当前位置: 首页 > news >正文

bat脚本实现获取非微软官方服务列表

Get-CimInstance -ClassName Win32_Service |Where-Object { $_.State -eq 'Running' -and $_.StartMode -ne 'Disabled' } |
ForEach-Object {$isMicrosoft = $false$signerInfo = '无可执行路径'if ($_.PathName) {# 提取可执行文件路径(处理带引号/参数的路径)$exePath = $_.PathName.Trim()if ($exePath -match '^\"(.+?)\"') {$exePath = $matches[1]  # 提取引号内路径} else {$exePath = $exePath.Split(' ')[0]  # 取第一个空格前的部分}# 验证是否为文件(非目录)且存在if ($exePath -and (Test-Path -LiteralPath $exePath -PathType Leaf -ErrorAction SilentlyContinue)) {try {$sig = Get-AuthenticodeSignature -FilePath $exePath -ErrorAction Stopif ($sig.SignerCertificate) {$subject = $sig.SignerCertificate.Subject$issuer = $sig.SignerCertificate.Issuer$signerInfo = "$subject;$issuer"# 检查是否微软签名if ($signerInfo -match 'Microsoft|Windows') {$isMicrosoft = $true}} else {$signerInfo = '未签名'}} catch {$signerInfo = "签名错误: $($_.Exception.Message)"}} else {$signerInfo = '路径无效或非文件'}}if (-not $isMicrosoft) {[PSCustomObject]@{Name        = $_.NameDisplayName = $_.DisplayNameStartMode   = $_.StartModeState       = $_.StateCompany     = $signerInfo}}
} |
Sort-Object DisplayName |
Format-Table -AutoSize -Property Name, DisplayName, StartMode, State, Company

虽然powershell 直接可以执行但ps1的执行不如bat方便,因此制作了此脚本,非加密

powershell -EncodedCommand "RwBlAHQALQBDAGkAbQBJAG4AcwB0AGEAbgBjAGUAIAAtAEMAbABhAHMAcwBOAGEAbQBlACAAVwBpAG4AMwAyAF8AUwBlAHIAdgBpAGMAZQAgAHwACgAgAFcAaABlAHIAZQAtAE8AYgBqAGUAYwB0ACAAewAgACQAXwAuAFMAdABhAHQAZQAgAC0AZQBxACAAJwBSAHUAbgBuAGkAbgBnACcAIAAtAGEAbgBkACAAJABfAC4AUwB0AGEAcgB0AE0AbwBkAGUAIAAtAG4AZQAgACcARABpAHMAYQBiAGwAZQBkACcAIAB9ACAAfAAKAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAAgAHsACgAgACAAIAAgACQAaQBzAE0AaQBjAHIAbwBzAG8AZgB0ACAAPQAgACQAZgBhAGwAcwBlAAoAIAAgACAAIAAkAHMAaQBnAG4AZQByAEkAbgBmAG8AIAA9ACAAJwDgZe9TZ2JMiO+NhF8nAAoACgAgACAAIAAgAGkAZgAgACgAJABfAC4AUABhAHQAaABOAGEAbQBlACkAIAB7AAoAIAAgACAAIAAgACAAIAAgACMAIADQY9ZT71NnYkyIh2X2Tu+NhF8I/wRZBnQmXhVf91MvAMJTcGWEdu+NhF8J/woAIAAgACAAIAAgACAAIAAgACQAZQB4AGUAUABhAHQAaAAgAD0AIAAkAF8ALgBQAGEAdABoAE4AYQBtAGUALgBUAHIAaQBtACgAKQAKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQB4AGUAUABhAHQAaAAgAC0AbQBhAHQAYwBoACAAJwBeAFwAIgAoAC4AKwA/ACkAXAAiACcAKQAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAGUAeABlAFAAYQB0AGgAIAA9ACAAJABtAGEAdABjAGgAZQBzAFsAMQBdACAAIAAjACAA0GPWUxVf91OFUe+NhF8KACAAIAAgACAAIAAgACAAIAB9ACAAZQBsAHMAZQAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAGUAeABlAFAAYQB0AGgAIAA9ACAAJABlAHgAZQBQAGEAdABoAC4AUwBwAGwAaQB0ACgAJwAgACcAKQBbADAAXQAgACAAIwAgANZTLHsATipOeno8aE1ShHbokAZSCgAgACAAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAAgACAAIAAgACMAIACMmsGLL2YmVDpOh2X2Tgj/XpfudlVfCf8UTlhbKFcKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQB4AGUAUABhAHQAaAAgAC0AYQBuAGQAIAAoAFQAZQBzAHQALQBQAGEAdABoACAALQBMAGkAdABlAHIAYQBsAFAAYQB0AGgAIAAkAGUAeABlAFAAYQB0AGgAIAAtAFAAYQB0AGgAVAB5AHAAZQAgAEwAZQBhAGYAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAKQApACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHQAcgB5ACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABzAGkAZwAgAD0AIABHAGUAdAAtAEEAdQB0AGgAZQBuAHQAaQBjAG8AZABlAFMAaQBnAG4AYQB0AHUAcgBlACAALQBGAGkAbABlAFAAYQB0AGgAIAAkAGUAeABlAFAAYQB0AGgAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAdABvAHAACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAJABzAGkAZwAuAFMAaQBnAG4AZQByAEMAZQByAHQAaQBmAGkAYwBhAHQAZQApACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHMAdQBiAGoAZQBjAHQAIAA9ACAAJABzAGkAZwAuAFMAaQBnAG4AZQByAEMAZQByAHQAaQBmAGkAYwBhAHQAZQAuAFMAdQBiAGoAZQBjAHQACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABpAHMAcwB1AGUAcgAgAD0AIAAkAHMAaQBnAC4AUwBpAGcAbgBlAHIAQwBlAHIAdABpAGYAaQBjAGEAdABlAC4ASQBzAHMAdQBlAHIACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABzAGkAZwBuAGUAcgBJAG4AZgBvACAAPQAgACIAJABzAHUAYgBqAGUAYwB0ADsAJABpAHMAcwB1AGUAcgAiAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACMAIADAaOVnL2YmVK5fb49+ew1UCgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAaQBmACAAKAAkAHMAaQBnAG4AZQByAEkAbgBmAG8AIAAtAG0AYQB0AGMAaAAgACcATQBpAGMAcgBvAHMAbwBmAHQAfABXAGkAbgBkAG8AdwBzACcAKQAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAGkAcwBNAGkAYwByAG8AcwBvAGYAdAAgAD0AIAAkAHQAcgB1AGUACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAfQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAfQAgAGUAbABzAGUAIAB7AAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAcwBpAGcAbgBlAHIASQBuAGYAbwAgAD0AIAAnACpnfnsNVCcACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAH0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAB9ACAAYwBhAHQAYwBoACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABzAGkAZwBuAGUAcgBJAG4AZgBvACAAPQAgACIAfnsNVBmV74s6ACAAJAAoACQAXwAuAEUAeABjAGUAcAB0AGkAbwBuAC4ATQBlAHMAcwBhAGcAZQApACIACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAAgACAAIAAgAH0AIABlAGwAcwBlACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAcwBpAGcAbgBlAHIASQBuAGYAbwAgAD0AIAAnAO+NhF/gZUhlFmJel4dl9k4nAAoAIAAgACAAIAAgACAAIAAgAH0ACgAgACAAIAAgAH0ACgAKACAAIAAgACAAaQBmACAAKAAtAG4AbwB0ACAAJABpAHMATQBpAGMAcgBvAHMAbwBmAHQAKQAgAHsACgAgACAAIAAgACAAIAAgACAAWwBQAFMAQwB1AHMAdABvAG0ATwBiAGoAZQBjAHQAXQBAAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIABOAGEAbQBlACAAIAAgACAAIAAgACAAIAA9ACAAJABfAC4ATgBhAG0AZQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEQAaQBzAHAAbABhAHkATgBhAG0AZQAgAD0AIAAkAF8ALgBEAGkAcwBwAGwAYQB5AE4AYQBtAGUACgAgACAAIAAgACAAIAAgACAAIAAgACAAIABTAHQAYQByAHQATQBvAGQAZQAgACAAIAA9ACAAJABfAC4AUwB0AGEAcgB0AE0AbwBkAGUACgAgACAAIAAgACAAIAAgACAAIAAgACAAIABTAHQAYQB0AGUAIAAgACAAIAAgACAAIAA9ACAAJABfAC4AUwB0AGEAdABlAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAQwBvAG0AcABhAG4AeQAgACAAIAAgACAAPQAgACQAcwBpAGcAbgBlAHIASQBuAGYAbwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAB9AAoAfQAgAHwACgBTAG8AcgB0AC0ATwBiAGoAZQBjAHQAIABEAGkAcwBwAGwAYQB5AE4AYQBtAGUAIAB8AAoARgBvAHIAbQBhAHQALQBUAGEAYgBsAGUAIAAtAEEAdQB0AG8AUwBpAHoAZQAgAC0AUAByAG8AcABlAHIAdAB5ACAATgBhAG0AZQAsACAARABpAHMAcABsAGEAeQBOAGEAbQBlACwAIABTAHQAYQByAHQATQBvAGQAZQAsACAAUwB0AGEAdABlACwAIABDAG8AbQBwAGEAbgB5AA=="

