Method and device for detecting occupied files in batch in resource manager
By combining the remote thread injection module and other components in the resource manager, batch detection and rapid positioning of files are achieved, and the problem of low file occupation detection efficiency in the prior art is solved, and the convenience and efficiency of file management are improved.
Patent Information
- Application Number
- CN202411978141.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art detects whether files are occupied one by one in the computer resource manager, resulting in extremely low efficiency when processing a large number of files, and users need to wait for a long time to complete the operation, which seriously affects work efficiency.
The target dynamic link library file is remotely injected into the resource manager process through the remote thread injection module, and the function replacement module, file enumeration module, file occupation detection module and file occupation prompt module are used to realize batch detection, fast positioning and one-time occupation prompt of files.
It significantly improves the efficiency of file occupation detection and reduces the difficulty of users in relieving file occupation. Users can re-occupy multiple files at one time, providing a more convenient and efficient file management experience.
Smart Images

Figure CN119988324A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method and device for batch detecting occupied files in a resource manager, a storage medium, and a computer device. Background Art
[0002] In current computer operating systems, resource managers (such as Explorer in Windows systems) are important tools for users to manage files and folders. When a user tries to delete or move a file, the resource manager will perform a series of operations to ensure the operability of the file, and one of the key steps is to detect whether the file is occupied by other programs. However, the prior art has significant defects and deficiencies in this link.
[0003] The prior art adopts a method of detecting whether files are occupied one by one. When a user selects multiple files or folders for deletion or move operations, the resource manager will check the status of each file one by one. Although this method is accurate, the operation process is time-consuming, especially when dealing with a large number of files, the efficiency is extremely low. As the number of files increases, the detection time increases linearly, causing users to wait for a long time to complete the operation, which seriously affects work efficiency. In addition, when the prior art detects occupied files, it will prompt the user one by one. This means that if multiple files are occupied, the user will receive multiple independent prompt messages. This one-by-one prompt method not only increases the number of clicks and operation difficulty of the user, but may also cause the user to confuse or miss important information. Especially when dealing with a large number of files, it is difficult for users to quickly identify which files are occupied and which files can be safely operated. Summary of the invention
[0004] In view of this, the present application provides a method and apparatus, storage medium, and computer equipment for batch detecting occupied files in a resource manager. The target dynamic link library file is remotely injected into the resource manager process through a remote thread injection module, and components such as a function replacement module, a file enumeration module, a file occupancy detection module, and a file occupancy prompt module are used to implement batch detection, rapid positioning, and one-time occupancy prompts of files. This method not only significantly improves the efficiency of file occupancy detection, but also reduces the difficulty of users to release file occupation. Users can release multiple files at one time, providing users with a more convenient and efficient file management experience.
[0005] According to one aspect of the present application, a method for batch detecting occupied files in a resource manager is provided, comprising:
[0006] The remote thread injection module responds to the startup instruction of the resource manager process and remotely injects the target dynamic link library file into the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module;
[0007] After the target dynamic link library file is loaded, the function replacement module replaces the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function;
[0008] When the preset hook function receives the file operation information, the file enumeration module determines the operation file object set based on the file operation information, and obtains the file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information;
[0009] The file occupancy detection module detects the occupancy status of each operation file based on the file path corresponding to the operation file, and obtains the occupancy status detection result corresponding to each operation file;
[0010] The file occupancy prompt module generates occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and displays the occupied file information on a display device.
[0011] According to another aspect of the present application, a device for batch detecting occupied files in a resource manager is provided, comprising:
[0012] A remote thread injection module, for remotely injecting a target dynamic link library file into the resource manager process in response to a startup instruction of the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module;
[0013] The function replacement module is used to replace the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function after the target dynamic link library file is loaded;
[0014] The file enumeration module is used to determine an operation file object set based on the file operation information when the preset hook function receives the file operation information, and obtain a file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information;
[0015] The file occupancy detection module is used to detect the occupancy status of each operation file based on the file path corresponding to the operation file, and obtain the occupancy status detection result corresponding to each operation file;
[0016] The file occupancy prompt module is used to generate occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and display the occupied file information on the display device.
[0017] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method for batch detecting occupied files in a resource manager is implemented.
