日志名称: System来源: Service Control Manager
日期: 2020/4/1 星期三 23:41:10
事件 ID: 7045
任务类别: 无
级别: 信息
关键字: 经典
用户: G50-70\Administrator
计算机: G50-70
描述:
服务已安装在系统中。
服务名称: WinRing0_1_1_1
服务文件名: F:\桌面任务栏\TaskbarX_成品\WinRing0x64.sys
服务类型: 内核模式驱动程序
服务启动类型: 按需启动
服务帐户:
事件 Xml:
<
Event
xmlns
=
"http://schemas.microsoft.com/win/2004/08/events/event"
>
<
System
>
<
Provider
Name
=
"Service Control Manager"
Guid
=
"{555908d1-a6d7-4695-8e1e-26931d2012f4}"
EventSourceName
=
"Service Control Manager"
/>
<
EventID
Qualifiers
=
"16384"
>7045</
EventID
>
<
Version
>0</
Version
>
<
Level
>4</
Level
>
<
Task
>0</
Task
>
<
Opcode
>0</
Opcode
>
<
Keywords
>0x8080000000000000</
Keywords
>
<
TimeCreated
SystemTime
=
"2020-04-01T15:41:10.340075200Z"
/>
<
EventRecordID
>4261</
EventRecordID
>
<
Correlation
/>
<
Execution
ProcessID
=
"796"
ThreadID
=
"9080"
/>
<
Channel
>System</
Channel
>
<
Computer
>G50-70</
Computer
>
<
Security
UserID
=
"S-1-5-21-937344446-2590225397-1265241895-500"
/>
</
System
>
<
EventData
>
<
Data
Name
=
"ServiceName"
>WinRing0_1_1_1</
Data
>
<
Data
Name
=
"ImagePath"
>F:\桌面任务栏\TaskbarX_成品\WinRing0x64.sys</
Data
>
<
Data
Name
=
"ServiceType"
>内核模式驱动程序</
Data
>
<
Data
Name
=
"StartType"
>按需启动</
Data
>
<
Data
Name
=
"AccountName"
>
</
Data
>
</
EventData
>
</
Event
>