Trend Micro, Inc.
July 2013
Trend Micro™ OfficeScan™
Version 10.6 Service Pack 3
This readme file is current as of the date above. However, all customers are advised to check Trend Micro's website for documentation updates at http://docs.trendmicro.com/en-us/enterprise/officescan.aspx.
Register online with Trend Micro within 30 days of installation to continue downloading new pattern files and product updates from the Trend Micro website. Register during installation, or online at http://olr.trendmicro.com.
Trend Micro always seeks to improve its documentation. Your feedback is always welcome. Please evaluate this documentation on the following site: www.trendmicro.com/download/documentation/rating.asp.
Trend Micro™ OfficeScan™ protects enterprise networks from malware, network viruses, web-based threats, spyware, and mixed threat attacks. An integrated solution, OfficeScan consists of a client program that resides at the endpoint and a server program that manages all clients. The client guards the endpoint and reports its security status to the server. The server, through the web-based management console, makes it easy to set coordinated security policies and deploy updates to every client.
OfficeScan is powered by the Trend Micro™ Smart Protection Network™, a next generation cloud-client infrastructure that delivers security that is smarter than conventional approaches. Unique in-the-cloud technology and a lighter-weight client reduce reliance on conventional pattern downloads and eliminate the delays commonly associated with desktop updates. Businesses benefit from increased network bandwidth, reduced processing power, and associated cost savings. Users get immediate access to the latest protection wherever they connectwithin the company network, from home, or on the go.
OfficeScan includes the following new features and enhancements:
What's New in OfficeScan 10.6 Service Pack 3
Data Protection Enhancements
The Data Protection enhancements in this release include the following features.
Forensic data quarantine: OfficeScan clients create and upload encrypted forensic data files to the server allowing companies to track and record the specific Data Loss Prevention incidents that occur on the network. OfficeScan generates a hash value for each forensic file for verification and integrity purposes.
Through integration with Control Manager, security officers can view the exact digital asset that caused each incident and take appropriate measures.
Extended DLP channel support: Data Loss Prevention can now monitor the following:
Command & Control Contact Alert Services
Command & Control Contact Alert Services provides OfficeScan administrators the first line of defense to protect against the increasing number of targeted attacks occurring over the Internet. Trend Micro is continually developing more sophisticated methods to detect and defend against C&C servers and targeted attacks. Command & Control Contact Alert Services is only the first of a series of measures that Trend Micro is adopting to meet the security needs for all customers.
This version of OfficeScan provides administrators with heightened detection capabilities for Command & Control servers.
Global Intelligence and Virtual Analyzer C&C server lists
OfficeScan can automatically detect any known C&C server through use of the Trend Micro Smart Protection Network Global Intelligence list. Web Reputation Services checks all URLs against both the traditional malicious list, and the new Global Intelligence C&C server list.
Administrators that have integrated a Smart Protection Server with Deep Discovery Advisor can also check the risk level of suspicious network connections using the Virtual Analyzer C&C server list. The Virtual Analyzer generates this list based on data received from connected Trend Micro products ensuring very company-specific protection.
C&C IP list
The C&C IP list works in conjunction with the Network Content Inspection Engine (NCIE) to detect network connections with known C&C servers. NCIE detects C&C server contact through any network channel.
Notifications for administrators and users
OfficeScan C&C Contact Alert Services provides standard and outbreak notifications that keep administrators and users informed about any known or potential advanced persistent threat or C&C callbacks originating from the network.
C&C Callback Events widget
The C&C Callback Events widget provides administrators with a quick view of all callbacks from the network, the targets of the attacks, the risk level of the attack, and the callback address.
Behavior Monitoring Scan Enhancement
Behavior Monitoring works in conjunction with Web Reputation Services to verify the prevalence of files downloaded through HTTP channels or email applications. After detecting a "newly encountered" file, administrators can choose to prompt users before executing the file. Trend Micro classifies a program as newly encountered based on the number of file detections or historical age of the file as determined by the Smart Protection Network.
Virus Scan Performance Enhancement
The OfficeScan Virus Scan Engine (VSAPI 9.713 or later) has been updated with a deferred scanning feature to improve file copying performance.
Web Reputation Pattern Enhancement
This version of OfficeScan enhances the integrated Smart Protection Server's Web Reputation Pattern. The Web Reputation Pattern has been redesigned to provide the following benefits:
Rollback Enhancements
The version of OfficeScan simplifies the procedure required to rollback the OfficeScan server and clients. During OfficeScan 10.6 SP3 installation, administrators can choose to back up the server files which can then be used to roll back the server and clients to the previously installed version. For detailed rollback instructions, refer to Appendix D: OfficeScan Rollback in the OfficeScan 10.6 SP3 Administrator's Guide.
