viewer9 documentation

RegDeleteValue PML Operation

Example from 32-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegDeleteValue opcode=2,10

ev=11479 modify=1

Time:2022-05-17 14:24:34.2547143
Duration:0.0000148
ResultCode:NAME NOT FOUND
Tid:420
Path:HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A

evdata[0-108] file offset 3668176

069 80 48 4b 4c 4d 5c 53 i.HKLM\S
84f 46 54 57 41 52 45 5c OFTWARE\
164d 69 63 72 6f 73 6f 66 Microsof
2474 5c 53 79 73 74 65 6d t\System
3243 65 72 74 69 66 69 63 Certific
4061 74 65 73 5c 41 75 74 ates\Aut
4868 52 6f 6f 74 5c 43 65 hRoot\Ce
5672 74 69 66 69 63 61 74 rtificat
6465 73 5c 41 44 37 45 31 es\AD7E1
7243 32 38 42 30 36 34 45 C28B064E
8046 38 46 36 30 30 33 34 F8F60034
8830 32 30 31 34 43 33 44 02014C3D
9630 45 33 33 37 30 45 42 0E3370EB
10435 38 41 4d 00 58AM.

Call Stack stacksize=34

StackAddressmodModNameModPath
0x816d40c871ntoskrnl.exe + 0x26b0c8C:\Windows\system32\ntoskrnl.exe
0x816eaf6371ntoskrnl.exe + 0x281f63C:\Windows\system32\ntoskrnl.exe
0x8155ce2b71ntoskrnl.exe + 0xf3e2bC:\Windows\system32\ntoskrnl.exe
0x7714b6ba57ntdll.dll + 0x6b6baC:\Windows\SYSTEM32\ntdll.dll
0x74b995cd37KERNELBASE.dll + 0x295cdC:\Windows\system32\KERNELBASE.dll
0x74b9966337KERNELBASE.dll + 0x29663C:\Windows\system32\KERNELBASE.dll
0x74949580237CRYPT32.dll + 0x29580C:\Windows\system32\CRYPT32.dll
0x74949535237CRYPT32.dll + 0x29535C:\Windows\system32\CRYPT32.dll
0x749494de237CRYPT32.dll + 0x294deC:\Windows\system32\CRYPT32.dll
0x7494947d237CRYPT32.dll + 0x2947dC:\Windows\system32\CRYPT32.dll
0x7496d9a2237CRYPT32.dll + 0x4d9a2C:\Windows\system32\CRYPT32.dll
0x7496daa4237CRYPT32.dll + 0x4daa4C:\Windows\system32\CRYPT32.dll
0x74963897237CRYPT32.dll + 0x43897C:\Windows\system32\CRYPT32.dll
0x7496de46237CRYPT32.dll + 0x4de46C:\Windows\system32\CRYPT32.dll
0x7496dd9d237CRYPT32.dll + 0x4dd9dC:\Windows\system32\CRYPT32.dll
0x749ba68e237CRYPT32.dll + 0x9a68eC:\Windows\system32\CRYPT32.dll
0x749bba7c237CRYPT32.dll + 0x9ba7cC:\Windows\system32\CRYPT32.dll
0x7498f51d237CRYPT32.dll + 0x6f51dC:\Windows\system32\CRYPT32.dll
0x6ffda93b447cryptsvc.dll + 0xa93bc:\windows\system32\cryptsvc.dll
0x76a27f9b50RPCRT4.dll + 0x7f9bC:\Windows\system32\RPCRT4.dll
0x76ad924650RPCRT4.dll + 0xb9246C:\Windows\system32\RPCRT4.dll
0x76ada10950RPCRT4.dll + 0xba109C:\Windows\system32\RPCRT4.dll
0x76a285e950RPCRT4.dll + 0x85e9C:\Windows\system32\RPCRT4.dll
0x76a284d950RPCRT4.dll + 0x84d9C:\Windows\system32\RPCRT4.dll
0x76a2b90150RPCRT4.dll + 0xb901C:\Windows\system32\RPCRT4.dll
0x76a28af050RPCRT4.dll + 0x8af0C:\Windows\system32\RPCRT4.dll
0x76a288a850RPCRT4.dll + 0x88a8C:\Windows\system32\RPCRT4.dll
0x76a2dc2750RPCRT4.dll + 0xdc27C:\Windows\system32\RPCRT4.dll
0x76a2da4350RPCRT4.dll + 0xda43C:\Windows\system32\RPCRT4.dll
0x7710811b57ntdll.dll + 0x2811bC:\Windows\SYSTEM32\ntdll.dll
0x7710730c57ntdll.dll + 0x2730cC:\Windows\SYSTEM32\ntdll.dll
0x754241a846KERNEL32.DLL + 0x41a8C:\Windows\system32\KERNEL32.DLL
0x77132e3157ntdll.dll + 0x52e31C:\Windows\SYSTEM32\ntdll.dll
0x77132dff57ntdll.dll + 0x52dffC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.