processmonitor.cpp 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148
  1. #include "processmonitor.h"
  2. BOOL EnablePrivilege(LPCWSTR privilege)
  3. {
  4. HANDLE hToken;
  5. TOKEN_PRIVILEGES tp;
  6. LUID luid;
  7. if (!OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hToken)) {
  8. return FALSE;
  9. }
  10. if (!LookupPrivilegeValue(NULL, privilege, &luid)) {
  11. CloseHandle(hToken);
  12. return FALSE;
  13. }
  14. tp.PrivilegeCount = 1;
  15. tp.Privileges[0].Luid = luid;
  16. tp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
  17. if (!AdjustTokenPrivileges(hToken, FALSE, &tp, sizeof(TOKEN_PRIVILEGES), NULL, NULL)) {
  18. CloseHandle(hToken);
  19. return FALSE;
  20. }
  21. CloseHandle(hToken);
  22. return GetLastError() == ERROR_SUCCESS;
  23. }
  24. ProcessMonitor::ProcessMonitor()
  25. {
  26. filter.insert({"System", true});
  27. filter.insert({"svchost.exe", true});
  28. filter.insert({"wininit.exe", true});
  29. filter.insert({"NVDisplay.Container.exe", true});
  30. }
  31. std::vector<std::shared_ptr<ProcessMonitor::ProcessInfo>> ProcessMonitor::checkProcesses()
  32. {
  33. data.clear();
  34. mapData.clear();
  35. // 创建进程快照
  36. HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
  37. if (hSnapshot != INVALID_HANDLE_VALUE) {
  38. PROCESSENTRY32 pe32;
  39. pe32.dwSize = sizeof(PROCESSENTRY32);
  40. // 获取第一个进程信息
  41. if (Process32First(hSnapshot, &pe32)) {
  42. do {
  43. // 获取当前进程的PID
  44. DWORD pid = pe32.th32ProcessID;
  45. if (pid != 0) {
  46. // 获取进程信息
  47. std::shared_ptr<ProcessInfo> info = getProcessInfo(pid);
  48. info->parentPid = pe32.th32ParentProcessID; // 直接从pe32获取父进程PID
  49. std::string processName = QString::fromWCharArray(pe32.szExeFile).toStdString();
  50. info->processName = processName;
  51. data.push_back(info);
  52. mapData[pid] = info;
  53. }
  54. } while (Process32Next(hSnapshot, &pe32)); // 循环获取下一个进程信息
  55. }
  56. CloseHandle(hSnapshot);
  57. }
  58. std::vector<std::shared_ptr<ProcessInfo>> timeProcess;
  59. // 获取全部根节点信息
  60. auto rootNodes = root();
  61. std::shared_ptr<ProcessInfo> explorerNode = nullptr;
  62. for (auto rootNode : rootNodes) {
  63. //在过滤里面
  64. if (rootNode) {
  65. if (filter.find(rootNode->processName) != filter.end()) {
  66. } else {
  67. // qDebug() << "[" << QString::fromStdString(rootNode->processName) << "]"
  68. // << rootNode->pid << rootNode->parentPid;
  69. timeProcess.push_back(rootNode);
  70. }
  71. if (rootNode->processName == "explorer.exe" || rootNode->processName == "Explorer.exe") {
  72. explorerNode = rootNode;
  73. }
  74. }
  75. }
  76. // 获取全部根节点的过滤
  77. if (explorerNode) {
  78. for (const auto& item : data) {
  79. if (item->parentPid == explorerNode->pid) {
  80. // qDebug() << "-- explorerNode [" << QString::fromStdString(item->processName) << "]"
  81. // << item->pid << item->parentPid;
  82. timeProcess.push_back(item);
  83. }
  84. }
  85. }
  86. return timeProcess;
  87. }
  88. DWORD ProcessMonitor::getRootPid(DWORD pid)
  89. {
  90. if (mapData.find(pid) != mapData.end()) {
  91. const auto value = mapData.at(pid);
  92. if (pid == value->pid) {
  93. return pid;
  94. }
  95. if (pid == value->parentPid) {
  96. return pid;
  97. }
  98. DWORD id = getRootPid(value->parentPid);
  99. if (id == -1) {
  100. return pid;
  101. }
  102. }
  103. return -1;
  104. }
  105. std::set<std::shared_ptr<ProcessMonitor::ProcessInfo>> ProcessMonitor::root()
  106. {
  107. std::set<std::shared_ptr<ProcessInfo>> roots;
  108. for (const auto& item : data) {
  109. DWORD rootPid = getRootPid(item->parentPid);
  110. if (rootPid != -1) {
  111. roots.insert(mapData[rootPid]);
  112. }
  113. }
  114. return roots;
  115. }
  116. std::shared_ptr<ProcessMonitor::ProcessInfo> ProcessMonitor::getProcessInfo(DWORD pid)
  117. {
  118. std::shared_ptr<ProcessInfo> info = std::make_shared<ProcessInfo>();
  119. // ProcessInfo info;
  120. info->pid = pid;
  121. HANDLE hProcess = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ, FALSE, pid);
  122. if (hProcess) {
  123. char processName[MAX_PATH] = {0};
  124. if (GetModuleFileNameExA(hProcess, NULL, processName, sizeof(processName) / sizeof(char))) {
  125. info->name = std::string(processName);
  126. }
  127. // 获取进程时间
  128. if (GetProcessTimes(hProcess,
  129. &info->creationTime,
  130. &info->exitTime,
  131. &info->kernelTime,
  132. &info->userTime)) {
  133. }
  134. CloseHandle(hProcess);
  135. }
  136. return info;
  137. }