1. Critical Patch Release Information

Resolved Known Issues

This Critical Patch resolves the following issue(s):

Issue 1 (SEG-37086)

OfficeScan agents cannot to connect to the network with a wireless LAN using RADIUS verification.

Solution:

This critical patch updates the OfficeScan agent program and moves the ofcsslagent certificate from the "Personal" folder to the "OfficeScan SSL Agent" folder to resolve this issue.

Issue 2 (SEG-37386)

OfficeScan agents may experience a performance issue if a query to the Certified Safe Software Service is unsuccessful.

Solution:

This hotfix updates Behavior Monitoring to limit the number of queries sent to the Certified Safe Software Service. If Behavior Monitoring is unable to successfully query the Certified Safe Software Service 5 times, the query is queued for 180 seconds to reduce the performance impact.

Procedure:

  1. Unload the agent
  2. Add and modify the following key to change the default value:
  • \HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS\
  • NFCSuspFailCnt=dword:00000010
  • NFCSuspPeriod=dword:00000001 Example: Query to the Certified Safe Software Service unsuccessful for 10 times, Behavior Monitoring will ignore query for 1 second.
  1. Reload the agent

Enhancements

The following enhancements are included in this Critical Patch:

Enhancement 1 (SEG-38464)

This critical patch enables the OfficeScan XG Service Pack 1 agent program to support Windows 10 (version 1809) October 2018 Update.

Files Included in this Release

A. Files for Current Issue(s)
-------------------------------------------------------------------
Filename                                               Build Number
------------------------------                         ------------
OfficeScan\PCCSRV\Admin\Utility\EdgeServer\*.*

OfficeScan\PCCSRV\Admin\Utility\SQL\*.*

OfficeScan\PCCSRV\Pccnt\Disk1\*.*

OfficeScan\PCCSRV\
-------------------------------------------------------------------
AutoPcc.exe                                            12.0.0.5261             
AutoPccP.exe                                           12.0.0.5261             
CGIResUTF8.dll                                         12.0.0.5261             
libcurl.dll                                            7.58.0.0                
libeay32.dll                                           1.0.2.16                
libNetCtrl.dll                                         13.0.0.5308             
loadhttp.dll                                           13.0.0.5308             
ofc_loadhttp.dll                                       13.0.0.5308             
OfcPfwCommon.dll                                       13.0.0.5308             
OfcPIPC.dll                                            13.0.0.5308             
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Admin\
-------------------------------------------------------------------
ciussi32.dll                                           2.0.0.2074              
ciussi64.dll                                           2.0.0.2074              
InstNTRes.dll                                          12.0.0.5261             
InstReg.exe                                            13.0.0.5308             
loadhttp.dll                                           13.0.0.5308             
ofc_loadhttp.dll                                       13.0.0.5308             
patchbld.dll                                           12.21.0.0               
PATCHW32.DLL                                           12.21.0.0               
patchw64.dll                                           12.20.0.0               
pbld64.dll                                             12.20.0.0               
SetupUsr.dll                                           12.0.0.5261             
Wizard.exe                                             13.0.0.5308             
Wizard_64x.exe                                         13.0.0.5308             

OfficeScan\PCCSRV\Admin\Utility\ClientPackager\
-------------------------------------------------------------------
OfcPfwCommon.dll                                       13.0.0.5308             

OfficeScan\PCCSRV\Admin\Utility\IpXfer\
-------------------------------------------------------------------
IpXfer.exe                                             13.0.0.5308             
IpXfer_x64.exe                                         13.0.0.5308             

OfficeScan\PCCSRV\Admin\Utility\ListDeviceInfo\
-------------------------------------------------------------------
listDeviceInfo.exe                                     6.2.0.1233              

OfficeScan\PCCSRV\Admin\Utility\PolicyExportTool\
-------------------------------------------------------------------
CGIResUTF8.dll                                         12.0.0.5261             
ServerMigrationTool.ex_                                12.0.0.5261             

OfficeScan\PCCSRV\Admin\Utility\SaasStorageMgr\
-------------------------------------------------------------------
ofcASMgr.exe                                           12.0.0.5261             

OfficeScan\PCCSRV\Admin\Utility\ServerMigrationTool\
-------------------------------------------------------------------
CGIResUTF8.dll                                         12.0.0.5261             
ServerMigrationTool.exe                                12.0.0.5261             

OfficeScan\PCCSRV\Admin\Utility\SQL\
-------------------------------------------------------------------
libSQLDatabaseUpgrade.dll                              12.0.0.5261             
oscedbt.exe                                            12.0.0.5261             

OfficeScan\PCCSRV\Admin\Utility\TMVS\
-------------------------------------------------------------------
DatFHS.dll                                             13.0.0.5308             
libeay32.dll                                           1.0.2.16                
loadhttp.dll                                           13.0.0.5308             
ssleay32.dll                                           1.0.2.16                
TMVS.exe                                               12.0.0.5261             

OfficeScan\PCCSRV\CmAgent\
-------------------------------------------------------------------
CGIResUTF8.dll                                         12.0.0.5261             
libcurl.dll                                            7.43.0.0                
libeay32.dll                                           1.0.2.16                
ProductLibrary.dll                                     12.0.0.5261             
ProductUI.zip                                               *                  
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Download\Engine\
-------------------------------------------------------------------
BMdriver_x32.sig                                            *                  
BMdriver_x32.zip                                            *                  
BMdriver_x64.sig                                            *                  
BMdriver_x64.zip                                            *                  
bmservice_x32.sig                                           *                  
bmservice_x32.zip                                           *                  
bmservice_x64.sig                                           *                  
bmservice_x64.zip                                           *                  

OfficeScan\PCCSRV\Download\Product\
-------------------------------------------------------------------
DlpLite_Common.zip                                          *                  
DlpLite_Common_x64.zip                                      *                  

OfficeScan\PCCSRV\Engine\
-------------------------------------------------------------------
TmAegisSysEvt.dll                                      2.976.0.2194            
TMBMCLI.dll                                            2.976.0.2194            
TMBMSRV.exe                                            2.976.0.2194            
tmCfwApi.dll                                           5.83.0.1059             
tmcomeng.dll                                           2.976.0.2194            
TmEngDrv.dll                                           2.976.0.2194            
tmHash.dll                                             5.83.0.1059             
TMPEM.dll                                              2.976.0.2194            
TmPfw.exe                                              5.83.0.1059             
TmPfwApi.dll                                           5.83.0.1059             
TmPfwRul.dll                                           5.83.0.1059             
TmSysEvt.dll                                           7.0.0.1162              
tmtap.dll                                              6.0.0.1074              
tmwlutil.dll                                           2.976.0.2194            
trxhandler.dll                                         1.100.0.1060            

OfficeScan\PCCSRV\Engine\x64\
-------------------------------------------------------------------
TmAegisSysEvt.dll                                      2.976.0.2194            
TMBMCLI.dll                                            2.976.0.2194            
TMBMSRV.exe                                            2.976.0.2194            
tmCfwApi.dll                                           5.83.0.1059             
tmcomeng.dll                                           2.976.0.2194            
TmEngDrv.dll                                           2.976.0.2194            
tmHash.dll                                             5.83.0.1059             
TMPEM.dll                                              2.976.0.2194            
TmPfw.exe                                              5.83.0.1059             
TmPfwApi.dll                                           5.83.0.1059             
TmPfwRul.dll                                           5.83.0.1059             
TmSysEvt.dll                                           7.0.0.1162              
tmtap.dll                                              6.0.0.1074              
tmwlutil.dll                                           2.976.0.2194            
trxhandler.dll                                         1.100.0.1060            

OfficeScan\PCCSRV\LWCS\
-------------------------------------------------------------------
libcurl.dll                                            7.55.1.0                
libeay32.dll                                           1.0.2.16                
lwcs_msg.ini                                                *                  
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Pccnt\
-------------------------------------------------------------------
ClientConsole.zip                                           *                  
NTMonRes.dll                                           12.0.0.5261             
NTRtScan.exe                                           13.0.0.5308             
NTSvcRes.dll                                           12.0.0.5261             

OfficeScan\PCCSRV\Pccnt\Common\
-------------------------------------------------------------------
7z.dll                                                 18.5.0.0                
7z.exe                                                 18.5.0.0                
ApricotCBRuleHandler.dll                               2.0.0.1041              
ApricotManagerModule.dll                               2.0.0.1041              
CCSF_WIN32.zip                                              *                  
CNTAoSMgr.exe                                          2.3.0.4516              
CompRmv.exe                                            13.0.0.5308             
crc0filter.dll                                         2.82.0.1059             
DatFHS.dll                                             13.0.0.5308             
fcWofieUI.dll                                          13.0.0.5308             
FileBrowsingRuleHandler.dll                            2.0.0.1041              
ICRCHdler.dll                                          2.82.0.1059             
libApricotLog.dll                                      2.0.0.1041              
libcurl.dll                                            7.59.0.0                
libeay32.dll                                           1.0.2.16                
libNetCtrl.dll                                         13.0.0.5308             
libprotobuf.dat                                             *                  
libprotobuf.dll                                             *                  
loadhttp.dll                                           13.0.0.5308             
NTRmv.exe                                              13.0.0.5308             
ofc_loadhttp.dll                                       13.0.0.5308             
OfcCCCAUpdate.exe                                      13.0.0.5308             
OfcPfwCommon.dll                                       13.0.0.5308             
OfcPfwSvc.dll                                          13.0.0.5308             
OfcPIPC.dll                                            13.0.0.5308             
PccNT.exe                                              13.0.0.5308             
PccNTMon.exe                                           13.0.0.5308             
PccNTUpd.exe                                           13.0.0.5308             
ssleay32.dll                                           1.0.2.16                
SurrogateTmListen.exe                                  13.0.0.5308             
tmCfwApi.dll                                           5.83.0.1059             
TmFpHcEx.exe                                           5.83.0.1059             
tmHash.dll                                             5.83.0.1059             
TmListen.dll                                           13.0.0.5308             
TmListen.exe                                           13.0.0.5308             
TmListenShare.dll                                      13.0.0.5308             
TmOPP.dll                                              13.0.0.5308             
TmPfw.exe                                              5.83.0.1059             
TmPfwApi.dll                                           5.83.0.1059             
TmPfwCtl.dll                                           5.83.0.1059             
TmPfwCtl_xp.dll                                        5.83.0.1059             
TmPfwRul.dll                                           5.83.0.1059             
TmSock.dll                                             13.0.0.5308             
TmSSClient.exe                                         13.0.0.5308             
tmwfpapi.dll                                           5.83.0.1059             
UpdGuide.exe                                           13.0.0.5308             
Upgrade.exe                                            13.0.0.5308             
utilPfwInstCondChecker.exe                             13.0.0.5308             
WofieLauncher.exe                                      13.0.0.5308             
xpupg.exe                                              13.0.0.5308             

OfficeScan\PCCSRV\Pccnt\Drv\
-------------------------------------------------------------------
tmactmon.cat                                                *                  
tmactmon.inf                                                *                  
tmactmon.sys                                           2.976.0.2193            
tmcomm.cat                                                  *                  
tmcomm.inf                                                  *                  
tmcomm.sys                                             7.0.0.1162              
tmevtmgr.cat                                                *                  
tmevtmgr.inf                                                *                  
tmevtmgr.sys                                           2.976.0.2193            
tmlwf.cat                                                   *                  
tmlwf.inf                                                   *                  
tmlwf.sys                                              5.83.0.1059             
tmlwfins.exe                                           5.83.0.1059             
tmusa.cat                                                   *                  
tmusa.inf                                                   *                  
tmusa.sys                                              3.0.0.1047              
tmwfp.cat                                                   *                  
tmwfp.inf                                                   *                  
tmwfp.sys                                              5.83.0.1059             
tmwfpins.exe                                           5.83.0.1059             

OfficeScan\PCCSRV\Pccnt\Drv\x64\
-------------------------------------------------------------------
tmactmon.cat                                                *                  
tmactmon.inf                                                *                  
tmactmon.sys                                           2.976.0.2193            
tmcomm.cat                                                  *                  
tmcomm.inf                                                  *                  
tmcomm.sys                                             7.0.0.1162              
tmevtmgr.cat                                                *                  
tmevtmgr.inf                                                *                  
tmevtmgr.sys                                           2.976.0.2193            
tmlwf.cat                                                   *                  
tmlwf.inf                                                   *                  
tmlwf.sys                                              5.83.0.1059             
tmlwfins.exe                                           5.83.0.1059             
tmusa.cat                                                   *                  
tmusa.inf                                                   *                  
tmusa.sys                                              3.0.0.1047              
tmwfp.cat                                                   *                  
tmwfp.inf                                                   *                  
tmwfp.sys                                              5.83.0.1059             
tmwfpins.exe                                           5.83.0.1059             

