WMI ConnectServer到ROOT \ CIMV2对于C ++应用程序返回“访问被拒绝”,但对于C#应用程序可以正常使用

时间:2018-10-28 12:07:03

标签: c# c++ windows winapi win32-process

我正在关注this文章以查询WMI。目的是通过使用查询Select * from Win32_Process来获取正在运行的进程的详细信息,一旦查询成功,将遍历结果。但是在调用pLoc->ConnectServer(_bstr_t(L"\\ROOT\\CIMV2"), NULL, NULL,0,NULL,0,0,&pSvc);的过程中,我得到HRESULT_FROM_WIN32(ERROR_SERVICE_DOES_NOT_EXIST) : The specified service does not exist as an installed service.,我已经检查了compmgmt.msc中的WMI Control权限,这似乎很好。我试图以管理员身份运行该应用程序,但结果相同。

修改代码

HRESULT hres;

// Initialize COM.
hres = CoInitializeEx(0, COINIT_MULTITHREADED);
if (FAILED(hres))
{
    cout << "Failed to initialize COM library. "
        << "Error code = 0x"
        << hex << hres << endl;
    return 1;              // Program has failed.
}

// Initialize 
hres = CoInitializeSecurity(
    NULL,
    -1,      // COM negotiates service                  
    NULL,    // Authentication services
    NULL,    // Reserved
    RPC_C_AUTHN_LEVEL_DEFAULT,    // authentication
    RPC_C_IMP_LEVEL_IMPERSONATE,  // Impersonation
    NULL,             // Authentication info 
    EOAC_NONE,        // Additional capabilities
    NULL              // Reserved
);


if (FAILED(hres))
{
    cout << "Failed to initialize security. "
        << "Error code = 0x"
        << hex << hres << endl;
    CoUninitialize();
    return 1;          // Program has failed.
}

// Obtain the initial locator to Windows Management
// on a particular host computer.
IWbemLocator *pLoc = 0;

hres = CoCreateInstance(
    CLSID_WbemLocator,
    0,
    CLSCTX_INPROC_SERVER,
    IID_IWbemLocator, (LPVOID *)&pLoc);

if (FAILED(hres))
{
    cout << "Failed to create IWbemLocator object. "
        << "Error code = 0x"
        << hex << hres << endl;
    CoUninitialize();
    return 1;       // Program has failed.
}

IWbemServices *pSvc = 0;

// Connect to the root\cimv2 namespace with the
// current user and obtain pointer pSvc
// to make IWbemServices calls.

hres = pLoc->ConnectServer(

    _bstr_t(L"\\ROOT\\CIMV2"), // WMI namespace
    NULL,                    // User name
    NULL,                    // User password
    0,                       // Locale
    NULL,                    // Security flags                 
    0,                       // Authority       
    0,                       // Context object
    &pSvc                    // IWbemServices proxy
);

if (FAILED(hres))
{
    cout << "Could not connect. Error code = 0x"
        << hex << hres << endl;
    pLoc->Release();
    CoUninitialize();
    return 1;                // Program has failed.
}

cout << "Connected to ROOT\\CIMV2 WMI namespace" << endl;

// Set the IWbemServices proxy so that impersonation
// of the user (client) occurs.
hres = CoSetProxyBlanket(

    pSvc,                         // the proxy to set
    RPC_C_AUTHN_WINNT,            // authentication service
    RPC_C_AUTHZ_NONE,             // authorization service
    NULL,                         // Server principal name
    RPC_C_AUTHN_LEVEL_CALL,       // authentication level
    RPC_C_IMP_LEVEL_IMPERSONATE,  // impersonation level
    NULL,                         // client identity 
    EOAC_NONE                     // proxy capabilities     
);

if (FAILED(hres))
{
    cout << "Could not set proxy blanket. Error code = 0x"
        << hex << hres << endl;
    pSvc->Release();
    pLoc->Release();
    CoUninitialize();
    return 1;               // Program has failed.
}


// Use the IWbemServices pointer to make requests of WMI. 
// Make requests here:

// For example, query for all the running processes
IEnumWbemClassObject* pEnumerator = NULL;
hres = pSvc->ExecQuery(
    bstr_t("WQL"),
    bstr_t("SELECT * FROM Win32_Process"),
    WBEM_FLAG_FORWARD_ONLY | WBEM_FLAG_RETURN_IMMEDIATELY,
    NULL,
    &pEnumerator);

if (FAILED(hres))
{
    cout << "Query for processes failed. "
        << "Error code = 0x"
        << hex << hres << endl;
    pSvc->Release();
    pLoc->Release();
    CoUninitialize();
    return 1;               // Program has failed.
}
else
{
    IWbemClassObject *pclsObj;
    ULONG uReturn = 0;

    while (pEnumerator)
    {
        hres = pEnumerator->Next(WBEM_INFINITE, 1,
            &pclsObj, &uReturn);

        if (0 == uReturn)
        {
            break;
        }

        VARIANT vtProp;

        // Get the value of the Name property
        hres = pclsObj->Get(L"Name", 0, &vtProp, 0, 0);
        wcout << "Process Name : " << vtProp.bstrVal << endl;
        VariantClear(&vtProp);

        pclsObj->Release();
        pclsObj = NULL;
    }

}

// Cleanup
// ========

pSvc->Release();
pLoc->Release();
pEnumerator->Release();

CoUninitialize();

return 0;   // Program successfully completed.

}

我在C#中也有类似的代码库。我正在使用ObjectQuery来形成sql查询,并使用ManagementObjectSearcher来返回结果。我使用的查询略有不同Select * from Win32_Process Where ProcessID = '" + PID + "'。通过迭代Process.GetProcesses()的结果来传递PID。这个C#应用程序运行良好,我能够看到所有正在运行的进程的详细信息。

修改代码

 ObjectQuery sq = new ObjectQuery
             ("Select * from Win32_Process Where ProcessID = '" + PID + "'");

            ManagementObjectSearcher searcher = new ManagementObjectSearcher(scope, sq);
            if (searcher == null)
            {
                Console.WriteLine("Searcher is empty...returning");
                return String.Empty;
            }
            if (searcher.Get().Count == 0)
                return OwnerSID;
            foreach (ManagementObject oReturn in searcher.Get())
            {
                using (ManagementObjectCollection oReturnC = searcher.Get())
                {
                    FullPath = (from mo in oReturnC.Cast<ManagementObject>() select mo["ExecutablePath"]).First().ToString();
                    CommandLine = (from mo in oReturnC.Cast<ManagementObject>() select mo["CommandLine"]).First().ToString();
                    parentprocessid = (from mo in oReturnC.Cast<ManagementObject>() select mo["ParentProcessId"]).First().ToString();
                    ppid = Convert.ToInt32(parentprocessid);
                    Process parentProcess = Process.GetProcessById(ppid);
                    ppname = parentProcess.ProcessName;
                }

            }

我发现的另一个奇怪行为是,当我将C#从应用程序更改为dll,并在 this 之后在C ++应用程序中使用该dll(传统原因)时,我得到了相同的错误-The specified service does not exist as an installed service

我在Google上搜索了很多,找不到任何解决该问题的方法。有什么原因使C#能够访问WMI而不是C ++。

1 个答案:

答案 0 :(得分:0)

以下页面指示在连接到本地系统时不要使用前导\:https://docs.microsoft.com/en-us/windows/desktop/wmisdk/creating-a-connection-to-a-wmi-namespace