Hi,
after removing the Elastic Agent with Endpoint Security the service registration of ElasticEndpoint is stuck in Windows. In services I can see Elastic Endpoint, with "Failed to read description. Error code 2". Also sc query elasticendpoint returns the service.
OS is Windows 2021R2. All Elastic software used are version 8.1.1.
"sc delete" returns access denied. I have no entries in "HKLM\SYSTEM\CurrentControlSet\Services. Tried multiple tools to remove the service or run a command prompt as SYSTEM or TrustedInstaller.
Tried fixing it from safe boot, but the Elastic Endpoint registration is not visible?
"endpoint-security.exe uninstall" cannot remove the service, also due to access denied (see log below).
Any ideas how to fix this? As long as I cannot remove this registration, I cannot reinstall Endpoint Security.
2022-04-06 13:06:30: info: Main.cpp:284 Executing uninstall
2022-04-06 13:06:30: debug: Service.cpp:817 PPL is supported. This process is unprotected. (TrustLevelSid: absent)
2022-04-06 13:06:30: error: Util.cpp:578 Unexpected failure querying service protection configuration: 2
2022-04-06 13:06:30: trace: Util.cpp:623 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: warning: Util.cpp:1136 Error encountered while unprotecting service for uninstall
2022-04-06 13:06:30: error: Service.cpp:329 OpenServiceW(ElasticEndpointDriver)failed with error 1060
2022-04-06 13:06:30: trace: Service.cpp:330 Function returned error status (Failure in an external software component) because of system status (1060/The specified service does not exist as an installed service.)
2022-04-06 13:06:30: trace: Service.cpp:389 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: error: Service.cpp:187 DeleteService(ElasticEndpoint) failed with error 5
2022-04-06 13:06:30: trace: Service.cpp:188 Function returned error status (Failure in an external software component) because of system status (5/Access is denied.)
2022-04-06 13:06:30: warning: Util.cpp:1174 Endpoint service scheduled for deletion at next reboot.
2022-04-06 13:06:30: error: Service.cpp:178 OpenServiceW(ElasticEndpointDriver)failed with error 1060
2022-04-06 13:06:30: trace: Service.cpp:179 Function returned error status (Failure in an external software component) because of system status (1060/The specified service does not exist as an installed service.)
2022-04-06 13:06:30: error: Util.cpp:1197 Endpoint driver service was unable tobe deleted or scheduled for deletion.
2022-04-06 13:06:30: error: Service.cpp:329 OpenServiceW(ElasticELAMDriver) failed with error 1060
2022-04-06 13:06:30: trace: Service.cpp:330 Function returned error status (Failure in an external software component) because of system status (1060/The specified service does not exist as an installed service.)
2022-04-06 13:06:30: trace: Service.cpp:389 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: error: Service.cpp:178 OpenServiceW(ElasticELAMDriver) failed with error 1060
2022-04-06 13:06:30: trace: Service.cpp:179 Function returned error status (Failure in an external software component) because of system status (1060/The specified service does not exist as an installed service.)
2022-04-06 13:06:30: error: Util.cpp:1223 ELAM driver service was unable to be deleted or scheduled for deletion.
2022-04-06 13:06:30: trace: Util.cpp:351 Function returned error status (Failedto delete registry key)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:920 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:699 Function returned error status (I/O error) because of system status (3/The system cannot find the path specified.)
2022-04-06 13:06:30: trace: File.cpp:699 Function returned error status (I/O error) because of system status (2/The system cannot find the file specified.)
2022-04-06 13:06:30: error: Util.cpp:578 Unexpected failure querying service protection configuration: 2
2022-04-06 13:06:30: trace: Util.cpp:710 Function returned error status (Failure in an external software component)
2022-04-06 13:06:30: trace: File.cpp:395 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:874 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:426 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:874 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:426 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:874 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:426 Function returned error status (Not found)
2022-04-06 13:06:30: trace: File.cpp:874 Function returned error status (Not found)
2022-04-06 13:06:30: warning: InstallLib.cpp:272 System reboot required to finish uninstall