脚本查询注册表路径并补建缺失键失败求助(含McAfee版本获取)
Fixing Your McAfee Agent Registry Check & Repair Script
First, let's break down the key issues in your current code:
- You aren’t properly capturing the output of
REG QUERY(needs wrapping in$()to assign to a variable) - There’s no error handling to detect when the registry key/value is missing
- The code to create the missing registry entry is incomplete
Below are two revised versions of your script that fix these problems—one using REG.exe (matching your original approach) and another using PowerShell’s native registry cmdlets (a more robust, maintainable alternative):
Option 1: Using REG.exe Commands
$Servers = "Testserver01" ForEach ($Server in $Servers) { # Get McAfee Agent Version Write-Host "Checking McAfee Agent version on $Server..." $agentVersionQuery = REG QUERY "\\$Server\HKLM\SOFTWARE\McAfee\DLP\Agent" /v AgentVersion 2>&1 if ($LASTEXITCODE -eq 0) { Write-Host "McAfee Agent Version found: $agentVersionQuery" } else { Write-Warning "McAfee Agent Version registry entry missing on $Server!" # Optional: Add code to trigger McAfee Agent reinstall if needed } # Check and repair the target registry key (adjust path/value to match your actual requirement) $targetKeyPath = "\\$Server\HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" $targetValueName = "FeatureSettingsOverride" Write-Host "Checking target registry key on $Server..." REG QUERY $targetKeyPath /v $targetValueName 2>&1 | Out-Null if ($LASTEXITCODE -ne 0) { Write-Host "Creating missing registry entry on $Server..." # Create the value (REG ADD auto-creates parent keys if needed with /f) REG ADD $targetKeyPath /v $targetValueName /t REG_DWORD /d 0 /f if ($LASTEXITCODE -eq 0) { Write-Host "Successfully created registry entry on $Server" } else { Write-Error "Failed to create registry entry on $Server" } } else { Write-Host "Registry entry already exists on $Server" } }
Key Fixes & Improvements:
- Redirected error output (
2>&1) to capture failures fromREG QUERY - Used
$LASTEXITCODEto check if the registry query succeeded or failed - Added explicit code to create the missing registry value with
REG ADD, including error checking - Added clear status messages for debugging
Option 2: Using PowerShell Native Registry Cmdlets (Recommended)
PowerShell’s built-in registry tools are more reliable and easier to read than REG.exe:
$Servers = "Testserver01" ForEach ($Server in $Servers) { # Connect to remote server's HKLM registry hive $remoteHKLM = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey('LocalMachine', $Server) # Get McAfee Agent Version Write-Host "Checking McAfee Agent version on $Server..." $mcAfeeKey = $remoteHKLM.OpenSubKey("SOFTWARE\McAfee\DLP\Agent") if ($mcAfeeKey) { $agentVersion = $mcAfeeKey.GetValue("AgentVersion") Write-Host "McAfee Agent Version found: $agentVersion" $mcAfeeKey.Close() } else { Write-Warning "McAfee Agent registry key missing on $Server!" } # Check and repair target registry key Write-Host "Checking target registry key on $Server..." # Open key with write access ($true parameter) $targetKey = $remoteHKLM.OpenSubKey("SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management", $true) if ($targetKey) { $targetValue = $targetKey.GetValue("FeatureSettingsOverride") if ($null -eq $targetValue) { Write-Host "Creating missing registry value on $Server..." $targetKey.SetValue("FeatureSettingsOverride", 0, [Microsoft.Win32.RegistryValueKind]::DWord) Write-Host "Successfully created registry entry on $Server" } else { Write-Host "Registry entry already exists on $Server with value: $targetValue" } $targetKey.Close() } else { Write-Error "Failed to access target registry key path on $Server" } $remoteHKLM.Close() }
Why This Is Better:
- No need to parse command-line output or exit codes
- Direct, type-safe access to registry values
- More readable and maintainable code
- Fine-grained control over permissions and value types
Important Notes:
- Ensure your account has administrative access to the remote servers (required to modify registry keys)
- Adjust the target registry path/value name in the script to match your actual repair requirement
- Test the script on a non-production server first to validate functionality
内容的提问来源于stack exchange,提问作者Slyons
相关产品推荐
相关产品推荐

