viewer9 documentation

RegEnumKey PML Operation

BufferSize is a 32-bit integer ("Length" in Procmon, though it is not shown on SUCCESS). Index (0-based) is a 32-bit integer. On SUCCESS, evresults contains the Name of the enumerated subkey and the timestamp LastWriteTime (not shown in Procmon).

Example from 64-bit PML

Hover over field values like Time, ResultCode, LastWriteTime, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegEnumKey opcode=2,7

ev=221 regread=76 B

Time:2012-03-06 11:36:31.3321245
Duration:0.0000061
ResultCode:SUCCESS
Tid:4336
Path:HKLM\SOFTWARE\Microsoft\CTF\TIP
BufferSize:288
Index:6
LastWriteTime:2006-11-02 10:31:08.2820755
Name:{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}

evdata[0-46] file offset 94734

01f 80 5c 00 20 01 00 00 ..\. ...
806 00 00 00 00 00 00 00 ........
1648 4b 4c 4d 5c 53 4f 46 HKLM\SOF
2454 57 41 52 45 5c 4d 69 TWARE\Mi
3263 72 6f 73 6f 66 74 5c crosoft\
4043 54 46 5c 54 49 50 CTF\TIP

evresults[0-91] file offset 94783

093 50 fe ea 93 fe c6 01 .P......
800 00 00 00 4c 00 00 00 ....L...
167b 00 38 00 31 00 44 00 ..8.1.D.
2434 00 45 00 39 00 43 00 4.E.9.C.
3239 00 2d 00 31 00 44 00 9.-.1.D.
4033 00 42 00 2d 00 34 00 3.B.-.4.
4831 00 42 00 43 00 2d 00 1.B.C.-.
5639 00 45 00 36 00 43 00 9.E.6.C.
642d 00 34 00 42 00 34 00 -.4.B.4.
7230 00 42 00 46 00 37 00 0.B.F.7.
8039 00 45 00 33 00 35 00 9.E.3.5.
8845 00 7d 00 E...

