Trend Micro, Inc.
October 2018
Trend Micro™ OfficeScan™
Version XG Service Pack 1
This readme file is current as of the date above. However, all customers are advised to check Trend Micro's website for documentation updates at http://docs.trendmicro.com/en-us/enterprise/officescan.aspx.
Register online with Trend Micro within 30 days of installation to continue downloading new pattern files and product updates from the Trend Micro website. Register during installation, or online at http://olr.trendmicro.com.
Trend Micro always seeks to improve its documentation. Your feedback is always welcome. Please evaluate this documentation on the following site: http://docs.trendmicro.com/en-us/survey.aspx.
Trend Micro™ OfficeScan™ protects enterprise networks from malware, network viruses, web-based threats, spyware, and mixed threat attacks. An integrated solution, OfficeScan consists of an agent program that resides at the endpoint and a server program that manages all agents. The agent guards the endpoint and reports its security status to the server. The server, through the web-based management console, makes it easy to set coordinated security policies and deploy updates to every agent.
OfficeScan is powered by the Trend Micro™ Smart Protection Network™, a next generation cloud-client infrastructure that delivers security that is smarter than conventional approaches. Unique in-the-cloud technology and a lighter-weight agent reduce reliance on conventional pattern downloads and eliminate the delays commonly associated with desktop updates. Businesses benefit from increased network bandwidth, reduced processing power, and associated cost savings. Users get immediate access to the latest protection wherever they connectwithin the company network, from home, or on the go.
OfficeScan includes the following new features and enhancements:
What's New in OfficeScan XG Service Pack 1
Enhanced “Fileless” Script Detections
Enhanced Platform Support
Windows 10 Fall Creators Update (Version 1709)
Update Agent Connections
You can configure OfficeScan agents to use HTTPS protocol when using an Update Agent as the update source.
Behavior Monitoring Exception List
Enhancements to the Exception List support the use of wildcard characters.
Predictive Machine Learning
Predictive Machine Learning has been enhanced to detect malicious script execution.
Cloud Synchronization Channel for Ransomware Detections
OfficeScan agents detect ransomware downloaded through supported cloud synchronization channels.
Proxy Settings Enhancement
All proxy settings for both the OfficeScan server and OfficeScan agents have been consolidated in the same location.
Suspicious Object Lists
OfficeScan supports the detection of Suspicious Domain Objects through integration with Control Manager.
OfficeScan Data Protection Enhancements
Ransomware Protection enhancements
Your protection against ransomware attacks has been further enhanced to allow OfficeScan agents to recover files encrypted by ransomware threats, block processes associated with ransomware, and prevent compromised executable files from infecting your network.
Newly Encountered Program protection enhancement
To more easily maximize your ransomware protection security policy on individual agents, the newly encountered program detection feature has been moved to the Behavior Monitoring settings screen.
You can also customize the message that displays on agent endpoints after a user downloads and executes a newly encountered program.
Predictive Machine Learning
The Predictive Machine Learning engine can protect your network from new, previously unidentified, or unknown threats through advanced file feature analysis and heuristic process monitoring. Predictive Machine Learning can ascertain the probability that a threat exists in a file or process and the probable threat type, protecting you from zero-day attacks.
OfficeScan Edge Relay Server
The OfficeScan Edge Relay server provides you greater visibility and increased protection for endpoints that leave the local intranet by providing the following features:
Suspicious File Sample Submission
To further enhance your integration with a Deep Discovery Virtual Analyzer, OfficeScan agents can now detect and send suspicious files that may contain previously unknown threats directly to the Virtual Analyzer for further analysis. After verifying that a threat exists, the Suspicious Object lists are immediately updated and synchronized to all agents, preventing the threat from spreading across your network.
Dashboard UI enhancements
The Dashboard has been redesigned to provide better visibility of your network's protection status.
Control Manager integration enhancements
To prevent unauthorized communication between the Control Manager and OfficeScan servers, registration to the Control Manager server requires certificate authentication and policy management through the Control Manager server is managed using public-key encryption.
Anti-exploit protection
Real-time Scan allows you to detect and block threats using Common Vulnerabilities and Exposures (CVE) exploits.
Behavior Monitoring can also detect abnormal program behavior that is common to exploit attacks.
Suspicious Connections enhancement
You can now configure the Suspicious Connections feature to log or block network connections detected by the Global C&C IP list and malware network fingerprinting.
Firewall enhancements
The application filter of the OfficeScan Firewall now supports Windows 8 and later platforms.
You can grant OfficeScan agent users the privilege of configuring the firewall security level and exceptions list.
Independent mode
The previously named "Roaming" mode has been renamed as "Independent" mode.
Platform and browser support
This version of OfficeScan provides support for the following:
Note: This version of OfficeScan discontinues support of the Apache Web Server.
OfficeScan XG Service Pack 1 resolves the following product issues:
For information regarding hot fix solutions and the enhancements available in OfficeScan XG Service Pack 1, go to:
http://esupport.trendmicro.com/solution/en-US/1118551.aspx
The document set for the OfficeScan server includes:
Download the latest versions of the PDF documents and readme at http://docs.trendmicro.com/en-us/enterprise/officescan.aspx.
The OfficeScan server and agent can be installed on endpoints running Microsoft Windows platforms. The OfficeScan agent is also compatible with various third-party products.
Visit the following website for a complete list of system requirements and compatible third-party products:
http://docs.trendmicro.com/en-us/enterprise/officescan.aspx
Size of Deployment Package
Note: All of the following deployment package sizes are for packages that do not include any additional plug-in features. The size of the deployment package may vary if additional plug-in features are included in the package.
