viewer9 documentation

RegSetValue PML Operation

RegType ("Type" in Procmon) is the enumerated Windows Registry data type such as "REG_SZ".

Length is the byte length of the data value being set.

RegData ("Data" in Procmon and note that Procmon sometimes shows junk at the end of Data, see Procmon Bug: Garbage in Registry Data) is the data converted according to RegType into readable form. Normally a PML only includes up to 16 bytes for RegType REG_BINARY/REG_NONE and up to 2KB for other types. A Length greater than the RegData displayed (SZ types are 2 bytes per character) indicates RegData is not completely captured.

Example from 64-bit PML

Hover over field values like Time, ResultCode, RegType, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegSetValue opcode=2,4

ev=35170 modify=1 regwrite=4 B

Time:2022-05-17 16:06:22.5920094
Duration:0.0000027
ResultCode:SUCCESS
Tid:3448
Path:HKCU\Software\Google\Chrome\UsageStatsInSample
RegType:REG_DWORD
Length:4
RegData:1

evdata[0-65] file offset 20271795

02e 80 0b 3f 04 00 00 00 ...?....
804 00 00 00 04 00 00 00 ........
1648 4b 43 55 5c 53 6f 66 HKCU\Sof
2474 77 61 72 65 5c 47 6f tware\Go
326f 67 6c 65 5c 43 68 72 ogle\Chr
406f 6d 65 5c 55 73 61 67 ome\Usag
4865 53 74 61 74 73 49 6e eStatsIn
5653 61 6d 70 6c 65 01 00 Sample..
6400 00 ..

Call Stack stacksize=36

StackAddressmodModNameModPath
0xfffff80002c2e470161ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002be0e89161ntoskrnl.exe + 0x392e89C:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c89daa2ntdll.dll + 0x69daaC:\Windows\SYSTEM32\ntdll.dll
0x7fee7f69036683chrome.dll + 0x2849036C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeb99c6d1683chrome.dll + 0x627c6d1C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feec0b7d22683chrome.dll + 0x6997d22C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee6b23019683chrome.dll + 0x1403019C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee6b0944b683chrome.dll + 0x13e944bC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee6b04d63683chrome.dll + 0x13e4d63C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8202224683chrome.dll + 0x2ae2224C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeacca802683chrome.dll + 0x55aa802C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeaccd032683chrome.dll + 0x55ad032C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeaccca0d683chrome.dll + 0x55aca0dC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeacc9c58683chrome.dll + 0x55a9c58C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feea640709683chrome.dll + 0x4f20709C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7feeacc9eca683chrome.dll + 0x55a9ecaC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee90903e6683chrome.dll + 0x39703e6C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8d2788a683chrome.dll + 0x360788aC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee97e1e71683chrome.dll + 0x40c1e71C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8bd8f60683chrome.dll + 0x34b8f60C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8bd7d35683chrome.dll + 0x34b7d35C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee932e35d683chrome.dll + 0x3c0e35dC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5a41049683chrome.dll + 0x321049C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee60f5b0a683chrome.dll + 0x9d5b0aC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee63785b1683chrome.dll + 0xc585b1C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee66fff62683chrome.dll + 0xfdff62C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee66ffc4f683chrome.dll + 0xfdfc4fC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee7ca5f92683chrome.dll + 0x2585f92C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee6148a21683chrome.dll + 0xa28a21C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee6146bcd683chrome.dll + 0xa26bcdC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x13ffccae6681chrome.exe + 0x9cae6C:\Program Files\Google\Chrome\Application\chrome.exe
0x13ffcc648681chrome.exe + 0x9c648C:\Program Files\Google\Chrome\Application\chrome.exe
0x14004b062681chrome.exe + 0x11b062C:\Program Files\Google\Chrome\Application\chrome.exe
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.