非常感谢,找到了,可是显示是svchost.exe==!为什么会这样呢~
[mw_shl_code=css,true]16:30:14.4193171 svchost.exe 3056 CreateFile E:\serverlg.txt SUCCESS Desired Access: Generic Read/Write, Disposition: OpenIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created
16:30:14.4197059 svchost.exe 3056 QueryFileInternalInformationFile E:\serverlg.txt SUCCESS IndexNumber: 0x4000000015421
16:30:14.4197619 svchost.exe 3056 QueryStandardInformationFile E:\serverlg.txt SUCCESS AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False
16:30:14.4198179 svchost.exe 3056 QueryStandardInformationFile E:\serverlg.txt SUCCESS AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False
16:30:14.4198637 svchost.exe 3056 QueryStandardInformationFile E:\serverlg.txt SUCCESS AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False
16:30:14.4199128 svchost.exe 3056 WriteFile E:\serverlg.txt SUCCESS Offset: 0, Length: 20, Priority: Normal
16:30:14.4200163 svchost.exe 3056 QueryStandardInformationFile E:\serverlg.txt SUCCESS AllocationSize: 24, EndOfFile: 20, NumberOfLinks: 1, DeletePending: False, Directory: False
16:30:14.4201001 svchost.exe 3056 CloseFile E:\serverlg.txt SUCCESS
[/mw_shl_code] |