日志名称: Application
来源: Microsoft-Windows-LoadPerf
日期: 2015/3/22 12:25:23
事件 ID: 1001
任务类别: 无
级别: 信息
关键字:
用户: SYSTEM
计算机: P7ZMZ2Q66QC037H
描述:
已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
事件 Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-LoadPerf" Guid="{122EE297-BB47-41AE-B265-1CA8D1886D40}" />
<EventID>1001</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2015-03-22T04:25:23.280482300Z" />
<EventRecordID>1662</EventRecordID>
<Correlation />
<Execution ProcessID="5232" ThreadID="5236" />
<Channel>Application</Channel>
<Computer>P7ZMZ2Q66QC037H</Computer>
<Security UserID="S-1-5-18" />
</System>
<UserData>
<EventXML xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events" xmlns="LoadPerf">
<param1>WmiApRpl</param1>
<param2>WmiApRpl</param2>
<binaryDataSize>12</binaryDataSize>
<binaryData>4A1900004B19000034070000</binaryData>
</EventXML>
</UserData>
</Event>
评论0