Windows event logs & finding evil 1st mini module

After getting the answer as “TiWorker.exe” from ques 1, the ques 2 goes as this:
“Build an XML query to determine if the previously mentioned executable modified the auditing settings of C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll. Enter the time of the identified event in the format HH:MM:SS as your answer.” Can someone give me the answer and if you can please explain it as well. Your help would mean a lot. I am stuck atm. Thanks