Kaseya Community

Auto remove other AV clients

  • Other AV software clients (such as Trend) will automatically remove other AV software. We're finding the rollout of KES is much more labor intensive because of this.

    Please consider adding this.

    Cheers,
    bp

    Legacy Forum Name: Auto remove other AV clients,
    Legacy Posted By Username: bob.penland@kaseya.com
  • We just developed a quick script in Kaseya that removes CA eTrust 7.x & 8.x clients from Windows machines then pushed it out ourselves... in other words Kaseya has given us the tool to quickly and easily do it ourselves!

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: boudj
  • I second boudj's comment - we had a similar situation with SAV 10.x and just scripted up a "remove SAV" script.
    it was pretty straightforward - step 1, set the registry key that makes it not require an uninstall password, step 2, msiexec.exe /x with the right "stuff" to make it uninstall without interaction.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: Matthew Bartels
  • I agree this would be a very cool and useful feature. Sure, you can probably figure out how to do it yourself if you want to research every AV product out there and figure out how to silently uninstall each version, etc. Lots of work though, and even worse, lots and lots of testing and continuous upkeep for new versions.

    Since this is probably a common issue (we run into it with virtually every new client) and removal of existing AV is a prerequisite of KES, I think Kaseya (or KES provider) should invest in this research and implement this feature. It would certainly be innovative...

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: benny@geeksaknockin.com
  • bpenland
    Other AV software clients (such as Trend) will automatically remove other AV software. We're finding the rollout of KES is much more labor intensive because of this.

    Please consider adding this.

    Cheers,
    bp


    We have recently acquired an office that is / was running Trend. You can script the removal as follows.

    1. Impersonate an admin user.

    2. HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\Allow Uninstall (this is a REG_DWORD reg type).

    3. "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"

    4. Execute Shell
    "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"
    as user

    The process takes about 30 seconds total. As long as you have administrator rights to the machine you will be able to execute this without issue.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: bholloman
  • We have multiple customers we are upgrading to KES. We encounter multiple forms of Symantec, our previous A/V of choice ( SEP 11.x,10.x, NAV 2004, 2005 etc.). The regedit is usually not the same from one customer to another, and we don't always have to deal with uninstall passwords. Is there a quick easy way to address thes uninstalls? Or will I need to create several scripts? We also encounter Trend, and Zone Alarm users as well.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: BruceP
  • I would suggest taking an audit of all systems you want to move AV from. Then create a "select view" for machine groups by the software app you wish to remove (for example etrust antivirus). This will allow you to only view those machines that have the AV you are targeting. Next (looking up what you need in forums) create a script for the AV product you wish to remove. Finally, run it against the machine group you are filtering by software app.

    In the end you'll need to create different scripts for different apps because the uninstall process is designed by the app vendor and follows whatever process they require.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: boudj
  • Thanks, Cool Idea.
    It looks like I will need to create a few scripts for the different packages.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: BruceP
  • You probably will... however you'll find most of what you need in the forums.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: boudj
  • We are currently planning on adding this into KES 1.5 (development ongoing). If you have scripts that you'd like us to consider (that help us remove competitive products), please send them to me.

    Jeff.Keyes@kaseya.com

    Current products we are evaluating this automatic removal:

    Trend
    McAffee
    Symantec

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: Jeff.Keyes
  • trend-uninstall.txt
    Here's the script we use that does everything needed for the Trend OfficeScan 8.0 SP1 and higher. I just use reg import and this reg key to push the settings and then i run the ntrmv.exe like they say. However we don't allow local admins on the bulk of our macines so the impersonate user comes in extreeeemely handy here. I've uploaded the reg key here as well and it can be thinned down however needed, i just found it to be quicker personally.


    Script Name: Trend Micro Uninstall
    Script Description: This script will uninstall Trend Micro OfficeScan even if it has a master password assigned. For OfficeScan 80 SP1 and higher.

    IF True
    THEN
    Impersonate User
    Parameter 1 : admin-account
    Parameter 2 : password
    Parameter 3 : domain
    OS Type : 0
    Execute Shell Command
    Parameter 1 : net stop tmlisten
    Parameter 2 : 0
    OS Type : 0
    Execute Shell Command
    Parameter 1 : net stop ntrtscan
    Parameter 2 : 0
    OS Type : 0
    Write File
    Parameter 1 : c:\trend-uninstall.reg
    Parameter 2 : VSASharedFiles\Trend Uninstall\trend-uninstall.reg
    OS Type : 0
    Execute Shell Command
    Parameter 1 : reg import c:\trend-uninstall.reg
    Parameter 2 : 0
    OS Type : 0
    Delete File
    Parameter 1 : c:\trend-uninstall.reg
    OS Type : 0
    Execute File
    Parameter 1 : %programFiles%\Trend Micro\OfficeScan Client\ntrmv.exe
    Parameter 2 :
    Parameter 3 : 1
    OS Type : 0
    ELSE



    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: tsorensen@group1auto.com
  • Unfortunately we needed to CUT this feature from KES 2.0 (the renamed 1.5)

    BUT

    We also added a simpler feature for us which allows pre and post script processing as part of the roll-out. This will allow all of us to work on the never ending set of scripts that will remove the competitive environments prior to roll-out...as well as to clean up things that you would like to have differently after the KES endpoint is installed (like some folks want to remove the AVG status bar icon).

    That said,

    Seems like we'll need to collaborate on a master "get rid of any AV product out there" kind of script that we can all share...

    Jeff

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: Jeff.Keyes
  • I posted a no-nav script in the Scripts forum a couple of months ago. It removes all SAV and Norton installation pre SEP11.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: Lmhansen
  • Jeff.Keyes

    Seems like we'll need to collaborate on a master "get rid of any AV product out there" kind of script that we can all share...

    Jeff


    That being said, can Kaseya share the work on this to-date so that we can collaborate on it together going forward? Thanks Jeff.

    Michael

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: RCS-Michael
  • Also, I'd recommend a "special" forum for AV removal posts only. This way they are all organized on 1 spot.

    Legacy Forum Name: Kaseya End Point Security,
    Legacy Posted By Username: boudj