What's New in OfficeScan 10.6 Service Pack 2
Platform and Browser Support
This version of OfficeScan provides support for client installations on Windows 8™ and Windows Server™ 2012/Server Core 2012.
This version of OfficeScan provides support for server installations on Windows Server™ 2012.
This version of OfficeScan provides support for Internet Explorer™ 10.
Detection and Performance Enhancements
MSI Installation
Real-time scanning now verifies the file signature of an MSI installation package before proceeding with an installation. Once OfficeScan receives verification that the file signature is trusted, real-time scan allows the installation to proceed without further file scanning.
VDI Enhancement
This version of OfficeScan enhances the smart scan update feature for virtual environments. When a large number of smart scan clients request a pattern update, the server now places the client requests in a queue until the server can send a response. As each client completes the update, the server prompts the next client in the queue to begin updating.
Data Loss Prevention Enhancements
This version of OfficeScan enhances the Data Loss Prevention feature to provide:
Windows 8, Windows Server 2012, Windows Server Core 2012 support
What's New in OfficeScan 10.6 Service Pack 1
Policy Management from Control Manager 6.0
Control Manager 6.0 allows administrators to create and deploy policies to the OfficeScan servers that Control Manager manages.
Behavior Monitoring 64-bit Support
The Behavior Monitoring capabilities of OfficeScan now support 64-bit versions of the following platforms:
Client Self-protection 64-bit Support
Client Self-protection now supports 64-bit versions of the following platforms:
Device Control 64-bit Support for Unauthorized Change Prevention
The Device Control capabilities of OfficeScan now support 64-bit versions of the following platforms during Unauthorized Change Prevention monitoring:
Note: Device Control for Data Protection provides support for all 64-bit versions of Windows platforms.
Data Protection Enhancements
The Data Protection enhancements in OfficeScan 10.6 SP1 include the following support and upgrades:
Virtual Desktop Infrastructure Enhancements
This version of OfficeScan enhances Virtual Desktop Infrastructure (VDI) support and capabilities.
Extended Web Reputation Port Scanning
OfficeScan can now scan HTTP traffic on all ports for web reputation policy violations. If administrators do not want to scan traffic on all ports, OfficeScan provides the option of scanning traffic on the default 80, 81, and 8080 HTTP ports.
Data Protection
The Data Protection module provides Data Loss Prevention and expands the range of devices monitored by Device Control.
Plug-In Manager manages the installation and licensing of the Data Protection module.
Data Protection Features |
Details |
Data Loss Prevention |
Data Loss Prevention safeguards an organization's digital assets against accidental or deliberate leakage. Data Loss Prevention allows you to:
|
Device Control |
OfficeScan out-of-the-box has a Device Control feature that regulates access to USB storage devices, CD/DVD, floppy disks, and network drives. Device Control that is part of the Data Protection module expands the range of devices by regulating access to the following devices:
|
Plug-in Manager 2.0
Plug-in Manager 2.0 installs with the OfficeScan server. This Plug-in Manager version delivers widgets.
Widgets provide a quick visual reference for the OfficeScan features and plug-in solutions that you deem most vital to your business. Widgets are available in the OfficeScan server’s Summary dashboard, which replaces the Summary screen in previous OfficeScan versions.
IPv6 Support
The OfficeScan server and clients can now be installed on IPv6 computers.
In addition, new versions of Control Manager and Smart Protection Server now support IPv6 to provide seamless integration with the OfficeScan server and clients.
Cache Files for Scans
The OfficeScan client now builds cache files, which contain information about safe files that have been scanned previously and files that Trend Micro deems trustworthy. Cache files provide a quick reference during on-demand scans, thus reducing the usage of system resources. On-demand scans (Manual Scan, Scheduled Scan, and Scan Now) are now more efficient, providing up to 40% improvement to speed performance.
Startup Enhancement
When a computer starts, the OfficeScan client will postpone the loading of some client services if CPU usage is more than 20%. When CPU usage is below the limit, the client starts to load the services.
Services include:
Damage Cleanup Services Enhancement
Damage Cleanup Services can now run in advanced cleanup mode to stop activities by rogue security software, also known as FakeAV. The client also uses advanced cleanup rules to proactively detect and stop applications that exhibit FakeAV behavior.