OfficeScan\PCCSRV\Pccnt\Win64\X64\
-------------------------------------------------------------------
7z.dll                                                 18.5.0.0                
7z.exe                                                 18.5.0.0                
ApricotCBRuleHandler.dll                               2.0.0.1041              
ApricotManagerModule.dll                               2.0.0.1041              
CCSF_X64.zip                                                *                  
CompRmv.exe                                            13.0.0.5308             
crc0filter.dll                                         2.82.0.1059             
DatFHS.dll                                             13.0.0.5308             
fcWofieUI.dll                                          13.0.0.5308             
FileBrowsingRuleHandler.dll                            2.0.0.1041              
ICRCHdler.dll                                          2.82.0.1059             
libApricotLog.dll                                      2.0.0.1041              
libcurl.dll                                            7.59.0.0                
libeay32.dll                                           1.0.2.16                
libNetCtrl_64x.dll                                     13.0.0.5308             
libprotobuf.dat                                             *                  
libprotobuf.dll                                             *                  
loadhttp_64x.dll                                       13.0.0.5308             
NTRmv.exe                                              13.0.0.5308             
Ntrtscan.exe                                           13.0.0.5308             
ofc_loadhttp_64x.dll                                   13.0.0.5308             
OfcCCCAUpdate.exe                                      13.0.0.5308             
OfcPfwCommon_64x.dll                                   13.0.0.5308             
OfcPfwSvc_64x.dll                                      13.0.0.5308             
OfcPIPC_64x.dll                                        13.0.0.5308             
PccNT.exe                                              13.0.0.5308             
PccNTMon.exe                                           13.0.0.5308             
PccNTUpd.exe                                           13.0.0.5308             
ssleay32.dll                                           1.0.2.16                
SurrogateTmListen.exe                                  13.0.0.5308             
tmCfwApi.dll                                           5.83.0.1059             
TmFpHcEx.exe                                           5.83.0.1059             
tmHash.dll                                             5.83.0.1059             
TmListen.exe                                           13.0.0.5308             
TmListen_64x.dll                                       13.0.0.5308             
TmListenShare_64x.dll                                  13.0.0.5308             
TmOPP_64x.dll                                          13.0.0.5308             
TmPfw.exe                                              5.83.0.1059             
TmPfwApi.dll                                           5.83.0.1059             
TmPfwCtl.dll                                           5.83.0.1059             
TmPfwCtl_xp.dll                                        5.83.0.1059             
TmPfwRul.dll                                           5.83.0.1059             
TmSock_64x.dll                                         13.0.0.5308             
TmSSClient.exe                                         13.0.0.5308             
tmwfpapi.dll                                           5.83.0.1059             
UpdGuide.exe                                           13.0.0.5308             
Upgrade.exe                                            13.0.0.5308             
utilPfwInstCondChecker.exe                             13.0.0.5308             
WofieLauncher.exe                                      13.0.0.5308             
xpupg.exe                                              13.0.0.5308             

OfficeScan\PCCSRV\Private\
-------------------------------------------------------------------
DlpClc.xml                                                  *                  

OfficeScan\PCCSRV\Private\certificate\
-------------------------------------------------------------------
libeay32.dll                                           1.0.2.16                
openssl.exe                                                 *                  
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Private\LogServer\
-------------------------------------------------------------------
7z.dll                                                 18.5.0.0                
7z.exe                                                 18.5.0.0                
OfcPIPC.dll                                            13.0.0.5308             

OfficeScan\PCCSRV\SRS\
-------------------------------------------------------------------
libcurl.dll                                            7.55.1.0                
libeay32.dll                                           1.0.2.16                
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Web\Service\
-------------------------------------------------------------------
7z.dll                                                 18.5.0.0                
AosProxy.exe                                           12.0.0.5261             
CGIOCommon.dll                                         12.0.0.5261             
CGIResUTF8.dll                                         12.0.0.5261             
CmdHLClient.dll                                        12.0.0.5261             
CmdHOConsole.dll                                       12.0.0.5261             
cme_dll.dll                                            6.2.0.1196              
cme_vxe_dll_static.dll                                 6.2.0.1196              
DatFHS.dll                                             13.0.0.5308             
DbServer.exe                                           12.0.0.5261             
libCmdHndlrClientV2.dll                                12.0.0.5261             
libCmdHndlrConsoleV2.dll                               12.0.0.5261             
libcurl.dll                                            7.58.0.0                
libcurl_ofc.dll                                        7.58.0.0                
libeay32.dll                                           1.0.2.16                
loadhttp.dll                                           13.0.0.5308             
LogCache.dll                                           12.0.0.5261             
NTSvcRes.dll                                           12.0.0.5261             
ofc_loadhttp.dll                                       13.0.0.5308             
OfcCCCAUpdate.exe                                      13.0.0.5308             
OfcDBBackup.exe                                        12.0.0.5261             
OfcDownload.dll                                        12.0.0.5261             
OfcHotFix.exe                                          12.0.0.5261             
OfcNotifyQueue.dll                                     12.0.0.5261             
OfcPfwCommon.dll                                       13.0.0.5308             
OfcService.exe                                         12.0.0.5261             
ssleay32.dll                                           1.0.2.16                
VerConn.exe                                            12.0.0.5261             

OfficeScan\PCCSRV\Web\Service\PLM\
-------------------------------------------------------------------
7z.dll                                                 18.5.0.0                

OfficeScan\PCCSRV\Web_OSCE\Web\CGI\
-------------------------------------------------------------------
cgiExportInfo.exe                                      12.0.0.5261             
CGIResUTF8.dll                                         12.0.0.5261             
libcurl.dll                                            7.58.0.0                
libeay32.dll                                           1.0.2.16                
loadhttp.dll                                           13.0.0.5308             
OfcPfwCommon.dll                                       13.0.0.5308             
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Web_OSCE\Web_Console\CGI\
-------------------------------------------------------------------
cgiAuthManagement.exe                                  12.0.0.5261             
cgiChkMasterPwd.exe                                    12.0.0.5261             
CGIOCommon.dll                                         12.0.0.5261             
CGIResUTF8.dll                                         12.0.0.5261             
cgiShowActiveDirectory.exe                             12.0.0.5261             
cgiShowClientAdm.exe                                   12.0.0.5261             
cgiShowLogs.exe                                        12.0.0.5261             
cgiShowServerAdm.exe                                   12.0.0.5261             
cgiShowSummary.exe                                     12.0.0.5261             
cgiShowUpdate.exe                                      12.0.0.5261             
fcgiOfcDDA.exe                                         12.0.0.5261             
libcurl.dll                                            7.58.0.0                
libeay32.dll                                           1.0.2.16                
loadhttp.dll                                           13.0.0.5308             
OfcPfwCommon.dll                                       13.0.0.5308             
ssleay32.dll                                           1.0.2.16                

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\ad_integration\
-------------------------------------------------------------------
ad_integration.htm                                          *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\aegis\
-------------------------------------------------------------------
device_control.htm                                          *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\Auth\
-------------------------------------------------------------------
admin_account_info.htm                                      *                  
admin_account_menu.htm                                      *                  
Admin_Role_Add.htm                                          *                  
Admin_User_List.htm                                         *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\behavior_monitoring\
-------------------------------------------------------------------
bm_settings.htm                                             *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\clientmag\
-------------------------------------------------------------------
client_cfg_wtp.htm                                          *                  
client_globalsetting.htm                                    *                  
client_list_2.htm                                           *                  
client_urlfiltering_profiles.htm                            *                  
install_remote.htm                                          *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\cloud_service\
-------------------------------------------------------------------
import_bw_list.htm                                          *                  
scan_source.htm                                             *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\common\
-------------------------------------------------------------------
js-clientmag.js                                             *                  
ln_cloud.js                                                 *                  
ln_common.js                                                *                  
trend-ui-opt_list.js                                        *                  
trend-ui.domaintree.js                                      *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\common\css\
-------------------------------------------------------------------
index.css                                                   *                  
l10n-style.css                                              *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\common\l10n\
-------------------------------------------------------------------
l10n.clientmag.js                                           *                  
l10n.dlp.js                                                 *                  
l10n.global.js                                              *                  
l10n.logs.js                                                *                  
l10n.update.js                                              *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\common\util\
-------------------------------------------------------------------
common.js                                                   *                  
osce.menubar.js                                             *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\compliance_report\
-------------------------------------------------------------------
compliance_report.htm                                       *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\dlp\
-------------------------------------------------------------------
dlp_compliance_tpl_addedit.htm                              *                  
dlp_FileAttr_addedit.htm                                    *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\logs\
-------------------------------------------------------------------
logs_bm_view.htm                                            *                  
logs_dac_view.htm                                           *                  
logs_network_malware_view.htm                               *                  
logs_pfw.htm                                                *                  
logs_pfw_detail.htm                                         *                  
logs_pfw_view.htm                                           *                  
logs_spyware_view.htm                                       *                  
logs_suspicious_file_view.htm                               *                  
logs_trendx_view.htm                                        *                  
logs_virus_view.htm                                         *                  
logs_WebSecurity_view.htm                                   *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\outbreak\
-------------------------------------------------------------------
opp_mutex_block.htm                                         *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\PFW\
-------------------------------------------------------------------
profile_edit.htm                                            *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\root\
-------------------------------------------------------------------
help_start.htm                                              *                  
logon.htm                                                   *                  
menu.html                                                   *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\serveradm\
-------------------------------------------------------------------
edge_server.htm                                             *                  
server_cmagent_saas.htm                                     *                  
server_migration.htm                                        *                  
server_proxy.htm                                            *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\tools\
-------------------------------------------------------------------
tools_admin_clients.htm                                     *                  

OfficeScan\PCCSRV\Web_OSCE\Web_console\HTML\widget\
-------------------------------------------------------------------
osce_proxy.php                                              *                  

OfficeScan\PCCSRV\WEB_OSCE\Web_Console\HTML\widget\repository\widgetPool\product\
-------------------------------------------------------------------
config.php                                                  *                  

OfficeScan\PCCSRV\WEB_OSCE\Web_Console\HTML\widget\repository\widgetPool\wp%RETCODE%\widget\modOSCESecurityRiskDetection\
-------------------------------------------------------------------
module.js                                                   *                  

OfficeScan\PCCSRV\Web_OSCE\Web_Console\RemoteInstallCGI\
-------------------------------------------------------------------
cgiRemoteInstall.exe                                   12.0.0.5261             
CGIResUTF8.dll                                         12.0.0.5261             
libcurl.dll                                            7.58.0.0                
libeay32.dll                                           1.0.2.16                
loadhttp.dll                                           13.0.0.5308             
ssleay32.dll                                           1.0.2.16                
Wizard.exe                                             13.0.0.5308             
Wizard_64x.exe                                         13.0.0.5308             


B. Network Traffic Required in Deployment
-------------------------------------------------------------------
   Estimated size (in terms of bandwidth) of deployed agent files 
   in this hotfix.
   - 32-bit agent total = 80.0 MB
   - 64-bit agent total = 113.2 MB

                        

2. Documentation Set

To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com

  • Online Help: The Online Help contains an overview of features and key concepts, and information on configuring and maintaining the product.

To access the Online Help, go to http://docs.trendmicro.com

  • Installation Guide (IG): The Installation Guide contains information on requirements and procedures for installing and deploying the product.
  • Administrator's Guide (AG): The Administrator's Guide contains an overview of features and key concepts, and information on configuring and maintaining the product.
  • Getting Started Guide (GSG): The Getting Started Guide contains product overview, installation planning, installation and configuration instructions, and basic information intended to get the product 'up and running'.
  • Support Portal: The Support Portal contains information on troubleshooting and resolving known issues.
  • To access the Support Portal, go to http://esupport.trendmicro.com

3. System Requirements

1. Trend Micro OfficeScan 12.0 XG - Service Pack 1 Build 4345 - English - Windows - x32-x64

4. Installation/Uninstallation

Installing

To install:

  1. Copy the Critical Patch executable file to a temporary folder on the server, for example, "C:\temp".
  2. Double-click the file. The modules are automatically copied to the correct destination.

This Critical Patch installation package automatically rolls back the OfficeScan server to its previous configuration if there are problems during installation. If you encounter problems after installation, do a manual rollback.

Uninstalling

To manually roll back to the previous build:

  1. Locate the backup folder that the Critical Patch package created in the "\PCCSRV\Backup\Critical Patch_B5261" directory.
  2. Stop the OfficeScan Master Service.
  3. Stop the OfficeScan CMAgent Service.
  4. Copy the backup modules to the original folders.
  5. Start the OfficeScan CMAgent Service.
  6. Start the OfficeScan Master Service.

5. Post-installation Configuration

No post-installation steps are required.

NOTE: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing the product.

6. Known Issues

Known issues in this release:

Known Issue 1

The following NT Event Log is generated when an OfficeScan agent computer shuts down or restarts.

  • Event ID: 7043
  • Level: Error
  • Message: The OfficeScan NT Listener service did not shut down properly after receiving a preshutdown control.

7. Release History

Prior Hotfixes


Only this hotfix was tested for this release. Prior hotfixes were tested at the time of their release.

Issue 1 of Critical Patch 4406

(SEG-17879)

After upgrading to OfficeScan XG Service Pack 1, the OfficeScan agent program and some other applications (for example, Print spooler) may encounter an HTTP service issue.

