同意。樓主提醒我們的用意不錯,但做出的結論基本屬於猜測。提到的有些‘有趣的’,‘頻繁被進行讀取’的文件操作對於正版校驗應該也是正常的,比如文件legitcheckcontrol.dll,在網上查到其用途是‘The Windows Genuine Advantage Validation DLL file. This file validates your Windows version each time you connect to the Microsoft website for updates.’