What is "Uninstall" evidence?
Summary
This article explains what "Uninstall" evidence is and how it's detected.
Synopsis
Applications that have the Evidence Type Uninstall are detected from the uninstall registry keys for Windows installer properties (Registry Editor).
They are written under this registry key:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\UninstallHKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
The values are stored in a subkey identified by the application's product code GUID.
The Uninstall value is among a select few values retrieved in the Raw evidence type column of the Evidence Tab that are specific only to the Raw evidence type and will not display in the Evidence type column on the All Evidence page.
"Uninstall" can indicate either it is installed or it has been removed (inappropriately) and the Windows registry key still remains in the system.
Note: In most cases, the Raw Installer Evidence Type of Uninstall, will only be used when referencing genuine uninstall evidence from the registry on a Windows device. However, some evidence is fabricated for specialist inventory collected by the agent, such as Oracle databases and applications (from the Oracle NDI), as well as IBM DB2 instances. This fabricated evidence is categorized under the Uninstall type. Additionally, the Uninstall type may be used for installer evidence imported from third party sources when the inventory source does not specify a particular evidence type.