viewer9 documentation | Index Home |
RegEnumValue PML Operation
Index (0-based) is a 32-bit integer.
All fields other than Index are the same as in RegQueryValue: BufferSize, QueryValType, Name, RegType, Length and RegData.
Note that Procmon sometimes shows junk on the end of the data it displays (see Procmon Bug: Garbage in Registry Data).
Example from 64-bit PML
Hover over field values like Time, ResultCode, RegType, and bytes of evdata and evresults in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
RegEnumValue opcode=2,6
ev=410069 regread=24 B
Time: | 2022-05-17 16:07:12.6021408 |
Duration: | 0.0000025 |
ResultCode: | SUCCESS |
Tid: | 1092 |
Path: | HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d43f41b2_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F} |
BufferSize: | 220 |
Index: | 0 |
QueryValType: | 1 |
Name: | 3 |
RegType: | REG_BINARY |
Length: | 24 |
RegData: | 04 00 00 00 00 00 00 00 00 00 80 3f 00 00 00 00 |
evdata[0-151] file offset 218486127
0 | 88 80 07 00 dc 00 00 00 | ........ |
8 | 00 00 00 00 01 00 00 00 | ........ |
16 | 48 4b 43 55 5c 53 6f 66 | HKCU\Sof |
24 | 74 77 61 72 65 5c 4d 69 | tware\Mi |
32 | 63 72 6f 73 6f 66 74 5c | crosoft\ |
40 | 49 6e 74 65 72 6e 65 74 | Internet |
48 | 20 45 78 70 6c 6f 72 65 | Explore |
56 | 72 5c 4c 6f 77 52 65 67 | r\LowReg |
64 | 69 73 74 72 79 5c 41 75 | istry\Au |
72 | 64 69 6f 5c 50 6f 6c 69 | dio\Poli |
80 | 63 79 43 6f 6e 66 69 67 | cyConfig |
88 | 5c 50 72 6f 70 65 72 74 | \Propert |
96 | 79 53 74 6f 72 65 5c 64 | yStore\d |
104 | 34 33 66 34 31 62 32 5f | 43f41b2_ |
112 | 30 5c 7b 32 31 39 45 44 | 0\.219ED |
120 | 35 41 30 2d 39 43 42 46 | 5A0-9CBF |
128 | 2d 34 46 33 41 2d 42 39 | -4F3A-B9 |
136 | 32 37 2d 33 37 43 39 45 | 27-37C9E |
144 | 35 43 35 46 31 34 46 7d | 5C5F14F. |
evresults[0-39] file offset 218486281
0 | 00 00 00 00 03 00 00 00 | ........ |
8 | 18 00 00 00 18 00 00 00 | ........ |
16 | 02 00 00 00 33 00 2d 00 | ....3.-. |
24 | 04 00 00 00 00 00 00 00 | ........ |
32 | 00 00 80 3f 00 00 00 00 | ...?.... |
Call Stack stacksize=30
StackAddress | mod | ModName | ModPath |
---|---|---|---|
0xfffff80002c2e470 | 161 | ntoskrnl.exe + 0x3e0470 | C:\Windows\system32\ntoskrnl.exe |
0xfffff80002be10e4 | 161 | ntoskrnl.exe + 0x3930e4 | C:\Windows\system32\ntoskrnl.exe |
0xfffff800028eff53 | 161 | ntoskrnl.exe + 0xa1f53 | C:\Windows\system32\ntoskrnl.exe |
0x77c898da | 2 | ntdll.dll + 0x698da | C:\Windows\SYSTEM32\ntdll.dll |
0x77a0d17c | 0 | kernel32.dll + 0xd17c | C:\Windows\system32\kernel32.dll |
0x77a0cfd3 | 0 | kernel32.dll + 0xcfd3 | C:\Windows\system32\kernel32.dll |
0x7fefc0548f6 | 391 | audiosrv.dll + 0x248f6 | c:\windows\system32\audiosrv.dll |
0x7fefc03c72a | 391 | audiosrv.dll + 0xc72a | c:\windows\system32\audiosrv.dll |
0x7fefc03c51a | 391 | audiosrv.dll + 0xc51a | c:\windows\system32\audiosrv.dll |
0x7fefc03cf97 | 391 | audiosrv.dll + 0xcf97 | c:\windows\system32\audiosrv.dll |
0x7fefc035ee3 | 391 | audiosrv.dll + 0x5ee3 | c:\windows\system32\audiosrv.dll |
0x7fefc0358bc | 391 | audiosrv.dll + 0x58bc | c:\windows\system32\audiosrv.dll |
0x7fefc038da7 | 391 | audiosrv.dll + 0x8da7 | c:\windows\system32\audiosrv.dll |
0x7fefc0380e4 | 391 | audiosrv.dll + 0x80e4 | c:\windows\system32\audiosrv.dll |
0x7fefc0376fb | 391 | audiosrv.dll + 0x76fb | c:\windows\system32\audiosrv.dll |
0x7feff9ce845 | 60 | RPCRT4.dll + 0x2e845 | C:\Windows\system32\RPCRT4.dll |
0x7feffa7b4ee | 60 | RPCRT4.dll + 0xdb4ee | C:\Windows\system32\RPCRT4.dll |
0x7feff9b88a0 | 60 | RPCRT4.dll + 0x188a0 | C:\Windows\system32\RPCRT4.dll |
0x7feff9c25b4 | 60 | RPCRT4.dll + 0x225b4 | C:\Windows\system32\RPCRT4.dll |
0x7feff9c2416 | 60 | RPCRT4.dll + 0x22416 | C:\Windows\system32\RPCRT4.dll |
0x7feff9c2b6e | 60 | RPCRT4.dll + 0x22b6e | C:\Windows\system32\RPCRT4.dll |
0x7feff9c280d | 60 | RPCRT4.dll + 0x2280d | C:\Windows\system32\RPCRT4.dll |
0x7feffa01db6 | 60 | RPCRT4.dll + 0x61db6 | C:\Windows\system32\RPCRT4.dll |
0x7feffa01a40 | 60 | RPCRT4.dll + 0x61a40 | C:\Windows\system32\RPCRT4.dll |
0x7feff9c25eb | 60 | RPCRT4.dll + 0x225eb | C:\Windows\system32\RPCRT4.dll |
0x7feff9ded65 | 60 | RPCRT4.dll + 0x3ed65 | C:\Windows\system32\RPCRT4.dll |
0x77c7621d | 2 | ntdll.dll + 0x5621d | C:\Windows\SYSTEM32\ntdll.dll |
0x77d19a14 | 2 | ntdll.dll + 0xf9a14 | C:\Windows\SYSTEM32\ntdll.dll |
0x77a1556d | 0 | kernel32.dll + 0x1556d | C:\Windows\system32\kernel32.dll |
0x77c7372d | 2 | ntdll.dll + 0x5372d | C:\Windows\SYSTEM32\ntdll.dll |
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.