本帖最后由 Tariel 于 2021-9-13 20:13 编辑
这是焦点放在微信里,让电脑闲置一整天,今天晚上发现自定义词全都没有了之后,重新切换输入法的监控记录:
19:38:02:095, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl.bak, access:0x00100100 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200020 , 0x00000000 [操作成功完成。 ], 19:38:02:096, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl.bak, access:0x00010080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200040 , 0x00000000 [操作成功完成。 ],
19:38:02:096, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl.bak, access:0x00010080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200040 , 0x00000000 [操作成功完成。 ],
19:38:02:096, WeChat.exe, 8088:8092, 8088, FILE_remove, ...\HuayuPY\wordlib\user.uwl.bak, , 0x00000000 [操作成功完成。 ],
19:38:02:097, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00200064 , 0x00000000 [操作成功完成。 ],
19:38:02:098, WeChat.exe, 8088:8092, 8088, FILE_touch, ...\HuayuPY\wordlib\user.uwl.bak, access:0x0017019F alloc_size:513024 attrib:0x00000020 share_access:0x00000000 disposition:0x00000005 options:0x00000064 , 0x00000000 [操作成功完成。 ],
19:38:02:098, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl.bak, access:0x0017019F alloc_size:0 attrib:0x00000000 share_access:0x00000000 disposition:0x00000005 options:0x00000064 , 0x00000000 [操作成功完成。 ],
19:38:02:099, WeChat.exe, 8088:8092, 8088, FILE_read, ...\HuayuPY\wordlib\user.uwl, offset:0x00000000 datalen:0x00020000 , 0x00000000 [操作成功完成。 ],
19:38:02:099, WeChat.exe, 8088:8092, 8088, FILE_write, ...\HuayuPY\wordlib\user.uwl.bak, offset:0x00000000 datalen:0x00020000 , 0x00000000 [操作成功完成。 ],
19:38:02:101, WeChat.exe, 8088:0, 8088, FILE_modified, ...\HuayuPY\wordlib\user.uwl.bak, , 0x00000000 [操作成功完成。 ],
19:38:02:101, WeChat.exe, 8088:8092, 8088, FILE_truncate, ...\HuayuPY\wordlib\user.uwl, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
19:38:02:101, WeChat.exe, 8088:0, 8088, FILE_open, ...\HuayuPY\wordlib\user.uwl, access:0x00120196 alloc_size:0 attrib:0x00000000 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ],
19:38:02:102, WeChat.exe, 8088:8092, 8088, FILE_write, ...\HuayuPY\wordlib\user.uwl, offset:0x00000000 datalen:0x00001000 , 0x00000000 [操作成功完成。 ],
19:38:02:103, WeChat.exe, 8088:0, 8088, FILE_modified, ...\HuayuPY\wordlib\user.uwl, , 0x00000000 [操作成功完成。 ],
19:38:11:369, WeChat.exe, 8088:6800, 8088, FILE_truncate, ...\HuayuPY\wordlib\user.uwl, eof:0x00001000 , 0x00000000 [操作成功完成。 ],
|