Call Stack stacksize=80

StackAddressmodModNameModPath
0xfffff80001d9119d1ntoskrnl.exe + 0x38819dC:\Windows\system32\ntoskrnl.exe
0xfffff80001d391311ntoskrnl.exe + 0x330131C:\Windows\system32\ntoskrnl.exe
0xfffff80001a62f331ntoskrnl.exe + 0x59f33C:\Windows\system32\ntoskrnl.exe
0x77cb6eba0ntdll.dll + 0x46ebaC:\Windows\System32\ntdll.dll
0x758877f6266wow64.dll + 0x277f6C:\Windows\System32\wow64.dll
0x7587244c266wow64.dll + 0x1244cC:\Windows\System32\wow64.dll
0x7586a996266wow64.dll + 0xa996C:\Windows\System32\wow64.dll
0x758c3688267wow64cpu.dll + 0x3688C:\Windows\System32\wow64cpu.dll
0x7586ab46266wow64.dll + 0xab46C:\Windows\System32\wow64.dll
0x7586621a266wow64.dll + 0x621aC:\Windows\System32\wow64.dll
0x7562aa32260wow64win.dll + 0x1aa32C:\Windows\System32\wow64win.dll
0x77cb6ac60ntdll.dll + 0x46ac6C:\Windows\System32\ntdll.dll
0xfffff80001cdcb7d1ntoskrnl.exe + 0x2d3b7dC:\Windows\system32\ntoskrnl.exe
0xfffff960001365bc3win32k.sys + 0xc65bcC:\Windows\System32\win32k.sys
0xfffff96000135db63win32k.sys + 0xc5db6C:\Windows\System32\win32k.sys
0xfffff960001325e33win32k.sys + 0xc25e3C:\Windows\System32\win32k.sys
0xfffff960001a3c033win32k.sys + 0x133c03C:\Windows\System32\win32k.sys
0xfffff9600010ec743win32k.sys + 0x9ec74C:\Windows\System32\win32k.sys
0xfffff960001002403win32k.sys + 0x90240C:\Windows\System32\win32k.sys
0xfffff9600009be863win32k.sys + 0x2be86C:\Windows\System32\win32k.sys
0xfffff960000adae53win32k.sys + 0x3dae5C:\Windows\System32\win32k.sys
0xfffff960001120713win32k.sys + 0xa2071C:\Windows\System32\win32k.sys
0xfffff96000103b8a3win32k.sys + 0x93b8aC:\Windows\System32\win32k.sys
0xfffff960001009723win32k.sys + 0x90972C:\Windows\System32\win32k.sys
0xfffff96000103ae93win32k.sys + 0x93ae9C:\Windows\System32\win32k.sys
0xfffff9600014a04b3win32k.sys + 0xda04bC:\Windows\System32\win32k.sys
0xfffff80001a62f331ntoskrnl.exe + 0x59f33C:\Windows\system32\ntoskrnl.exe
0x7564a29a260wow64win.dll + 0x3a29aC:\Windows\System32\wow64win.dll
0x75633e96260wow64win.dll + 0x23e96C:\Windows\System32\wow64win.dll
0x7586a996266wow64.dll + 0xa996C:\Windows\System32\wow64.dll
0x758c3688267wow64cpu.dll + 0x3688C:\Windows\System32\wow64cpu.dll
0x7586ab46266wow64.dll + 0xab46C:\Windows\System32\wow64.dll
0x7586a14c266wow64.dll + 0xa14cC:\Windows\System32\wow64.dll
0x77cab9130ntdll.dll + 0x3b913C:\Windows\System32\ntdll.dll
0x77cab59c0ntdll.dll + 0x3b59cC:\Windows\System32\ntdll.dll
0x77c963be0ntdll.dll + 0x263beC:\Windows\System32\ntdll.dll
0x75a67ff4271advapi32.dll + 0x47ff4C:\Windows\SysWOW64\advapi32.dll
0x7691cafe277msctf.dll + 0xcafeC:\Windows\SysWOW64\msctf.dll
0x76923558277msctf.dll + 0x13558C:\Windows\SysWOW64\msctf.dll
0x7691cce5277msctf.dll + 0xcce5C:\Windows\SysWOW64\msctf.dll
0x76921376277msctf.dll + 0x11376C:\Windows\SysWOW64\msctf.dll
0x769212e0277msctf.dll + 0x112e0C:\Windows\SysWOW64\msctf.dll
0x76921662277msctf.dll + 0x11662C:\Windows\SysWOW64\msctf.dll
0x7692171b277msctf.dll + 0x1171bC:\Windows\SysWOW64\msctf.dll
0x7691990a277msctf.dll + 0x990aC:\Windows\SysWOW64\msctf.dll
0x76921f43277msctf.dll + 0x11f43C:\Windows\SysWOW64\msctf.dll
0x76921ef9277msctf.dll + 0x11ef9C:\Windows\SysWOW64\msctf.dll
0x76920322277msctf.dll + 0x10322C:\Windows\SysWOW64\msctf.dll
0x76920011277msctf.dll + 0x10011C:\Windows\SysWOW64\msctf.dll
0x7691ff9d277msctf.dll + 0xff9dC:\Windows\SysWOW64\msctf.dll
0x76920729277msctf.dll + 0x10729C:\Windows\SysWOW64\msctf.dll
0x7691da10277msctf.dll + 0xda10C:\Windows\SysWOW64\msctf.dll
0x7691d986277msctf.dll + 0xd986C:\Windows\SysWOW64\msctf.dll
0x759d2eb9270imm32.dll + 0x12eb9C:\Windows\SysWOW64\imm32.dll
0x759d2e10270imm32.dll + 0x12e10C:\Windows\SysWOW64\imm32.dll
0x759d1da7270imm32.dll + 0x11da7C:\Windows\SysWOW64\imm32.dll
0x759d21c0270imm32.dll + 0x121c0C:\Windows\SysWOW64\imm32.dll
0x7676fb70275user32.dll + 0x1fb70C:\Windows\SysWOW64\user32.dll
0x7676c8eb275user32.dll + 0x1c8ebC:\Windows\SysWOW64\user32.dll
0x7676d071275user32.dll + 0x1d071C:\Windows\SysWOW64\user32.dll
0x76769d85275user32.dll + 0x19d85C:\Windows\SysWOW64\user32.dll
0x77e4e496291ntdll.dll + 0x1e496C:\Windows\SysWOW64\ntdll.dll
0x40ca35218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0xca35C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x401816218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0x1816C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x40ca01218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0xca01C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x76768817275user32.dll + 0x18817C:\Windows\SysWOW64\user32.dll
0x7677542a275user32.dll + 0x2542aC:\Windows\SysWOW64\user32.dll
0x767754f9275user32.dll + 0x254f9C:\Windows\SysWOW64\user32.dll
0x7678f6ed275user32.dll + 0x3f6edC:\Windows\SysWOW64\user32.dll
0x767775a2275user32.dll + 0x275a2C:\Windows\SysWOW64\user32.dll
0x76778445275user32.dll + 0x28445C:\Windows\SysWOW64\user32.dll
0x7678247a275user32.dll + 0x3247aC:\Windows\SysWOW64\user32.dll
0x767a63b2275user32.dll + 0x563b2C:\Windows\SysWOW64\user32.dll
0x40b5f9218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0xb5f9C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x40b67b218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0xb67bC:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x40c016218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0xc016C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x410f08218javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe + 0x10f08C:\jdk\regdeploy\javafx-2_1_0-beta-b15-windows-i586-28_feb_2012.exe
0x76a6eccb278kernel32.dll + 0x8eccbC:\Windows\SysWOW64\kernel32.dll
0x77ead80d291ntdll.dll + 0x7d80dC:\Windows\SysWOW64\ntdll.dll
0x77eada1f291ntdll.dll + 0x7da1fC:\Windows\SysWOW64\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.