[0018] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned method of batch detecting occupied files in a resource manager when executing the program.
[0019] By means of the above technical solution, the present application provides a method and device for batch detecting occupied files in a resource manager, a storage medium, and a computer device. First, when the user starts the resource manager, the remote thread injection module can respond to the startup instruction of the resource manager process and remotely inject the target dynamic link library file into the resource manager process. Then, after the target dynamic link library file is loaded, the function replacement module is responsible for modifying the virtual function table of the file operation class in the resource manager process. Specifically, the first virtual function corresponding to the move operation method under the file operation class and the second virtual function corresponding to the delete operation method can be replaced with a preset hook function. Subsequently, after the preset hook function receives the file operation information, the file enumeration module can determine the operation file object set based on this information and obtain the file path corresponding to each operation file. Further, the file occupancy detection module can detect the occupancy status of the operation file according to the file path corresponding to each operation file to obtain the occupancy status detection result. Finally, the file occupancy prompt module generates the occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and displays this information on a display device (such as a screen). The embodiment of the present application remotely injects the target dynamic link library file into the resource manager process through the remote thread injection module, and utilizes components such as the function replacement module, the file enumeration module, the file occupancy detection module, and the file occupancy prompt module to implement batch detection, rapid positioning, and one-time occupancy prompts of files. This method not only significantly improves the efficiency of file occupancy detection, but also reduces the difficulty of users to release file occupation. Users can release multiple files at one time, providing users with a more convenient and efficient file management experience.
[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0022] Figure 1 A flow chart of a method for batch detecting occupied files in a resource manager provided by an embodiment of the present application is shown;
[0023] Figure 2 A schematic diagram of the structure of a device for batch detecting occupied files in a resource manager provided by an embodiment of the present application is shown;
[0024] Figure 3 A schematic diagram of the device structure of a computer device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0025] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.
[0026] In this embodiment, a method for batch detecting occupied files in a resource manager is provided, such as Figure 1 As shown, the method includes:
[0027] Step 101, the remote thread injection module responds to the startup instruction of the resource manager process and remotely injects the target dynamic link library file into the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module.
[0028] A method for batch detecting occupied files in a resource manager provided in an embodiment of the present application can be applied to a computer device. First, when a user starts the resource manager, the remote thread injection module can respond to the startup instruction of the resource manager process and remotely inject the target dynamic link library file into the resource manager process. Here, the resource manager can specifically refer to the resource manager under the Windows system (such as explorer in the Windows system). The remote thread injection module is a module responsible for injecting code into another process, which can be specifically implemented by using the API functions provided by the Windows operating system, such as CreateRemoteThread and LoadLibrary. The target dynamic link library file is a DLL file containing specific functions. This DLL file mainly contains four modules, namely a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module. These modules work together to achieve batch detection and prompts of file occupancy status.
[0029] Step 102: After the target dynamic link library file is loaded, the function replacement module replaces the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function.
[0030] Next, after the target dynamic link library file is loaded, the function replacement module is responsible for modifying the virtual function table of the file operation class in the resource manager process. Specifically, the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class can be replaced with a preset hook function. For example, the virtual function table (vtable) can be modified to replace the pointers pointing to the first virtual function and the second virtual function with pointers pointing to the custom hook function, so that the file move operation and the delete operation can be intercepted so as to perform further processing when the file operation occurs. The file operation class refers to a class used to process file operations in the resource manager, such as a class for moving files and deleting files. For example, the file operation class is the IFileOperation class, the move operation method is MoveItems, and the delete operation method is DeleteItems. The move operation method and the delete operation method are methods in the file operation class, which are used to implement the file move and delete functions respectively. The preset hook function is used to be called when the file operation occurs, so as to intercept these file operations and perform subsequent processing. Later, when the user deletes or moves a file in the resource manager, the resource manager can pass the corresponding file operation information into the preset hook function.
[0031] Step 103, when the preset hook function receives file operation information, the file enumeration module determines an operation file object set based on the file operation information, and obtains a file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information.
