system 用户创建的进程创建当前用户(如Administrator)的进程。

	//获取当前进程的灵牌
	HANDLE hTokenDup = NULL; 
	HANDLE hThisProcess = GetCurrentProcess(); 

	DWORD dwSessionId = 0; 
	dwSessionId = ::WTSGetActiveConsoleSessionId();
	if(dwSessionId == 0xFFFFFFFF)
	{
		DWORD f_dwErr = GetLastError(); 
		CString str;
		str.Format( _T("%s, %d, GefSvr::CreateUsrProcess WTSGetActiveConsoleSessionId Error, Error is 0x%08x"), __FILE__, __LINE__, f_dwErr ); 
		AfxMessageBox(str);
		return FALSE;
	}
	if(!WTSQueryUserToken(dwSessionId,&hTokenDup))
	{
		DWORD f_dwErr = GetLastError(); 
		CString str;
		str.Format( _T("%s, %d, GefSvr::CreateUsrProcess WTSQueryUserToken Error, Error is 0x%08x"), __FILE__, __LINE__, f_dwErr ); 
		AfxMessageBox(str);
		return FALSE;
	}
	STARTUPINFO si = {'\0'};
	PROCESS_INFORMATION pi = {'\0'}; 
	si.cb = sizeof(si);
	si.lpDesktop = _T("WinSta0\\Default");

	DWORD dwCreationFlag = NORMAL_PRIORITY_CLASS/* | CREATE_NEW_CONSOLE | CREATE_UNICODE_ENVIRONMENT*/;
	//LPVOID pEnv = NULL; 
	//CreateEnvironmentBlock( &pEnv, hTokenDup, FALSE );

	//TCHAR szCmd[MAX_PATH * 2] = {'\0'}; 
	//_tcscpy_s( szCmd, _countof(szCmd), lpCmd ); 
	
	//SvrDebug( _T("%s, %d, GefSvr::CreateProcessAsUser %s"), 
	//	__FILE__, __LINE__, szCmd ); 

	TCHAR szCurDir[MAX_PATH*2] = {0};
	GetModuleFileName(NULL,szCurDir,_countof(szCurDir));
	PathRemoveFileSpec(szCurDir); 

	SetCurrentDirectory(lpWorkDir);
	if (!CreateProcessAsUser( hTokenDup,_T("iexplore.exe"),lpCmd,NULL, NULL, FALSE, 
		dwCreationFlag, NULL,lpWorkDir<span style="font-family: Arial, Helvetica, sans-serif;">, &si, &pi )) </span>
	{
		DWORD f_dwErr = GetLastError(); 
		CString str;
		str.Format( _T("%s, %d, GefSvr::CreateProcessAsUser %s Faile, Err is 0x%08x"), 
			__FILE__, __LINE__, lpCmd, f_dwErr );
		AfxMessageBox(str);
		CloseHandle( hTokenDup ); 
		SetLastError( f_dwErr ); 
	} 

	CloseHandle( pi.hThread ); 
	CloseHandle( pi.hProcess );  
	CloseHandle( hTokenDup );
	SetCurrentDirectory(szCurDir);


  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值