Symantec Endpoint Protection Client Uninstall

I am trying to use a managed installation to uninstall Symantec. I am able to get it to work using the uninstall command from the software page:

Uninstall Command:

MsiExec.exe /I{7D256468-9487-4498-9C6F-F18E9DCEA212}

The problem is I can't get it to work silently. I've tried the /qb switch and the /silent switch. I've tried it before the /I switch and I've tried it after the product key. It always looks like it runs successfully but Symantec is never uninstalled.

Anyone ever do this successfully and if so how did you do it? Symantec is telling me I have to user clean wipe one each of our 1300 PCs individually.


1 Comment   [ + ] Show comment
  • the /I switch in MSIs signify install rather than uninstall. You'll want something like: MsiExec.exe /qn /X {7D256468-9487-4498-9C6F-F18E9DCEA212} - JasonEgg 1 year ago

Answers (4)

Posted by: Hobbsy 1 year ago
Red Belt

Do you still have the installation msi file? If so I would run it with a /? In the command line to see if the option has actually been made available by Symantec. There is a chance that they have not done this, in which case it is a Symantec issue rather than a KACE issue and you will just have to accept that it can’t be done, good luck

Posted by: andrea.gennari@aslmn.it 1 year ago
Yellow Belt

Hi, the only way to perfectly uninstall SEP is to run the Cleanwipe utility. I tried in many way to deploy this automatically but always fault. 

Posted by: ScottAday 12 months ago
Senior Yellow Belt

We had similar issues removing SEP from our workstations. Using the uninstall command via KACE was hit or miss and sometimes running it locally still required running it a couple of times to get the uninstall to complete. Cleanwipe is the best way to get rid of this.

Posted by: angelous1186 11 months ago
White Belt

I was able to remove SEP using PowerShell commands. 

This command will pull the MSI ID for the uninstall.
GWMI Win32_Product | where{$_.Caption -like "*Symantec*"}

If you find like me you have both End Point and Cloud Agent then this took two separate runs.

First I had to disable the startups.
Set-Service -Name SsPaAdm -StartupType Disabled
Set-Service -Name ssPaSetMgr -StartupType Disabled

Then run the below for End Point. Change your MIS Id as needed
msiexec /x "{4C89867B-2E80-4B0D-87DB-1BD643D5EF5D}" /qb

Follow by a restart. 

After I used the below to remove Cloud Agent. Keep in mind the above for End Point doesn't Force a reboot. And occasionally it took two reboots. The below will force a reboot on the machine.
(Get-WmiObject -Class Win32_Product -Filter "Name='Symantec.cloud - Cloud Agent'").Uninstall()

This worked for most of our workstations. 

This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