Regarding:
It doesn’t reproduce any error but it doesn’t seem to generate a executable or it’s removed before I can see it
Regarding:
It generates an executable that is immediately removed as expected
Regarding:
It doesn’t reproduce any error but it doesn’t seem to generate a executable or it’s removed before I can see it
Regarding:
It generates an executable that is immediately removed as expected
Well for the Se.exe.tmp.exe it seems to be that BemSvc.exe was granted access to it before it was unistaled:
A handle to an object was requested.
Subject:
Security ID: SYSTEM
Account Name: DELTA-MATE$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Users\user88\AppData\Local\crystal\cache\crystal-run-Se.exe.tmp.exe
Handle ID: 0x123c
Resource Attributes: -
Process Information:
Process ID: 0x1a60
Process Name: C:\Program Files\HP\Sure Click\servers\BemSvc.exe
Access Request Information:
Transaction ID: {00000000-0000-0000-0000-000000000000}
Accesses: DELETE
READ_CONTROL
SYNCHRONIZE
ReadData (or ListDirectory)
ReadAttributes
Access Reasons: DELETE: Granted by D:(A;;FA;;;SY)
READ_CONTROL: Granted by D:(A;;FA;;;SY)
SYNCHRONIZE: Granted by D:(A;;FA;;;SY)
ReadData (or ListDirectory): Granted by D:(A;;FA;;;SY)
ReadAttributes: Granted by D:(A;;FA;;;SY)
Access Mask: 0x130081
Privileges Used for Access Check: -
Restricted SID Count: 0
But for the other file the Se.exe.tmp.pdb it seems to be the crystal.exe
A handle to an object was requested.
Subject:
Security ID: DELTA-MATE\user88
Account Name: user88
Account Domain: DELTA-MATE
Logon ID: 0x45FC4
Object:
Object Server: Security
Object Type: File
Object Name: C:\Users\user88\AppData\Local\crystal\cache\crystal-run-Se.exe.tmp.pdb
Handle ID: 0x1fc
Resource Attributes: -
Process Information:
Process ID: 0x5548
Process Name: C:\Users\user88\AppData\Local\Programs\Crystal\crystal.exe
Access Request Information:
Transaction ID: {00000000-0000-0000-0000-000000000000}
Accesses: DELETE
ReadAttributes
Access Reasons: DELETE: Granted by D:(A;;FA;;;S-1-5-21-844892204-3111969441-295238923-1001)
ReadAttributes: Granted by D:(A;;FA;;;S-1-5-21-844892204-3111969441-295238923-1001)
Access Mask: 0x10080
Privileges Used for Access Check: -
Restricted SID Count: 0
Yeah, it was the BemSvc, basically it uninstalled the exe before avast warned me about which is why stopped nagging me about the executable and before crystal could use it, so this situation is more of a Hp problem than a Windows problem. Thanks, @npn, @straight-shoota and @beta-ziliani. Sorry for the inconvenience at the end it wasn’t even a Crystal thing, should I change the tittle so it isn’t inaccurate or leave it alone?
Great find
I think we can leave the title as is. It wasn’t very accurate from the beginning anyway (your probem wasn’t with installing but using Crystal ;) )