C#检测Windows进程数字签名报错:File无GetDigitalSignatures方法
问题解决:File类不存在GetDigitalSignatures方法
首先明确:.NET 原生的System.IO.File类并没有GetDigitalSignatures这个方法,你可能混淆了第三方库或自定义方法的名称。要检测文件数字签名,需要用.NET提供的安全相关API实现。
解决方案1:使用X509Certificate2检查签名(基础版)
通过System.Security.Cryptography.X509Certificates命名空间下的X509Certificate2类,可以读取文件的签名信息。如果文件没有签名,加载时会抛出异常。
修改后的完整代码
using System; using System.Diagnostics; using System.Security.Cryptography.X509Certificates; void DriverCheck() { Process[] processes = Process.GetProcesses(); foreach (Process process in processes) { try { if (process.MainModule != null) { bool isSigned = false; string filePath = process.MainModule.FileName; try { // 尝试加载文件的数字证书 using var cert = new X509Certificate2(filePath); // 如果加载成功,说明存在签名 isSigned = !string.IsNullOrEmpty(cert.Subject); } catch (CryptographicException) { // 无签名或加载失败时抛出此异常 isSigned = false; } catch (Exception ex) { // 处理其他异常(如文件无法访问) Console.WriteLine($"处理文件 {filePath} 时出错: {ex.Message}"); } if (isSigned) { Console.WriteLine($"{process.ProcessName} 的主模块已签名"); // 可以在这里获取证书详情,比如发行者、有效期等 // using var cert = new X509Certificate2(filePath); // Console.WriteLine($"发行者: {cert.Issuer}"); } else { Console.WriteLine($"{process.ProcessName} 的主模块未签名"); } } } catch (System.ComponentModel.Win32Exception) { // 进程无主模块或权限不足 } } }
解决方案2:使用WinVerifyTrust验证签名(严谨版)
如果需要验证签名是否受信任(而不仅仅是存在签名),可以调用Windows APIWinVerifyTrust,这是更准确的方式,因为有些签名可能无效或不在信任链中。
实现代码
using System; using System.Diagnostics; using System.Runtime.InteropServices; void DriverCheck() { Process[] processes = Process.GetProcesses(); foreach (Process process in processes) { try { if (process.MainModule != null) { string filePath = process.MainModule.FileName; bool isTrustedSigned = WinVerifyTrust(filePath); if (isTrustedSigned) { Console.WriteLine($"{process.ProcessName} 的主模块已签名且可信"); } else { Console.WriteLine($"{process.ProcessName} 的主模块未签名或签名不可信"); } } } catch (System.ComponentModel.Win32Exception) { // 进程无主模块或权限不足 } } } // P/Invoke 声明WinVerifyTrust相关结构和方法 [StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)] private struct WINTRUST_FILE_INFO { public uint cbStruct; public string pcwszFilePath; public IntPtr hFile; public IntPtr pgKnownSubject; } [StructLayout(LayoutKind.Sequential)] private struct WINTRUST_DATA { public uint cbStruct; public IntPtr pPolicyCallbackData; public IntPtr pSIPClientData; public uint dwUIChoice; public uint fdwRevocationChecks; public uint dwUnionChoice; public IntPtr pFile; public uint dwStateAction; public IntPtr hWVTStateData; public string pwszURLReference; public uint dwProvFlags; public uint dwUIContext; public IntPtr pSignatureSettings; } [DllImport("wintrust.dll", CharSet = CharSet.Unicode, SetLastError = true)] private static extern uint WinVerifyTrust(IntPtr hWnd, IntPtr pgActionID, ref WINTRUST_DATA pWVTData); private const uint WTD_UI_NONE = 2; private const uint WTD_REVOKE_NONE = 0; private const uint WTD_CHOICE_FILE = 1; private const uint WTD_STATEACTION_VERIFY = 1; private const uint WTD_STATEACTION_CLOSE = 2; private const uint WTD_PROV_FLAGS_IGNORE_NOT_TIME_NESTED = 0x00000200; private static bool WinVerifyTrust(string filePath) { var fileInfo = new WINTRUST_FILE_INFO { cbStruct = (uint)Marshal.SizeOf(typeof(WINTRUST_FILE_INFO)), pcwszFilePath = filePath }; var trustData = new WINTRUST_DATA { cbStruct = (uint)Marshal.SizeOf(typeof(WINTRUST_DATA)), dwUIChoice = WTD_UI_NONE, fdwRevocationChecks = WTD_REVOKE_NONE, dwUnionChoice = WTD_CHOICE_FILE, pFile = Marshal.AllocHGlobal(Marshal.SizeOf(typeof(WINTRUST_FILE_INFO))), dwStateAction = WTD_STATEACTION_VERIFY, dwProvFlags = WTD_PROV_FLAGS_IGNORE_NOT_TIME_NESTED }; Marshal.StructureToPtr(fileInfo, trustData.pFile, false); try { // 调用WinVerifyTrust,返回0表示验证通过 uint result = WinVerifyTrust(IntPtr.Zero, IntPtr.Zero, ref trustData); return result == 0; } finally { trustData.dwStateAction = WTD_STATEACTION_CLOSE; WinVerifyTrust(IntPtr.Zero, IntPtr.Zero, ref trustData); Marshal.FreeHGlobal(trustData.pFile); } }
注意事项
- 运行代码需要足够的权限,否则可能无法访问某些系统进程的主模块。
- 第一种方法仅检查是否存在签名,不验证签名是否有效或受信任;第二种方法会验证签名的信任链,结果更可靠。
内容的提问来源于stack exchange,提问作者user18922970
相关产品推荐
相关产品推荐

