+34 900 840 407
support@cytomic.ai

How to uninstall Advanced EPDR/EDR in Windows, Linux, macOS, iOS and Android

Related Products_
  • Advanced EPDR
  • Advanced EDR
Introduction

You can uninstall the Advanced EPDR/EDR software manually from the operating system?s control panel, or remotely from the Computers area or from the Computer protection status and Licenses lists.

Manual Uninstallation

The Advanced EPDR/EDR software can be manually uninstalled by end users themselves, provided the administrator has not set an uninstallation password when configuring the security profile for the computer in question. If an uninstallation password has been set, the end user will need authorization or the necessary credentials to uninstall the protection.
Installing Advanced EPDR/EDR  products actually installs multiple independent programs depending on the target platform:

  • Windows and macOS computers: agent and protection.
  • Linux computers: agent, protection and kernel module.
  • Android devices: protection.
  • iOS devices: Protection and MDM profile if the device is managed by an MDM solution.

To completely uninstall the software, all modules must be removed. If only the protection module is uninstalled, the agent will install it again after some time.

  • On Windows:
    • On Windows 8 and later: Control Panel > Programs > Uninstall a program.
      Alternatively, type ‘uninstall a program‘ at the Windows Start Screen.
    • On Windows Vista, Windows 7, Windows Server 2003 and later: Control Panel > Programs and Features > Uninstall or change a program.
    • On Windows XP: Control Panel > Add or remove programs.
    • During the uninstallation process, some files or libraries might not be completely removed, causing errors.
      In a case like that, it is necessary to use the tool provided by Advanced EPDR/EDR to completely uninstall the agent and protection. Please follow the steps below:

      1. Download and unzip the file dg_aether.zip (password panda).
      2. First, run the agent removal file DG_AETHER.exe file and restart the computer.
      3. Next, run the protection removal file DG_PANDAPROT_8_XX.exe and restart the computer.
      4. The uninstallation process may take a few minutes. Once it is complete, restart the computer.
  • On macOS:
    • Open Finder > Applications > Utilities > Terminal and run the following command:
      sudo sh /Applications/Endpoint-Protection.app/Contents/uninstall.sh
    • To remove the agent, you have to run the following command:
      sudo sh /Applications/Management-Agent.app/Contents/uninstall.sh
  • On Android devices:
    1. Go to Settings, Security > Device administrators
    2. Clear the Advanced EPDR/EDR checkbox. Then, tap Disable > OK.
    3. Back in the Settings window, tap Apps.
    4. Click the product, for example, EDR > Uninstall > OK.
  • On Linux:
    On Linux, use the desktop environment to manage the packages included in the distribution.

    • Fedora: Activities > Software > Installed
    • Ubuntu: Ubuntu software> Installed
    • We recommend using the command line to uninstall the product:
      • /usr/local/management-agent/repositories/pa/install –remove
        (this will remove the protection)
      • /usr/local/management-agent/repositories/ma/install –remove
        (this will remove the agent and repositories)
  • On an iOS device not enrolled into an MDM solution
    • Tap and hold the WatchGuard Mobile Security app on the Home screen. All the apps on the device start jiggling and the icon “-” appears on all of them.
    • Tap the “-“ icon in the upper-left corner of the WatchGuard Mobile Security app. The Delete WatchGuard Mobile Security? dialog box opens.
    • Tap Delete app. The Do you want to delete WatchGuard Mobile Security? dialog box opens.
    • Tap Delete. The app is uninstalled from the mobile device.
  • On an iOS device enrolled into the Cytomic MDM solution
    • On the Home screen, tap Settings. The Settings app opens.
    • From the side panel, tap General. The General window opens.
    • Tap VPN and device management. The WatchGuard MDM Service downloaded profile is shown.
    • Tap Remove management. The Remove management window opens.
    • Tap the Remove button. The management profile is removed. Next, the WatchGuard Mobile Security app is also removed.
  • On an iOS device enrolled into a third-party MDM solution
    Unlike with devices enrolled into the Cytomic MDM solution, in this case we recommend that you uninstall the WatchGuard Mobile Security app using the third-party MDM solution from which it is managed. If you delete the management profile manually from the smartphone, all the software that was installed using the MDM solution is also lost, and the device can no longer be centrally managed from the MDM solution.

Remote uninstallation
To remotely uninstall the Advanced EPDR/EDR software on a Windows computer:

  • Go to the Computers menu (or the Licenses or Computer protection status lists), and select the checkboxes for the computers whose protection you want to uninstall.
  • From the action bar, click Delete. A confirmation window is displayed.
  • In the confirmation window, select the Uninstall the agent from the selected computers checkbox to completely remove the Advanced EPDR/EDR software.

Remote uninstallation is only supported on Windows platforms. On Linux and macOS platforms, the affected computer is removed from the management console and all of its counters, but it reappears in the next discovery task.

Remote Uninstallation

Follow these steps to remotely uninstall the software from a Windows computer:

  • Access the Computers area (or the Licenses or Computer protection status lists), and select the checkboxes of the computers whose protection you want to uninstall.
  • From the action bar, click the Delete button. A confirmation window will be displayed.
  • In the confirmation window, select the Uninstall the Cytomic agent from the selected computers checkbox to completely remove the Cytomic software.

Once uninstalled, all data associated with the computers will disappear from the management console and its different counters (malware detected, URLs blocked, emails filtered, devices blocked, etc.). However, all that information will be retrieved as soon as you reinstall the Cytomic software.

NOTE: Remote uninstallation is only supported on Windows platforms. On Linux and macOS platforms, the affected computer and its associated information will be removed from the management console and its counters, but they will immediately reappear in the next discovery task.