{"id":10731,"date":"2012-03-18T00:01:00","date_gmt":"2012-03-18T00:01:00","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2012\/03\/18\/use-powershell-to-find-and-remove-remote-registry-entries\/"},"modified":"2012-03-18T00:01:00","modified_gmt":"2012-03-18T00:01:00","slug":"use-powershell-to-find-and-remove-remote-registry-entries","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/use-powershell-to-find-and-remove-remote-registry-entries\/","title":{"rendered":"Use PowerShell to Find and Remove Remote Registry Entries"},"content":{"rendered":"<p><b>Summary<\/b>: Microsoft Scripting Guy, Ed Wilson, shows how to use Windows PowerShell to find and remove registry entries from remote systems.<\/p>\n<p>Microsoft Scripting Guy, Ed Wilson, is here. It seems that weekends go faster and faster these days. For one thing, spring has definitely sprung down here in Charlotte, North Carolina in the southern portion of the United States. In fact, this past week we had to mow the grass in our yard. But we have not yet turned on our solar collector (that will happen in about another week or so).<\/p>\n<p>Anyway, I am mellowing out around the house this morning&mdash;the Scripting Wife plans to meet up with a few friends later in the day. Tomorrow is <a href=\"http:\/\/ipugd.org\/\" target=\"_blank\">International PowerShell User Group Day<\/a>, and I am reviewing the presentation I will make for that important event. On Friday, I make two presentations at the <a href=\"http:\/\/www.carolinait.org\/MeetingInfoPublic.aspx?mid=147\" target=\"_blank\">Charlotte IT Pro Appreciation Day<\/a> conference in Charlotte, North Carolina. That conference is expected to attract nearly a thousand people from all over the area, and it should be an excellent educational opportunity. I am looking forward to attending some great sessions, in addition to the two sessions that I present.<\/p>\n<p>One question I received during the <a href=\"http:\/\/blogs.technet.com\/b\/heyscriptingguy\/archive\/2012\/03\/06\/windows-powershell-for-the-busy-admin.aspx\" target=\"_blank\">past week of Live Meetings<\/a> was about finding and removing registry entries&mdash;not only from a local session, but also from remote computers. To do this, I like to use the Windows PowerShell registry provider, and incorporate it with Windows PowerShell remoting.<\/p>\n<p>In <a href=\"http:\/\/blogs.technet.com\/b\/heyscriptingguy\/archive\/2012\/03\/16\/use-powershell-to-edit-the-registry-on-remote-computers.aspx\" target=\"_blank\">Use PowerShell to Edit the Registry on Remote Computers<\/a>, I talked about one way to use Windows PowerShell remoting to create new entries on a remote computer. In <a href=\"http:\/\/blogs.technet.com\/b\/heyscriptingguy\/archive\/2012\/03\/17\/edit-the-registry-on-multiple-remote-computers-with-powershell.aspx\" target=\"_blank\">Edit the Registry on Multiple Computers with PowerShell<\/a>, I talked about running one command and editing the registry on multiple computers.<\/p>\n<p><b>Note<\/b>&nbsp;&nbsp;&nbsp; Today I will continue that discussion as I discuss finding and removing registry entries from multiple computers. For a good introduction to using Windows PowerShell to work with the registry, see <a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/2010\/04\/20\/hey-scripting-guy-april-20-2010.aspx\" target=\"_blank\">The Scripting Wife, Windows PowerShell, and the Registry<\/a>. <br \/> For more advanced topics, check out some of the other <a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/tags\/operating+system+\/registry\/Windows+PowerShell\/default.aspx\" target=\"_blank\">blog posts about the registry<\/a> in the Hey, Scripting Guy! Blog archives. There you will find blogs such as:<\/p>\n<ul>\n<li><a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/2009\/11\/30\/hey-scripting-guy-november-30-2009.aspx\" target=\"_blank\">Can I Change the Default Value of a Registry Key on Multiple Computers?<\/a><\/li>\n<li><a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/2009\/12\/01\/hey-scripting-guy-december-1-2009.aspx\" target=\"_blank\">How Can I List All User Profiles on a Remote Computer?<\/a><\/li>\n<li><a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/2009\/12\/02\/hey-scripting-guy-december-2-2009.aspx\" target=\"_blank\">Can I Use the Registry to Retrieve a List of the Most Recently Run Programs?<\/a><\/li>\n<li><a href=\"http:\/\/blogs.technet.com\/heyscriptingguy\/archive\/2009\/12\/03\/hey-scripting-guy-december-3-2009.aspx\" target=\"_blank\">How Can I Change Browser History Settings via the Registry?<\/a><\/li>\n<\/ul>\n<p>In the image that follows, there is an <b>HSG<\/b><i> <\/i>registry key that contains a <b>ForScripting<\/b><i> <\/i>property. Both of these need to be detected, and if they exist, they need to be deleted.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8272.WES-3-18-12-01.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8272.WES-3-18-12-01.png\" alt=\"Image of file\" title=\"Image of file\" \/><\/a><\/p>\n<p>The steps involved in detecting and removing the <b>HSG<\/b><i> <\/i>registry key are as follows:<\/p>\n<ol>\n<li>Use <b>Push-Location <\/b>to store the current location (<b>pushd<\/b> is an alias).<\/li>\n<li>Use <b>Set-Location <\/b>to change the working location to the registry drive (<b>sl<\/b> is an alias).