Problem uninstalling Cortex XDR Agent

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Problem uninstalling Cortex XDR Agent

L0 Member

I often have the problem that the host loses connection to Cortex console due to a failed agent update and I cannot uninstall the agent on it and reinstalling the agent results in a rollback. There is a file named "tdevflt.sys" left in the "C:\Program Files\Palo Alto Networks\Traps" folder that prevents me from reinstalling the agent. The only thing I can do is reinstall the operating system, because deleting the file forcibly results in a problem with the I/O devices. Is there any tool I can use to completely remove the remains of the Cortex agent from the host so I can reinstall it??


L2 Linker

Yes, there is a tool you can leverage in that situation.

We recommend you open a support case with Palo Alto Networks Support -

They will securely provide you the appropriate version of Cortex uninstaller tool and the process without re-installing the OS.



In future, to cleanly uninstall Cortex XDR from endpoints, disable tamper protect first before you start uninstall process.

L3 Networker

Hi there,


as @malalade stated the best course of action would be to open a case with support but not just for the so-called "XDRcleaner" but to find out why "tdevflt.sys" prevents you from uninstalling/upgrading the agent.


By the way, do you start the upgrade process from the XDR console?

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!