1.通过windows API OpenProcess打开一个进程获取进程的handle
2.通过OpenProcessToken函数获取指定句柄的 token信息
3.通过哦CreateProcessAsUser函数通过哦指定的token信息创建进程
代码如下:
explorer_pids = self.Get_process_pid("explorer.exe") # 通过进程名称获取PID这个是自己写的方法
run_finish = False
for one_pid in explorer_pids:
try:
handle = win32api.OpenProcess(win32con.PROCESS_QUERY_INFORMATION | win32con.PROCESS_VM_READ, False, one_pid)
token = win32security.OpenProcessToken(handle, win32security.TOKEN_ALL_ACCESS)
# print(token )
win32process.CreateProcessAsUser(token , cmd_order_str, None, None, None, True, win32con.NORMAL_PRIORITY_CLASS, None,
None, win32process.STARTUPINFO())
run_finish = True
break
except:
print("start process failed. file path:{0} ".format(cmd_order_str))
print("explorer pid is:{0}".format(one_pid))
print_info(traceback.format_exc())
if not explorer_pids:
print("get the explorer pid error, this is none.")
return run_finish
windows API相关函数介绍:
OpenProcess:https://docs.microsoft.com/zh-cn/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess
OpenProcessToken:https://docs.microsoft.com/zh-cn/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocesstoken
CreateProcessAsUser:https://docs.microsoft.com/zh-cn/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessasusera