You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

C#检测Windows进程数字签名报错:File无GetDigitalSignatures方法

问题解决:File类不存在GetDigitalSignatures方法

首先明确:.NET 原生的System.IO.File类并没有GetDigitalSignatures这个方法,你可能混淆了第三方库或自定义方法的名称。要检测文件数字签名,需要用.NET提供的安全相关API实现。

解决方案1:使用X509Certificate2检查签名(基础版)

通过System.Security.Cryptography.X509Certificates命名空间下的X509Certificate2类,可以读取文件的签名信息。如果文件没有签名,加载时会抛出异常。

修改后的完整代码

using System;
using System.Diagnostics;
using System.Security.Cryptography.X509Certificates;

void DriverCheck()
{
    Process[] processes = Process.GetProcesses();

    foreach (Process process in processes)
    {
        try
        {
            if (process.MainModule != null)
            {
                bool isSigned = false;
                string filePath = process.MainModule.FileName;
                
                try
                {
                    // 尝试加载文件的数字证书
                    using var cert = new X509Certificate2(filePath);
                    // 如果加载成功,说明存在签名
                    isSigned = !string.IsNullOrEmpty(cert.Subject);
                }
                catch (CryptographicException)
                {
                    // 无签名或加载失败时抛出此异常
                    isSigned = false;
                }
                catch (Exception ex)
                {
                    // 处理其他异常(如文件无法访问)
                    Console.WriteLine($"处理文件 {filePath} 时出错: {ex.Message}");
                }

                if (isSigned)
                {
                    Console.WriteLine($"{process.ProcessName} 的主模块已签名");
                    // 可以在这里获取证书详情,比如发行者、有效期等
                    // using var cert = new X509Certificate2(filePath);
                    // Console.WriteLine($"发行者: {cert.Issuer}");
                }
                else
                {
                    Console.WriteLine($"{process.ProcessName} 的主模块未签名");
                }
            }
        }
        catch (System.ComponentModel.Win32Exception)
        {
            // 进程无主模块或权限不足
        }
    }
}

解决方案2:使用WinVerifyTrust验证签名(严谨版)

如果需要验证签名是否受信任(而不仅仅是存在签名),可以调用Windows APIWinVerifyTrust,这是更准确的方式,因为有些签名可能无效或不在信任链中。

实现代码

using System;
using System.Diagnostics;
using System.Runtime.InteropServices;

void DriverCheck()
{
    Process[] processes = Process.GetProcesses();

    foreach (Process process in processes)
    {
        try
        {
            if (process.MainModule != null)
            {
                string filePath = process.MainModule.FileName;
                bool isTrustedSigned = WinVerifyTrust(filePath);

                if (isTrustedSigned)
                {
                    Console.WriteLine($"{process.ProcessName} 的主模块已签名且可信");
                }
                else
                {
                    Console.WriteLine($"{process.ProcessName} 的主模块未签名或签名不可信");
                }
            }
        }
        catch (System.ComponentModel.Win32Exception)
        {
            // 进程无主模块或权限不足
        }
    }
}

// P/Invoke 声明WinVerifyTrust相关结构和方法
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
private struct WINTRUST_FILE_INFO
{
    public uint cbStruct;
    public string pcwszFilePath;
    public IntPtr hFile;
    public IntPtr pgKnownSubject;
}

[StructLayout(LayoutKind.Sequential)]
private struct WINTRUST_DATA
{
    public uint cbStruct;
    public IntPtr pPolicyCallbackData;
    public IntPtr pSIPClientData;
    public uint dwUIChoice;
    public uint fdwRevocationChecks;
    public uint dwUnionChoice;
    public IntPtr pFile;
    public uint dwStateAction;
    public IntPtr hWVTStateData;
    public string pwszURLReference;
    public uint dwProvFlags;
    public uint dwUIContext;
    public IntPtr pSignatureSettings;
}

[DllImport("wintrust.dll", CharSet = CharSet.Unicode, SetLastError = true)]
private static extern uint WinVerifyTrust(IntPtr hWnd, IntPtr pgActionID, ref WINTRUST_DATA pWVTData);

private const uint WTD_UI_NONE = 2;
private const uint WTD_REVOKE_NONE = 0;
private const uint WTD_CHOICE_FILE = 1;
private const uint WTD_STATEACTION_VERIFY = 1;
private const uint WTD_STATEACTION_CLOSE = 2;
private const uint WTD_PROV_FLAGS_IGNORE_NOT_TIME_NESTED = 0x00000200;

private static bool WinVerifyTrust(string filePath)
{
    var fileInfo = new WINTRUST_FILE_INFO
    {
        cbStruct = (uint)Marshal.SizeOf(typeof(WINTRUST_FILE_INFO)),
        pcwszFilePath = filePath
    };

    var trustData = new WINTRUST_DATA
    {
        cbStruct = (uint)Marshal.SizeOf(typeof(WINTRUST_DATA)),
        dwUIChoice = WTD_UI_NONE,
        fdwRevocationChecks = WTD_REVOKE_NONE,
        dwUnionChoice = WTD_CHOICE_FILE,
        pFile = Marshal.AllocHGlobal(Marshal.SizeOf(typeof(WINTRUST_FILE_INFO))),
        dwStateAction = WTD_STATEACTION_VERIFY,
        dwProvFlags = WTD_PROV_FLAGS_IGNORE_NOT_TIME_NESTED
    };

    Marshal.StructureToPtr(fileInfo, trustData.pFile, false);

    try
    {
        // 调用WinVerifyTrust,返回0表示验证通过
        uint result = WinVerifyTrust(IntPtr.Zero, IntPtr.Zero, ref trustData);
        return result == 0;
    }
    finally
    {
        trustData.dwStateAction = WTD_STATEACTION_CLOSE;
        WinVerifyTrust(IntPtr.Zero, IntPtr.Zero, ref trustData);
        Marshal.FreeHGlobal(trustData.pFile);
    }
}

注意事项

  • 运行代码需要足够的权限,否则可能无法访问某些系统进程的主模块。
  • 第一种方法仅检查是否存在签名,不验证签名是否有效或受信任;第二种方法会验证签名的信任链,结果更可靠。

内容的提问来源于stack exchange,提问作者user18922970

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 09:50:33