Solution:

This critical patch ensures that OfficeScan agents do not stop the HTTP service allowing other applications to function normally after upgrading to OfficeScan XG Service Pack 1.

Issue 2 of Critical Patch 4406

(SEG-18068)

The Trend Micro Control Manager(TM) server SQL database grows rapidly because the OfficeScan server sends a large number of plug-in service (PLS) status logs to the Control Manager server.

Solution:

This critical patch resolves the issue by ensuring that the OfficeScan server does not send old PLS status logs repeatedly to the Control Manager server.

Issue 3 of Critical Patch 4406

(SEG-18115)

The Behavior Monitoring approved list does not work on files specified by a network path.

Solution:

This critical patch updates the logic for the Behavior Monitoring approved list to ensure that it works on files specified by a network path.

Issue 1 of Hotfix 4417

(SEG-18460)

After upgrading to OfficeScan XG Service Pack 1, the system may be unable to access certain third-party application files if Predictive Machine Learning is enabled.

Solution:

This hotfix updates the Behavior Monitoring service to not block valid third-party applications.

Issue 2 of Hotfix 4417

(SEG-18096)

When Trend Micro Smart Feedback is enabled, it shares anonymous threat information with the SPN. However, Predictive Machine Learning does not use anonymous information when sending the SPN feedback information.

Solution:

This hotfix updates the Falcon Core Engine and the OfficeScan agent program to resolve the issue.

Issue 1 of Hotfix 4423

(SEG-19719)

The OfficeScan Behavior Monitoring feature may cause high CPU usage on protected computers.

Solution:

This hotfix updates the Behavior Monitoring module to resolve the issue.

Issue 2 of Hotfix 4423

(SEG-19626)

The OfficeScan server cannot add UNC paths to the approved list in the Behavior Monitoring Settings.

Solution:

This hotfix updates the OfficeScan server file to enable it to add UNC paths in the Behavior Monitoring approved list.

Enhancement 1 of Hotfix 4423

(SEG-20254)

This hotfix provides a way for users to generate an installation package for coexisting OfficeScan agents on the On-Premise OfficeScan server.

Procedure:

To generate the installation package for coexisting OfficeScan agents:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • SupportCoexistMode=1
  1. Save the changes and close the file.
  2. Restart the OfficeScan Master Service.
  3. After the OfficeScan Master service is running, open a command prompt with administrator privilege, and navigate to the "\PCCSRV\Admin\Utility\ClientPackager\" directory.
  4. Run the following command to create Windows installation package for OfficeScan agents using coexist mode:
  • For 32-bit:

    • Clnpack.exe /m /av /as /pfw /com /dcs /smart /o x86 /coexist /d "C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\Download\agent_coexist_x86.msi" /s "C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV"
  • For 64-bit:

    • Clnpack.exe /m /av /as /pfw /com /dcs /smart /o x64 /coexist /d "C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\Download\agent_coexist_x64.msi" /s "C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV"

Administrators can retrieve the following installation packages for coexisting OfficeScan agents from the "\PCCSRV\Download" folder on the OfficeScan server installation directory.

  • agent_coexist_x86.msi
  • agent_coexist_x64.msi

Issue 1 of Hotfix 4428

(SEG-20164)

An issue prevents the OfficeScan server from deploying the correct local language settings to agents.

Solution:

This hotfix resolves the issue by updating the OfficeScan agent program.

Issue 2 of Hotfix 4428

(SEG-20301)

OfficeScan stops generating logs unexpectedly after users enable the "Schedule scan connection verification" setting.

Solution:

This hotfix updates the logic flow from the check timer to solve this issue.

Issue 1 of Hotfix 4432

(SEG-20997)

The OfficeScan Behavior Monitoring feature may cause high CPU usage on protected endpoints when Sysmon.exe is running.

Solution:

This hotfix updates the Behavior Monitoring module to resolve the issue.

Issue 2 of Hotfix 4432

(SEG-20954)

Under certain scenarios, some OfficeScan processes may stop unexpectedly.

Solution:

This hotfix updates the Behavior Monitoring module to enhance the self-protect feature of OfficeScan processes.

Issue 1 of Hotfix 4440

(SEG-21322)

After upgrading to OfficeScan XG Service Pack 1, the OfficeScan web console will display the connection status of all OfficeScan agents as "independent".

Solution:

This hotfix resolves the issue by ensuring that the OfficeScan server can successfully retrieve the correct agent connection status.

Issue 2 of Hotfix 4440

(SEG-20549)

Data Loss Prevention(TM) (DLP) blocks the Skype application.

Solution:

This hotfix updates the DLP module that contains the improved process flow to prevent false positive alerts when the Skype application conducts file access events on its temporary files.

Issue 3 of Hotfix 4440

(SEG-20076), (SEG-20983)

32-bit OfficeScan processes may stop unexpectedly on 64-bit platforms.

Solution:

This hotfix resolves the issue by updating how the DLP module matches path names when locating the "wow64.dll" path.

Issue 4 of Hotfix 4440

(SEG-19818)

An interoperability issue between the VMware Horizon agent and the User-Mode Hooking feature of OfficeScan agents triggers a black screen when a protected computer restarts after agent installation.

Solution:

This hotfix updates the User-Mode Hooking driver to solve this issue.

Issue 5 of Hotfix 4440

(SEG-20121)

The firewall's "Quarantine" action in medium security level blocks the FTP session.

Solution:

This hotfix changes the "Quarantine" action to "Drop" in medium security level to resolve the issue.

Issue 6 of Hotfix 4440

(SEG-19174)

The Virus/Malware logs that agents send to the OfficeScan server disappear unexpectedly after administrators migrate the OfficeScan database from CodeBase to an SQL Server database using the SQL Server Migration Tool.

Solution:

This hotfix updates the OfficeScan server program to ensure that OfficeScan keeps security risk logs after migrating the database.

Issue 7 of Hotfix 4440

(VRTS-1181)

An attacker may be able to use the "Sc.exe" file to run unauthorized commands on a computer protected by OfficeScan.

Solution:

This hotfix updates the Behavior Monitoring module to resolve the issue.

Enhancement 1 of Hotfix 4440

(SEG-20630)

This hotfix enables the SQLMIGRATION.LOG in the OfficeScan XG Service Pack 1 server. By default, the SQLMIGRATION.LOG file is in the "\PCCSRV\Admin\Utility\SQL" folder on the OfficeScan server installation directory.

Issue 1 of Hotfix 4445

(SEG-20474)

An issue prevents the "showunlockbutton" feature from working on OfficeScan XG Service Pack 1.

Solution:

This hotfix updates the OfficeScan XG Service Pack 1 server file to ensure that the "showunlockbutton" feature works normally.

Issue 1 of Hotfix 4449

(SEG-21429)

OfficeScan does not propagate the OfficeScan Predictive Machine Learning settings to the clients or domains when applying the settings at the root level and using the Microsoft(TM) SQL database.

Solution:

This hotfix resolves this issue by using the correct parameter based on the implementation of the database APIs.

Issue 2 of Hotfix 4449

(SEG-21638)

An issue may prevent the OfficeScan agent from downloading pattern files.

Solution:

This hotfix updates the OfficeScan XG Service Pack 1 server file to ensure that the OfficeScan agent updates files normally.

Issue 3 of Hotfix 4449

(SEG-21643)

The OfficeScan agent downloads the SAL pattern file even if the current pattern file is already updated.

Solution:

This hotfix updates the OfficeScan XG Service Pack 1 server files to ensure that the OfficeScan agent only gets updated pattern files from the server.

Issue 1 of Hotfix 4453

(SEG-19769)

The OfficeScan server widget queries Data Loss Prevention(TM) (DLP) logs using the "root" account. This situation causes backend processes to always return all logs to any user.

Solution:

This hotfix resolves the issue by adding a method that allows administrators to check all viewable domains of currently logged-on users if the request comes from a widget. The hotfix adds a hidden key to enable or disable this feature.

Procedure:

To configure the new setting for "ofcserver.ini":

  1. Install this hotfix (see "Installation").
  2. Open the "ofcserver.ini" file in the "\PCCSRV\Private\" folder on the OfficeScan server.
  3. Under the "SERVER_CONSOLE_SECTION" section, manually configure the following:
  • [SERVER_CONSOLE_SECTION]
  • ShowDLPLogByAccountPermission=1
  1. Save the changes and close the file.
  2. Reload the browser.

Issue 1 of Hotfix 4456

(SEG-21508)

The OfficeScan Predictive Machine Learning feature may prevent users from printing Microsoft(TM) Office files or from downloading these files through a web browser normally.

Solution:

This hotfix provides a way for users to approve programs to run with deferred scanning by Predictive Machine Learning to prevent these issues.

Procedure:

To approve programs to run with deferred scanning by Predictive Machine Learning:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the following keys and specify each approved program separately.
  • [Global Setting]
  • DS_ProcessCount=the number of programs in the approved list, supports any integer from 1 to 1000
  • DS_ProcessName000=process name of the approved program, where "000" notes the first item on the list

For example:

  • [Global Setting]
  • DS_ProcessCount=4
  • DS_ProcessName000=iexplore.exe
  • DS_ProcessName001=Chrome.exe
  • DS_ProcessName002=FireFox.exe
  • DS_ProcessName003=WINWORD.EXE
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following entries of TXS.ini on all OfficeScan agent computers:
  • [TrendX_Settings]
  • DS_ProcessCount=4
  • DS_ProcessName000="The encrypted string of the preferred program"
  • DS_ProcessName001="The encrypted string of the preferred program"
  • DS_ProcessName002="The encrypted string of the preferred program"
  • DS_ProcessName003="The encrypted string of the preferred program" 

Issue 2 of Hotfix 4456

(SEG-22955)

The system information, product information, product version, and entity icon do not update automatically.

Solution:

This hotfix updates the OfficeScan 12.0 Service Pack 1 server file to ensure that the system information, product information, product version, and entity icon are updated correctly.

Issue 3 of Hotfix 4456

(VRTS-1974)

A time-of-check/time-of-use privilege escalation vulnerability exists with the "tmusa.sys" kernel file (Osprey).

Solution:

This hotfix updates the kernel files for Osprey to address the vulnerability.

Issue 4 of Hotfix 4456

(SEG-22406)

The certificate of the "saknet.sys" file is valid from March 23, 2016 to June 28, 2017 only.

Solution:

This hotfix replaces the "saknet.sys" file in the Trend Micro Data Loss Prevention(TM) (DLP) module with a "saknet.sys" file that contains a valid certificate.

Issue 5 of Hotfix 4456

(SEG-21120)

Some unexpected hostname IPs may be resolved during the drag-and-drop and open file dialog upload for supported web services and "facebook.com" IP resolution is not supported during browser file upload.

Solution:

This hotfix updates the DLP module to enable it to first check if a hostname belongs to the supported web services list before attempting to resolve the IP address during the drag-and-drop and open file dialog upload. This hotfix also adds support for "facebook.com" in the supported web services list.

Issue 6 of Hotfix 4456

(SEG-21805)

A protected computer may stop unexpectedly when an invalid policy is set for the DLP services.

Solution:

This hotfix updates the DLP module to add restrictions, particularly for operations, to the DLP XML policy validators to help prevent the issue.

Issue 7 of Hotfix 4456

(SEG-22771)

When an OfficeScan XG client performs the "Clean" action on certain backup files, it may also transfer the files to the "Virus" folder. The files in this folder are sent to the OfficeScan server along with quarantined files.

Solution:

This hotfix prevents OfficeScan XG clients from saving a copy of cleaned BR0 to BRF backup files, for example XXX.BR0, XXX.BR1, XXX.BR2 to XXX.BRF, in the suspected virus folder. This ensures that cleaned files are not sent to the OfficeScan server.

Enhancement 1 of Hotfix 4456

(SEG-21714)

This hotfix helps ensure that DLP violation logs displays the correct channel name and file path for Google Drive.

Enhancement 2 of Hotfix 4456

(SEG-21808)

The hotfix enables the DLP module to support Microsoft(TM) Windows(TM) 10 Redstone 4 Insider Preview (10.0.17083).

Issue 1 of Hotfix 4461

(SEG-21560)

The Data Loss Prevention(TM) (DLP) module does not monitor upload transfers in https://wetransfer.com.

Solution:

This hotfix adds https://wetransfer.com to the DLP module's "browser_pattern.xml" file to enable the module to monitor open file dialog and drag and drop operations on the website.

Issue 1 of Hotfix 4465

(SEG-20549)

The Data Loss Prevention(TM) (DLP) module blocks the Skype application.

Solution:

This hotfix updates the DLP module that contains the improved process flow to prevent false positive alerts when the Skype application conducts file access events on its temporary files.

Issue 2 of Hotfix 4465

(SEG-24020)

A protected computer stops responding when the Trend Micro Endpoint Sensor triggers frequent file scans.

Solution:

The hotfix ensures that a protected computer runs normally when the Trend Micro Endpoint Sensor triggers file scans frequently.

Issue 1 of Hotfix 4470

(SEG-23740)

Certain Dell computers freeze after installing the OfficeScan agent.

Solution:

This hotfix updates the Behavior Monitoring module to resolve the issue.