You can choose the cleanup mode when you configure virus/malware scan actions for Manual Scan, Real-time Scan, Scheduled Scan, and Scan Now.
Web Reputation HTTPS Support
Clients can now scan HTTPS traffic for web threats. You can configure this feature when you create a web reputation policy.
Windows Server Core 2008 Support
The OfficeScan client can now be installed on Windows Server Core 2008. Users can use the command line interface to launch the client console and check the endpoint’s protection status.
Other Enhancements
This release includes the following enhancements:
A. OfficeScan 10.6 SP3 resolves the following product issues:
For information regarding hot fix solutions and the enhancements available in OfficeScan 10.6 SP3, go to:
http://esupport.trendmicro.com/solution/en-us/1097407.aspx
B. OfficeScan 10.6 SP2 resolves the following product issues:
For information regarding hot fix solutions and the enhancements available in OfficeScan 10.6 SP2, go to:
http://esupport.trendmicro.com/solution/en-us/1095513.aspx
C. OfficeScan 10.6 SP1 resolves the following product issues:
For information regarding hot fix solutions and the enhancements available in OfficeScan 10.6 SP1, go to:
http://esupport.trendmicro.com/solution/en-us/1095512.aspx
The document set for the OfficeScan server includes:
Download the latest versions of the PDF documents and readme at http://docs.trendmicro.com/en-us/enterprise/officescan.aspx.
The OfficeScan server and client can be installed on computers running Microsoft Windows platforms. The OfficeScan client is also compatible with various third-party products.
Visit the following website for a complete list of system requirements and compatible third-party products:
http://docs.trendmicro.com/en-us/enterprise/officescan.aspx
Size of Deployment Package
Note: All of the following deployment package sizes are for packages that do not include any additional plug-in features. The size of the deployment package may vary if additional plug-in features are included in the package.
Size of the new install package (32/64-bit) via Client Packager Tool
For 32-bit Setup Package:
For 64-bit Setup Package:
For 32/64-bit MSI Package:
Estimated minimum bandwidth size for clients:
Before installing this service pack, take note of the following:
To install this Service Pack:
OfficeScan 10.6 Service Pack 3 provides rollback support for OfficeScan version 10.6 or later. For detailed rollback instructions, refer to Appendix D: OfficeScan Rollback in the OfficeScan 10.6 SP3 Administrator's Guide.
6. Post-installation Configuration
Verify if the OfficeScan server has been upgraded.
On the Control Manager console, the OfficeScan version should be 5162.
Note: Trend Micro recommends installing Trend Micro Control Manager™ 6.0 Patch 3 to ensure compatibility with OfficeScan 10.6 Service Pack 3.
If the update is unsuccessful, perform manual update immediately by going to Updates > Server > Manual Update. You can also refer to the online help for typical update problems and solutions or contact your Support provider for assistance.
Client installation on supported platforms
If users will use the Web install page to install the OfficeScan client to a computer running Windows 7, Windows XP Home, Vista Home Basic, Vista Home Premium, Server 2008, Windows 8, or Server 2012, instruct users to perform the following before installation:
If users will use Client Packager (EXE package) to install the OfficeScan client to a computer running Windows 7, Windows XP Home, Vista Home Basic, Vista Home Premium, Server 2008, Windows 8, or Server 2012, perform the following:
Send the package to users and instruct them to launch it on their computers.
To launch the EXE package:
If users will use Client Packager (MSI package) to install the OfficeScan client to a computer running Windows 7, Windows XP Home, Vista Home Basic, Vista Home Premium, Server 2008, Windows 8, or Server 2012, perform the following:
Note: You can also launch the MSI package (on the command prompt) and silently install the OfficeScan client to a remote computer running Windows 7, Windows XP Home, Vista Home Basic, Vista Home Premium, Server 2008, Windows 8, or Server 2012.
If users will use Login Script Setup (AutoPcc.exe) to install the OfficeScan client to a computer running Windows 7, Windows XP Home, Vista Home Basic, Vista Home Premium, Server 2008, Windows 8, or Server 2012, instruct users to perform the following:
The following are the known issues in this release:
Server Installation, Upgrade, and Uninstallation
The OfficeScan web console and all OfficeScan services cannot be accessed if the OfficeScan server was installed on Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 before joining a domain. To resolve the issue:
For Windows Server 2008:
Go to Control Panel > System and Security > Windows Firewall > Exceptions tab.
Enable exception for File and Printer Sharing.
Add the following port exceptions:
Click OK.
For Windows Server 2008 R2:
Go to Control Panel > System and Security > Windows Firewall > Allowed Programs.