[0032] Subsequently, if the user deletes or moves batch files through the resource manager, since the first virtual function and the second virtual function have been replaced by the preset hook function at this time, the preset hook function receives the user's file operation information at this time. Here, the file operation information refers to the information obtained by the preset hook function when intercepting the file operation, which can be file movement information, file deletion information, etc. After the preset hook function receives the file operation information, the file enumeration module can determine the operation file object set based on this information and obtain the file path corresponding to each operation file. The operation file object set refers to the set of files to be operated (moved or deleted) determined by the file enumeration module according to the file operation information. The file path refers to the location of each operation file in the file system. The file enumeration module can obtain these file paths for subsequent file occupancy detection.
[0033] Step 104: the file occupancy detection module detects the occupancy status of each operation file based on the file path corresponding to each operation file, and obtains an occupancy status detection result corresponding to each operation file.
[0034] Furthermore, the file occupancy detection module can detect the occupancy status of the operation file according to the file path corresponding to each operation file. For example, by trying to open each operation file (using exclusive mode), it can be checked whether the operation file is locked or opened by other processes. Here, occupancy status detection refers to the process of trying to open the operation file in exclusive mode. If the operation file is occupied by other processes, the opening operation will fail and return a corresponding error code. The file occupancy detection module can determine the occupancy status of each operation file based on these error codes.
[0035] Step 105: the file occupation prompt module generates occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and displays the occupied file information on a display device.
[0036] Finally, the file occupation prompt module generates occupied file information corresponding to the operation file object set according to the occupancy status detection results corresponding to each operation file, and displays this information on a display device (such as a screen). Here, a user interface (UI) element (such as a pop-up window or a status bar message) can be created to display the occupied file information. In this way, the user can be informed which files are occupied, thereby avoiding operation failures or data loss that may be caused by moving or deleting these files when the files are occupied. The occupied file information refers to the information set generated by the file occupation prompt module according to the occupancy status detection results, which may specifically include the path of the occupied file, the process information occupying the file, etc.
[0037] By applying the technical solution of this embodiment, first, when the user starts the resource manager, the remote thread injection module can respond to the startup instruction of the resource manager process and remotely inject the target dynamic link library file into the resource manager process. Then, after the target dynamic link library file is loaded, the function replacement module is responsible for modifying the virtual function table of the file operation class in the resource manager process. Specifically, the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class can be replaced with a preset hook function. Subsequently, after the preset hook function receives the file operation information, the file enumeration module can determine the operation file object set based on this information and obtain the file path corresponding to each operation file. Further, the file occupancy detection module can detect the occupancy status of the operation file according to the file path corresponding to each operation file, and obtain the occupancy status detection result. Finally, the file occupancy prompt module generates the occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and displays this information on a display device (such as a screen). The embodiment of the present application remotely injects the target dynamic link library file into the resource manager process through the remote thread injection module, and utilizes components such as the function replacement module, the file enumeration module, the file occupancy detection module, and the file occupancy prompt module to implement batch detection, rapid positioning, and one-time occupancy prompts of files. This method not only significantly improves the efficiency of file occupancy detection, but also reduces the difficulty of users to release file occupation. Users can release multiple files at one time, providing users with a more convenient and efficient file management experience.
[0038] In an embodiment of the present application, optionally, the step 102 of "replacing the first virtual function corresponding to the move operation method under the file operation class and the second virtual function corresponding to the delete operation method with a preset hook function" includes: creating a target object through a component object model library, and determining the table address of the virtual function under the file operation class based on the base address corresponding to the target object; obtaining the virtual function table stored under the table address, and traversing the virtual function table to search the virtual function table for the first address corresponding to the first virtual function and the second address corresponding to the second virtual function; replacing the first address and the second address with the function address corresponding to the preset hook function through an interception function.
[0039] In this embodiment, first, a target object can be created through the component object model library, that is, an object belonging to a file operation class (such as IFileOperation) is instantiated. The component object model (COM) is a software architecture provided by Microsoft, which is used to allow different applications or components to interact with each other, and the target object can be a COM object. Then, the table address of the virtual function under the file operation class can be found through the base address of the target object. Here, each COM object has a starting address in the memory, which is called the base address. For a class containing a virtual function, its COM object contains a pointer to a virtual function table, which is usually located at the starting position (or fixed offset) of the COM object. The virtual function table is a structure that stores the addresses of all virtual functions of the file operation class.
