viewer9 documentation

Procmon Bug: RegRestoreKey/RegSaveKey Path and HivePath

32-bit Procmon records bad data for the Path and File Name ("HivePath" in viewer9), which are adjacent in the PML binary. The Path is truncated at the end, and the File Name is truncated at the beginning and suffixed with garbage:

Procmon will crash for either operation if the key has a numeric character followed by a non-alphanumeric and alphanumeric character (e.g., "1_a" or "test1_2"), and the "(Default)" value of the key is not set (either blank or "(value not set)").

viewer9 can only display the bad data recorded by Procmon, but the evdata binary shows where the problem occurs:

See also

Posted 22 Nov 2022 last updated 22 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.