On Mon, 2 Nov 2020 15:17:01 -0000 (UTC), Arlen Holder wrote:
> Note: What we need is an installation logger which will log every change
> during an installation to see if the expiry date is in the registry.
It's just bad form that WhoCrashed has a secret hidden expiry date
o That makes any software archive utterly useless
But maybe we can figure out _where_ they put the hidden expiry date?
I will need to open a separate thread on how to archive installations
o To test, I ran "IObit Uninstaller" freeware on the WhoCrashed install
Although I know they could hide the hard-coded expiry date anywhere
o Nonetheless, I will look for clues in the installation monitor log
For example, maybe there's a clue to the expiry in these registry keys:
o HKCU\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.ExCount
o HKCU\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.FirstEx
o HKCU\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.LastTimeRun
o HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|InstallDate
etc.
===< below is the IOBit "MonitorLog_WhoCrashed 6.70 (x64).txt" >===
Program Information
Display name: WhoCrashed 6.70 (x64)
Publisher: Resplendence Software Projects Sp.
Version: -
Registry entries: 32
Files: 34
Total size: 32.2 MB
Install date: 11/2/2020 6:56:07 AM
Install package: C:\tmp\whoCrashedSetup (1).exe
Location: C:\app\hardware\bsod\whocrashed\
Installation duration: 41 seconds
Registry entries
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.ExCount
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.FirstEx
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WhoCrashed.v67031101.home.LastTimeRun
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WindowContainerSettings1
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WindowContainerSettings2
HKEY_CURRENT_USER\SOFTWARE\Resplendence Sp\WhoCrashed|Value|WindowContainerSettings3
HKEY_CURRENT_USER\Software\Resplendence Sp\WhoCrashed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data|Value|418A073AA3BC3475
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|DisplayIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: App Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: Deselected Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: Icon Group
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: Selected Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: Setup Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Inno Setup: User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|QuietUninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1|Value|URLUpdateInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WhoCrashed_is1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-1978554382-385915032-812892281-1001|Value|\Device\HarddiskVolume3\app\hardware\bsod\whocrashed\WhoCrashedEx.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-1978554382-385915032-812892281-1001|Value|\Device\HarddiskVolume3\Users\arlen\AppData\Local\Temp\is-70KGK.tmp\whoCrashedSetup (1).tmp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-1978554382-385915032-812892281-1001|Value|\Device\HarddiskVolume3\Users\arlen\AppData\Local\Temp\is-S995K.tmp\whoCrashedSetup (1).tmp
Files
C:\app\hardware\bsod\whocrashed
C:\app\hardware\bsod\whocrashed\dbgeng.dll
C:\app\hardware\bsod\whocrashed\dbghelp.dll
C:\app\hardware\bsod\whocrashed\dbgmodel.dll
C:\app\hardware\bsod\whocrashed\ext.dll
C:\app\hardware\bsod\whocrashed\exts.dll
C:\app\hardware\bsod\whocrashed\kdexts.dll
C:\app\hardware\bsod\whocrashed\kext.dll
C:\app\hardware\bsod\whocrashed\libeay32.dll
C:\app\hardware\bsod\whocrashed\LICENSE.TXT
C:\app\hardware\bsod\whocrashed\msvcr100.dll
C:\app\hardware\bsod\whocrashed\rspCrash32.inf
C:\app\hardware\bsod\whocrashed\rspCrash32.sys
C:\app\hardware\bsod\whocrashed\rspCrash64.inf
C:\app\hardware\bsod\whocrashed\rspCrash64.sys
C:\app\hardware\bsod\whocrashed\rspSymSrv32.dll
C:\app\hardware\bsod\whocrashed\ssleay32.dll
C:\app\hardware\bsod\whocrashed\symbolcheck.dll
C:\app\hardware\bsod\whocrashed\symsrv.dll
C:\app\hardware\bsod\whocrashed\unins000.dat
C:\app\hardware\bsod\whocrashed\unins000.exe
C:\app\hardware\bsod\whocrashed\WhoCrashed.txt
C:\app\hardware\bsod\whocrashed\WhoCrashed32.dll
C:\app\hardware\bsod\whocrashed\WhoCrashedEx.exe
C:\app\hardware\bsod\whocrashed\WinXP
C:\app\hardware\bsod\whocrashed\WinXP\dbgeng.dll
C:\app\hardware\bsod\whocrashed\WinXP\dbghelp.dll
C:\app\hardware\bsod\whocrashed\WinXP\msvcr100.dll
C:\app\hardware\bsod\whocrashed\WinXP\symbolcheck.dll
C:\app\hardware\bsod\whocrashed\WinXP\symsrv.dll
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed\WhoCrashed.lnk
C:\Users\arlen\AppData\Local\Temp\rsptmp410843312000.html
C:\Users\arlen\Desktop\WhoCrashed.lnk
===< above is the MonitorLog_WhoCrashed 6.70 (x64).txt >===