ThreatBook Agent
A way to uninstall ThreatBook Agent from your system
This web page is about ThreatBook Agent for Windows. Below you can find details on how to remove it from your computer. It is made by
Beijing ThreatBook Technology Co., Ltd. You can read more on Beijing ThreatBook Technology Co., Ltd or check for application updates
here. Detailed information about ThreatBook Agent can be seen at
https://threatbook.cn/. ThreatBook Agent is usually installed in the C:\Program Files (x86)\Threatbook\Agent directory, depending on the user's option. You can uninstall ThreatBook Agent by clicking on the Start menu of Windows and pasting the command line C:\Program Files (x86)\Threatbook\Agent\uninst.exe. Keep in mind that you might receive a notification for admin rights. ThreatBook Agent's main file takes around 488.78 KB (500512 bytes) and is named tbAgent.exe.
The executable files below are installed together with ThreatBook Agent. They occupy about 4.41 MB (
4623904 bytes) on disk.
- CtrlSC.exe (266.77 KB)
- safeSrv.exe (550.78 KB)
- tbAgent.exe (488.78 KB)
- tbAgentSrv.exe (430.28 KB)
- tbCommonHelper_x64.exe (513.28 KB)
- tbGuard.exe (620.78 KB)
- tbHelper.exe (896.28 KB)
- uninst.exe (506.28 KB)
- Tbhpca.exe (242.30 KB)
...click to view all...The information on this page is only about version
2.6.0.1100 of ThreatBook Agent. You can find below a few links to other ThreatBook Agent versions:
...click to view all...
Some files and registry entries are regularly left behind when you remove ThreatBook Agent.
Folders found on disk after you uninstall ThreatBook Agent from your PC:- C:\Program Files (x86)\Threatbook\Agent
The files below were left behind on your disk when you remove ThreatBook Agent:- C:\Program Files (x86)\Threatbook\Agent\7z.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\AmNvLMon.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\AmNvLMon64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\ca.dat
- C:\Program Files (x86)\Threatbook\Agent\cardinal\qrotload.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RNdrCfg.dat
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RNdrMonitor_x64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RNdrMonitor_x86.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RpsGRdn.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RpsGRdn64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RSvNrSor.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\RSvNrSor64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\samVigiL64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbAmsiProv.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbAmsiProv64.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinal.dat
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinal_Win7_X64.sys
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinal_Win7_X86.sys
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinal_Win8_X64.sys
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinal_Win8_X86.sys
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbCardinalDll.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\Tbhpca.exe
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbIjSecBase.dll
- C:\Program Files (x86)\Threatbook\Agent\cardinal\TbIjSecBase64.dll
- C:\Program Files (x86)\Threatbook\Agent\CtrlSC.dll
- C:\Program Files (x86)\Threatbook\Agent\CtrlSC.exe
- C:\Program Files (x86)\Threatbook\Agent\data\AbnormalProcControlMapping.dat
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\agent.common.attr
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\agent.module.attr
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\baseInfo
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\bdsetting
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\clouddetect
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\dbMgr
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\plugbase
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\PlugDisplay
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\PlugEndpointAsset
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\plugsaasedr
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\PlugSecurityBase
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\product
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\proxyInfo
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\quarantinePolicy
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\scanAuxilary
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\terminal.device.info
- C:\Program Files (x86)\Threatbook\Agent\data\bundle\venus
- C:\Program Files (x86)\Threatbook\Agent\data\content\aegis_base
- C:\Program Files (x86)\Threatbook\Agent\data\content\avSetting
- C:\Program Files (x86)\Threatbook\Agent\data\content\heliosSetting
- C:\Program Files (x86)\Threatbook\Agent\data\content\onAccessSetting
- C:\Program Files (x86)\Threatbook\Agent\data\content\popup_window
- C:\Program Files (x86)\Threatbook\Agent\data\content\tdSetting
- C:\Program Files (x86)\Threatbook\Agent\data\content\ti_collector
- C:\Program Files (x86)\Threatbook\Agent\data\content\trident
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\AUX_MISKILLING_tbagent_edr
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\AUX_QUARANTINE
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\CQData
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\crDATA
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\csDATA
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\ExcMon
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\Moneta3
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\oavsec
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\ProtectionLog
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\Store_E0
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\Store_SDC
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\Store_SEJ0
- C:\Program Files (x86)\Threatbook\Agent\data\ddb\tbsfp
- C:\Program Files (x86)\Threatbook\Agent\data\FileTrace.dat
- C:\Program Files (x86)\Threatbook\Agent\data\gol\AegisCore\2025042509_tbAgent.exe_W0_AegisCore_55176.log
- C:\Program Files (x86)\Threatbook\Agent\data\gol\AegisCore\2025042811_tbAgent.exe_W0_AegisCore_6900.log
- C:\Program Files (x86)\Threatbook\Agent\data\gol\gateway_saas\2025042509_tbAgentSrv.exe_Master_gateway_saas_53276.log
- C:\Program Files (x86)\Threatbook\Agent\data\gol\gateway_saas\2025042810_tbAgentSrv.exe_Master_gateway_saas_6660.log
- C:\Program Files (x86)\Threatbook\Agent\data\gol\PlugSaaSEdr\2025042509_tbAgent.exe_W0_PlugSaaSEdr_55176.log
- C:\Program Files (x86)\Threatbook\Agent\data\gol\PlugSaaSEdr\2025042811_tbAgent.exe_W0_PlugSaaSEdr_6900.log
- C:\Program Files (x86)\Threatbook\Agent\data\param\urgentHotfixParam
- C:\Program Files (x86)\Threatbook\Agent\data\PidGuidMapping.dat
- C:\Program Files (x86)\Threatbook\Agent\data\updroots.cab
- C:\Program Files (x86)\Threatbook\Agent\framework\cacert.pem
- C:\Program Files (x86)\Threatbook\Agent\framework\gateway.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\gateway_saas.dll
- C:\Program Files (x86)\Threatbook\Agent\framework\NetConfig.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.PlugDisplay.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.PlugEndpointAsset.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.Pluglc.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.PlugSaaSEdr.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.PlugSecurityBase.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.Plugtd.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\plugconf\conf.PlugTrident.xml
- C:\Program Files (x86)\Threatbook\Agent\framework\strategy\agent_strategy
- C:\Program Files (x86)\Threatbook\Agent\framework\tbTrident.dll
- C:\Program Files (x86)\Threatbook\Agent\framework\tbTrident.xml
- C:\Program Files (x86)\Threatbook\Agent\general\ActionLog\ActionLog.dll
- C:\Program Files (x86)\Threatbook\Agent\general\ActionLog\ActionLog.xml
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\backup\Security-bookmark.xml
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\libevtom.dll
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\libntwom.dll
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\libpsom.dll
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\lightmi.xml
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\MICore.dll
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\providers\EvtProvider.xml
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\providers\NtwProvider.xml
- C:\Program Files (x86)\Threatbook\Agent\general\LightMI\providers\PsProvider.xml
Use regedit.exe to manually remove from the Windows Registry the data below:- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\TBAgent
Open regedit.exe in order to remove the following values:- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\safeSrv\ImagePath
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tbAgentSrv\ImagePath
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tbGuardSrv\ImagePath
How to remove ThreatBook Agent from your PC with Advanced Uninstaller PRO
ThreatBook Agent is a program offered by the software company Beijing ThreatBook Technology Co., Ltd. Frequently, users decide to uninstall it. Sometimes this is efortful because removing this by hand requires some knowledge related to removing Windows programs manually. The best QUICK solution to uninstall ThreatBook Agent is to use Advanced Uninstaller PRO. Take the following steps on how to do this:
1. If you don't have Advanced Uninstaller PRO already installed on your system, install it. This is a good step because Advanced Uninstaller PRO is the best uninstaller and all around tool to optimize your system.
DOWNLOAD NOW- go to Download Link
- download the setup by pressing the DOWNLOAD button
- set up Advanced Uninstaller PRO
2. Start Advanced Uninstaller PRO. It's recommended to take your time to get familiar with the program's design and number of features available. Advanced Uninstaller PRO is a powerful package of tools.
3. Click on the General Tools button

