Kako pronaći datum zadnje izmjene za usluge u sustavu Windows?

Sadržaj:

Kako pronaći datum zadnje izmjene za usluge u sustavu Windows?
Kako pronaći datum zadnje izmjene za usluge u sustavu Windows?

Video: Kako pronaći datum zadnje izmjene za usluge u sustavu Windows?

Video: Kako pronaći datum zadnje izmjene za usluge u sustavu Windows?
Video: How to use Apple Diagnostic on your Mac to find Hardware Issues - YouTube 2024, Travanj
Anonim
Ako imate ugroženi sustav Windows i želite analizirati kada su usluge instalirane ili izmijenjene, kako to učiniti? Danas SuperUser Q & A post ima odgovore na pitanje čudnog čitatelja.
Ako imate ugroženi sustav Windows i želite analizirati kada su usluge instalirane ili izmijenjene, kako to učiniti? Danas SuperUser Q & A post ima odgovore na pitanje čudnog čitatelja.

Današnja pitanja i odgovori nam se javljaju zahvaljujući SuperUseru - podjele Stack Exchange-a, zajednice-driven grupiranja Q & A web stranica.

Snimak zaslona Notepada ljubaznošću Flyk (SuperUser).

Pitanje

Čitač SuperUser Lucas Kauffman želi znati kako pronaći Datum stvaranja (ili Zadnji izmijenjeni datum) za usluge u sustavu Windows:

If you have a compromised operating system that you are trying to analyze for newly installed services or when services were installed, how do you do that? Where can I find the Creation Date for a particular service in the Windows registry?

Kako ste pronašli Datum stvaranja ili Zadnji izmijenjeni datum za usluge u sustavu Windows?

Odgovor

SuperKorisni suradnici Flyk i Andrew Medico imaju odgovor za nas. Prvo, Flyk:

There is no way to determine the Creation Date for a particular Windows service as both the services applet and Windows registry do not store any dates related to creation.

There is, however, a Last Modified Date that is hidden away from view (even in the Windows registry editor), but it can be accessed using RegQueryInfoKey. Since all Windows services are stored in the registry, you can check the Last Modified Date against the registry keys related to the service in question by looking in HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices.

Alternatively, if you export the registry keys you want information about as text file, you will see the Last Modified Date for each key is written in the text file.

Image
Image

Finally, a solution using PowerShell to return the Last Modified Date has already been discussed on Stack Overflow.

Slijedi odgovor Andrew Medico:

Starting with Vista, service creation is logged to the System Event Log under Service Control Manager Event ID 7045.

For example, the following command:

Produced the following event log entry:
Produced the following event log entry:
Image
Image

Imate li nešto za objašnjenje? Zvuči u komentarima. Želite li pročitati više odgovora od drugih tehnoloških korisnika Stack Exchangea? Pogledajte ovdje cijelu raspravu.

Preporučeni: