NetLock RMMNetLock RMM Docs
III — How-To Guides

Uninstall an agent

Cleanly remove the NetLock RMM agent from a Windows, Linux, or macOS device using the installer's uninstall mode.

Uninstall an agent

This guide removes the NetLock RMM agent from a device and leaves it in a clean state — services deleted, processes stopped, install and data directories gone. It is the counterpart to Guide H.1. Uninstalling only affects the local device; the device record stays in the Console until you delete it there (see Verify it worked).

Before you start

  • You have administrator or root access on the target device. The uninstaller deletes services and protected directories, so it requires elevation on every supported OS.
  • You have the matching agent installer binary for the device's platform and architecture. Any build removes the agent — the embedded server configuration is ignored in this mode — but it must match the OS and architecture (for example a win-x64 build to uninstall on 64-bit Windows). On Windows, use a build from version 3.3.0.6 on: older builds leave the Windows Update settings the agent applied in place (see What gets removed). If you no longer have the original .zip, rebuild one from the Agent Download wizard as described in Guide H.1.
  • The uninstaller is part of the Standard Installer (console). If you only kept the GUI Installer, download a Standard Installer build for the uninstall.

What gets removed

The uninstall mode performs a full cleanup, in order:

  1. Stops the services — NetLock_RMM_Agent_Comm, NetLock_RMM_Agent_Remote, and NetLock_RMM_Agent_Health (plus the legacy 2.0.0.0 service names on Windows).
  2. Terminates the processes — the three agent services, the user process, the UAC helper, and the tray icon.
  3. Deletes the services — removes the Windows services, the Linux systemd units under /etc/systemd/system/, or the macOS LaunchDaemons under /Library/LaunchDaemons/, and unregisters the user-process and tray-icon Run entries on Windows.
  4. Releases Windows Update (Windows) — removes the Windows Update settings the agent applied for Disable Windows built-in automatic updates (see Chapter 6 — Policies): NoAutoUpdate and SetDisableUXWUAccess under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, and TrayIconVisibility under HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings. Only values the agent recorded as its own are removed; a WSUS configuration and values from your own group policies stay. Automatic updates resume, the Windows Update page shows its controls again without the "Some settings are managed by your organization" notice, and the Windows Update icon in the notification area is no longer hidden. The step also removes a NoAutoUpdate string value that agent versions before 3.2.0.0 wrote, the agent's registry key HKLM\SOFTWARE\WOW6432Node\NetLock RMM, and HKLM\SOFTWARE\0x101 Cyber Security once it is empty. No service is restarted.
  5. Deletes the directories and logs — the install tree under Program Files and the data tree under ProgramData, plus the agent service logs on Linux and macOS.

After it finishes, no NetLock RMM service, process, or directory remains on the device, and Windows Update is back under Windows' control.

Note: A fresh installation over an existing agent (clean mode, the --server parameter mode, or the installer with its embedded configuration) runs the same cleanup first. On a device whose policy disables Windows' automatic updates, the agent applies the Windows Update settings again within a few minutes of its first policy sync. A repair (fix, also used by agent updates) keeps the settings.

Steps

  1. Copy the agent installer .zip to the target device (or locate the one you already deployed with).
  2. Extract it and run the installer with the uninstall argument from an elevated shell.

Windows (PowerShell, elevated):

Expand-Archive .\NetLockAgent.zip -DestinationPath .\NetLockAgent
.\NetLockAgent\NetLock_RMM_Agent_Installer.exe uninstall

For an unattended removal via GPO, Intune, or a script, combine uninstall with the same flags the installer accepts:

.\NetLock_RMM_Agent_Installer.exe uninstall --hidden --no-log
  • --hidden / -h — hide the console window (Windows only).
  • --no-log / --nolog — delete installer logs after completion.
  • --temp <path> / -t <path> — use a custom temporary directory (useful on appliance distros that block execution from the default temp location).

Linux / macOS (Bash, with sudo):

unzip NetLockAgent.zip -d NetLockAgent
chmod +x NetLockAgent/NetLock_RMM_Agent_Installer
sudo ./NetLockAgent/NetLock_RMM_Agent_Installer uninstall
  1. Wait for the installer to print Uninstall complete. and exit with code 0.

Note: uninstall is one of the installer's positional modes, alongside clean "<path-to-server_config.json>" (fresh install with an external config) and fix "<path>" (repair while preserving the server config). See Guide H.1 for the install and repair modes.

Verify it worked

  • The installer reports Uninstall complete. and exits without an error code.

  • The agent services are gone — Get-Service NetLock_RMM_Agent_* returns nothing on Windows, systemctl status netlock-rmm-agent-comm reports "not found" on Linux, and launchctl list | grep netlock is empty on macOS.

  • The install and data directories no longer exist:

    • Windows — C:\Program Files\0x101 Cyber Security and C:\ProgramData\0x101 Cyber Security.
    • Linux — /usr/0x101_Cyber_Security and /var/0x101 Cyber Security, and the logs under /var/log/netlock-rmm-agent-*.log.
    • macOS — /usr/local/bin/0x101_Cyber_Security and /Library/Application Support/0x101 Cyber Security.
  • Windows — the Windows Update settings are released. In an elevated command prompt:

    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /s
    reg query "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v TrayIconVisibility
    reg query "HKLM\SOFTWARE\0x101 Cyber Security" /s

    The first command lists neither NoAutoUpdate nor SetDisableUXWUAccess (it may report that the key does not exist, or show WSUS and group policy values, which stay). The second reports that the value was not found, the third that the key does not exist. Reopen Settings › Windows Update: Check for updates is available again.

  • The device still shows in the Console — uninstalling does not delete the record. Remove it from Devices (or Unauthorized Devices) by hand once the agent stops reporting in. See Chapter 3 — Managing Devices.

Troubleshooting

  • "Failed to elevate" and the installer exits. The uninstaller needs administrative or root privileges to delete services and protected directories. Re-run from an elevated PowerShell prompt (Windows) or with sudo (Linux / macOS).

  • A service is "marked for deletion" or a directory is locked. A process still holds a handle. The uninstaller already waits for the service manager to release handles, but if it raced an open management console or a running agent process, reboot the device and run uninstall again — the second pass clears any leftovers.

  • The device keeps reappearing in the Console. That is the cached device record, not a live agent. Confirm the services are gone (above), then delete the record in Devices. If the device genuinely re-registers, an installer or deployment task is reinstalling it — check your GPO, Intune, or Ansible jobs.

  • Windows Update stays locked after the uninstall ("Some settings are managed by your organization", no Check for updates). Installer builds before 3.3.0.6 do not release the Windows Update settings. A remote uninstall from the Console downloads the installer from your server, so it releases them once the server provides the 3.3.0.6 agent packages. For a device that was already uninstalled with an older build, remove the values in an elevated command prompt:

    reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /f
    reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v SetDisableUXWUAccess /f
    reg delete "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v TrayIconVisibility /f
    reg delete "HKLM\SOFTWARE\0x101 Cyber Security\NetLock RMM\Comm Agent" /v wu_lockdown_applied /f

    These commands delete single values, never a whole key; a value that does not exist only produces an error message. Skip the first two if your own group policy sets NoAutoUpdate or SetDisableUXWUAccess. If the values come back after a while, a group policy writes them — check with gpresult /h report.html.

  • Uninstaller fails on a Linux NAS or appliance distro. Some distributions — notably Synology and similar NAS systems — block execution from the default temporary directory. Re-run with --temp <path> / -t <path> pointing at a directory the system permits execution from, then retry.