viewer9 documentation

RegCloseKey PML Operation

The evdata of this event only contains the Path.

Example from 32-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegCloseKey opcode=2,2

ev=5710

Time:2011-01-20 16:47:04.9259238
Duration:0.0000035
ResultCode:SUCCESS
Tid:2772
Path:HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers

evdata[0-63] file offset 481396

03e 80 48 4b 4c 4d 5c 53 >.HKLM\S
84f 46 54 57 41 52 45 5c OFTWARE\
1650 6f 6c 69 63 69 65 73 Policies
245c 4d 69 63 72 6f 73 6f \Microso
3266 74 5c 57 69 6e 64 6f ft\Windo
4077 73 5c 53 61 66 65 72 ws\Safer
485c 43 6f 64 65 49 64 65 \CodeIde
566e 74 69 66 69 65 72 73 ntifiers

Call Stack stacksize=9

StackAddressmodModNameModPath
0x8054164c79ntkrnlpa.exe + 0x6a64cC:\WINDOWS\system32\ntkrnlpa.exe
0x7c91c9f337ntdll.dll + 0x1c9f3C:\WINDOWS\system32\ntdll.dll
0x7c91c66a37ntdll.dll + 0x1c66aC:\WINDOWS\system32\ntdll.dll
0x7c91626a37ntdll.dll + 0x1626aC:\WINDOWS\system32\ntdll.dll
0x7c9164d337ntdll.dll + 0x164d3C:\WINDOWS\system32\ntdll.dll
0x7c9386f937ntdll.dll + 0x386f9C:\WINDOWS\system32\ntdll.dll
0x7c938aec37ntdll.dll + 0x38aecC:\WINDOWS\system32\ntdll.dll
0x7c9210af37ntdll.dll + 0x210afC:\WINDOWS\system32\ntdll.dll
0x7c90e45737ntdll.dll + 0xe457C:\WINDOWS\system32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.