Select the following features and allow access for the Domain profile:
Click OK.
For Windows Server 2012:
Go to Control Panel > System and Security > Windows Firewall > Advanced settings.
Click Inbound Rules. Allow access to all required File and Printer Sharing rules.
Click Inbound Rules > New Rule... > Port.
Add the following port exceptions:
When the OfficeScan server is installed to a disk using the FAT32 file system, role-based logon to the OfficeScan Web console does not work.
During upgrade, if the existing OfficeScan database file (found in the "HTTPDB" folder under "OfficeScan/PCCSRV") is very large, the upgrade process may time out. Trend Micro recommends doing the following before upgrading:
When Trend Micro Mobile Security version 7.0 or 8.0 Communication Server is installed on the same computer as the OfficeScan server, its virtual website folders may be deleted after an OfficeScan server upgrade. This issue occurs because the Communication Server and OfficeScan server use the same virtual website folders. During the OfficeScan server upgrade, the standalone Communication Server virtual folders are not rebuilt on the IIS website.
To resolve this issue:
Client Installation, Upgrade, and Uninstallation
After moving an OfficeScan client from an OfficeScan 8.0 SP1 server to the OfficeScan 10.6 server, the client successfully upgrades but reloads the OfficeScan client several times. To avoid this issue, Trend Micro recommends using Login Scrip Setup or Client Packager to upgrade the OfficeScan client. Using these methods, the OfficeScan client will only reload once.
Upgrade may fail if using an MSI package to upgrade an OfficeScan client that was originally installed also using an MSI package. Perform the following steps:
The OfficeScan client is unable to query the web reputation servers after performing a fresh installation or upgrade. To resolve the issue, ensure that clients restart their computers if a restart notification appears.
If you create a login script in Active Directory and then log on as administrator on a computer running Windows Vista Home, Server 2008, 7, 8, or Server 2012, the OfficeScan client cannot be installed to the computer and the message that displays states that the account used is not an administrator account.
When this product version is installed to a Citrix Presentation server, the Citrix client loses connection with the server. To address this issue:
The ServerProtect Normal Server Migration tool is unable to:
To resolve these issues, open Registry Editor on the Normal Server and Information Server and add following registry key:
Microsoft IIS 7 does not work when:
A message displays on the computer using Windows Server 2008 without Service Pack 2, instructing the user to restart the IIS service to resolve the issue.
When installing the client from the Web install page, users may get an error message stating that ActiveX setup controls did not download information needed for installation. When users retry the installation, the error message no longer displays and installation proceeds.
To avoid seeing the error message, enable Automatic prompting for ActiveX controls in Internet Explorer.
After upgrading OfficeScan, the following issues occur:
To resolve these issues, perform the following steps:
Open a command prompt (cmd.exe) and run the following commands:
regsvr32 wintrust.dll
regsvr32 netcfgx.dll
The administrator will not be able to remotely install OfficeScan client to Windows 7 x86 platforms without enabling the default administrator account. To resolve this issue:
Note: Enable the Remote Registry service on the Windows 7 machine. By default, Windows 7 machines disable this feature.
Option A: Use the domain administrator account to remotely install OfficeScan 10.5 clients to Windows 7 machines.
Option B: Use the default administrator account:
When installing the OfficeScan client on Windows 8 and Windows Server 2012 platforms using the browser-based installation method, the installation is unsuccessful if the user is currently in Windows UI mode. This is due to Internet Explorer 10 not allowing ActiveX controls to run.
To resolve this issue:
Switch to desktop mode on Windows 8 and Windows Server 2012 platforms while performing a browser-based installation of the OfficeScan client.
A Microsoft Hyper-V virtual machine might not be able to start if the host computer has OfficeScan client installed. This is because the OfficeScan client and Hyper-V virtual machine access the same Hyper-V xml file, which causes file access violation. As a workaround:
In a Citrix environment, when the OfficeScan client detects a security risk during a particular user session, the notification message for the security risk displays on all active user sessions.
Security risk can be any of the following:
On the web console's Update Status for Networked Computers screen (Updates > Summary), the Behavior Monitoring Configuration Pattern, Policy Enforcement Pattern, and Digital Signature Pattern do not appear correctly due to JavaScript caching. To resolve this issue:
Clear the browser cache to update the component names.
While using Autopcc.exe to install an OfficeScan client, ofcscan.ini is blocked during the UNC copy process if the "Taiwan: SKH Hospital Medical Record Number" template is deployed with the SMB channel. This causes the client installation to be unsuccessful. To resolve this issue:
Create an exception for INI files in the Data Loss Prevention policy:
Create a new File Attribute type data identifier.
