I am a support analyst for my company - one of our users is trying to install Designer 2025 but the installer is having difficulty removing the currently installed 2024 version.. Additionally, our IT security team flagged some suspicious activity related to the removal process on the user's computer:
A process event captured the execution of pcalua.exe with the following command line, which launched an executable from the user profile of US\girijavV:
C:\WINDOWS\system32\pcalua.exe -a C:\Users\girijavV\AppData\Roaming\Alteryx\Engine\2024.2\UninstallAYX.exe
The parent process for pcalua.exe was the Windows Task Scheduler service:
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
The pcalua.exe process ran in the context of user US\girijavV and subsequently started:
C:\Users\girijavV\AppData\Roaming\Alteryx\Engine\2024.2\UninstallAYX.exe
Process creation and event capture times confirm the sequence:
No additional processes or activities related to this event are included in the provided data.
Timeline
Process Tree
wininit.exe
└── C:\WINDOWS\system32\services.exe
└── C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
└── C:\WINDOWS\system32\pcalua.exe -a C:\Users\girijavV\AppData\Roaming\Alteryx\Engine\2024.2\UninstallAYX.exe
└── C:\Users\girijavV\AppData\Roaming\Alteryx\Engine\2024.2\UninstallAYX.exe
They are concerned that a scheduled task was launched and that the Windows 11 Program Compatibility Assistant was used in the process.
Need to confirm that this is expected behavior for removing Alteryx or if this is malicious activity.
I would submit this as a case to Alteryx if there is a concern about security - you can submit it here: MyAlteryx
unfortunately we do not have an Alteryx support plan that I know of!
Can you try to log in and see if you can still? Usually you can submit a case, the response time just may be slower

