Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Manually uninstalling Deep Security Agent, Relay, and Notifier from Windows

    • Updated:
    • 25 Jan 2016
    • Product/Version:
    • Deep Security 8.0
    • Deep Security 9.0
    • Deep Security 9.5
    • Platform:
    • Windows 2003 Enterprise
    • Windows 2003 Enterprise 64-bit
    • Windows 2003 Standard
    • Windows 2003 Standard 64-bit
    • Windows 2008 Enterprise
    • Windows 2008 Enterprise 64-bit
    • Windows 2008 Server R2
    • Windows 2008 Standard
    • Windows 2008 Standard 64-bit
Summary

Perform manual uninstallation when a customer is having issues uninstalling the Deep Security Agent, Relay, and Notifier.

Details
Public

To manually uninstall the Deep Security Agent, Relay and Notifier:

  1. Disable the agent self-protection feature from the Deep Security Manager (DSM).
    If you cannot connect to the DSM, disable self-protection from command line or the registry.
  2. Stop the following services:
    • Trend Micro Deep Security Relay
    • Trend Micro Deep Security Agent
    • Trend Micro Deep Security Notifier
    • Trend Micro Solution Platform
  3. Go to Local Area Network Properties and uninstall the following items:
    • Trend Micro DSA Filter Driver (For Windows 2003)
    • Trend Micro LightWeight Filter Driver (For Windows 2008)
  4. Open the command prompt and run the following commands to delete the services:
    • sc delete ds_agent
    • sc delete ds_notifier
    • sc delete Amsp
    • sc delete tmactmon
    • sc delete tmevtmgr
    • sc delete tmcomm
  5. Delete the following registry entries:

     
    Always back up the whole registry before making any modifications. Incorrect changes to the registry can cause serious system problems
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AMSP
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AMSPStatus
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Deep Security Agent
    • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\WL
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Amsp
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_agent
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_notifier
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tbimdsa
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmactmon
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmcomm
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmevtmgr
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Deep / Security Agent
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Deep / Security Relay
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\tbimdsa\

     

    (Agent 32-bit)

    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
      80E7CC013A4CD8F44AC9B49EB061392B]\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
      80E7CC013A4CD8F44AC9B49EB061392B]\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
      689D08D76B5A47A4FB59D97D2C4B9308]\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
      689D08D76B5A47A4FB59D97D2C4B9308]\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
      {10CC7E08-C4A3-4F8D-A49C-4BE90B1693B2}]\

     

    (Agent 64-bit)

    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
      C4AF20E48325C454BBBE163E418FCEA9\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
      C4AF20E48325C454BBBE163E418FCEA9\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
      689D08D76B5A47A4FB59D97D2C4B9308\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
      689D08D76B5A47A4FB59D97D2C4B9308\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
      {4E02FA4C-5238-454C-BBEB-61E314F8EC9A}\

     

    (Relay 32-bit)

    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
      C576B4AC76DEBD7428E62A20748B5BEE\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
      C576B4AC76DEBD7428E62A20748B5BEE\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
      9595A43D099883B49B6A1D3194B54E48\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
      9595A43D099883B49B6A1D3194B54E48\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
      {CA4B675C-ED67-47DB-826E-A20247B8B5EE}\

     

    (Relay 64-bit)

    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
      8AD1116DC93642C4F9032F4EFE4F1425\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
      8AD1116DC93642C4F9032F4EFE4F1425\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
      9595A43D099883B49B6A1D3194B54E48\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
      9595A43D099883B49B6A1D3194B54E48\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
      {D6111DA8-639C-4C24-9F30-F2E4EFF44152} \

     

    (Notifier 32-bit)

    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
      C2B7CFB8EB0E6FC4CA6C5E010B7B4298\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
      C2B7CFB8EB0E6FC4CA6C5E010B7B4298\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
      FD7DF71DF377E464F8F59FDA68339BD0\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\
      FD7DF71DF377E464F8F59FDA68339BD0\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
      {8BFC7B2C-E0BE-4CF6-ACC6-E510B0B72489} \
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
      Deep Security Notifier (string / REG _ SZ)
  6. Restart the machine.
  7. Delete the following files and folders:
    • C:\WINDOWS\System32\Drivers\tbimdsa.sys
    • C:\WINDOWS\System32\Drivers\tmactmon.sys
    • C:\WINDOWS\System32\Drivers\tmcomm.sys
    • C:\WINDOWS\System32\Drivers\tmevtmgr.sys
    • C:\WINDOWS\System32\LogFiles\ds_agent\
    • C:\Program Files\Trend Micro \AMSP\
    • C:\Program Files\Trend Micro \Deep Security Agent\Agent
    • C:\Program Files\Trend Micro \Deep Relay of Security Settings\Local (Relay)
    • C:\Program Files\Trend Micro \Deep Notifier of Security Settings\Local (Notifier)
    • C:\ProgramData\Microsoft\Windows\Start Menu \Programs\Trend Micro\
      Deep Security\Trend Micro Deep Security Notifier (for Windows 2008)
    • C:\Documents and Settings\All Users\Start menu\programs\Trend Micro\
      Deep Security\Trend Micro Deep Security Notifier (for Windows 2003)
    • C:\Windows\Installer\ {10CC7E08-C4A3-4F8D-A49C-4BE90B1693B2} / (Agent 32-bit)
    • C:\Windows\Installer\ {4E02FA4C-5238-454C-BBEB-61E314F8EC9A} / (Agent 64-bit)
    • C:\Windows\Installer\ {CA4B675C-ED67-47DB-826E-A20247B8B5EE} / (Relay 32-bit)
    • C:\Windows\Installer\ {D6111DA8-639C-4C24-9F30-F2E4EFF44152} / (Relay 64-bit)
    • C:\Windows\Installer\ {8BFC7B2C-E0BE-4CF6-ACC6-E510B0B72489} / (Notifier 32-bit)
Premium
Internal
Rating:
Category:
Uninstall
Solution Id:
1096150
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.