
To manually uninstall the Deep Security Agent, Relay and Notifier:

Trend Micro Deep Security NuAgent is only applicable for DS Agent version 20.0
  1. Disable the agent self-protection feature from the Deep Security Manager (DSM).
    If you cannot connect to Deep Security Manager, disable self-protection from command line.
  2. Stop the following services:
    • Trend Micro Deep Security Agent
    • Trend Micro Deep Security Monitor
    • Trend Micro Deep Security Notifier
    • Trend Micro Solution Platform
  3. Go to Local Area Network Properties and uninstall the following items:
    • Trend Micro Deep Security Agent Filter Driver (For Windows 2003)
    • Trend Micro LightWeight Filter Driver (For Windows 2008)

    Uninstall Trend Micro LightWeight Filter Driver

  4. Open the Command prompt and run the following commands to stop and delete the services:
    • sc stop tmactmon
    • sc stop tmevtmgr
    • sc stop tmcomm
    • sc stop tmumh
    • sc stop tmebc
    • sc stop tbimdsa
    • sc stop tmeyes
    • sc delete Amsp
    • sc delete ds_agent
    • sc delete ds_monitor
    • sc delete ds_notifier
    • sc delete tmactmon
    • sc delete tmevtmgr
    • sc delete tmcomm
    • sc delete tmumh
    • sc delete tmebc
    • sc delete tbimdsa
    • sc delete tmeyes

    Note that some service deletions may fail due to access denied and you can just skip it because Step 5 will completely delete the services after reboot.

  5. Delete the following registry entries:

    Always back up the whole registry before making any modifications. Incorrect changes to the registry can cause serious system problems
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Deep Security Agent
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Amsp
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_agent
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_monitor
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_notifier
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tbimdsa
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmactmon
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmcomm
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmevtmgr
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TMEBC
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmumh
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmeyes
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Deep Security Agent
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\tbimdsa\

    (Agent 32-bit)

    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and search "Deep Security" and delete the folder containing it.

    (Agent 64-bit)

    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and search "Deep Security" and delete the folder containing it.

    (Relay 32-bit)

    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and search "Deep Security" and delete the folder containing it.

    (Relay 64-bit)

    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and search "Deep Security" and delete the folder containing it.

    (Notifier 32-bit)

    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
    • Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ and search "Deep Security" and delete the folder containing it.
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
      Deep Security Notifier (string / REG _ SZ)
  6. Delete the following files and folders:
    • C:\WINDOWS\System32\Drivers\tbimdsa.sys
    • C:\WINDOWS\System32\Drivers\tmactmon.sys
    • C:\WINDOWS\System32\Drivers\tmcomm.sys
    • C:\WINDOWS\System32\Drivers\tmevtmgr.sys
    • C:\WINDOWS\System32\Drivers\tmeyes.sys
    • C:\WINDOWS\System32\Drivers\tmumh.sys
    • C:\WINDOWS\System32\Drivers\TMEBC64.sys
    • C:\WINDOWS\System32\Drivers\TMEBC32.sys
    • C:\WINDOWS\System32\LogFiles\ds_agent\
    • C:\Program Files\Trend Micro \AMSP\
    • C:\Program Files\Trend Micro \Deep Security Agent
    • C:\Program Files\Trend Micro \Deep Security Notifier
    • C:\ProgramData\Trend Micro\AMSP\
    • C:\ProgramData\Trend Micro\Deep Security Agent\
    • C:\ProgramData\Trend Micro\Deep Security Notifier\
    • C:\ProgramData\Microsoft\Windows\Start Menu \Programs\Trend Micro\
    • Deep Security\Trend Micro Deep Security Notifier (for Windows 2008)
    • C:\Documents and Settings\All Users\Start menu\programs\Trend Micro\
    • Deep Security\Trend Micro Deep Security Notifier (for Windows 2003)
  7. Restart the machine.
Comments (0)