[0040] Once the address of the virtual function table is obtained, the virtual function table can be accessed. The virtual function table can be specifically an array, each element of which is a pointer to a virtual function. By traversing the array, the addresses corresponding to the move operation method (first virtual function) and the delete operation method (second virtual function) can be found. Afterwards, the first address and the second address are replaced with the function addresses corresponding to the custom preset hook function through the interception function. Among them, the interception function is a predefined function. In one embodiment, the interception function can be the DetourAttach method in the Hook library - detours provided by Windows. After replacing the original first virtual function and the second virtual function, the call that should have called the original first virtual function and the second virtual function will be changed to call the preset hook function.
[0041] In an embodiment of the present application, optionally, the "obtaining the file path corresponding to each operation file in the operation file object set" in step 103 includes: determining the operation mode corresponding to each operation file in the operation file object set, and grouping the operation files in the operation file object set according to the operation mode to obtain multiple target groups; for each of the target groups, determining the file enumeration mode corresponding to the target group according to the operation mode corresponding to the target group, and determining the file path corresponding to each operation file under the target group through the file enumeration mode.
[0042] In this embodiment, when obtaining the file path corresponding to each operation file, first, the operation mode of each operation file can be determined. Here, when the user moves or deletes files in the resource manager, there can be multiple operation modes, such as direct dragging or cutting. When the user deletes or moves files in the resource manager through different operation modes, the organization form of the files is different. Therefore, different file path acquisition methods need to be used to obtain the file path. Therefore, further, according to the operation mode of each operation file, they can be divided into different groups, and then multiple target groups can be obtained, each target group contains operation files with the same operation mode. The purpose of doing this is to be able to adopt different file enumeration methods according to different operation modes in the future.
[0043] For each target group, a matching file enumeration method is selected according to its corresponding operation method. After the file enumeration method is determined, the file enumeration method can return a list of file paths that meet the conditions, so that the corresponding file path can be determined for the operation file under each target group.
[0044] For example, file enumeration methods may include the following: IDataObject, IShellItemArray, IEnumShellItems, and IPersistIDList.
[0045] IDataObject is mainly used for clipboard operations and data drag and drop. When users drag files to another location or clipboard (using Ctrl+C / Ctrl+X and Ctrl+V) in Explorer, the data transfer involved is usually implemented through the IDataObject interface. Therefore, when developing applications that support drag and drop or clipboard operations, if you need to access the list of files and their paths that are dragged or copied to the clipboard, you can use the IDataObject interface to retrieve this data.
[0046] IShellItemArray represents an array of Shell items, which can be files, folders, shortcuts, etc. IShellItemArray provides a convenient way to handle multiple Shell items, for example, when the user selects multiple files or folders. Therefore, when developing applications that need to handle multiple files or folders, such as file managers, batch processing tools, etc., you can use IShellItemArray to obtain the full file paths of all items selected by the user.
[0047] IEnumShellItems is used to enumerate a collection of Shell items (such as files and folders). These items are usually provided by the file system, Shell namespace, or other Shell data sources. Therefore, when you need to traverse and access a set of files or folders in the file system or Shell namespace, you can use IEnumIDList (or similar enumeration interfaces) to obtain the identification (PIDL) and related information of these items one by one, which can then be converted into a full path.
[0048] IPersistIDList is an interface for persisting objects, especially those associated with Shell items. It allows an object to save its state as one or more PIDLs (Item Identifier Lists), which can represent files, folders, or other Shell items. Therefore, when developing applications that need to save and restore state associated with Shell items, for example, custom Shell extensions or components, you can use IPersistIDList to save and load data associated with files or folders.
[0049] In an embodiment of the present application, optionally, the "based on the file path corresponding to each operation file, detecting the occupancy status of the operation file to obtain the occupancy status detection result corresponding to each operation file" in step 104 includes: creating a restart manager session, and registering the file path corresponding to each operation file in the restart manager session; calling an enumeration function through the restart manager session, obtaining the occupancy status corresponding to each file path registered in the restart manager session based on the enumeration function, and obtaining an enumerator containing the occupancy status corresponding to each file path; traversing the enumerator to obtain the occupancy status detection result corresponding to each operation file.