4. Click on the Uninstall Programs tool

5. A list of the programs installed on the PC will appear
6. Scroll the list of programs until you find ThreatBook Agent or simply activate the Search field and type in "ThreatBook Agent". If it is installed on your PC the ThreatBook Agent app will be found automatically. After you select ThreatBook Agent in the list of programs, the following data about the application is shown to you:
- Star rating (in the lower left corner). The star rating explains the opinion other users have about ThreatBook Agent, ranging from "Highly recommended" to "Very dangerous".
- Opinions by other users - Click on the Read reviews button.
- Details about the application you want to uninstall, by pressing the Properties button.
For instance you can see that for ThreatBook Agent:
- The software company is: https://threatbook.cn/
- The uninstall string is: C:\Program Files (x86)\Threatbook\Agent\uninst.exe
7. Press the Uninstall button. A confirmation page will come up. Confirm the uninstall by clicking the Uninstall button. Advanced Uninstaller PRO will then uninstall ThreatBook Agent.

8. After uninstalling ThreatBook Agent, Advanced Uninstaller PRO will offer to run a cleanup. Click Next to go ahead with the cleanup. All the items of ThreatBook Agent which have been left behind will be found and you will be able to delete them. By removing ThreatBook Agent with Advanced Uninstaller PRO, you can be sure that no Windows registry entries, files or folders are left behind on your computer.
Your Windows computer will remain clean, speedy and ready to take on new tasks.
Disclaimer
The text above is not a recommendation to uninstall ThreatBook Agent by Beijing ThreatBook Technology Co., Ltd from your computer, we are not saying that ThreatBook Agent by Beijing ThreatBook Technology Co., Ltd is not a good software application. This page simply contains detailed instructions on how to uninstall ThreatBook Agent supposing you decide this is what you want to do. The information above contains registry and disk entries that Advanced Uninstaller PRO discovered and classified as "leftovers" on other users' PCs.
Last update on: 2025-04-28 03:26:13.160