求可检测用户Local AppData中Chrome安装情况的PowerShell脚本
检测多用户机器上Local AppData中的Google Chrome
为什么你的脚本没结果
你用的脚本只查询了**HKLM(系统级)的卸载注册表项,而用户个人安装到Local AppData的Chrome,不会注册到系统级注册表,只会写在当前用户的HKCU(用户级)**注册表,或者直接以绿色版形式放在用户目录里,所以检测不到。
解决方案脚本
方案1:直接遍历用户目录查找Chrome程序
这个脚本会遍历所有本地用户的AppData\Local\Google\Chrome\Application目录,检查是否存在chrome.exe,同时输出用户名和计算机名:
# 获取本地所有用户目录 $userProfiles = Get-ChildItem -Path "C:\Users" -Directory | Where-Object { $_.Name -notin @("Public", "Default", "Default User", "All Users") } # 遍历每个用户目录检查Chrome foreach ($user in $userProfiles) { $chromePath = Join-Path -Path $user.FullName -ChildPath "AppData\Local\Google\Chrome\Application\chrome.exe" if (Test-Path -Path $chromePath) { [PSCustomObject]@{ ComputerName = $env:COMPUTERNAME Username = $user.Name ChromePath = $chromePath InstallType = "Local AppData 个人安装" } } }
方案2:加载用户注册表 hive 查找卸载项
如果Chrome在用户级注册了卸载信息,可以加载每个用户的NTUSER.dat文件来查询,需要管理员权限:
# 获取本地所有用户目录 $userProfiles = Get-ChildItem -Path "C:\Users" -Directory | Where-Object { $_.Name -notin @("Public", "Default", "Default User", "All Users") } foreach ($user in $userProfiles) { $ntuserPath = Join-Path -Path $user.FullName -ChildPath "NTUSER.dat" if (Test-Path -Path $ntuserPath) { # 临时加载用户注册表 hive $regPath = "HKU\Temp_$($user.Name)" reg load $regPath $ntuserPath | Out-Null # 查询用户级卸载项中的Chrome $chromeUninstall = Get-ItemProperty -Path "$regPath\Software\Microsoft\Windows\CurrentVersion\Uninstall\*" -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -eq "Google Chrome" } if ($chromeUninstall) { [PSCustomObject]@{ ComputerName = $env:COMPUTERNAME Username = $user.Name DisplayName = $chromeUninstall.DisplayName InstallLocation = $chromeUninstall.InstallLocation InstallType = "用户级注册表注册" } } # 卸载临时加载的 hive(必须执行,否则用户无法登录) reg unload $regPath | Out-Null } }
注意事项
- 运行脚本需要管理员权限,否则无法访问其他用户的目录或加载NTUSER.dat。
- 部分用户目录可能因权限限制无法访问,脚本会自动跳过。
- 方案2中如果用户当前登录,NTUSER.dat可能被锁定无法加载,此时方案1更可靠。
内容的提问来源于stack exchange,提问作者Uhmazing34
相关产品推荐
相关产品推荐

