viewer9 documentation

RegSetInfoKey PML Operation

The value of KeySetInfoClass (short for KeySetInformationClass) determines additional evdata fields. For KeySetHandleTagsInformation there is a 16-bit integer Length, and for KeyWow64FlagsInformation there is a 32-bit hex integer Wow64Flags.

Example from 64-bit PML

Hover over field values like Time, ResultCode, KeySetInfoClass, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegSetInfoKey opcode=2,8

ev=72339

Time:2022-05-17 20:43:25.1085943
Duration:0.0000028
ResultCode:SUCCESS
Tid:464
Path:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners
KeySetInfoClass:KeySetHandleTagsInformation
Length:0

evdata[0-80] file offset 23003579

041 80 01 00 05 00 00 00 A.......
804 00 00 00 00 00 8a 02 ........
1648 4b 4c 4d 5c 53 4f 46 HKLM\SOF
2454 57 41 52 45 5c 4d 69 TWARE\Mi
3263 72 6f 73 6f 66 74 5c crosoft\
4057 69 6e 64 6f 77 73 5c Windows\
4843 75 72 72 65 6e 74 56 CurrentV
5665 72 73 69 6f 6e 5c 53 ersion\S
6469 64 65 42 79 53 69 64 ideBySid
7265 5c 57 69 6e 6e 65 72 e\Winner
8073 s

Call Stack stacksize=25

StackAddressmodModNameModPath
0xfffff80002be347049ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002b95bcd49ntoskrnl.exe + 0x392bcdC:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x7708ad9a4ntdll.dll + 0x6ad9aC:\Windows\System32\ntdll.dll
0x76e0c9332kernel32.dll + 0xc933C:\Windows\System32\kernel32.dll
0x76e134f52kernel32.dll + 0x134f5C:\Windows\System32\kernel32.dll
0x76e135bd2kernel32.dll + 0x135bdC:\Windows\System32\kernel32.dll
0x7fefca44622267sxs.dll + 0x24622C:\Windows\System32\sxs.dll
0x7fefca44417267sxs.dll + 0x24417C:\Windows\System32\sxs.dll
0x7fefca41382267sxs.dll + 0x21382C:\Windows\System32\sxs.dll
0x7fefca410dc267sxs.dll + 0x210dcC:\Windows\System32\sxs.dll
0x7fefca4090f267sxs.dll + 0x2090fC:\Windows\System32\sxs.dll
0x7fefca405a2267sxs.dll + 0x205a2C:\Windows\System32\sxs.dll
0x7fefca3fec6267sxs.dll + 0x1fec6C:\Windows\System32\sxs.dll
0x7fefca3fa4c267sxs.dll + 0x1fa4cC:\Windows\System32\sxs.dll
0x7fefca3f665267sxs.dll + 0x1f665C:\Windows\System32\sxs.dll
0x7fefca2c70c267sxs.dll + 0xc70cC:\Windows\System32\sxs.dll
0x7fefca2c5f7267sxs.dll + 0xc5f7C:\Windows\System32\sxs.dll
0x7fefca2e4c9267sxs.dll + 0xe4c9C:\Windows\System32\sxs.dll
0x7fefcae2a5d268sxssrv.dll + 0x2a5dC:\Windows\System32\sxssrv.dll
0x7fefcae40c0268sxssrv.dll + 0x40c0C:\Windows\System32\sxssrv.dll
0x7fefcae1a60268sxssrv.dll + 0x1a60C:\Windows\System32\sxssrv.dll
0x7fefcb34e51270basesrv.dll + 0x4e51C:\Windows\System32\basesrv.dll
0x7fefcb554a6271csrsrv.dll + 0x54a6C:\Windows\System32\csrsrv.dll
0x770737354ntdll.dll + 0x53735C:\Windows\System32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.