Create a new template for the exception.
When the security level on a Citrix server is medium or high, perform the following steps:
For Windows XP and Windows Server 2003 platforms hosting VMware clients, incoming packets to a VMware client computer are dropped if the host machine has the OfficeScan client installed.
Workaround (for all clients):
On the server computer, open ofcscan.ini under the \PCCSRV folder.
Add the following setting under [Global Setting]: EnableGlobalPfwBypassRule=1
On the Web console, go to Networked Computers > Global Client Settings and click Save to deploy the setting to all clients.
Workaround (for specific clients):
Add the following registry value:
Key: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
For x64 computers: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
If you enable the option "Check HTTPS URLs" in a web reputation policy:
Clients can browse blocked sites if using Juniper Networks VPN and proxy servers to connect to the Internet. To resolve this issue:
After upgrading, the Web Reputation Services is unavailable until the Web Blocking List is fully updated. To resolve this issue, go to Smart Protection > Smart Protection Sources and select a secondary Smart Protection Server for clients to use until the Web Blocking List has completed the update.
Note: OfficeScan begins updating the Web Blocking List immediately after the server upgrades.
Policy Server and Cisco Trust Agent
When accessing the OfficeScan server using the single-sign on function in Control Manager:
Refresh the page if any of these conditions occur.
There are several tools included in this version. Refer to the OfficeScan server Help for instructions on how to use them. The tool folders are located under \PCCSRV\Admin\Utility.
The following are the permissions for the OfficeScan folders:
Directory/User |
Administrator |
Everyone |
IUser _<Server Name> |
System |
Network Service |
\PCCSRV |
Full control |
RX |
N/A |
Full control |
N/A |
\PCCSRV\Download |
Full control |
R |
R |
Full control |
N/A |
\PCCSRV\HTTPDB |
Full control |
N/A |
N/A |
N/A |
N/A |
\PCCSRV\Log |
Full control |
N/A |
N/A |
Full control |
N/A |
\PCCSRV\Private |
Full control |
N/A |
N/A |
Full control |
RX |
\PCCSRV\Temp |
Full control |
N/A |
RWXD |
N/A |
RWXD |
\PCCSRV\Virus |
Full control |
N/A |
RW (Special Access) |
N/A |
N/A |
\PCCSRV\Web |
Full control |
N/A |
R |
Full control |
N/A |
\PCCSRV\Web\Cgi |
Full control |
N/A |
RX |
N/A |
N/A |
\PCCSRV\Web_OSCE\Web_console |
Full control |
RX |
N/A |
Full control |
N/A |
\PCCSRV\Web_OSCE\Web_console\HTML\ClientInstall |
Full control |
N/A |
RWXD |
N/A |
N/A |
\PCCSRV\Web_OSCE\Web_console\RemoteInstallCGI |
Full control |
N/A |
RWXD |
N/A |
N/A |
A license to the Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, Maintenance must be renewed on an annual basis at Trend Micro's then-current Maintenance fees.
You can contact Trend Micro via fax, phone, and email, or visit us at http://www.trendmicro.com.
Evaluation copies of Trend Micro products can be downloaded from our website.
Global Mailing Address/Telephone numbers
For global contact information in the Asia/Pacific region, Australia and New Zealand, Europe, Latin America, and Canada, refer to http://www.trendmicro.com/en/about/overview.htm.
The Trend Micro "About Us" screen displays. Click the appropriate link in the "Contact Us" section of the screen.
Note: This information is subject to change without notice.
Trend Micro Incorporated, a global leader in Internet content security and threat management, aims to create a world safe for the exchange of digital information for businesses and consumers. A pioneer in server-based antivirus with over 20 years experience, we deliver top-ranked security that fits our customers' needs, stops new threats faster, and protects data in physical, virtualized and cloud environments. Powered by the Trend Micro™ Smart Protection Network™ infrastructure, our industry-leading cloud-computing security technology and products stop threats where they emerge, on the Internet, and are supported by 1,000+ threat intelligence experts around the globe. For additional information, visit http://www.trendmicro.com.
Copyright 2013, Trend Micro Incorporated. All rights reserved. Trend Micro, the t-ball logo and OfficeScan are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other product or company names may be trademarks or registered trademarks of their owners.
Information about your license agreement with Trend Micro can be viewed at http://us.trendmicro.com/us/about/company/user_license_agreements/.
License Attributions can be viewed from the OfficeScan web console.