记录后通过ipcservice.dll将日志保存为C:\Documents and Settings\[当前用户名]\ApplicationData\360safe\LogInfo\360_tmp_xxxx.log.
以下是一条记录的示例:
<t=2010-11-18 09:50:26><m=6db5c3797939054df8dcb0ffbc4e1154><p=ipc><c=ad><t=logprocess><started=1><src_path=C:\WINDOWS\explorer.exe><src_cn=MicrosoftCorporation><src_pn=Microsoft(R) Windows(R) OperatingSystem><src_sn=Microsoft Windows Component Publisher><src_in=explorer><src_lc=(C)Microsoft Corporation. All rights reserved.><dst_path=C:\ProgramFiles\AliWangWang\AliIM.exe><dst_cn=Alibaba software (Shanghai)Corporation.><dst_pn=AliIM 应用程序><dst_sn=Alibaba(China) Co. Ltd.><dst_in=NULL><dst_lc=Alibaba software (Shanghai)Corporation. All rights reserved.>
360安全卫士将C:\Documents and Settings\[当前用户名]\Application Data\360safe\LogInfo\目录下的log记录合并后,立即删除相应log文件,并在用户临时目录(C:\Documents and Settings\[当前用户名]\Local Settings\Temp)中创建一个文件压缩后进行上传。压缩文件被命名为随机字符,不易被发现。