The ThreatDown Uninstall Tool (TDUninstallTool.exe) is a standalone utility that removes ThreatDown files, services, drivers, and registry entries from a Windows endpoint. Use it as a last resort when the standard uninstall process doesn't complete successfully, which can happen for the following reasons:
- The Endpoint Agent is corrupted.
- Leftover files or registry entries from a prior uninstall attempt block the uninstall.
Before you begin
You'll need the following to use the ThreatDown Uninstall Tool:
- A Nebula Super Admin or Administrator, or a OneView Global, Site, or Customer Administrator, to download the tool.
- Local administrator privileges on the endpoint.
Delete the endpoint from Nebula or OneView before running the tool to remove it from the console. A reboot may also be required to complete removal after using the tool, so save any open work first.
Download the tool
- Sign in to Nebula or OneView.
- In the left navigation menu, click Download Center > Advanced Tools.
- For OneView, select a site from the site drop-down list.
- Under ThreatDown Uninstall Tool, click Download. This downloads TDUninstallTool.exe for the Nebula account or OneView site. The file cannot be used across multiple accounts or sites.
- The download action is logged on the Events page for auditing purposes.
- The tool is valid for 72 hours after download to ensure admin authentication before use. Once the time expires, an admin must log in to the platform again to obtain a new copy.
Run the tool
- Copy TDUninstallTool.exe to the target endpoint.
- Double-click TDUninstallTool.exe.
- Press Y to accept and continue with the removal.
- Wait for the on-screen message confirming the removal succeeded. A reboot may be required to complete the cleanup.
Status messages and error codes
The tool's events are logged locally on the endpoint in C:\Windows\Temp\mbst-clean-results.txt
Refer to the table below for resolutions to the messages or codes provided by the tool.
| Message | Error Code | Resolution |
|---|---|---|
| The ThreatDown Agent has been successfully uninstalled from your system | ERROR_SUCCESS (0) | No action needed. |
| A restart is required to finish removing the ThreatDown Agent | ERROR_SUCCESS_RESTART_REQUIRED (3011) | Restart the endpoint to complete removal. |
| The ThreatDown Agent could not be uninstalled from the system. Please contact ThreatDown support for assistance. | ERROR_UNABLE_TO_CLEAN (4311) | Contact Support and provide the tool's log file. |
| The uninstall tool has expired. Please download it again from the ThreatDown Downloads Center. If you see the issue again, contact ThreatDown support for assistance. | ERROR_PASSWORD_EXPIRED (1330) |
The 72-hour window has passed. Return to the Download Center > Advanced Tools and download the tool again. If the issue persists, contact Support and provide the tool's log file. |
| Your uninstall tool isn't authenticated. Please download it again from the ThreatDown Downloads Center. If you see the issue again, contact ThreatDown support for assistance. | ERROR_NOT_AUTHENTICATED (1244) |
The copy of the tool is for a different account. Download a fresh copy from the correct Nebula account or OneView site's Download Center. If the issue persists, contact Support and provide the tool's log file. |