查看事件日志,发现是由Kernel-General进行修改的,具体日志如下:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
<EventID>1</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000010</Keywords>
<TimeCreated SystemTime="2019-10-29T00:10:08.500000000Z" />
<EventRecordID>185797</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="92" />
<Channel>System</Channel>
<Computer>iZ25ty7of40Z</Computer>
<Security UserID="S-1-5-18" />
</System> - <EventData>
<Data Name="NewTime">2019-10-29T00:10:08.500000000Z</Data>
<Data Name="OldTime">2019-10-29T00:11:43.513671900Z</Data>
</EventData>
</Event>