[0050] In this embodiment, when the occupancy status of each operation file is detected, first, a restart manager session can be created, which can be implemented by calling the RmStartSession function, which accepts a session key (usually a GUID) and session options as parameters and returns a session handle. The restart manager session is a session that interacts with the restart manager. The restart manager is a service provided by Windows to manage the restart of the system during application installation, update or uninstallation. It can help applications identify which files or services are in use, allowing the application to prompt the user to save work and restart the system when necessary.
[0051] After creating the restart manager session, you can register the file path of each operation file to be checked for occupancy with this session. This can be achieved by calling the RmRegisterResources function, which accepts the session handle, an array containing the resources to be registered (here, the file paths), and the number of resources as parameters.
[0052] After registering the file paths, the next step is to call the enumeration function provided by the restart manager to obtain the occupancy status of these files. In the Windows API, this can be achieved through the RmGetList function, which accepts a session handle and a pointer to a RM_SESSION_ENUM structure as parameters. The RM_SESSION_ENUM structure contains an enumerator handle, which is used to subsequently traverse the file occupancy status. The RmGetList function can fill in the other members of the RM_SESSION_ENUM structure, including a pointer to the RM_PROCESS_INFO array, which contains information about the process that occupies each registered file. In addition, an enumerator containing the occupancy status corresponding to each file path can be returned.
[0053] Once an enumerator containing the occupancy status is obtained, it can be traversed to obtain the occupancy status detection results of each operating file. Specifically, functions such as RmFirstFileInSession and RmNextFileInSession can be used to access the file paths and corresponding occupancy status in the enumerator one by one. For each operating file, it can be checked whether it is occupied (that is, whether there is a process using it) and what process is occupying it. This information can be used for subsequent processing, such as prompting the user to close the process occupying the file. The embodiment of the present application implements a safe and reliable method to detect the occupancy status of operating files by utilizing the Windows restart manager API.
[0054] In an embodiment of the present application, optionally, the "generating occupied file information corresponding to the operation file object set according to the occupancy status detection results corresponding to each of the operation files" in step 105 includes: determining the file information of the operation files in the occupied state according to the occupancy status detection results corresponding to each of the operation files, wherein the file information includes at least one of the file name, the occupying process name and the occupying process unique identifier; generating the occupied file information corresponding to the operation file object set according to the file information and file path of each operation file in the occupied state in the operation file object set.
[0055] In this embodiment, after determining the occupancy status detection result corresponding to each operation file, further, the operation files in the occupied state can be screened out from these occupancy status detection results. Then, for each occupied operation file, a series of key information of the operation file is extracted, including but not limited to: file name: This is the basic identification of the file, which is used to display on the user interface or log record; occupied process name: This is the name of the process that is currently using or locking the file. Knowing the name of the occupied process can help users or administrators identify which program is using the file; occupied process unique identification: This is the unique identifier of the occupied process (such as process ID, PID), which allows more accurate identification and control of the process occupying the file. This information can be obtained through functions provided by the restart manager API (such as RmGetList, RmGetProcessInfo, etc.) or system calls (such as querying the process name through the process ID).
[0056] Based on the file path of the occupied operation file determined in the above step and the extracted file information, a set containing all the information related to the occupied files, i.e., the occupied file information, can be generated. The occupied file information can be a data structure (such as a list, a dictionary, or a custom object), in which each element represents an occupied file and contains information such as the file path, file name, occupying process name, and unique identifier of the file.
[0057] The embodiment of the present application parses the occupancy status detection results of the operation files, extracts key file information, and finally generates occupied file information containing information related to all occupied files. By providing detailed occupied file information, the user can determine all the operation files in the occupied state corresponding to the batch operation at one time, and perform subsequent processing, which helps to improve the user experience.
[0058] In an embodiment of the present application, optionally, the occupied file information also includes a process closing interaction button corresponding to each operating file in an occupied state; the method also includes: the file occupation prompt module responds to a trigger instruction of any process closing interaction button, generates a corresponding closing risk prompt according to the file path corresponding to any process closing interaction button, and displays the closing risk prompt on the display device; and, based on the confirmation instruction of the closing risk prompt, closes the process corresponding to any process closing interaction button.
