Uninstalling disguised Windows xAgent software

Prev Next

This section describes how to uninstall disguised Endpoint Security (HX) xAgent software running on your Windows endpoint.

To uninstall disguised Windows xAgent software:
  1. Locate the .msi installation file for the xAgent software. This must be for the same xAgent version that is installed on the host endpoint.

  2. Run the .msi file, selecting the Remove option when prompted.

  3. Confirm the software removal by responding Yes or clicking Remove as necessary.

    Important

    A reboot is necessary after uninstalling Trellix Endpoint Security (HX) xAgent version 29.

    Note

    Artifacts that remain in the C:\Windows\FireEye folder after the xAgent software has been uninstalled will be deleted the next time the endpoint host is rebooted.

    If a Windows xAgent uninstall attempt fails because the binary is missing or corrupt or because the

    ProgramData/FireEye
    or
    Program Files/FireEye
    directories are missing or corrupt, reinstall the agent using command-line commands (
    msiexec /i xagt.msi /qn
    ) and then uninstall it.