0

查看事件日志,发现是由Kernel-General进行修改的,具体日志如下:

  • <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  • <System>
    <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
    <EventID>1</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000010</Keywords>
    <TimeCreated SystemTime="2019-10-29T00:10:08.500000000Z" />
    <EventRecordID>185797</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="92" />
    <Channel>System</Channel>
    <Computer>iZ25ty7of40Z</Computer>
    <Security UserID="S-1-5-18" />
    </System>
  • <EventData>
    <Data Name="NewTime">2019-10-29T00:10:08.500000000Z</Data>
    <Data Name="OldTime">2019-10-29T00:11:43.513671900Z</Data>
    </EventData>
    </Event>
10月29日提问
0 个回答

撰写答案

推广链接