[0059] In this embodiment, in addition to the relevant information of the occupied operation file, the occupied file information may also include a process closing interactive button corresponding to each occupied operation file. The user clicks this button to trigger the operation of closing the process occupying the file. When the user clicks a process closing interactive button, the file occupation prompt module may receive a trigger instruction. This instruction contains information about which button was clicked, so that the corresponding occupied file and occupied process can be identified. After receiving the trigger instruction, the file occupation prompt module generates a closing risk prompt according to the path of the occupied file. This prompt may include information about the process to be closed (such as process name, process ID, tasks being executed by the process, etc.), and the risks that may be caused by closing the process (such as data loss, program crash, etc.). The closing risk prompt can be displayed on the user's display device so that the user can read and understand the consequences of closing the process.
[0060] After reading the closing risk warning, if the user decides to close the process occupying the file, he can generate a confirmation instruction by clicking a confirmation button or performing other confirmation operations. After receiving the confirmation instruction, the file occupation prompt module can call the system API or perform other appropriate operations to close the process occupying the file. The embodiment of the present application provides users with an intuitive way to deal with file occupation problems by adding a process closing interactive button to the occupied file information of the occupied file. The user can trigger the operation of closing the process by clicking a button, and understand the possible consequences through the closing risk warning before closing, which not only improves the convenience of user operation, but also increases the safety of operation.
[0061] In an embodiment of the present application, optionally, after "obtaining the file path corresponding to each operation file in the operation file object set" in step 103, the method also includes: the file occupancy prompt module creates a processing progress update task, groups the operation file object set based on the current task processing status of each thread in multiple threads, assigns a first target thread to each group, and assigns a second target thread to the processing progress update task; the file occupancy prompt module determines the occupancy status of the operation file for each first target thread based on the file path of the assigned operation file, obtains the occupancy status detection result corresponding to each assigned operation file, and, for the second target thread, sends processing progress inquiry information to each first target thread at a preset frequency, updates the occupancy status detection progress of the operation file object set based on the feedback information of each first target thread, and displays the updated occupancy status detection progress on the display device.
[0062] In this embodiment, after obtaining the file path corresponding to each operation file, further, a processing progress update task can be created. Then, the current task processing status corresponding to each thread in the multiple threads can be determined. According to the current task processing status corresponding to each thread, an idle target thread or a target thread with fewer current processing tasks is selected from the multiple threads, and one of the target threads is used as the second target thread, and the remaining ones are used as the first target threads, and the operation file object set is grouped according to the number of first target threads. For example, if there are 3 first target threads, the operation file object set can be divided into 3 groups. After grouping, a first target thread is assigned to each group of operation files. Through the first target thread, the steps of determining the occupancy status of the operation file based on the file path of the assigned operation file and obtaining the occupancy status detection results corresponding to each assigned operation file can be executed, thereby obtaining the occupancy status detection result of each operation file in the group. In the process of extracting information from the operation file through the first target thread, the second target thread can also send processing progress inquiry information to each first target thread at a preset frequency. After receiving the processing progress inquiry information, the first target thread can generate feedback information and return the feedback information to the second target thread. The second target thread can know how many operation files the first target thread has processed through the received feedback information, thereby updating the occupancy status detection progress of the operation file object set according to the feedback information of each first target thread, and displaying it in the display device after the update. The embodiment of the present application not only ensures the smoothness of the occupancy status detection process of the operation file object set through multi-threaded processing of the occupancy status detection of the operation file object set and real-time updating of the processing progress information, but also can display the processing progress, so that the user can understand the detection situation in a timely manner, which is conducive to improving the user experience.
[0063] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a device for batch detecting occupied files in a resource manager, such as Figure 2 As shown, the device comprises:
[0064] A remote thread injection module, for remotely injecting a target dynamic link library file into the resource manager process in response to a startup instruction of the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module;
[0065] The function replacement module is used to replace the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function after the target dynamic link library file is loaded;
[0066] The file enumeration module is used to determine an operation file object set based on the file operation information when the preset hook function receives the file operation information, and obtain a file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information;
[0067] The file occupancy detection module is used to detect the occupancy status of each operation file based on the file path corresponding to the operation file, and obtain the occupancy status detection result corresponding to each operation file;
[0068] The file occupancy prompt module is used to generate occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and display the occupied file information on the display device.