Issue 2 of Hotfix 4470

(SEG-22052)

Ntrtscan stops unexpectedly while patterns are reloaded and OfficeScan still waits for the scan to stop. This happens when there are too many manual scan context instances.

Solution:

This hotfix resolves the issue by preventing OfficeScan from waiting for Ntrtscan to finish when it has already stopped and removes unused manual scan context instances from OfficeScan computers.

Issue 3 of Hotfix 4470

(SEG-23862)

The Certified Safe Software Service may not work properly on OfficeScan XG Service Pack 1 agents if users enabled the Smart Protection Service Proxy for service queries.

Solution:

This hotfix updates the OfficeScan agent program to ensure that the Certified Safe Software Service works as expected.

Issue 4 of Hotfix 4470

(SEG-13780)

The "ClientUUID" information in the "OfcCCCAUpdate.ini" file of OfficeScan XG clients is one character shorter than the correct value and contains garbled characters.

Solution:

This hotfix updates the OfficeScan XG client files to ensure that OfficeScan clients retrieves and stores the correct "ClientUUID" information.

Issue 5 of Hotfix 4470

(SEG-13780)

Communication between OfficeScan and Trend Micro Control Manager(TM) stops when the "SourceUUID" information in the "ofcDdaSrv.ini" file changes.

Solution:

This hotfix updates OfficeScan XG server files to ensure that the communication between OfficeScan XG and Control Manager is not interrupted when the "SourceUUID" information changes.

Issue 6 of Hotfix 4470

(SEG-21136)

When OfficeScan integrates with an Active Directory (AD) Server, users on the first layer will have the same domain management scope. While users on the second layer can login to the OfficeScan web console normally, they do not have privileges to view and manage the domains under the OfficeScan server.

Solution:

This hotfix changes the method to get all AD groups from the logon token and allow each AD user account to query all groups and manage domains under the same OfficeScan server.

Issue 1 of Hotfix 4476

(SEG-17659)

The Behavior Monitor re-entry on the PostCreate event may trigger a blue scree of death (BOSD) on Microsoft(TM) Windows(TM) XP embedded systems.

Solution:

This hotfix adds an anti-re-entry checking mechanism to the ActMonFilePostCreate task to resolve the issue.

Issue 2 of Hotfix 4476

(SEG-24160)

A network bandwidth issue occurs while Update Now is running.

Solution:

This hotfix adds the following conditions to prevent the OfficeScan agent from querying the Active Directory (AD) to prevent the network bandwidth issue.

  • AegisEnableDac=1
  • service switch of AEGIS or DLP=1

Issue 3 of Hotfix 4476

(VRTS-2185)

An issue related to the Trend Micro OfficeScan Firewall driver may cause multiple Privilege Escalation and Pool Corruption vulnerabilities.

Solution:

This hotfix updates the Trend Micro OfficeScan Firewall driver to resolve the vulnerabilities.

Issue 4 of Hotfix 4476

(SEG-24468)

An issue prevents OfficeScan from blocking sensitive information sent through the HTTP(S) in "dlptest.com".

Solution:

This hotfix ensures that OfficeScan can block sensitive information in "dlptest.com" by adding a new formdata pattern for the site.

Enhancement 1 of Hotfix 4476

(SEG-22060)

This hotfix updates the OfficeScan Data Loss Prevention(TM) (DLP) module to enable its Device Control feature to work on portable devices with read-only permission.

Procedure:

To enable the new service settings:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • InstallDLPWpdDriver=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to clients.
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\DlpLite
  • Key: InstallDLPWpdDriver
  • Type: DWORD
  • Value:
    • 0 = Device Control does not work on portable devices with read-only permission
    • 1 = Device Control works on portable devices with read-only permission

Issue 1 of Hotfix 4480

(SEG-20334)

An OfficeScan agent computer stops responding when the Data Loss Prevention(TM) (DLP) service is enabled while OneDrive for Business is running.

Solution:

This hotfix resolves the issue by updating the DLP module to improve the OneDrive for Business synchronization folder checking mechanism.

Issue 2 of Hotfix 4480

(SEG-25098)

There is a spelling error in the "Action on Exception Rule" page of the OfficeScan agent console.

Solution:

This hotfix updates the OfficeScan agent program to correct the spelling error on the page.

Issue 3 of Hotfix 4480

(SEG-25326)

Users may experience long loading times for websites when Web Reputation is enabled. This happens because OfficeScan XG agents that use a Proxy Auto-Configuration (PAC) file to establish proxy connection with a Smart Protection Server do not connect to the expected proxy.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 4 of Hotfix 4480

(SEG-24934)

The "Offline Time" column on the OfficeScan web console displays inaccurate information.

Solution:

This hotfix updates the OfficeScan server files to ensure that the correct offline time information appears in the "Offline Time" column.

Issue 5 of Hotfix 4480

(SEG-24934)

The OfficeScan server may export the wrong agent list information because there is not enough buffer memory.

Solution:

This hotfix enlarges the buffer size to fix this issue.

Issue 6 of Hotfix 4480

(SEG-23999)

Users may encounter an "Update Failed" alert when they try to update the product license through the OfficeScan management console.

Solution:

This hotfix updates the OfficeScan server program to ensure that users can update the product license successfully through the OfficeScan management console.

Enhancement 1 of Hotfix 4480

(SEG-21635)

This hotfix enables DLP to support UnionPay credit cards.

Issue 1 of Hotfix 5110

(SEG-24756)

The Security Threat URL information in Virus/Malware logs do not appear in search results.

Solution:

The hotfix updates the OfficeScan server program and the "Virus_Encyclopedia_URL" to ensure that the correct Virus/Malware information appears on the redirected Threat Encyclopedia web page.

Issue 2 of Hotfix 5110

(SEG-23762)

The OfficeScan agent's memory usage increases when users open and close sub windows too many times.

Solution:

This hotfix allows users to configure OfficeScan to monitor the pccnt memory usage and to close the pccnt console automatically once the memory usage reaches 512 MB.

Procedure:

To configure OfficeScan to monitor the pccnt memory usage and to close the pccnt console automatically once the memory usage reaches 512 MB:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • MonitorPccntMemory=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to clients.
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro \PC-cillinNTCorp\CurrentVersion\Misc.
  • Key: MonitorPccntMemoryUsage
  • Type: DWORD
  • Value: 1 = OfficeScan supports pccnt console will be closed automatically if pccnt memory usage is over 512 MB.

Issue 3 of Hotfix 5110

(SEG-22489)

The assessment function lists OfficeScan agent computers under the "No OfficeScan agent installed".

Solution:

This hotfix resolves the issue by enabling the assessment engine to try both HTTPS and HTTP to connect to clients.

Issue 4 of Hotfix 5110

(SEG-25336)

When the HTTPS communication port of OfficeScan XG Service Pack 1 agents is not configured correctly, these agents will not be able to connect to an OfficeScan XG Service Pack 1 server that was upgraded from an OfficeScan 11 server.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 5 of Hotfix 5110

(SEG-25670)

There are spelling errors in the French version of the OfficeScan agent console's "Console Flyover" page.

Solution:

This hotfix updates the OfficeScan agent program to correct the spelling error on the page.

Issue 6 of Hotfix 5110

(SEG-24585)

OfficeScan agents in conventional scan mode without Internet connection cannot send Predictive Machine Learning threat queries when the "Use configured Smart Protection Sources for service queries" feature is enabled.

Solution:

This hotfix resolves the issue generating the necessary registry values to properly configure the Predictive Machine Learning and the "Use configured Smart Protection Sources for service queries" feature.

Issue 7 of Hotfix 5110

(SEG-25901), (SEG-21738)

Microsoft(TM) added a feature in Microsoft Windows(TM) 10 Fall Creators Update (RS3). After this update, the Windows Defender Security Center can no longer recognize the status of the OfficeScan antivirus and firewall.

Solution:

This hotfix enables the OfficeScan agent to report the "substatus" of both the antivirus and firewall to the Windows Security Center so that the Windows Defender Security Center displays the correct antivirus product status.

Issue 8 of Hotfix 5110

(SEG-25109)

In Microsoft Internet Explorer(TM) 11, illegal attachments in Yahoo Mail US attached using the "attached" button are not blocked.

Solution:

The hotfix enables OfficeScan to recognize the attachment filename in Yahoo Mail encoded in UTF-8 MIME.

Issue 9 of Hotfix 5110

(SEG-25911)

Trend Micro Endpoint Encryption (TMEE) cannot encrypt files normally when iDLP is enabled.

Solution:

The hotfix adds the new TMEE build (6.0.2023) in the approved list of the DLP module to resolve this issue.

Issue 10 of Hotfix 5110

(SEG-25802)

The Microsoft(TM) Windows(TM) 10 services do not start when a protected computer starts.

Solution:

This hotfix implements customized configurations to allow users to enable or disable the VMware ThinApp application detection feature which can help ensure that Windows 10 services start normally.

Procedure:

To configure the new setting for DLP:

  1. Install this hotfix (see "Installation").
  2. Open the "dlp.ini" file in the "\PCCSRV\Private\" folder on the OfficeScan server.
  3. Under the "Configure" section, manually add the "check_vmware_thinapp" key and set its value to "false".
  • [Configure]
  • check_vmware_thinapp=false
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and click "Agents > Agent Management > Select domains or agents > Settings > DLP settings".
  3. Click "Save" to deploy the settings to agents. The OfficeScan server deploys the settings to OfficeScan agents and adds the following key in the "dsa.pro" file in the "\Windows\System32\dgagent\" folder:
  • check_vmware_thinapp=false

Issue 11 of Hotfix 5110

(SEG-24426)

The "Agents Connected to the Edge Relay Server" widget may display inaccurate date information if the server and browser are both set to time zone earlier than UTC-1, for example, UTC-6.

Solution:

This hotfix implements the following to resolve this issue:

  1. When collecting data, the widget will start from the midnight of the sixth day before the present day based on the local time zone.
  2. When adding a timestamp to information, the widget will set it to midnight of the same day based on the local time zone.

Issue 12 of Hotfix 5110

(SEG-24123)

Scans triggered by the PccNT command may not be able to scan a file on a network drive.

Solution:

This hotfix updates the OfficeScan client program to ensure that it can scan files in a network drive normally.

Issue 13 of Hotfix 5110

(SEG-19783)

Samples are sent to the Deep Discovery Analyzer server without any host name information.

Solution:

This hotfix ensures that OfficeScan server sends samples to the Deep Discovery Analyzer with the correct source host information.

Enhancement 1 of Hotfix 5110

(SEG-21124), (SEG-5076), (SEG-19481)

This hotfix enables users to configure OfficeScan to allow a user with restricted access to connect to an approved wireless SSID and to block these users from connecting to any wired network. This helps ensure that the user does not connect to both a wireless and a wired network at the same time.

Procedure:

To enable restricted users to connect to an approved wireless SSID and block these users from using any wired network:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following keys and set the preferred value for each.
  • [Global Setting]
  • EnableWhiteListSSID=y

    • 1, enables the approved SSID list
    • 0, (default) disables the approved SSID list
  • WhiteListSSIDCount=x, the number of approved SSID on the list
  • WhiteListSSID_0=abcd, first SSID
  • WhiteListSSID_1=1111, subsequent SSID
  • WhiteListSSID(x-1)=2222, any SSID specified after this key will not be used
  • EnableBlockWiredNetwork=z

    • 1, blocks all wired network interfaces
    • 0, opens all wired network interfaces
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to clients.

NOTES:

  • After blocking wired network interfaces and unloading the agent, you can reconnect these interfaces through the \Windows\Control Panel\Network and Internet\Network Connections\ page.
  • When the SSID approved list is enabled, you can see the available wireless network SSIDs after unloading the agent.

Enhancement 2 of Hotfix 5110

(SEG-25901), (SEG-19481)

The OfficeScan web console does not display an alert when the Smart Scan Pattern is out-of-date.

Procedure:

To apply and deploy the solution globally:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • PatternTooOldSmartScan=1 NOTE: To disable the setting, set this key to "0" or delete it.
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path:

    • 32-bit: HKEYLOCALMACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\PatternTooOldSmartScan
    • 64-bit: HKEYLOCALMACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\PatternTooOldSmartScan
  • Key: PatternTooOldSmartScan
  • Type: DWORD
  • Value: 1
  1. Restart the OfficeScan agents.

Enhancement 3 of Hotfix 5110

(SEG-23501)

This hotfix updates the DLP module to support API hooking in Windows 10 RS4 (10.0.17133)

Enhancement 4 of Hotfix 5110

(SEG-25807)

The hotfix enables OfficeScan to monitor file upload traffic for "uploadfiles.io" and "file.io" by adding the related file upload patterns for specific websites.

Enhancement 5 of Hotfix 5110

(SEG-24608)

This hotfix extends the capacity of the Control Device USB Exception list to support up to 100,000 entries.

Issue 1 of Hotfix 5122

(SEG-25160)

Microsoft(TM) Surface(TM) computers where the OfficeScan agent is installed may stop unexpectedly and experience blue screen of death (BSOD) when the Behavior Monitoring feature is enabled.

