To manually uninstall the Vulnerability Protection Agent:
- Stop VPA services:
sc stop ds_agent
sc stop tbimdsa - Delete VPA services:
sc delete ds_agent
sc delete tbimdsa - Delete all files under following paths for VPA:
- C:\Program Files\Trend Micro\Vulnerability Protection Agent\*
- C:\ProgramData\Trend Micro\Deep Security Agent\*
- C:\Users\All Users\Trend Micro\Deep Security Agent\*
- C:\Windows\System32\DriverStore\FileRepository\nettbimdsa.inf_amd64_neutral_7bf92935b96598b1
- C:\Windows\System32\DriverStore\FileRepository\nettbimdsa.inf_amd64_neutral_7bf92935b96598b1\nettbimdsa.inf
- C:\Windows\System32\DriverStore\FileRepository\nettbimdsa.inf_amd64_neutral_7bf92935b96598b1\nettbimdsa.PNF
- C:\Windows\System32\DriverStore\FileRepository\nettbimdsa.inf_amd64_neutral_7bf92935b96598b1\tbimdsa.cat
- C:\Windows\System32\DriverStore\FileRepository\nettbimdsa.inf_amd64_neutral_7bf92935b96598b1\tbimdsa.sys
- Delete all the following registry keys for VPA:
- HKEY_CLASSES_ROOT\Installer\Products\F9103782F03CC464BA026FD9C854064A
- HKEY_CLASSES_ROOT\Installer\UpgradeCodes\689D08D76B5A47A4FB59D97D2C4B9308
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\F9103782F03CC464BA026FD9C854064A
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F9103782F03CC464BA026FD9C854064A
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\689D08D76B5A47A4FB59D97D2C4B9308
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\689D08D76B5A47A4FB59D97D2C4B9308\
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2873019F-C30F-464C-AB20-F69D8C4560A4}. The name {2873019F-C30F-464C-AB20-F69D8C4560A4} may be different with different versions/architectures of the OS. You can search for those with the key "Display name" = "Trend Micro Vulnerability Protection Agent".
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Deep Security Agent
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Vulnerability Protection Agent
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBIMDSA
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ds_agent
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tbimdsae
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Vulnerability Protection Agent