1

Is it possible that a malware can edit the Windows Event Log to hide System Event Log entries (specifically 6005 and 6006, which indicate startup and shutdown respectively)?

If it is not possible, can you please explain the technical reason why even sophisticated malware may not be able to modify this record?

schroeder
  • 123,438
  • 55
  • 284
  • 319
CompCat
  • 379
  • 3
  • 6
  • There is no such thing as "military-grade malware", just like there is no "military-grade encryption". It's a buzzword that is designed to sound cool. –  May 21 '19 at 15:19

0 Answers0