viewer9 documentation

RegSaveKey PML Operation

HivePath ("File Name" in Procmon) is the path of the saved file.

RegSaveFlags ("Format" in Procmon) is enumerated "REG_STANDARD_FORMAT", "REG_LATEST_FORMAT", or "REG_NO_COMPRESSION".

Example from 64-bit PML

Hover over field values like Time, ResultCode, CreatedTime, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegSaveKey opcode=2,20

ev=0

Time:2022-10-10 18:50:47.5340036
Duration:0.0019221
ResultCode:SUCCESS
Tid:2872
Path:HKLM\HARDWARE
RegSaveFlags:REG_NO_COMPRESSION
HivePath:C:\Users\johnk\AppData\Local\Temp\REG93B5.tmp

evdata[0-65] file offset 1100

00d 80 2d 80 04 00 00 00 ..-.....
848 4b 4c 4d 5c 48 41 52 HKLM\HAR
1644 57 41 52 45 43 3a 5c DWAREC:\
2455 73 65 72 73 5c 6a 6f Users\jo
3268 6e 6b 5c 41 70 70 44 hnk\AppD
4061 74 61 5c 4c 6f 63 61 ata\Loca
486c 5c 54 65 6d 70 5c 52 l\Temp\R
5645 47 39 33 42 35 2e 74 EG93B5.t
646d 70 mp

Call Stack stacksize=14

StackAddressmodModNameModPath
0xfffff80002bf847049ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002d031fe49ntoskrnl.exe + 0x4eb1feC:\Windows\system32\ntoskrnl.exe
0xfffff800028b9f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0xfffff800028af6c049ntoskrnl.exe + 0x976c0C:\Windows\system32\ntoskrnl.exe
0xfffff80002d0311d49ntoskrnl.exe + 0x4eb11dC:\Windows\system32\ntoskrnl.exe
0xfffff800028b9f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77bbac7a4ntdll.dll + 0x6ac7aC:\Windows\System32\ntdll.dll
0x77a839b93kernel32.dll + 0x539b9C:\Windows\System32\kernel32.dll
0x77ac7c083kernel32.dll + 0x97c08C:\Windows\System32\kernel32.dll
0xff494546203reg.exe + 0x4546C:\Windows\System32\reg.exe
0xff4921b0203reg.exe + 0x21b0C:\Windows\System32\reg.exe
0xff49ff1d203reg.exe + 0xff1dC:\Windows\System32\reg.exe
0x77a4556d3kernel32.dll + 0x1556dC:\Windows\System32\kernel32.dll
0x77ba372d4ntdll.dll + 0x5372dC:\Windows\System32\ntdll.dll

See also

Posted 22 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.