You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows会话首次SSD文本文件读取过慢的编程方案咨询

Windows Defender导致SSD首次文件读取缓慢的检测与解决方案

1. 编程检测Windows Defender导致的读取变慢

核心思路是通过对比首次读取耗时与缓存后读取耗时的比值,结合Windows Defender的启用状态来判断。具体步骤如下:

  • 准备测试文件:使用与业务场景同类型、相近大小的文本文件(如100MB),避免因文件过小导致耗时误差。
  • 排除系统缓存干扰:清理当前进程的工作集,确保首次读取时无系统缓存加持。
  • 对比读取耗时:分别记录首次和二次读取的耗时,若首次耗时是二次的20倍以上(可根据实际场景调整阈值),则怀疑是Defender扫描导致。
  • 验证Defender状态:检查Defender是否处于启用状态,排除其他因素干扰。

C# 检测示例代码

using System;
using System.Diagnostics;
using System.IO;
using System.Runtime.InteropServices;
using Microsoft.Win32;

public static class DefenderSlowReadDetector
{
    [DllImport("psapi.dll", SetLastError = true)]
    private static extern bool EmptyWorkingSet(IntPtr hProcess);

    public static bool IsDefenderCausingSlowReads(string testFilePath, int thresholdRatio = 20)
    {
        if (!File.Exists(testFilePath))
            throw new FileNotFoundException("测试文件不存在", testFilePath);

        // 清理进程工作集,减少系统缓存影响
        EmptyWorkingSet(Process.GetCurrentProcess().Handle);

        // 首次读取耗时
        var stopwatch = Stopwatch.StartNew();
        _ = File.ReadAllBytes(testFilePath);
        stopwatch.Stop();
        long firstReadMs = stopwatch.ElapsedMilliseconds;

        // 二次读取耗时
        stopwatch.Restart();
        _ = File.ReadAllBytes(testFilePath);
        stopwatch.Stop();
        long secondReadMs = stopwatch.ElapsedMilliseconds;

        if (secondReadMs == 0 || (double)firstReadMs / secondReadMs < thresholdRatio)
            return false;

        // 验证Windows Defender是否启用
        using var defenderKey = Registry.LocalMachine.OpenSubKey(@"SOFTWARE\Microsoft\Windows Defender");
        if (defenderKey == null) return false;
        
        var disableValue = defenderKey.GetValue("DisableAntiSpyware");
        return disableValue == null || (int)disableValue == 0;
    }
}

注意事项

  • 测试需在系统空闲时执行,避免其他进程占用资源导致误判。
  • 建议多次测试取平均值,提升检测准确性。
  • 若目标文件已在Defender排除列表中,该检测方法会失效。

2. 编程控制Windows Defender的文件扫描

可以通过编程实现,但必须具备管理员权限,且受Windows版本限制(家庭版部分功能可能受限),优先推荐添加排除列表而非完全禁用扫描。

方案一:添加文件/文件夹到Defender排除列表(推荐)

通过WMI修改Defender的排除项,不会影响整体安全防护,仅跳过目标文件的扫描:

using System;
using System.Linq;
using System.Management;

public static class DefenderExclusionManager
{
    public static void AddPathToExclusions(string targetPath)
    {
        var scope = new ManagementScope(@"root\Microsoft\Windows\Defender");
        scope.Connect();

        var query = new ObjectQuery("SELECT * FROM MSFT_MpPreference");
        using var searcher = new ManagementObjectSearcher(scope, query);
        
        foreach (var preferenceObj in searcher.Get())
        {
            var currentExclusions = preferenceObj.GetPropertyValue("ExclusionPath") as string[] ?? Array.Empty<string>();
            if (!currentExclusions.Contains(targetPath, StringComparer.OrdinalIgnoreCase))
            {
                var updatedExclusions = currentExclusions.Concat(new[] { targetPath }).ToArray();
                preferenceObj.SetPropertyValue("ExclusionPath", updatedExclusions);
                preferenceObj.Put();
            }
        }
    }
}

方案二:临时禁用实时保护(不推荐)

仅在特殊场景下使用,会降低系统安全性:

using System.Management;

public static class DefenderRealtimeControl
{
    public static void DisableRealtimeMonitoring()
    {
        var scope = new ManagementScope(@"root\Microsoft\Windows\Defender");
        scope.Connect();

        var query = new ObjectQuery("SELECT * FROM MSFT_MpPreference");
        using var searcher = new ManagementObjectSearcher(scope, query);
        
        foreach (var preferenceObj in searcher.Get())
        {
            preferenceObj.SetPropertyValue("DisableRealtimeMonitoring", true);
            preferenceObj.Put();
        }
    }
}

注意事项

  • 所有操作需以管理员权限执行,程序需请求UAC提升。
  • Windows家庭版可能无法通过WMI/注册表修改Defender设置,需依赖组策略或手动操作。
  • 禁用实时保护后,建议在操作完成后立即恢复,避免系统暴露在风险中。

内容的提问来源于stack exchange,提问作者Patrick from NDepend team

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 18:03:33