Solution:

This hotfix updates the Behavior Monitoring module to resolve the issue.

Issue 2 of Hotfix 5122

(SEG-23490), (SEG-19697)

The performance of protected computers slows down when the engine processes a PostClose event in "\Device\Volume".

Solution:

This hotfix provides a way to configure OfficeScan to skip PreClose and PostClose events in "\Device\Volume".

Procedure:

To enable OfficeScan to skip PreClose and PostClose events in "\Device\Volume":

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • tmevtmgr_SkipDeviceVolume=1
  • NOTE: To disable the setting, set this key to "0" or delete it.
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmevtmgr\Parameters
  • Key: SkipDeviceVolume
  • Type: DWORD
  • Value: 1
  1. Restart the OfficeScan agents.

Issue 3 of Hotfix 5122

(SEG-23490), (SEG-14536)

The Keyparc Business program may take one minute to open a newly-created file on an encrypted drive on OfficeScan client computers.

Solution:

This hotfix imports new tmcomm drivers to help ensure that the Keyparc Business program can open newly-created files on encrypted drives normally.

Procedure:

To enable the new service settings:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • TmCommBypassVolDevNormalizeReparse=1
  • NOTE: Setting this key to "1" prevents OfficeScan from reparsing path normalization to prevent performance drop issues, BSOD, and other performance issues.
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmcomm\Parameters
  • Key: BypassVolDevNormalizeReparse
  • Type: DWORD
  • Value: 1 = OfficeScan skips reparsing of path normalization to prevent certain performance issues
  1. Restart the OfficeScan agents.

Issue 4 of Hotfix 5122

(SEG-23542)

After a session times out, an Active Directory (AD) account user can logon to the OfficeScan web console again without providing a username and password by refreshing the web page.

Solution:

This hotfix resolves the issue to ensure that AD account users are required to provide the login credentials again after refreshing the web page.

Issue 5 of Hotfix 5122

(SEG-25939)

OfficeScan's CPU usage may rise when uploading files to Citrix "sharefile.com" website.

Solution:

This hotfix helps keep OfficeScan's CPU usage within the manageable levels when it uploads files to "sharefile.com".

Issue 6 of Hotfix 5122

(SEG-26513)

The Data Loss Prevention(TM) (DLP) module stops unexpectedly while processing General Data Protection Regulation (GDPR) information.

Solution:

This hotfix ensures that the DLP module can process GDPR strings normally.

Issue 7 of Hotfix 5122

(SEG-24694)

The DLP module uses a large amount of CPU resources.

Solution:

The hotfix keeps the DLP module's CPU usage within normal levels.

Issue 8 of Hotfix 5122

(SEG-25427)

The CPU usage of the Trend Micro Data Protection Service reaches up to 25 to 30 percent when users upload an .mp4 file to Google Drive through a web browser.

Solution:

The hotfix provides a way to prevent the CPU usage of the Data Protection Services from rising when users upload .mp4 files to Google Drive and Dropbox.

Procedure:

To configure the new setting for DLP on Google Drive and Dropbox:

  1. Install this hotfix (see "Installation").
  2. Open the "dlp.ini" file in the "\PCCSRV\Private\" folder on the OfficeScan server.
  3. Under the "Configure" section, manually add its value.
  • [Configure]
  • cloudstorage_http2_check=false
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and click "Agents > Agent Management > Select domains or agents > Settings > DLP settings".
  3. Click "Save" to deploy the settings to agents". The OfficeScan server deploys the settings to OfficeScan agents and adds the following key in the "dsa.pro" file in the "\Windows\System32\dgagent\" folder:
  • cloudstorage_http2_check=false
  1. Find a target machine for verification

Issue 9 of Hotfix 5122

(SEG-23571)

OfficeScan agents with duplicate IP addresses are not removed automatically after the server-agent connection is verified.

Solution:

The hotfix ensures that OfficeScan automatically removes older agents with duplicate IP addresses after verifying the server-agent connection.

Issue 10 of Hotfix 5122

(SEG-15460)

The OfficeScan Firewall service may block the connection of a new generation NIC interface on Miracast devices.

Solution:

This hotfix provides a way to adopt the new NIC interface settings from Miracast devices.

Procedure:

To enable the new settings:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • EventTriggerIPChange=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entries on all OfficeScan agent endpoints:
  • Path:
  • For x64 platforms: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\
  • For x86 platforms: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\
  • Key: EventTriggerIPChange
  • Type: REG_DWORD
  • Value: 1

Issue 11 of Hotfix 5122

(SEG-26381)

OfficeScan agents with the program inspection feature enabled may encounter issues with third-party programs due to a conflict with the Memory Scan Trigger pattern (tmmst.ptn/tmmst64.ptn).

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 12 of Hotfix 5122

(SEG-24736)

The OfficeScan User Mode Hooking (UMH) function may prevent the system from shutting down normally.

Solution:

This hotfix updates the OfficeScan UMH module to resolve this issue.

Issue 13 of Hotfix 5122

(SEG-23873)

The User Mode Hooking (UMH) module exclusion list does not accept UNC paths that contain any wildcard character.

Solution:

This hotfix enables the UMH module exclusion list to accept UNC paths that contain wildcard characters.

Issue 1 of Hotfix 5130

(SEG-22908)

The Scan Exclusion Directories and Scan Exclusion Files lists allow users to add more than 256 items.

Solution:

This hotfix ensures that OfficeScan only allows users to add up to 256 items to the lists which is the limitation indicated in the Administrator's Guide.

Issue 2 of Hotfix 5130

(SEG-27028)

After users apply Hotfix 5110, the "Role" column disappears from the "User Accounts" screen of the web console.

Solution:

This hotfix resolves the issue to ensure that the "Role" column appears on the "User Accounts" screen.

Issue 3 of Hotfix 5130

(SEG-27218)

Trend Micro Vulnerability Scanner (TMVS) stop working when users select more than two endpoints to install Trend Micro OfficeScan agent(s).

Solution:

This hotfix resolves the issue and provides a way to ensure that the correct port is used in "TMVS.ini" and "Schedule.ini".

Procedure:

To modify "TMVS.ini" and "Schedule.ini" so that both use the correct port:

  1. Install this hotfix (see "Installation").
  2. Open the "TMVS.ini" file in the "\PCCSRV\Admin\Utility\TMVS\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "OfficeScan Server Setting" section, manually delete the host name of the OfficeScan server from the key below:
  • [OfficeScan Server Setting]
  • OsceServer=
  1. Save the changes and close the file.
  2. Run "TMVS.exe". The "OsceServerPort" key under the "OfficeScan Server Setting" section in "TMVS.ini" will automatically be set to the SSL port.
  • [OfficeScan Server Setting]
  • OsceServerPort= SSL port
    NOTE: "TMVS.exe" can be used for Manual Scan after modifying "TMVS.ini". If you have already created a scheduled scan record before applying this hotfix, proceed to the next step.
  1. Open the "Schedule[number].ini" file in the "\PCCSRV\Admin\Utility\TMVS\" folder of the OfficeScan server installation directory using a text editor.
    NOTES:
  • [number] depends on the user's environment, it may be Schedule1, Schedule2...
  • All "Schedule[number].ini" files created before applying this hotfix should be modified.
  1. Under the "OfficeScan Server Setting" section, manually delete the host name of the OfficeScan server from the following key
  • [OfficeScan Server Setting]
  • OsceServer=
  1. Save the changes and close the file.
  2. Repeat steps 6 to 8 for each "Schedule[number].ini" file.
  3. Run "TMVS.exe". The "OsceServerPort" under the "OfficeScan Server Setting" section in "Schedule[number].ini" will be set to the SSL port.
  • [OfficeScan Server Setting]
  • OsceServerPort= SSL port
    NOTE: "TMVS.exe" can be used for Scheduled Scan after modifying "TMVS.ini" and "Schedule.ini".

Issue 4 of Hotfix 5130

(SEG-20456)

When an Edge Server is installed and used in an environment and users deploy gateway IPs to an OfficeScan agent machine, and if the assigned gateway IPs and gateway IPs on the machine do not match, the OfficeScan agent will only connect to Edge Server even when the agent can connect to the OfficeScan Server in the same network.

Solution:

The hotfix updates the "Synchronize" registry key in the Misc file for Client/Server Communication so that when it is set to "0", the agent will connect to the OfficeScan server under the scenario described above.

Issue 5 of Hotfix 5130

(SEG-2847)

OfficeScan agents may appear "Offline" on the OfficeScan web console but "Online" when viewing the OfficeScan agent icon.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 6 of Hotfix 5130

(SEG-25982)

The Data Loss Prevention(TM) (DLP) service of the OfficeScan agent may not be installed or started properly.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 7 of Hotfix 5130

(SEG-26122)

The Dashboard Summary on the OfficeScan web console shows that there are violation logs generated within the last 24 hours but a manual check indicates that no logs were generated in the same time frame.

Solution:

This hotfix updates the OfficeScan server program to ensure that the Dashboard Summary displays accurate information.

Issue 8 of Hotfix 5130

(SEG-25595), (SEG-26902)

When users log on to any non-English version of the OfficeScan web console with a created user account, the Dashboard pages show English content.

Solution:

The hotfix ensures that the Dashboard pages display in the correct language when users log on to the OfficeScan web console using user accounts created after installing this hotfix.

Issue 9 of Hotfix 5130

(SEG-27050)

An agent's connection status icon is grayed-out in the agent console flyover when the agent uses conventional scan mode and only Real-time Scan is enabled.

Solution:

The hotfix ensures that the connection status icon is green when agents use conventional scan mode and only Real-time Scan is enabled. The connection status signal will be grayed-out only if all modules are disabled even when agents are connected to the OfficeScan server.

Issue 10 of Hotfix 5130

(SEG-24168)

A SQL exception occurs when the OfficeScan agent GUID field is empty.

Solution:

The hotfix enables OfficeScan to handle the exception to resolve the issue.

Issue 11 of Hotfix 5130

(SEG-25661)

The PccNtMon service does not apply updates to the Local Area Network (LAN) proxy settings to the proxy settings of Predictive Machine Learning when both the Smart Protection Service and Smart Scan are disabled.

Solution:

This hotfix ensures that changes to the LAN proxy settings are automatically applied to the Predictive Machine Learning proxy settings.

NOTE: If you experience this issue, you need to manually save the LAN proxy setting again after applying this hotfix.

Enhancement 1 of Hotfix 5130

(SEG-27168)

This hotfix adds the "MAX_FILE_SIZE" and "MAX_TXT_FILE_SIZE" parameters to enable users to set the file size limitation for DLP content scanning.

Enhancement 2 of Hotfix 5130

(SEG-26791)

This hotfix enables OfficeScan to monitor open file dialog and drag and drop events for Sugarsync and Hightail.

Enhancement 3 of Hotfix 5130

(SEG-25643)

A user requests for an API to automate the move and uninstall agent processes.

Procedure:

To enable the new settings:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following keys and set both values to "1".
  • [Global Setting]
  • EnableMoveNATClient=1
  • MoveNATClientRemoveEmptyDomain=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent endpoints:
  • Only "EnableMoveNATClient" will be deployed to client, the path:
  • For x64 platforms:
  • HKEYLOCALMACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\
  • For x86 platforms:
  • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\
  • Key:
  • EnableMoveNATClient
  • Type: REGDWORD
  • Value: 1

Enhancement 4 of Hotfix 5130

(SEG-26800)

This hotfix enables OfficeScan to detect "Italy: CF – Codice Fiscale (Tax Code)" keywords that do not contain any space.

Issue 1 of Hotfix 5137

(SEG-27830)

An issue prevents OfficeScan from detecting file attachments in Gmail.

Solution:

The hotfix resolves the issue by enabling OfficeScan to parse file attachments using an HTTP and HTTP/2 parser.

Issue 1 of Critical Patch 5147

(VRTS-2184), (VRTS-2185), (VRTS-2187), (VRTS-2189), (VRTS-2443)

An issue related to the Trend Micro OfficeScan Firewall driver may cause multiple Privilege Escalation and Pool Corruption vulnerabilities.

Solution:

This critical patch updates the Trend Micro OfficeScan Firewall driver to resolve the vulnerabilities.

Enhancement 1 of Critical Patch 5147

(SEG-26512)

This critical patch enables the OfficeScan XG Service Pack 1 agent program to support Windows 10 (version 1803) April 2018 Update.

Issue 1 of Hotfix 5154

(SEG-27828)

The Common Firewall driver generates incorrect and outdated search results on the OfficeScan web console.

Solution:

This hotfix updates the OfficeScan server program to prevent this issue from occurring.

Issue 2 of Hotfix 5154

(SEG-29180)

Users can enable "Export Scan Exclusions" to save the scan exclusions list in a CSV format on the OfficeScan server. However, the exclusion lists are not displayed correctly in the German version of OfficeScan.

Solution:

This hotfix updates the OfficeScan server files to resolve this issue.

Issue 3 of Hotfix 5154

(SEG-25101)

Even if users have local administrator privileges with their user accounts, the following error message still appears when installing OfficeScan XG Service Pack 1 agent using AUTOPCC via the login script:

"To install/uninstall the OfficeScan Agent, you must have administrator privileges to this computer."

