viewer9 documentation

RegFlushKey PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegFlushKey opcode=2,11

ev=359228

Time:2022-05-17 20:43:31.9634781
Duration:0.0282100
ResultCode:SUCCESS
Tid:2476
Path:HKCR\CID.Local\11e85101-66d9-489a-a897-4511e0d79b2d

evdata[0-52] file offset 135805334

033 80 48 4b 43 52 5c 43 3.HKCR\C
849 44 2e 4c 6f 63 61 6c ID.Local
165c 31 31 65 38 35 31 30 \11e8510
2431 2d 36 36 64 39 2d 34 1-66d9-4
3238 39 61 2d 61 38 39 37 89a-a897
402d 34 35 31 31 65 30 64 -4511e0d
4837 39 62 32 64 79b2d

Call Stack stacksize=15

StackAddressmodModNameModPath
0xfffff80002be347049ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002b8da7449ntoskrnl.exe + 0x38aa74C:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x7708a40a4ntdll.dll + 0x6a40aC:\Windows\System32\ntdll.dll
0x76e3f3352kernel32.dll + 0x3f335C:\Windows\System32\kernel32.dll
0x76e97acb2kernel32.dll + 0x97acbC:\Windows\System32\kernel32.dll
0x7fef650ca67685msdtcprx.dll + 0x5ca67C:\Windows\System32\msdtcprx.dll
0x7fef650bf2c685msdtcprx.dll + 0x5bf2cC:\Windows\System32\msdtcprx.dll
0x7fef65100a9685msdtcprx.dll + 0x600a9C:\Windows\System32\msdtcprx.dll
0x7fef650fcd2685msdtcprx.dll + 0x5fcd2C:\Windows\System32\msdtcprx.dll
0x7fef650fde8685msdtcprx.dll + 0x5fde8C:\Windows\System32\msdtcprx.dll
0x7fef6327df0693msdtctm.dll + 0x67df0C:\Windows\System32\msdtctm.dll
0x7fefeeea82d43sechost.dll + 0xa82dC:\Windows\System32\sechost.dll
0x76e1556d2kernel32.dll + 0x1556dC:\Windows\System32\kernel32.dll
0x7707372d4ntdll.dll + 0x5372dC:\Windows\System32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.