[0069] Optionally, the function replacement module is used to:
[0070] Creating a target object through a component object model library, and determining a table address of a virtual function under the file operation class based on a base address corresponding to the target object;
[0071] Obtaining a virtual function table stored under the table address, and performing a traversal operation on the virtual function table to search the virtual function table for a first address corresponding to the first virtual function and a second address corresponding to the second virtual function;
[0072] The first address and the second address are replaced by function addresses corresponding to the preset hook function through the interception function.
[0073] Optionally, the file enumeration module is used to:
[0074] Determine an operation mode corresponding to each operation file in the operation file object set, and group the operation files in the operation file object set according to the operation mode to obtain multiple target groups;
[0075] For each of the target groups, a file enumeration method corresponding to the target group is determined according to an operation method corresponding to the target group, and a file path corresponding to each operation file under the target group is determined through the file enumeration method.
[0076] Optionally, the file occupancy detection module is used to:
[0077] Creating a restart manager session, and registering a file path corresponding to each operation file in the restart manager session;
[0078] Calling an enumeration function through the restart manager session, obtaining an occupancy status corresponding to each file path registered in the restart manager session based on the enumeration function, and obtaining an enumerator containing the occupancy status corresponding to each file path;
[0079] The enumerator is traversed to obtain the occupancy status detection result corresponding to each of the operation files.
[0080] Optionally, the file occupancy prompt module is used to:
[0081] Determine the file information of the operation file in the occupied state according to the occupancy state detection result corresponding to each of the operation files, wherein the file information includes at least one of the file name, the occupying process name and the occupying process unique identifier;
[0082] The occupied file information corresponding to the operation file object set is generated according to the file information and the file path of each operation file in the operation file object set that is in an occupied state.
[0083] Optionally, the occupied file information also includes a process closing interactive button corresponding to each operating file in an occupied state; the file occupied prompt module is further used to:
[0084] In response to a trigger instruction of any process closing interactive button, generating a corresponding closing risk prompt according to the file path corresponding to the any process closing interactive button, and displaying the closing risk prompt on the display device; and,
[0085] Based on the confirmation instruction of closing the risk prompt, the process corresponding to any process closing interaction button is closed.
[0086] Optionally, the file occupancy prompt module is further used to:
[0087] After obtaining the file path corresponding to each operation file in the operation file object set, creating a processing progress update task, grouping the operation file object set based on the current task processing status of each thread in the multiple threads, assigning a first target thread to each group, and assigning a second target thread to the processing progress update task;
[0088] For each of the first target threads, based on the file path of the assigned operation file, the occupancy status of the operation file is determined, and the occupancy status detection results corresponding to each of the assigned operation files are obtained; and, for the second target thread, processing progress inquiry information is sent to each of the first target threads at a preset frequency, and based on the feedback information of each of the first target threads, the occupancy status detection progress of the operation file object set is updated, and the updated occupancy status detection progress is displayed on the display device.
[0089] It should be noted that for other corresponding descriptions of the functional units involved in the device for batch detecting occupied files in a resource manager provided in the embodiment of the present application, reference can be made to Figure 1 The corresponding description in the method will not be repeated here.
[0090] The present application also provides a computer device, which may be a personal computer, a server, a network device, etc. Figure 3 As shown, the computer device includes a bus, a processor, a memory and a communication interface, and may also include an input and output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in each method embodiment are implemented.
[0091] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0092] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0093] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0094] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0095] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0096] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0097] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A method for batch detecting occupied files in a resource manager, characterized in that: include: The remote thread injection module responds to the startup instruction of the resource manager process and remotely injects the target dynamic link library file into the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module; After the target dynamic link library file is loaded, the function replacement module replaces the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function; When the preset hook function receives the file operation information, the file enumeration module determines the operation file object set based on the file operation information, and obtains the file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information; The file occupancy detection module detects the occupancy status of each operation file based on the file path corresponding to the operation file, and obtains the occupancy status detection result corresponding to each operation file; The file occupancy prompt module generates occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and displays the occupied file information on a display device.