Solution:

This hotfix updates the OfficeScan server program to resolve this issue.

Issue 4 of Hotfix 5154

(SEG-27809)

When Data Loss Prevention(TM) (DLP) Service is enabled on a virtual Windows Server, it causes the endpoint to freeze or become unresponsive within intervals of a few minutes.

Solution:

This hotfix resolves the issue by updating the DLP module.

Issue 5 of Hotfix 5154

(SEG-28172)

When users perform a fresh installation of an OfficeScan agent with conventional scan mode using an "*.exe" package or the "AutoPcc.exe" file, the system does not generate some registry keys required by the Predictive Machine Learning feature.

Solution:

This hotfix ensures that the system generates all necessary registry keys when an OfficeScan agent is installed with conventional scan mode.

Issue 6 of Hotfix 5154

(SEG-23277)

A compatibility issue between "Optimus5.exe" and OfficeScan Behavior Monitoring may cause "Optimus5.exe" to become unresponsive.

Solution:

This hotfix resolves the issue by updating the Behavior Monitoring module.

Issue 7 of Hotfix 5154

(SEG-29538)

Trend Micro Vulnerability Scanner (TMVS) stops unexpectedly when users configure Scheduled Scan tasks that exceed 16 characters.

Solution:

This hotfix resolves the issue so users can configure Scheduled Scan tasks normally.

Issue 8 of Hotfix 5154

(SEG-28362)

Trend X alerts are disabled unexpectedly.

Solution:

The hotfix prevents OfficeScan from resetting the TrendxAlert registry key when the TmListen service starts if the agent is not a fresh installation.

Issue 9 of Hotfix 5154

(SEG-28559)

OfficeScan agents send a sample file even when sample submission is disabled.

Solution:

This hotfix enables OfficeScan agents to always check the "EnableSampleSubmission" key and apply the correct setting so that these agents do not send out sample files when sample submission is disabled.

Issue 10 of Hotfix 5154

(SEG-27256)

In some user environments where Windows Updates are not applied, OfficeScan agents may not be able to update their Smart Scan Pattern properly.

Solution:

This hotfix resolves the issue by updating the Active Update module.

Issue 11 of Hotfix 5154

(SEG-28180)

When an OfficeScan client detects a sample virus file (EICAR.COM), it may not be able to send the file to the OfficeScan server. This happens when a Windows socket error prevents it from extracting the correct IP address.

Solution:

This hotfix resolves this issue so that the OfficeScan client can retrieve the correct IP address and send the files out normally.

Enhancement 1 of Hotfix 5154

(SEG-27748)

The hotfix enables the Integrated Data Loss Prevention (DLP) module to support PGP Desktop 10.3.2 by adding the PGP 10.3.2 API pattern.

Enhancement 2 of Hotfix 5154

(SEG-28957)

This hotfix enables Data Loss Prevention(TM) (DLP) Endpoint SDK 6.2 to skip the Domain Name System (DNS) from resolving customized web sites.

Procedure:

To configure the new setting for DLP:

  1. Install this hotfix (see "Installation").
  2. Open the "dlp.ini" file in the "\PCCSRV\Private\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Configure" section, manually add the "BYPASS_DNS_RESOLVE_WEBSITES" key and set its value.
  • [Configure]
  • BYPASS_DNS_RESOLVE_WEBSITES=example1.com,example2.com
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Agent Management > Select domains or agents > Settings > DLP settings" screen.
  3. Click "Save" to deploy the setting to agents". The OfficeScan server deploys the setting to OfficeScan agents and adds the following key in the "dsa.pro" file in the "\Windows\System32\dgagent\" folder:
  • BYPASS_DNS_RESOLVE_WEBSITES=example1.com,example2.com

Issue 1 of Hotfix 5158

(SEG-28228)

Users have "Full Control" permission on the OfficeScan client folder because the Osprey function resets the OfficeScan client folder permission from "Read&Execute" to "Full Control".

Solution:

This hotfix resolves this issue by adjusting the OfficeScan client folder permission to "Read&Execute" right after the Osprey function runs.

Issue 2 of Hotfix 5158

(SEG-30730)

The Recent file list is missing from the right-click menu on the Microsoft(TM) Windows(TM) taskbar and from the "Start" menu when the Data Loss Prevention(TM) (DLP) Service is enabled.

Solution:

This hotfix resolves this issue by updating the file event scanning procedure for "RuntimeBroker.exe" with the Microsoft Windows Jump List under the "automaticdestinations-ms" folder.

Issue 3 of Hotfix 5158

(SEG-26606)

Users are unable to eject encrypted flash drives when the system enables Trend Micro Predictive Machine Learning on coexisting OfficeScan agents.

Solution:

This hotfix updates the OfficeScan agent program to prevent this issue from occurring.

Procedure:

To enable the feature for OfficeScan agents and the OfficeScan server:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • MonitorFixedDrive=1
  • NOTE: To disable the setting, set this key to "0".
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entries on all OfficeScan agent computers:
  • Path:
  • for x64 platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.
  • for x86 platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.

    • Key: MonitorFixedDrive
    • Type: REG_DWORD
    • Value: 1

Issue 4 of Hotfix 5158

(SEG-29206)

DLP Service may not be able to block devices properly if users enable these devices in the Device Manager function of the computer.

Solution:

This hotfix resolves the issue by updating the DLP module.

Issue 5 of Hotfix 5158

(SEG-23539)

Administrators cannot set a registry key when installing third- party applications, which is caused by the OfficeScan Self-protection function.

Solution:

This hotfix exempts the "Msiexec.exe" installer from the OfficeScan Self-protection function and ensures that administrators can successfully install third-party applications.

Issue 6 of Hotfix 5158

(SEG-26683)

Detection notification does not pop up and there is no record in the security risk log when users try to open a malware file from the network drive.

Solution:

This hotfix updates the OfficeScanNT real-time scan ("Ntrtscan.exe") function and enables the real-time scan to go through the correct process, ensuring that the real-time scan accesses and scans files located on network drives.

Issue 7 of Hotfix 5158

(SEG-29225)

Users experience PsTools interference issues because Windows cannot access "C:\Windows\System32\sc.exe" program on x86 platforms.

Solution:

The hotfix amends the Unauthorized Change Prevention policy to resolve this issue.

Issue 8 of Hotfix 5158

(SEG-30736)

The DLP version appears as 0.0.0 on both the management console and agent console.

Solution:

This hotfix ensures that the correct DLP version appears on both the management console and agent console.

Issue 9 of Hotfix 5158

(SEG-26869)

OfficeScan off-premises agents connected to the OfficeScan Edge Relay server fail to send virus/spyware logs to the OfficeScan server.

Solution:

The hotfix resolves this issue by enabling OfficeScan to resend the HTTP request while receiving the "ERROR_WINHTTP_RESEND_REQUEST" message.

Issue 10 of Hotfix 5158

(SEG-29928)

When the Advanced Protection Service is disabled in an OfficeScan agent, smvptn files accumulate and are not cleaned promptly.

Solution:

This hotfix resolves the issue by updating the NTRT module to check the current smv patterns to keep only the two most recent versions and delete all older versions.

Enhancement 1 of Hotfix 5158

(SEG-27626)

This hotfix provides administrators a way to adjust the header size limit and number of entities to detect risky emails.

Procedure:

To adjust the header size limit and number of entities to detect risky email messages:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following keys and set the values.
  • [Global Setting]
  • BytesPerEntHdr=size of all header fields allowed in each entity
  • EntPerMsg=number of entities allowed in each mail message

    For example:

  • [Global Setting]
  • BytesPerEntHdr=32768
  • EntPerMsg=64
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and set the following registry entry on all OfficeScan agent endpoints:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Osprey\Scan\Common\MailManager\config
  • Key: BytesPerEntHdr
  • Type: DWORD
  • Value: For example: 0x00008000 (32768)
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Osprey\Scan\Common\MailManager\config
  • Key: EntPerMsg
  • Type: DWORD
  • Value: For example: 0x00000040 (64)

Enhancement 2 of Hotfix 5158

(SEG-30242)

This hotfix enables DLP Endpoint SDK 6.2 to support the device type exception keys for USB devices in the DLP Device Control mode.

Issue 1 of Hotfix 5167

(SEG-26570)

Users may not be able to print files normally on a protected endpoint when both the OfficeScan Predictive Machine Learning feature and the Behavior Monitoring feature are enabled.

Solution:

This hotfix resolves the issue by updating the Behavior Monitoring module.

Issue 2 of Hotfix 5167

(SEG-27727)

The Behavior Monitoring feature may prevent users from opening Microsoft(TM) Office programs normally if the OfficeScan agent cannot connect to the Trend Micro Census Server properly.

Solution:

This hotfix resolves the issue by updating the Behavior Monitoring module.

Issue 3 of Hotfix 5167

(SEG-30296)

The Data Loss Prevention(TM) (DLP) Service may prevent users from accessing Microsoft(TM) Excel files normally.

Solution:

This hotfix resolves the issue by updating the DLP module.

Issue 4 of Hotfix 5167

(SEG-24733)

Microsoft Internet Explorer(TM) (IE) stops unexpectedly because of a Browser Exploit Prevention memory allocation failure when users browse files through a 3rd-party web application.

Solution:

This hotfix updates the Browser Exploit Prevention module to prevent it from stopping unexpectedly when it encounters issues while allocating memory.

Issue 5 of Hotfix 5167

(SEG-30241)

Users encounter an "Update Failed" message after clicking the "Update Information" button on the product license page.

Solution:

This hotfix resolves the issue by enabling OfficeScan to clear existing garbage data in the structures.

Issue 6 of Hotfix 5167

(SEG-29900)

Sometimes, the database cannot retrieve strings with special characters when the server queries the Domain Name. When this happens, garbage characters appear on the "Agent Component Update Details" page.

Solution:

This hotfix updates the related database modules to ensure that the database can retrieve strings with special characters while resolving domain names.

Issue 7 of Hotfix 5167

(SEG-31152)

After users apply Hotfix 5158 included in version 6.2.1208 of the DLP module, the list of approved devices does not work until after the DLP service restarts.

Solution:

The hotfix updates the DLP module to resolve the issue.

Issue 8 of Hotfix 5167

(VRTS-2465), (VRTS-2466), (VRTS-2467)

An attacker may craft a malicious request and cause AMSP to help on creating a process that provides SYSTEM privileges to the attackers.

Solution:

This hotfix updates the AMSP file ("coreCommandmanager.dll") to resolve this issue.

Enhancement 1 of Hotfix 5167

(SEG-25083)

This hotfix adds a new configuration key to allow users to manually add websites to the monitored list.

Procedure:

To configure the new setting for DLP:

  1. Install this hotfix (see "Installation").
  2. Open the "dlp.ini" file in the "\PCCSRV\Private\" folder on the OfficeScan server.
  3. Under the "Configure" section, manually add the "monitor_file_upload_websites" key and set its value to the specific website.
  • [Configure]
  • monitor_file_upload_websites=web.airdroid.com
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and click "Agents > Agent Management > Select domains or agents > Settings > DLP settings".
  3. Click "Save" to deploy the settings to agents".

The OfficeScan server deploys the settings to OfficeScan agents and adds the following key in the "dsa.pro" file in the "\Windows\System32\dgagent\" folder:

  • monitor_file_upload_websites=web.airdroid.com

Issue 1 of Hotfix 5180

(SEG-31393)

Scheduled scan is postponed because OfficeScan detects full screen mode even when there are no windows in full screen mode.

Solution:

This hotfix enables OfficeScan to ignore windows that do not have visible content during full screen mode detection.

Issue 2 of Hotfix 5180

(SEG-31525)

The OfficeScan NT Listener service ("TmListen.exe") may stop unexpectedly after the OfficeScan XG Service Pack 1 agent restarts. When this happens, the agent update fails.

Solution:

This hotfix updates the OfficeScan agent program to prevent the "TmListen.exe" from stopping unexpectedly.

Issue 3 of Hotfix 5180

(SEG-28309)

When the OfficeScan agent detects a virus/malware, it may not be able to move the quarantined file to the OfficeScan server. This happens when the OfficeScan agent could not resolve the hostname of the OfficeScan server properly.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Issue 4 of Hotfix 5180

(SEG-29948)

After upgrading to OfficeScan XG Service Pack 1, the default communication port between the OfficeScan agent and the server changed to SSL port 4343. For OfficeScan agents with the firewall enabled, the firewall continues to use the older port 8080 as a trusted port and prevents the OfficeScan agent from connecting to the server.

Solution:

This hotfix resolves this issue by ensuring that updated OfficeScan agents add port 4343 to the OfficeScan firewall trusted port list. To ensure that the network quarantine feature continues to function, this hotfix also adds the IPv4 DNS and WINS ports to the trusted port list.

Issue 5 of Hotfix 5180

(SEG-30980)

User encounter an "Invalid Session…" error when making changes to the OfficeScan settings through the web console using an Active Directory (AD) user account that belongs to a sub group.

