viewer9 documentation | Index Home |
RegSetValue PML Operation
RegType ("Type" in Procmon) is the enumerated Windows Registry data type such as "REG_SZ".
Length is the byte length of the data value being set.
RegData ("Data" in Procmon and note that Procmon sometimes shows junk at the end of Data, see Procmon Bug: Garbage in Registry Data) is the data converted according to RegType into readable form. Normally a PML only includes up to 16 bytes for RegType REG_BINARY/REG_NONE and up to 2KB for other types. A Length greater than the RegData displayed (SZ types are 2 bytes per character) indicates RegData is not completely captured.
Example from 64-bit PML
Hover over field values like Time, ResultCode, RegType, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
RegSetValue opcode=2,4
ev=35170 modify=1 regwrite=4 B
Time: | 2022-05-17 16:06:22.5920094 |
Duration: | 0.0000027 |
ResultCode: | SUCCESS |
Tid: | 3448 |
Path: | HKCU\Software\Google\Chrome\UsageStatsInSample |
RegType: | REG_DWORD |
Length: | 4 |
RegData: | 1 |
evdata[0-65] file offset 20271795
0 | 2e 80 0b 3f 04 00 00 00 | ...?.... |
8 | 04 00 00 00 04 00 00 00 | ........ |
16 | 48 4b 43 55 5c 53 6f 66 | HKCU\Sof |
24 | 74 77 61 72 65 5c 47 6f | tware\Go |
32 | 6f 67 6c 65 5c 43 68 72 | ogle\Chr |
40 | 6f 6d 65 5c 55 73 61 67 | ome\Usag |
48 | 65 53 74 61 74 73 49 6e | eStatsIn |
56 | 53 61 6d 70 6c 65 01 00 | Sample.. |
64 | 00 00 | .. |
Call Stack stacksize=36
StackAddress | mod | ModName | ModPath |
---|---|---|---|
0xfffff80002c2e470 | 161 | ntoskrnl.exe + 0x3e0470 | C:\Windows\system32\ntoskrnl.exe |
0xfffff80002be0e89 | 161 | ntoskrnl.exe + 0x392e89 | C:\Windows\system32\ntoskrnl.exe |
0xfffff800028eff53 | 161 | ntoskrnl.exe + 0xa1f53 | C:\Windows\system32\ntoskrnl.exe |
0x77c89daa | 2 | ntdll.dll + 0x69daa | C:\Windows\SYSTEM32\ntdll.dll |
0x7fee7f69036 | 683 | chrome.dll + 0x2849036 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeb99c6d1 | 683 | chrome.dll + 0x627c6d1 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feec0b7d22 | 683 | chrome.dll + 0x6997d22 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee6b23019 | 683 | chrome.dll + 0x1403019 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee6b0944b | 683 | chrome.dll + 0x13e944b | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee6b04d63 | 683 | chrome.dll + 0x13e4d63 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee8202224 | 683 | chrome.dll + 0x2ae2224 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeacca802 | 683 | chrome.dll + 0x55aa802 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeaccd032 | 683 | chrome.dll + 0x55ad032 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeaccca0d | 683 | chrome.dll + 0x55aca0d | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeacc9c58 | 683 | chrome.dll + 0x55a9c58 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feea640709 | 683 | chrome.dll + 0x4f20709 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7feeacc9eca | 683 | chrome.dll + 0x55a9eca | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee90903e6 | 683 | chrome.dll + 0x39703e6 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee8d2788a | 683 | chrome.dll + 0x360788a | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee97e1e71 | 683 | chrome.dll + 0x40c1e71 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee8bd8f60 | 683 | chrome.dll + 0x34b8f60 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee8bd7d35 | 683 | chrome.dll + 0x34b7d35 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee932e35d | 683 | chrome.dll + 0x3c0e35d | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee5a41049 | 683 | chrome.dll + 0x321049 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee60f5b0a | 683 | chrome.dll + 0x9d5b0a | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee63785b1 | 683 | chrome.dll + 0xc585b1 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee66fff62 | 683 | chrome.dll + 0xfdff62 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee66ffc4f | 683 | chrome.dll + 0xfdfc4f | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee7ca5f92 | 683 | chrome.dll + 0x2585f92 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee6148a21 | 683 | chrome.dll + 0xa28a21 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x7fee6146bcd | 683 | chrome.dll + 0xa26bcd | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x13ffccae6 | 681 | chrome.exe + 0x9cae6 | C:\Program Files\Google\Chrome\Application\chrome.exe |
0x13ffcc648 | 681 | chrome.exe + 0x9c648 | C:\Program Files\Google\Chrome\Application\chrome.exe |
0x14004b062 | 681 | chrome.exe + 0x11b062 | C:\Program Files\Google\Chrome\Application\chrome.exe |
0x77a1556d | 0 | kernel32.dll + 0x1556d | C:\Windows\system32\kernel32.dll |
0x77c7372d | 2 | ntdll.dll + 0x5372d | C:\Windows\SYSTEM32\ntdll.dll |
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.