The following are the options for uninstalling the Security Agent from Windows devices:
- TmIEplg.dll/TmIEplg32
- TmProxy.dll/TmProxy32.dll
To uninstall the Security Agent using the web console:
- Log on to the WFBS-SVC web console.
- Go to the Security Agents tab and look for the Security Agent/s by either using the Search box or finding it manually in the Agent tree.
-
Tick the checkbox to select the Security Agent/s.
Click image to enlarge
-
Click Tasks > Uninstall Security Agent.
Click image to enlarge
The WFBS-SVC server will then send the command to the Security Agent. This may take a few minutes.
Refer to the KB article Uninstalling the Worry-Free Business Security Services (WFBS-SVC) Agent in Windows.
Perform manual uninstallation only if you encounter issues while uninstalling from the web console or Windows Control Panel. If so, do the following:
- Log on to the computer using an account with Administrator privileges.
-
Unload/Exit the Security Agent. Refer to the KB article Unloading the Security Agent of Worry-Free Business Security Services (WFBS-SVC).
You can disable the unload/exist password of the Security Agent by doing the followng:
- Log on to the WFBS-SVC web console.
- Go to Policies > Global Security Agent > Agent Control tab.
- Under Exit/Unlock, untick Require a password to exit the Security Agent or unlock advanced settings then click Save.
- On the target Security Agent, right-click on the icon on the system tray then click Update Now.
-
Open the Services console and stop the following services:
- Trend Micro Application Control Service (Agent) (For WFBS-SVC 6.6)
- Trend Micro Client/Server Security Agent
- Trend Micro Common Client Solution Framework
- Trend Micro Endpoint Application Control Agent Service (For WFBS-SVC 6.2 or newer)
- Trend Micro Endpoint Sensor Engine Wrapper (For WFBS-SVC 6.6)
- Trend Micro Endpoint Sensor Service (Agent) (For WFBS-SVC 6.6)
- Trend Micro Security Agent
- Trend Micro Security Agent Data Protection Service
- Trend Micro Security Agent Firewall
- Trend Micro Security Agent Listener
- Trend Micro Security Agent NT Proxy Service (For Windows XP, Vista/2008 computers or older)
- Trend Micro Security Agent RealTime Scan
- Trend Micro Unauthorized Change Prevention Service
- Worry-Free Business Security Services Windows Security Center Service
-
Open the Task Manager and make sure the following processes are not running:
- AcAgentService.exe (For WFBS-SVC 6.2 or newer)
- AcAgentUI.exe (For WFBS-SVC 6.2 or newer)
- Dsagent.exe
- Dtoop.exe
- ESClient.exe (For WFBS-SVC 6.6)
- ESEFrameworkHost.exe (For WFBS-SVC 6.6)
- ESEServiceShell.exe (For WFBS-SVC 6.6)
- HostedAgent.exe
- logWriter.exe
- Ntrtscan.exe
- PccNT.exe
- PccNtMon.exe
- PccNTUpd.exe
- TMBMSRV.exe
- TmCCSF.exe
- TMCPMAdapter.exe (For WFBS-SVC 6.1 or newer)
- TMiACAgentSvc.exe (For WFBS-SVC 6.6)
- TmListen.exe
- TmPfw.exe
- TmProxy.exe (For Windows XP, Vista/2008 computers or older)
- TmWSCSvc.exe (For WFBS-SVC 6.6)
- svcGenericHost.exe
- XPUpg.exe
-
Open the command prompt using administrator privileges and execute the following commands one by one:
-
For 32-bit:
regsvr32 /u /s "C:\Program Files\Trend Micro\Client Server Security Agent\TmdShell.dll"
regsvr32 /s /u "C:\Program Files\Trend Micro\Client Server Security Agent\AMSI\TmAMSIProvider.dll"
taskkill /F /IM explorer.exe
start explorer.exe -
For 64-bit:
regsvr32 /u /s "C:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmdShell_64x.dll"
regsvr32 /s /u "C:\Program Files (x86)\Trend Micro\Client Server Security Agent\AMSI\TmAMSIProvider64.dll"
taskkill /F /IM explorer.exe
start explorer.exe
-
-
Open the Registry Editor to delete registry keys that belong to WFBS-SVC.