Solution:

This hotfix resolves the issue by adding the caller function "checkingRBAMenuRoles" to use the AD token to get information from all domain layers.

Issue 6 of Hotfix 5180

(SEG-31880)

In assessment mode, Web Reputation logs display the "Action" results as "Assess" on the OfficeScan web console but shows "Block" in the Trend Micro Control Manager(TM) web console.

Solution:

This hotfix updates the OfficeScan Web Reputation module to ensure that the "Action" results in Web Reputation logs on the OfficeScan web console are consistent with the information on the Control Manager web console in assessment mode.

Issue 7 of Hotfix 5180

(SEG-32171)

When OfficeScan agents are configured not to upgrade the OfficeScan agent program or deploy hotfixes, inaccurate minor version information appears for the Advanced Threat Scan Engine (ATSE) on the agent console after ATSE updates from the ActiveUpdate (AU) Server. For example, the minor version number is displayed as "10.2.1006" instead of "10.200.1006".

Solution:

This hotfix ensures that the agent console displays the ATSE version information accurately.

Issue 8 of Hotfix 5180

(SEG-27671)

An exception error triggers the OfficeScan Master Service to stop unexpectedly while extracting a pattern file from a compressed file.

Solution:

This hotfix updates the OfficeScan Master Service to enable it to handle the exception.

Enhancement 1 of Hotfix 5180

(SEG-23154)

This hotfix improves OfficeScan's security checking feature for digital signatures during program deployment in air gap network environments by allowing users to configure the interval of the uploading digital signature check failure logs. This hotfix also decommissions the following settings:

  • CheckDigitalSignatureForHotfix
  • CheckDigitalSignatureForUpgrade
  • DOVF

Procedure:

To configure the interval of the uploading digital signature check failure logs:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following key and set it to the time interval in seconds.
  • [Global Setting]
  • DSInvalidLogUploadInterval=3600(default, sec)
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to clients.
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.
  • Key: DSInvalidLogUploadInterval
  • Type: DWORD
  • Value: 3600

Enhancement 2 of Hotfix 5180

(SEG-27559)

This hotfix enables users to configure the Behavior Monitoring autorun function to skip devices in the Device Access Control (DAC) approved list.

Procedure:

To configure the Behavior Monitoring autorun function to skip devices in the DAC approved list:

  1. Install this hotfix (see "Installation").
  2. Open the "Ofcscan.ini" file in the "\PCCSRV\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • SkipDACAutorunJunctionPointerChecking=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS
  • Key: SkipDACAutorunJunctionPointerChecking
  • Type: REG_DWORD
  • Value: 1

Issue 1 of Critical Patch 5180

(VRTS-2485)

A possible ZDI-CAN-6104 compromise may cause the OfficeScan NT RealTime Scan ("Ntrtscan.exe") service to stop unexpectedly.

Solution:

This critical patch updates the OfficeScan agent program to resolve the vulnerability.

Issue 1 of Hotfix 5182

(SEG-31268)

The "Channel" results in Data Loss Protection(TM) (DLP) logs appear as "FileWrite" on the OfficeScan agent console but are displayed as "IM (Skype for Business)" on the OfficeScan web console.

Solution:

This hotfix updates the OfficeScan agent program to ensure that "Channel" results in DLP logs on the OfficeScan agent console are consistent with the information on the OfficeScan web console.

Issue 2 of Hotfix 5182

(SEG-30308)

Some OfficeScan agents keep sending requests to the server frequently which causes a high CPU usage issue on the OfficeScan server.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Enhancement 1 of Hotfix 5182

(SEG-32176)

This hotfix enables users to specify a registry configuration for OfficeScan agents to work around interoperability or false alarm issues when the Anti-exploit Protection feature is enabled under the OfficeScan User-Mode Hooking settings.

Procedure:

To enable users to specify the registry configuration for OfficeScan agents:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value
  • [Global Setting]
  • SysUmExploitDefault=(hexadecimal value)
  • NOTE: This key supports any hexadecimal value between 00000000 and FFFFFFFF. To disable all the features, set "SysUmExploitDefault=00000000". To enable all the features, set "SysUmExploitDefault=FFFFFFFF".
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS\
  • Key: SysUmExploitDefault
  • Type: DWORD
  • Value: 0x00000000 ~ 0xFFFFFFFF

Enhancement 2 of Hotfix 5182

(SEG-32394)

This hotfix updates OfficeScan NT Listener and allows users to configure OfficeScan to automatically remove the Trend Micro NT Firewall Service (tmpfw.exe) and Trend Micro Network Driver Interface Specification Filter driver (tmlwf.sys) after OfficeScan Firewall service is disabled.

Procedure:

To configure OfficeScan to automatically remove the Trend Micro NT Firewall Service (tmpfw.exe) and Trend Micro Network Driver Interface Specification Filter driver (tmlwf.sys) after OfficeScan Firewall service is disabled:

  1. Install this hotfix (see "Installation") with Trend Micro NT Firewall Service enabled.
  2. Open OfficeScan web console and go to "Administration > Settings > Product License" > "Additional Services"
  3. Under "Additional Services", click the "Disable" button to stop the firewall service.
  4. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  5. Under the "Global Setting" section, manually add the following key and set its value.
  • [Global Setting]
  • RmvPFWifDisabled=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
  • Key: RmvPFWifDisabled
  • Type: DWORD
  • Value: 1
  1. Unload and then reload OfficeScan agents.

Issue 1 of Hotfix 5186

(SEG-30786)

Sometimes, Microsoft(TM) Windows(TM) Defender is not enabled automatically after uninstalling the OfficeScan agent even when configured to do so.

Solution:

This hotfix ensures that when configured to do so, Windows Defender is enabled automatically after uninstalling an OfficeScan agent.

Issue 2 of Hotfix 5186

(SEG-25062)

When an OfficeScan agent detects a file on the Volume Shadow copy, the "Action" result in the Suspicious File logs on the agent console and on the Trend Micro Control Manager(TM) web console appears as "Unable to quarantine the file", but displays as "Quarantined" on the OfficeScan web console.

Solution:

This hotfix updates the OfficeScan NT Listener service ("TmListen.exe") to ensure that the "Action" results in Suspicious File logs on the OfficeScan web console matches the information on the agent console and Control Manager web console.

Issue 3 of Hotfix 5186

(SEG-28350)

An OfficeScan agent may take a long time to complete an update while Device Control is enabled in a complicated Active Directory (AD) environment.

Solution:

The hotfix resolves the issue by enabling users to configure the OfficeScan agent to skip AD synchronization during updates.

Procedure:

To configure the OfficeScan agent to skip AD synchronization during updates:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • DisableUserBasedDC=1
  1. Save the changes and close the file.

Issue 1 of Hotfix 5194

(SEG-31231)

An issue related to the Data Loss Prevention(TM) (DLP) module may cause a platform's performance to slow down when multiple users login at the same time.

Solution:

This hotfix resolves the issue by updating the DLP module.

Issue 2 of Hotfix 5194

(SEG-33714)

After applying Hotfix 5180, the "Scan Now" and "Agent Uninstallation" pages display all OfficeScan agents even when users select only one or a few agents before clicking "Scan Now" or "Agent Uninstallation".

Solution:

This hotfix ensures that the "Scan Now" and "Agent Uninstallation" pages display only the selected agents.

Issue 3 of Hotfix 5194

(SEG-31333)

A process stops responding while starting up when DLP API hooking events logs are enabled.

Solution:

The hotfix resolves the issue by adding non-interested Microsoft(TM) Windows(TM) processes into the API hooking approved list.

Issue 1 of Hotfix 5202

(SEG-33648)

Users cannot add a Firewall Profile with the "Logon name" criterion on the OfficeScan web console.

Solution:

This hotfix enables users to add Firewall Profiles with the "Logon name" criterion.

Issue 2 of Hotfix 5202

(SEG-34165)

The "RelayClientGetHotfixFrom" setting in OfficeScan agents always indicate "HTTP" even when update agents communicate with other OfficeScan agents by HTTPS.

Solution:

This hotfix ensures that the "RelayClientGetHotfixFrom" registry key always indicates the correct setting.

Issue 3 of Hotfix 5202

(SEG-32040)

Device Control cannot block iPhones on Microsoft(TM) Windows(TM) 10 RS3 and any higher version.

Solution:

This hotfix updates the OfficeScan Data Loss Prevention(TM) (DLP) module to enable Device Control to block iPhones on Windows 10 RS3 and any higher version.

Issue 4 of Hotfix 5202

(SEG-32288)

The OfficeScan Predictive Machine Learning feature does not use anonymous information when sending threat information queries to the Trend Micro Backend Machine Learning Service and the Behavior Monitoring feature may share non-anonymous threat information with the Trend Micro Smart Protection Network (SPN).

Solution:

This hotfix updates the OfficeScan agent program and the Behavior Monitoring module to resolve this issue.

Issue 5 of Hotfix 5202

(SEG-32490)

Copying files from a shared folder to a USB flash drive may generate multiple copies of forensic data in the DLP forensic quarantine folder which may eventually take up too much disk space in both the OfficeScan server and client computers.

Solution:

This hotfix updates DLP Endpoint SDK 6.2 to add a log throttling feature to help prevent the issue from occurring.

Procedure:

To enable the log throttling feature:

  1. Install this hotfix (see "Installation").
  2. Open the "dlp.ini" file in the "\PCCSRV\Private\" folder of the OfficeScan server installation directory using a text editor.
  3. Under the "Configure" section, manually add the "log_throttle" key and set its value to "true".
  • [Configure]
  • log_throttle=true
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Agent Management > Select domains or agents > Settings > DLP settings" screen.
  3. Click "Save" to deploy the setting to agents". The OfficeScan server deploys the setting to OfficeScan agents and adds the following key in the "dsa.pro" file in the "\Windows\System32\dgagent\" folder:
  • log_throttle=true
  1. Restart the OfficeScan agents.

Issue 1 of Hotfix 5221

(SEG-33508)

An issue related to the OfficeScan Behavior Monitoring feature may prevent protected computers from accessing remote folders.

Solution:

This hotfix updates the Behavior Monitoring module and enables users to configure the feature to skip file events related to "desktop.ini" and remote directories to help resolve the issue.

Procedure:

To apply and deploy the solution globally:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the "AegisSkipDesktopINI" key and "AegisSkipRemoteDirectory" key and set both to "1".
  • [Global Setting]
  • AegisSkipDesktopINI=1
  • AegisSkipRemoteDirectory=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS
  • Key: SkipDesktopINI
  • Key: SkipRemoteDirectory
  • Type: DWORD
  • Value: 1
  1. Restart the OfficeScan agent

Issue 2 of Hotfix 5221

(SEG-34473)

Microsoft(TM) Internet Explorer(TM) (IE) stops unexpectedly because of a Browser Exploit Prevention memory allocation failure when users browse files through a 3rd-party web application.

Solution:

This hotfix updates the Browser Exploit Prevention module (version 9.2.2066) to prevent it from stopping unexpectedly when it encounters issues while allocating memory.

Issue 3 of Hotfix 5221

(SEG-27901)

The OfficeScan Data Loss Prevention(TM) (DLP) module cannot block users from uploading file attachments in Gmail on Mozilla(R) Firefox(R).

Solution:

This hotfix updates the DLP module to enable it to block the upload of file attachments in Gmail on Firefox.

Issue 4 of Hotfix 5221

(SEG-31609)

The OfficeScan DLP module still monitors non-monitored domain email messages.

Solution:

This hotfix ensures that the DLP module skips non-monitored domain email messages.

Issue 5 of Hotfix 5221

(SEG-34167)

On the OfficeScan web console, the tooltips in the "Behavior Monitoring Settings" under the "Global Agent Settings" may confuse users.

Solution:

This hotfix updates the tooltips to prevent confusion.

Before:

"For "newly encountered program" handling, the maximum prompt timer is 25 seconds. If the timer is set to a value greater than 25 seconds, the newly encountered program prompt defaults to 25. For normal Behavior Monitoring program access, the configured time is used."

After:

"For "newly encountered program" handling, the maximum prompt timer is 25 seconds, If the timer is set to a value greater than 25 seconds, the newly encountered program prompt defaults to 25. For "Ask when necessary" action of "Event Monitor" handling, the configured time is used."

Issue 6 of Hotfix 5221

(SEG-33615)

Endpoints may stop unexpectedly or experience a blue screen of death (BSOD) while accessing Microsoft Excel files when DLP is enabled on the OfficeScan agent.

Solution:

This hotfix updates the Data Protection module to resolve this issue.

Issue 7 of Hotfix 5221

(SEG-30856)

OfficeScan still receives false positive C&C callback alerts for IP addresses that have been added into the Network Content Inspection Engine (NCIE) approved list.

Solution:

This hotfix resolves this issue by enabling users to create a list of IP addresses exempted from C&C callback alerts.