<\/li>\n<li>Use <b>Test-Path <\/b>to determine if the <b>HSG<\/b><i> <\/i>registry key exists.<\/li>\n<li>Use <b>Remove-Item <\/b>to remove the registry key.<\/li>\n<li>Return to the original location by using <b>Pop-Location<\/b> (<b>popd<\/b> is an alias).<\/li>\n<\/ol>\n<p>The actual commands are shown here.<\/p>\n<p style=\"padding-left: 30px\">Pushd<\/p>\n<p style=\"padding-left: 30px\">sl HKCU:\\Software<\/p>\n<p style=\"padding-left: 30px\">Test-Path hsg<\/p>\n<p style=\"padding-left: 30px\">Remove-Item hsg<\/p>\n<p style=\"padding-left: 30px\">popd<\/p>\n<p>The commands and the output associated with the commands are shown in the image that follows.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8836.WES-3-18-12-02.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8836.WES-3-18-12-02.png\" alt=\"Image of command output\" title=\"Image of command output\" \/><\/a><\/p>\n<p>When I know I can successfully test for the presence of a specific registry key, and I know I can remove that registry key, I can put the commands together in a single command. This will facilitate using them with the <b>Invoke-Command <\/b>cmdlet to run against multiple remote computers.<\/p>\n<p>I recreate the registry key on my local computer by using the commands that are shown here.<\/p>\n<p style=\"padding-left: 30px\">pushd<\/p>\n<p style=\"padding-left: 30px\">sl HKCU:\\Software<\/p>\n<p style=\"padding-left: 30px\">New-Item -Name hsg<\/p>\n<p style=\"padding-left: 30px\">New-ItemProperty -Name forscripting -PropertyType string -Path hsg &ndash;Value &ldquo;PowerShell Rocks&rdquo;<\/p>\n<p style=\"padding-left: 30px\">popd<\/p>\n<p>Now, I create a single command to test for the registry key and to remove it if it exists. To do this, I use a semicolon to separate the logical commands. In addition, I added the <b>if<\/b><i> <\/i>statement to determine if the registry key exists before I attempt to delete it. In the <b>else<\/b><i> <\/i>condition, I display a message that the registry key does not exist. The command is shown here.<\/p>\n<p style=\"padding-left: 30px\">pushd;sl HKCU:\\Software; if(test-path hsg){remove-item hsg}ELSE{&#8220;hsg does not exist&#8221;};popd<\/p>\n<p>After I know the single line command works properly, I can easily add it to the <b>Invoke-Command <\/b>cmdlet to find and delete the registry key on all remote servers that are listed in the servers.txt file. The content of the servers.txt file is shown in the image that follows.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/6470.WES-3-18-12-03.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/6470.WES-3-18-12-03.png\" border=\"0\" alt=\"\" \/><\/a><\/p>\n<p>The revised command is a single-line logical command that spans multiple lines in the console. This command is shown here.<\/p>\n<p style=\"padding-left: 30px\">invoke-command -cn (cat c:\\fso\\servers.txt) -credential iammred\\administrator {pushd;sl HKCU:\\Software; if(test-path hsg){remove-item hsg}ELSE{&#8220;hsg does not exist&#8221;};popd}<\/p>\n<p>Well, that is about all there is to testing remote machines to see if they contain a specific registry key. I invite you to follow me on <a href=\"http:\/\/bit.ly\/scriptingguystwitter\" target=\"_blank\">Twitter<\/a> and <a href=\"http:\/\/bit.ly\/scriptingguysfacebook\" target=\"_blank\">Facebook<\/a>. If you have any questions, send email to me at <a href=\"mailto:scripter@microsoft.com\" target=\"_blank\">scripter@microsoft.com<\/a>, or post your questions on the <a href=\"http:\/\/bit.ly\/scriptingforum\" target=\"_blank\">Official Scripting Guys Forum<\/a>. See you tomorrow. Until then, peace.<\/p>\n<p><b>Ed Wilson, Microsoft Scripting Guy<\/b>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary: Microsoft Scripting Guy, Ed Wilson, shows how to use Windows PowerShell to find and remove registry entries from remote systems. Microsoft Scripting Guy, Ed Wilson, is here. It seems that weekends go faster and faster these days. For one thing, spring has definitely sprung down here in Charlotte, North Carolina in the southern portion [&hellip;]<\/p>\n","protected":false},"author":596,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[31,26,3,61,45],"class_list":["post-10731","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scripting","tag-operating-system","tag-registry","tag-scripting-guy","tag-weekend-scripter","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Summary: Microsoft Scripting Guy, Ed Wilson, shows how to use Windows PowerShell to find and remove registry entries from remote systems. Microsoft Scripting Guy, Ed Wilson, is here. It seems that weekends go faster and faster these days. For one thing, spring has definitely sprung down here in Charlotte, North Carolina in the southern portion [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/10731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/596"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=10731"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/10731\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=10731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=10731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=10731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}