viewer9 documentation

RegQueryMultipleValueKey PML Operation

The PML file does not capture data for this operation other than the Path but often you'll see ResultCode BUFFER OVERFLOW followed immediately by a repeat event with the same Path and ResultCode SUCCESS, showing the same underlying pattern as RegQueryKey so we know it is simply missing the data for fields such as BufferSize, and only serves to track calls rather than capture the data of calls.

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegQueryMultipleValueKey opcode=2,15

ev=416124

Time:2022-05-17 16:07:13.1981425
Duration:0.0000274
ResultCode:BUFFER OVERFLOW
Tid:6172
Path:HKU\.DEFAULT\Control Panel\International

evdata[0-41] file offset 221920227

028 80 48 4b 55 5c 2e 44 (.HKU\.D
845 46 41 55 4c 54 5c 43 EFAULT\C
166f 6e 74 72 6f 6c 20 50 ontrol P
2461 6e 65 6c 5c 49 6e 74 anel\Int
3265 72 6e 61 74 69 6f 6e ernation
4061 6c al

Call Stack stacksize=11

StackAddressmodModNameModPath
0xfffff80002c2e470161ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002b678e3161ntoskrnl.exe + 0x3198e3C:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c8a9da2ntdll.dll + 0x6a9daC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7eb1ce43KERNELBASE.dll + 0x1b1ceC:\Windows\system32\KERNELBASE.dll
0x7fefd7d799043KERNELBASE.dll + 0x7990C:\Windows\system32\KERNELBASE.dll
0x7fefd7da32243KERNELBASE.dll + 0xa322C:\Windows\system32\KERNELBASE.dll
0xff6717c4367svchost.exe + 0x17c4C:\Windows\system32\svchost.exe
0x7fefdf0a82d50sechost.dll + 0xa82dC:\Windows\SYSTEM32\sechost.dll
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.