Procedure:

To create a list and add IP addresses to the C&C callback alert exception list:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  3. Under the "INI_STANDARD_ALERT_CCCA_SECTION" section, add IP address in the following format:
  • [INI_STANDARD_ALERT_CCCA_SECTION]
  • Skip_CCCA_Addr_Count=5 (the total number of IP addreses on the list)
  • Skip_CCCA_Addr_1=xx.xx.xx.xx
  • Skip_CCCA_Addr_2=xx.xx.xx.xx
  • Skip_CCCA_Addr_3=xx.xx.xx.xx
  • Skip_CCCA_Addr_4=xx.xx.xx.xx
  • Skip_CCCA_Addr_5=xx.xx.xx.xx
  1. Save the changes and close the file.
  2. Restart the OfficeScan Master Service.

Issue 8 of Hotfix 5221

(SEG-33598)

In certain non-English versions of the OfficeScan web console, clicking on the "Web Reputation" link under the known threats section in the "Overall Threat Detections and Policy Violations" widget opens a blank browser window.

Solution:

This hotfix updates the OfficeScan server files to ensure that the information can be displayed normally.

Issue 9 of Hotfix 5221

(SEG-31178)

A deployment cache error may cause the Trend Micro Control Manager(TM) server to display inaccurate OfficeScan agent policy deployment status.

Solution:

This hotfix updates the policy cache handler in the policy cache to ensure that the most updated policy deployment status appears on the Control Manager console.

Issue 10 of Hotfix 5221

(SEG-34904)

OfficeScan agents block the Think-cell application used in the Microsoft Powerpoint and Excel when the User Mode Hooking (UMH) function enabled.

Solution:

This hotfix updates the OfficeScan UMH module to resolve this issue.

Issue 11 of Hotfix 5221

(SEG-34810)

The OfficeScan server cannot apply a Control Manager policy if the policy settings contain any UTF-8 character.

Solution:

This hotfix enables the OfficeScan server to handle UTF-8 strings in Control Manager policies to resolve the issue.

Issue 12 of Hotfix 5221

(SEG-34625)

Users encounter the "Unable to establish connection. Verify the connection settings and try again." error message after specifying an Active Directory (AD) domain password that contains a plus sign "+" in "Administration > Active Directory > Active Directory Integration > Specify Domain Credential > Input Domain Credential > Save and Synchronize" on the OfficeScan web console.

Solution:

This hotfix updates the OfficeScan server file to resolve the issue.

Issue 13 of Hotfix 5221

(SEG-33179)

The Threat Type of Security Risk Detections Over Time widget displays inaccurate information after users click on an item if the web console time zone is set to any time zone west of GMT.

Solution:

This hotfix resolves this issue by enabling the widget to use the local time zone to calculate the starting time stamp of "00:00" when exporting the database.

Issue 14 of Hotfix 5221

(SEG-35114)

After applying Hotfix 5186/5194/5202, certain OfficeScan processes may stop unexpectedly under certain scenarios.

Solution:

This hotfix updates the OfficeScan agent program to resolve this issue.

Procedure:

To configure the OfficeScan agent to skip AD synchronization during updates before applying this hotfix:

  1. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  2. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • DisableUserBasedDC=1
  1. Save the changes and close the file.
  2. Install this hotfix (see "Installation").
  3. Trigger agent update.
  4. Ensure all agent are upgraded to 5221 version.
  5. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  6. Under the "Global Setting" section, locate the following key and set its value to "0".
  • [Global Setting]
  • DisableUserBasedDC=0
  1. Save the changes and close the file.

Enhancement 1 of Hotfix 5221

(SEG-34133)

This hotfix enables OfficeScan to check if the following DLP PE files contain the Trend Micro Signature.

  • dsagent.exe
  • dbghelp.dll
  • dten600.dll (x86 platform)
  • dtengine64.dll (x64 platform)
  • icudt48.dll
  • icuin48.dll
  • icuuc48.dll
  • Microsoft Kernel-Mode Driver Framework Install-v1.9-Vista.msu
  • Microsoft Kernel-Mode Driver Framework Install-v1.9-Win2k-WinXP-Win2k3.exe
  • Microsoft User-Mode Driver Framework Install-v1.9-Vista.msu
  • Microsoft User-Mode Driver Framework Install-v1.9-WinXP-Srv03.exe
  • msvcm80.dll
  • msvcp80.dll
  • msvcr80.dll
  • WinUSB.exe
  • WinUSB_1.9.msu

Issue 1 of Hotfix 5225

(SEG-31399)

After the OfficeScanNT Real-time Scan ("Ntrtscan.exe") service restarts, it scans folders in the exclusion list.

Solution:

This hotfix updates the OfficeScanNT Real-time Scan ("Ntrtscan.exe") service to ensure that it skips folders and files in the exclusion list.

Issue 2 of Hotfix 5225

(SEG-33051)

After an OfficeScan agent computer shuts down, its connection status on the OfficeScan web console remains as "Online" instead of automatically changing to "Offline". This happens because an agent computer may not be able to report its status to the OfficeScan server when it shuts down too fast.

Solution:

This hotfix updates the OfficeScan agent program to ensure that the agent status on the OfficeScan web console is updated promptly after the agent computer shuts down.

Issue 3 of Hotfix 5225

(SEG-33331)

OfficeScan agent computers may experience blue screen of death (BSOD) while running the IBM ClearCase third-party program when Trend Micro Data Loss Prevention(TM) (DLP) is enabled.

Solution:

This hotfix updates the DLP module to resolve this issue.

Issue 4 of Hotfix 5225

(SEG-33396)

The DLP module cannot detect sensitive keywords that were specified using XML escape characters, for example &, <, >, followed by spaces in the Keyword List of Data Identifier.

Solution:

This hotfix updates the DLP module to ensure that it can catch these sensitive keywords normally.

Issue 5 of Hotfix 5225

(SEG-35771)

The OfficeScan server may hang because there are too many "cgiOnScan.exe" processes almost running at the same time. This situation occurs when the schedule scan runs on many OfficeScan agents.

Solution:

The hotfix resolves this issue by adding a random waiting time function for OfficeScan agents while calling the "cgiOnScan.exe" function.

Issue 6 of Hotfix 5225

(SEG-33081)

A DLP Endpoint SDK hotfix may not be deployed to OfficeScan XG Service Pack 1 agents properly when the "EnforceAuSign" setting is enabled.

Solution:

This hotfix updates the hotfix patch mechanism and the OfficeScan agent program to ensure that hotfixes are deployed successfully to OfficeScan XG Service Pack 1 agents when the "EnforceAuSign" setting is enabled.

Enhancement 1 of Hotfix 5225

(SEG-29275)

This hotfix enables users to configure customized update source lists by sending a command from Trend Micro Control Manager(TM) to a managed OfficeScan server. The customized update source list can be applied to all agents under the OfficeScan server.

NOTE: You need to apply Control Manager Hotfix 2964 to enable Control Manager to support this feature.

Issue 1 of Hotfix 5229

(SEG-33038)

When the "PrivilegeContolSetting" global setting is enabled on an OfficeScan agent, users cannot delete files from some folders, for example "FLog/HLog/Suspect", because of insufficient permissions.

Solution:

This hotfix resolves this issue by giving users the required read and write permissions for the "FLog/HLog/Suspect" folders when "PrivilegeContolSetting" is enabled.

Issue 2 of Hotfix 5229

(SEG-31091)

Issues related to the OfficeScan Behavior Monitoring feature may prevent users from accessing network drives and cause Microsoft(TM) Outlook(TM) to stop responding.

Solution:

This hotfix resolves the issues by updating the Behavior Monitoring module and enabling users to configure certain settings in the registry.

Procedure:

To apply and deploy the solution globally:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan server installation directory.
  3. Under the "Global Setting" section, manually add the following three keys and set all to "1".
  • [Global Setting]
  • AegisSkipDesktopINI=1
  • AegisSkipRemoteDirectory=1
  • AegisSkipRemoteDirectoryByPath=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AEGIS
  • Key: SkipDesktopINI
  • Key: SkipRemoteDirectory
  • Key: SkipRemoteDirectoryByPath
  • Type: DWORD
  • Value: 1
  1. Restart the OfficeScan agent

Issue 3 of Hotfix 5229

(SEG-34837)

On the Trend Micro Control Manager(TM) console, the value on the "Pattern/Rule Version" field in Virus/Malware information grid table reports is always "0".

Solution:

This hotfix resolves the issue to ensure that Virus/Malware information grid table reports on the Control Manager console display accurate "Pattern/Rule Version" information.

Issue 1 of Hotfix 5239

(SEG-32940)

When the server migration tool imports settings from OfficeScan 11 to OfficeScan XG Service Pack 1, the Behavior Monitoring settings of the root/domain level are not migrated successfully.

Solution:

This hotfix resolves the issue by ensuring that the server migration tool retrieves the Behavior Monitoring settings of the root/domain level from the correct configuration file (ofcscan.ini).

Issue 2 of Hotfix 5239

(SEG-33922)

In Microsoft(TM) Windows(TM) 10, the "Windows Security and Maintenance" page indicates that the "Trend Micro Personal Firewall" is "Off" after the Trend Micro NT Firewall Service has been removed manually.

Solution:

This hotfix updates the OfficeScan NT Listener service ("TmListen.exe") to ensure that the "Trend Micro Personal Firewall" no longer appears on the "Windows Security and Maintenance" page when it has been removed.

Procedure:

To configure OfficeScan to automatically remove "Trend Micro Personal Firewall" from the "Windows Security and Maintenance" page after the Trend Micro NT Firewall Service is removed:

  1. Install this hotfix (see "Installation") with Trend Micro NT Firewall Service enabled.
  2. Check if the "TrendMicro Personal Firewall" is "On" in "Windows Security and Maintenance".
  3. Open the "ofcscan.ini" file in the "\PCCSRV\" folder on the OfficeScan installation directory.
  4. Under the "Global Setting" section, manually add the following keys and set each value to "1".
  • [Global Setting]
  • RmvPFWbyCommand=1
  • RmvPFWifSSPFWDisabled=1
  • RmvPFWifDisabled=1
  1. Save the changes and close the file.
  2. Open the OfficeScan web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to agents. The OfficeScan server deploys the command to OfficeScan agents and adds the following registry entry on all OfficeScan agent computers:
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
  • Key: RmvPFWbyCommand=1
  • Key: RmvPFWifSSPFWDisabled=1
  • Key: RmvPFWifDisabled=1
  • Type: DWORD
  • Value: 1
  1. On the OfficeScan web console, go to "Administration > Settings > Product License > Additional Services".
  2. Under "Additional Services", click the "Disable" button to stop the firewall service.
  3. Wait for the agent to reload automatically on the client and check that the "TrendMicro Personal Firewall" entry does not appear in "Windows Security and Maintenance".

Issue 3 of Hotfix 5239

(SEG-35872)

The information in the "action" column on Data Loss Prevention(TM) (DLP) logs in OfficeScan is not consistent with the corresponding information in the DLP logs on Trend Micro Control Manager(TM).

Solution:

This hotfix resolves the issue by modifying the wording in the "action" column in DLP logs on both the OfficeScan server and agents.

Issue 4 of Hotfix 5239

(SEG-35951)

Regular expressions that contain a newline delimiter in a DLP policy do not work.

Solution:

The hotfix updates the DLP module to resolve the issue.

Issue 5 of Hotfix 5239

(SEG-34341)

The Data Loss Prevention(TM) (DLP) module does not work properly when the DLP policy is configured with multiple DLP templates.

Solution:

This hotfix updates the DLP module to ensure that it works normally when the DLP policy has multiple DLP templates.

Enhancement 1 of Hotfix 5239

(SEG-30843)

This hotfix updates the OfficeScan server files to speed up the performance of the OfficeScan web console in running an Advanced Search when there is a large number of multi-layered domains.

Procedure:

To improve the OfficeScan web console Advanced Search performance:

  1. Install this hotfix (see "Installation").
  2. Open the "ofcserver.ini" file in the "\PCCSRV\Private\" folder on the OfficeScan server.
  3. Under the "INI_DBE_ENGINE_SECTION" section, manually add the following key and set it to "1":
  • [INI_DBE_ENGINE_SECTION]
  • UpAdvancedSearch=1
  1. Save the changes and close the file.
  2. Restart the OfficeScan Master Service

Enhancement 2 of Hotfix 5239

(SEG-36300)

This hotfix enables OfficeScan to send the Data Protection Status on the agent management tree to the Control Manager server and allows the Control Manager server to query the Data Protection Status in Product Status logs to ensure that the information is consistent at both ends.

NOTE: This feature also requires the installation of a corresponding Control Manager hotfix.

Enhancement 3 of Hotfix 5239

(SEG-33760)

This hotfix updates the DLP module to support the new Gmail interface.

8. Contact Information

A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees.

Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products.

http://www.trendmicro.com/us/about-us/contact/index.html

NOTE: This information is subject to change without notice.

9. About Trend Micro

Smart, simple, security that fits

As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information.

Copyright 2018, Trend Micro Incorporated. All rights reserved.

Trend Micro, OfficeScan, Data Loss Prevention, and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies.

10. License Agreement

View information about your license agreement with Trend Micro at: http://www.trendmicro.com/us/about-us/legal-policies/license-agreements/

Third-party licensing agreements can be viewed:

  • By selecting the "About" option in the application user interface
  • By referring to the "Legal" page of the Administrator's Guide