viewer9 documentation

RegEnumValue PML Operation

Index (0-based) is a 32-bit integer.

All fields other than Index are the same as in RegQueryValue: BufferSize, QueryValType, Name, RegType, Length and RegData.

Note that Procmon sometimes shows junk on the end of the data it displays (see Procmon Bug: Garbage in Registry Data).

Example from 64-bit PML

Hover over field values like Time, ResultCode, RegType, and bytes of evdata and evresults in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegEnumValue opcode=2,6

ev=410069 regread=24 B

Time:2022-05-17 16:07:12.6021408
Duration:0.0000025
ResultCode:SUCCESS
Tid:1092
Path:HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d43f41b2_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}
BufferSize:220
Index:0
QueryValType:1
Name:3
RegType:REG_BINARY
Length:24
RegData:04 00 00 00 00 00 00 00 00 00 80 3f 00 00 00 00

evdata[0-151] file offset 218486127

088 80 07 00 dc 00 00 00 ........
800 00 00 00 01 00 00 00 ........
1648 4b 43 55 5c 53 6f 66 HKCU\Sof
2474 77 61 72 65 5c 4d 69 tware\Mi
3263 72 6f 73 6f 66 74 5c crosoft\
4049 6e 74 65 72 6e 65 74 Internet
4820 45 78 70 6c 6f 72 65 Explore
5672 5c 4c 6f 77 52 65 67 r\LowReg
6469 73 74 72 79 5c 41 75 istry\Au
7264 69 6f 5c 50 6f 6c 69 dio\Poli
8063 79 43 6f 6e 66 69 67 cyConfig
885c 50 72 6f 70 65 72 74 \Propert
9679 53 74 6f 72 65 5c 64 yStore\d
10434 33 66 34 31 62 32 5f 43f41b2_
11230 5c 7b 32 31 39 45 44 0\.219ED
12035 41 30 2d 39 43 42 46 5A0-9CBF
1282d 34 46 33 41 2d 42 39 -4F3A-B9
13632 37 2d 33 37 43 39 45 27-37C9E
14435 43 35 46 31 34 46 7d 5C5F14F.

evresults[0-39] file offset 218486281

000 00 00 00 03 00 00 00 ........
818 00 00 00 18 00 00 00 ........
1602 00 00 00 33 00 2d 00 ....3.-.
2404 00 00 00 00 00 00 00 ........
3200 00 80 3f 00 00 00 00 ...?....

Call Stack stacksize=30

StackAddressmodModNameModPath
0xfffff80002c2e470161ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002be10e4161ntoskrnl.exe + 0x3930e4C:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c898da2ntdll.dll + 0x698daC:\Windows\SYSTEM32\ntdll.dll
0x77a0d17c0kernel32.dll + 0xd17cC:\Windows\system32\kernel32.dll
0x77a0cfd30kernel32.dll + 0xcfd3C:\Windows\system32\kernel32.dll
0x7fefc0548f6391audiosrv.dll + 0x248f6c:\windows\system32\audiosrv.dll
0x7fefc03c72a391audiosrv.dll + 0xc72ac:\windows\system32\audiosrv.dll
0x7fefc03c51a391audiosrv.dll + 0xc51ac:\windows\system32\audiosrv.dll
0x7fefc03cf97391audiosrv.dll + 0xcf97c:\windows\system32\audiosrv.dll
0x7fefc035ee3391audiosrv.dll + 0x5ee3c:\windows\system32\audiosrv.dll
0x7fefc0358bc391audiosrv.dll + 0x58bcc:\windows\system32\audiosrv.dll
0x7fefc038da7391audiosrv.dll + 0x8da7c:\windows\system32\audiosrv.dll
0x7fefc0380e4391audiosrv.dll + 0x80e4c:\windows\system32\audiosrv.dll
0x7fefc0376fb391audiosrv.dll + 0x76fbc:\windows\system32\audiosrv.dll
0x7feff9ce84560RPCRT4.dll + 0x2e845C:\Windows\system32\RPCRT4.dll
0x7feffa7b4ee60RPCRT4.dll + 0xdb4eeC:\Windows\system32\RPCRT4.dll
0x7feff9b88a060RPCRT4.dll + 0x188a0C:\Windows\system32\RPCRT4.dll
0x7feff9c25b460RPCRT4.dll + 0x225b4C:\Windows\system32\RPCRT4.dll
0x7feff9c241660RPCRT4.dll + 0x22416C:\Windows\system32\RPCRT4.dll
0x7feff9c2b6e60RPCRT4.dll + 0x22b6eC:\Windows\system32\RPCRT4.dll
0x7feff9c280d60RPCRT4.dll + 0x2280dC:\Windows\system32\RPCRT4.dll
0x7feffa01db660RPCRT4.dll + 0x61db6C:\Windows\system32\RPCRT4.dll
0x7feffa01a4060RPCRT4.dll + 0x61a40C:\Windows\system32\RPCRT4.dll
0x7feff9c25eb60RPCRT4.dll + 0x225ebC:\Windows\system32\RPCRT4.dll
0x7feff9ded6560RPCRT4.dll + 0x3ed65C:\Windows\system32\RPCRT4.dll
0x77c7621d2ntdll.dll + 0x5621dC:\Windows\SYSTEM32\ntdll.dll
0x77d19a142ntdll.dll + 0xf9a14C:\Windows\SYSTEM32\ntdll.dll
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.