2. The method according to claim 1, characterized in that The step of replacing the first virtual function corresponding to the move operation method under the file operation class and the second virtual function corresponding to the delete operation method with a preset hook function includes: Creating a target object through a component object model library, and determining a table address of a virtual function under the file operation class based on a base address corresponding to the target object; Obtaining a virtual function table stored under the table address, and performing a traversal operation on the virtual function table to search the virtual function table for a first address corresponding to the first virtual function and a second address corresponding to the second virtual function; The first address and the second address are replaced by function addresses corresponding to the preset hook function through the interception function.
3. The method according to claim 1, characterized in that The obtaining of the file path corresponding to each operation file in the operation file object set includes: Determine an operation mode corresponding to each operation file in the operation file object set, and group the operation files in the operation file object set according to the operation mode to obtain multiple target groups; For each of the target groups, a file enumeration method corresponding to the target group is determined according to an operation method corresponding to the target group, and a file path corresponding to each operation file under the target group is determined through the file enumeration method.
4. The method according to claim 1, characterized in that: The detecting the occupation status of the operation files based on the file paths corresponding to the operation files to obtain the occupation status detection results corresponding to the operation files includes: Creating a restart manager session, and registering a file path corresponding to each operation file in the restart manager session; Calling an enumeration function through the restart manager session, obtaining an occupancy status corresponding to each file path registered in the restart manager session based on the enumeration function, and obtaining an enumerator containing the occupancy status corresponding to each file path; The enumerator is traversed to obtain the occupancy status detection result corresponding to each of the operation files.
5. The method according to claim 1, characterized in that The generating, according to the occupancy status detection result corresponding to each of the operation files, the occupancy file information corresponding to the operation file object set comprises: Determine the file information of the operation file in the occupied state according to the occupancy state detection result corresponding to each of the operation files, wherein the file information includes at least one of the file name, the occupying process name and the occupying process unique identifier; The occupied file information corresponding to the operation file object set is generated according to the file information and the file path of each operation file in the operation file object set that is in an occupied state.
6. The method according to claim 5, characterized in that The occupied file information also includes a process closing interactive button corresponding to each occupied operation file; the method also includes: The file occupation prompt module responds to a trigger instruction of any process closing interactive button, generates a corresponding closing risk prompt according to the file path corresponding to the any process closing interactive button, and displays the closing risk prompt on the display device; and Based on the confirmation instruction of closing the risk prompt, the process corresponding to any process closing interaction button is closed.
7. The method according to any one of claims 1 to 6, characterized in that After obtaining the file path corresponding to each operation file in the operation file object set, the method further includes: The file occupancy prompt module creates a processing progress update task, groups the operation file object set based on the current task processing status of each thread in the multiple threads, allocates a first target thread to each group, and allocates a second target thread to the processing progress update task; The file occupancy prompt module determines, for each of the first target threads, the occupancy status of the operation file based on the file path of the assigned operation file, obtains the occupancy status detection results corresponding to each of the assigned operation files, and, for the second target thread, sends processing progress inquiry information to each of the first target threads at a preset frequency, updates the occupancy status detection progress of the operation file object set based on the feedback information of each of the first target threads, and displays the updated occupancy status detection progress on the display device.
8. A device for batch detecting occupied files in a resource manager, characterized in that: include: A remote thread injection module, for remotely injecting a target dynamic link library file into the resource manager process in response to a startup instruction of the resource manager process, wherein the target dynamic link library file includes a function replacement module, a file enumeration module, a file occupancy detection module and a file occupancy prompt module; The function replacement module is used to replace the first virtual function corresponding to the move operation method and the second virtual function corresponding to the delete operation method under the file operation class with a preset hook function after the target dynamic link library file is loaded; The file enumeration module is used to determine an operation file object set based on the file operation information when the preset hook function receives the file operation information, and obtain a file path corresponding to each operation file in the operation file object set, wherein the file operation information includes file movement information and / or file deletion information; The file occupancy detection module is used to detect the occupancy status of each operation file based on the file path corresponding to the operation file, and obtain the occupancy status detection result corresponding to each operation file; The file occupancy prompt module is used to generate occupied file information corresponding to the operation file object set according to the occupancy status detection result corresponding to each operation file, and display the occupied file information on the display device.
9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.