http://www.dtcms.com/a/317225.html

相关文章:

  • Minio 高性能分布式对象存储
  • LiveQing视频RTMP推流视频点播服务功能-云端录像支持按时间段下载录像时间段下载视频mp4
  • eclipse2023创建工作集
  • 西门子PLC基础指令6:读取时钟指令、设置时钟指令、使能含义与注意
  • 比特币量化模型高级因子筛选与信号生成报告
  • 视图 vs 直接使用复杂SQL:深入比较
  • 场外期权的卖方是什么策略?
  • 未给任务“Fody.WeavingTask”的必需参数“IntermediateDir”赋值。 WpfTreeView
  • WPF的C1FlexGrid的单元格回车换行输入
  • 自学嵌入式 day45 ARM体系架构
  • Android Studio 利用工具检查未被使用的字符串
  • 排序算法(二)
  • vasp计算弹性常数
  • GISBox中OSGB数据转3DTiles格式指南
  • DDoS防护中的流量清洗与智能调度:构建网络安全坚实屏障
  • 《动手学深度学习》读书笔记—9.6编码器-解码器架构
  • 秋招笔记-8.6
  • Hive【应用 04】常用DDL操作(数据库操作+创建表+修改表+清空删除表+其他命令)
  • Win7 RTM和SP1的区别
  • 系统运维之PXE原理篇
  • 【软考系统架构设计师备考笔记5】 - 专业英语
  • 手机充电器质量体系模板
  • Rust进阶-part5-trait
  • 深入理解SpringMVC DispatcherServlet源码及全流程原理
  • PHP-Casbin:现代化 PHP 应用的权限管理引擎
  • 小程序中,给一段富文本字符串文案特殊内容加样式监听点击事件
  • 移动商城平台适配:ZKmall开源商城鸿蒙 / 小程序端开发要点
  • 盲盒抽卡机小程序系统开发:打造个性化娱乐新平台
  • 用html写一个类似于postman可以发送请求
  • 8.6 JavaWeb(请求响应 P67-P74)