\ (system hives) |
| Filename pattern | {GUID}.TxR.{n}.regtrans-ms (e.g. {3808876b-c176-4e48-b7ae-04046e6cc752}.TxR.0.regtrans-ms) |
| Typical file size | Tens of KB to a few MB; CLFS containers are pre-allocated in fixed-size blocks |
| Encryption | None; protected at OS level by SYSTEM/TrustedInstaller ACLs |
| File attributes | Hidden; locked by the OS while Windows is running |
| MIME type | application/octet-stream |
| Integrity mechanism | CLFS internal sector-sequence validation detects torn writes and enables log replay on recovery |
| Encoding | Binary |
| Supported operating systems | Windows Vista, Windows 7, Windows 8, Windows 10, Windows 11 |
| Released | Windows Vista (2007), with the Kernel Transaction Manager / Transactional Registry (TxR) and CLFS |
| Latest version | Same CLFS-based scheme in Windows 7/8/10/11; format is internal and undocumented for end users |
| Specification | learn.microsoft.com |
REGTRANS-MS conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about REGTRANS-MS files.