Always back up the whole registry before making any modifications. Incorrect changes to the registry can cause serious system problems. -
Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and delete the following registry keys:
- AcAgentService (For WFBS-SVC 6.2 or newer)
- AcDriver (For WFBS-SVC 6.2 or newer)
- AcDriverHelper (For WFBS-SVC 6.2 or newer)
- DiscSvc
- DSASvc
- iVPAgent
- Ntrtscan
- SAKCD
- SAKFile
- SvcGenericHost
- tbimdsa
- Tmactmon
- TMBMServer
- TmCCSF
- tmcfw (For Windows XP or older)
- tmcomm
- tmebc
- tmeevw (For Windows 7/2008 R2 computers or newer)
- TMESC (For WFBS-SVC 6.6)
- Tmescore (For WFBS-SVC 6.6)
- TMESE (For WFBS-SVC 6.6)
- Tmesflt (For WFBS-SVC 6.6)
- Tmesutil (For WFBS-SVC 6.6)
- tmeext (For Windows XP or older)
- tmel (For Windows 8, Windows Server 2012, or newer)
- tmevtmgr
- TmFilter
- TMiACAgentSvc
- Tmlisten
- tmlwf (For Windows Vista/2008 computers or newer)
- tmnciesc
- TmPfw
- TmPreFilter
- tmpreflt
- TmProxy (For Windows XP, Vista/2008 computers or older)
- tmtdi (For Windows XP, Vista/2008 computers or older)
- tmumh (For WFBS-SVC 6.1 or newer)
- Tmusa (For Windows 7/2008 R2 computers or newer)
- Tmwfp (For Windows Vista/2008 computers or later versions)
- TmWSCSvc (For WFBS-SVC 6.6)
- VSApiNt
-
Go to HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services and delete the following registry keys:
- dlpnetfltr
- Perf_iCrcPerfMonMgr
- Perf_iCrcPerfMonMgr
- SAKFile
-
Locate and delete the following registry keys:
-
For 32-bit:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OfficeScanNT Monitor
-
For 64-bit:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OfficeScanNT Monitor
-
-
Locate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and delete the following registry keys:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wofie
-
For 32-bit:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C1F6E833-B25E-4C39-A026-D3253958B0D0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BED0B8A2-2986-49F8-90D6-FA008D37A3D2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HostedAgent
-
For 64-bit:
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall{A38F51ED-D01A-4CE4-91EB-B824A00A8BDF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall{BED0B8A2-2986-49F8-90D6-FA008D37A3D2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HostedAgent
-
Locate and delete the following registry keys:
-
For both 32-bit and 64-bit: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\
- AEGIS
- AMSP
- AMSPStatus (For WFBS-SVC 6.6)
- ESC (For WFBS-SVC 6.6)
- ESE (For WFBS-SVC 6.6)
- ESEStatus (For WFBS-SVC 6.6)
- Falcon (For WFBS-SVC 6.6)
- iACAgent (For WFBS-SVC 6.6)
- Endpoint Application Control Agent (For WFBS-SVC 6.2 or newer)
- NSC
- Osprey (For Windows 7/2008 R2 computers or newer)
- TMESD (For WFBS-SVC 6.6)
- WL (For WFBS-SVC 6.6)
- Wofie
-
For 32-bit: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\
- ClientStatus
- CPM (For WFBS-SVC 6.1 or newer)
- OEM
- OfcWatchDog
- Pc-cillinNTCorp
- WFBSSUpdater
-
For 64-bit: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\
- AEGIS
- ClientStatus
- CPM (For WFBS-SVC 6.1 or newer)
- NSC
- OEM
- OfcWatchDog
- Osprey (For Windows 7/2008 R2 computers or newer)
- Pc-cillinNTCorp
- WFBSSUpdater
-
-
Locate and delete the following keys from the HKEY_CLASSES_ROOT\Installer\ registry hive:
-
For 32-bit:
- HKEY_CLASSES_ROOT\Installer\Features\338E6F1CE52B93C40A623D5293850B0D
- HKEY_CLASSES_ROOT\Installer\Products\338E6F1CE52B93C40A623D5293850B0D
- HKEY_CLASSES_ROOT\Installer\Products\2A8B0DEB68928F94096DAF00D8733A2D
- HKEY_CLASSES_ROOT\Installer\Upgradecodes\8A88AE84D667B304CB368C99791A74A6
-
For 32-bit:For 64-bit:
- HKEY_CLASSES_ROOT\Installer\Features\DE15F83AA10D4EC419BE8B420AA0B8FD
- HKEY_CLASSES_ROOT\Installer\Products\DE15F83AA10D4EC419BE8B420AA0B8FD
- HKEY_CLASSES_ROOT\Installer\Products\2A8B0DEB68928F94096DAF00D8733A2D
- HKEY_CLASSES_ROOT\Installer\Upgradecodes\8A88AE84D667B304CB368C99791A74A6
-
- Locate and delete the following keys:
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{6138A34F-DCA4-48D0-95CC-51E1D8F30B58}
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\AMSI\Providers\{6138A34F-DCA4-48D0-95CC-51E1D8F30B58}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AMSI\Providers\{6138A34F-DCA4-48D0-95CC-51E1D8F30B58}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6138A34F-DCA4-48D0-95CC-51E1D8F30B58}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Trend Micro Worry-Free Business Security Service Recovery Pack Tool
- Reboot the Computer.