如何用Python获取Windows文件的原始创建时间(非复制生成时间)
提取Windows文件原始内容创建时间的可行方法
在Windows系统中,os.path.getctime()返回的是文件在当前系统中的创建时间(即2022年复制后的时间),无法获取你提到的「来源」板块里的原始内容创建时间。以下是两种可行的解决方案:
1. 使用pywin32库调用Windows Shell属性
这是最直观的方法,通过Windows Shell接口直接读取文件的扩展属性,对应「来源」面板里的内容创建时间。
首先安装pywin32库:
pip install pywin32
然后使用以下代码提取原始创建时间:
import os from datetime import datetime import win32com.client def get_content_creation_time(file_path): # 初始化Shell对象 shell = win32com.client.Dispatch("Shell.Application") # 获取文件所在文件夹的Shell命名空间 folder_path = os.path.dirname(file_path) folder = shell.Namespace(folder_path) if not folder: return None # 获取文件对应的Shell项 file_name = os.path.basename(file_path) item = folder.ParseName(file_name) if not item: return None # 遍历属性索引,找到「内容创建时间」对应的索引(不同系统版本可能有差异) content_creation_index = -1 for i in range(0, 200): # 遍历前200个属性足够覆盖常用项 prop_name = folder.GetDetailsOf(folder.Items(), i) if prop_name == "内容创建时间": content_creation_index = i break if content_creation_index == -1: return None # 提取时间字符串并转换为datetime对象 time_str = folder.GetDetailsOf(item, content_creation_index) if not time_str: return None try: return datetime.strptime(time_str, "%Y/%m/%d %H:%M:%S") except ValueError: # 处理不同的时间格式(比如部分系统显示为"2020年1月1日 12:00") return datetime.strptime(time_str, "%Y年%m月%d日 %H:%M")
调用示例:
file_path = r"C:\path\to\your\file.txt" original_time = get_content_creation_time(file_path) if original_time: print(f"原始内容创建时间: {original_time}") else: print("无法获取原始内容创建时间")
2. 使用ctypes直接调用Windows API(无需第三方库)
如果不想依赖第三方库,可以通过ctypes直接调用Windows系统API读取文件的扩展属性。这种方法更底层,实现细节较复杂,以下是简化参考示例:
import ctypes from ctypes import wintypes import os from datetime import datetime # 定义Windows API函数 kernel32 = ctypes.WinDLL('kernel32', use_last_error=True) shell32 = ctypes.WinDLL('shell32', use_last_error=True) class SHFILEINFO(ctypes.Structure): _fields_ = [ ("hIcon", wintypes.HICON), ("iIcon", wintypes.INT), ("dwAttributes", wintypes.DWORD), ("szDisplayName", wintypes.WCHAR * 260), ("szTypeName", wintypes.WCHAR * 80) ] def get_original_creation_time(file_path): try: # 打开文件获取句柄 handle = kernel32.CreateFileW( file_path, wintypes.DWORD(0x00000001), # GENERIC_READ wintypes.DWORD(0x00000001 | 0x00000002), # FILE_SHARE_READ | FILE_SHARE_WRITE None, wintypes.DWORD(3), # OPEN_EXISTING wintypes.DWORD(0x80), # FILE_ATTRIBUTE_NORMAL None ) if handle == wintypes.HANDLE(-1).value: return None # 读取文件系统层面的创建时间(若要获取「来源」板块的内容创建时间,需额外调用Shell属性接口,实现复杂度较高) creation_time = wintypes.FILETIME() last_access = wintypes.FILETIME() last_write = wintypes.FILETIME() if kernel32.GetFileTime(handle, ctypes.byref(creation_time), ctypes.byref(last_access), ctypes.byref(last_write)): # 转换FILETIME为datetime对象 def filetime_to_dt(ft): return datetime.utcfromtimestamp(((ft.dwHighDateTime << 32) + ft.dwLowDateTime - 116444736000000000) / 10000000) return filetime_to_dt(creation_time) kernel32.CloseHandle(handle) except Exception: return None return None
注意:第二种方法的简化示例仅能获取文件系统层面的创建时间,若要精准获取「来源」板块的内容创建时间,需进一步调用Shell32的SHGetPropertyStoreFromParsingName等函数,实现繁琐,因此优先推荐第一种方法。
内容的提问来源于stack exchange,提问作者user1417007
相关产品推荐
相关产品推荐

