【发布时间】:2017-01-30 20:13:42
【问题描述】:
我想知道是否有办法检测进程是否正在删除或加密文件。我正在尝试用 C# 制作一个反勒索软件应用程序,所以我想知道是否有人可以提供帮助。
有什么建议吗?
【问题讨论】:
-
FileSystemWatcher 将让您监视目录中的更改,例如文件被删除。我猜想没有直接的方法(当然也没有万无一失的方法)来检测文件是否被加密。
标签: c# file encryption process
我想知道是否有办法检测进程是否正在删除或加密文件。我正在尝试用 C# 制作一个反勒索软件应用程序,所以我想知道是否有人可以提供帮助。
有什么建议吗?
【问题讨论】:
标签: c# file encryption process
你想看看FileSystemWatcher 类。
来自 MSDN 页面:
using System;
using System.IO;
using System.Security.Permissions;
public class Watcher
{
public static void Main()
{
Run();
}
[PermissionSet(SecurityAction.Demand, Name="FullTrust")]
public static void Run()
{
string[] args = System.Environment.GetCommandLineArgs();
// If a directory is not specified, exit program.
if(args.Length != 2)
{
// Display the proper way to call the program.
Console.WriteLine("Usage: Watcher.exe (directory)");
return;
}
// Create a new FileSystemWatcher and set its properties.
FileSystemWatcher watcher = new FileSystemWatcher();
watcher.Path = args[1];
/* Watch for changes in LastAccess and LastWrite times, and
the renaming of files or directories. */
watcher.NotifyFilter = NotifyFilters.LastAccess | NotifyFilters.LastWrite
| NotifyFilters.FileName | NotifyFilters.DirectoryName;
// Only watch text files.
watcher.Filter = "*.txt";
// Add event handlers.
watcher.Changed += new FileSystemEventHandler(OnChanged);
watcher.Created += new FileSystemEventHandler(OnChanged);
watcher.Deleted += new FileSystemEventHandler(OnChanged);
watcher.Renamed += new RenamedEventHandler(OnRenamed);
// Begin watching.
watcher.EnableRaisingEvents = true;
// Wait for the user to quit the program.
Console.WriteLine("Press \'q\' to quit the sample.");
while(Console.Read()!='q');
}
// Define the event handlers.
private static void OnChanged(object source, FileSystemEventArgs e)
{
// Specify what is done when a file is changed, created, or deleted.
Console.WriteLine("File: " + e.FullPath + " " + e.ChangeType);
}
private static void OnRenamed(object source, RenamedEventArgs e)
{
// Specify what is done when a file is renamed.
Console.WriteLine("File: {0} renamed to {1}", e.OldFullPath, e.FullPath);
}
}
【讨论】: