Manipulating Services
Querying services is simple to do with WMI. The Win32_Service
class is the WMI representation of a service. The Win32_Service class contains a lot of property methods that provide information about the service; the most useful ones have been listed in Table 29-2.
Table 29-2. Useful Win32_Service properties
|
Property |
Description |
|---|---|
|
|
Returns a Boolean indicating whether the service can be paused. |
|
|
Returns a Boolean indicating whether the service can be stopped. |
|
|
Description of the service. |
|
|
Display name of the service. |
|
|
Unique string identifier for the service. |
|
|
Fully qualified path to the service executable. |
|
|
Boolean indicating whether the service has been started. |
|
|
String specifying the start mode of the service. Will be one of Automatic, Manual, or Disabled. |
|
|
Account under which the service runs. |
|
|
Current state of the service. Will be one of Stopped, Start Pending, Stop Pending, Running, Continue Pending, Pause Pending, Paused, or Unknown. |
The following script retrieves all the running services on a machine. All we need to do is use a WQL query that finds all Win32_Service objects that have a state of "Running":
strComputer = "." Set objWMI = GetObject("winmgmts:\\" & strComputer & "\root\cimv2") Set objServices = objWMI.ExecQuery _ ("SELECT * FROM Win32_Service WHERE State = 'Running'") For Each objService In objServices WScript.Echo ...Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access