Size of the new install package (32/64-bit) via Agent Packager Tool
For 32-bit Setup Package:
For 64-bit Setup Package:
For 32/64-bit MSI Package:
Network Traffic for Upgrading OfficeScan Agents
Estimated size (in terms of bandwidth) of upgrading each OfficeScan agent:
OfficeScan Agent Post-Upgrade Requirements
After upgrading OfficeScan agents to OfficeScan XG Service Pack 1, you must restart the agent endpoints to ensure that the OfficeScan agent program properly adopts the HTTPS module and continues to properly communicate with the OfficeScan server.
See the Installation and Upgrade Guide for instructions on:
For OfficeScan agent installation instructions, refer to the Administrator's Guide.
Virus Scan Engine Upgrade Requirement
OfficeScan XG Service Pack 1 automatically upgrades the scan engine on the OfficeScan server and all OfficeScan agents immediately after installation (regardless of OfficeScan agent update settings.
Trend Micro recommends performing the upgrade during off-peak hours to minimize network disruptions.
SQL Server Installed Components
During installation, OfficeScan automatically installs the following SQL Server components. If you choose to uninstall the OfficeScan server, you must manually delete these components after the uninstallation completes.
Recommended Settings Enhancement
The OfficeScan XG SP1 installation package prompts you to enable specific features on Windows desktop platforms to enhance your protection agaianst network and ransomware attacks. You can choose to allow the installation program to enable the features automatically, or you can manually enable the features after the installation completes.
Recommended features:
6. Post-installation Configuration
Verify if the OfficeScan server has been upgraded.
On the Control Manager console, the OfficeScan version should be available.
Note: Trend Micro recommends installing Trend Micro Control Manager™ 7.0 to ensure compatibility with OfficeScan XG Service Pack 1.
If the update is unsuccessful, perform manual update immediately by going to Updates > Server > Manual Update. You can also refer to the online help for typical update problems and solutions or contact your Support provider for assistance.
Agent installation on supported platforms
If users will use Agent Packager (EXE package) to install the OfficeScan agent to an endpoint running Windows XP, 7, 8, 10, Server 2003, 2008, 2012, or 2016, perform the following:
Send the package to users and instruct them to launch it on their endpoints.
To launch the EXE package, instruct users to right-click the EXE file and select Run as administrator.
If users will use a web install page or Agent Packager (MSI package) to install the OfficeScan agent to an endpoint running Windows XP, 7, 8, 10, Server 2003, 2008, 2012, or 2016, perform the following:
Note: You can also launch the MSI package (on the command prompt) and silently install the OfficeScan agent to a remote endpoint running Windows XP, 7, 8, 10, Server 2003, 2008, 2012, or 2016.
If users will use Login Script Setup (AutoPcc.exe) to install the OfficeScan agent to an endpoint running Windows XP, 7, 8, 10, Server 2003, 2008, 2012, or 2016, instruct users to perform the following:
OfficeScan Agent Post-Upgrade Requirements
After upgrading OfficeScan agents to OfficeScan XG Service Pack 1, you must restart the agent endpoints to ensure that the OfficeScan agent program properly adopts the HTTPS module and continues to properly communicate with the OfficeScan server.
The following are the known issues in this release:
Server Installation, Upgrade, and Uninstallation
The OfficeScan web console and all OfficeScan services cannot be accessed if the OfficeScan server was installed on Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 before joining a domain. To resolve the issue:
For Windows Server 2008:
Go to Control Panel > System and Security > Windows Firewall > Exceptions tab.
Enable exception for File and Printer Sharing.
Add the following port exceptions:
Click OK.
For Windows Server 2008 R2:
Go to Control Panel > System and Security > Windows Firewall > Allowed Programs.
Select the following features and allow access for the Domain profile:
Click OK.
For Windows Server 2012 or Windows Server 2012 R2:
Go to Control Panel > System and Security > Windows Firewall > Advanced settings.
Click Inbound Rules. Allow access to all required File and Printer Sharing rules.
Click Inbound Rules > New Rule... > Port.
Add the following port exceptions:
When the OfficeScan server is installed to a disk using the FAT32 file system, role-based logon to the OfficeScan web console does not work.
During upgrade, if the existing OfficeScan database file (found in the "HTTPDB" folder under "OfficeScan/PCCSRV") is very large, the upgrade process may time out. Trend Micro recommends doing the following before upgrading:
Trend Micro Mobile Security is a standalone program and has no longer been supported as a plug-in program since OfficeScan 11.0. To continue using Mobile Security, Trend Micro recommends upgrading to the standalone version 9.0. For detailed migration steps, see http://esupport.trendmicro.com/solution/en-US/1098095.aspx.
During OfficeScan server installation, the "pre-scan" feature is unable to detect double-byte malware threats.
The web console Dashboard displays a "500 Internal Server Error" if Microsoft Visual C++ 2015 Redistributable Package (x86) is not installed. To resolve this issue, install Microsoft Visual C++ 2015 Redistributable Package (x86) and restart the IIS service.
If the OfficeScan server computer or an agent endpoint has not properly updated its root certificate(for example, the computer does not have an Internet connection), OfficeScan cannot verify the computer's digital signatures during Inter-Process Communication (IPC). To solve this issue, you must manually update the root certificate or perform a Windows Update.
An unexpected error occurred. Try clearing your browser's cache and trying the action again. If the problem persists, try restarting the server or contact your Trend Micro representative.
Unable to display data because of an unexpected error. Please try again later.
To resolve this issue:
When transferring the OfficeScan database to a SQL database installed on a Domain Controller endpoint, you must select the “Migrate the OfficeScan database to an existing SQL Server” option on the SQL Migration Tool (SQLTool.exe).
If you want to install a new SQL Server 2016 SP1 Express on a Domain Controller endpoint, you must follow the Microsoft Knowledge Base information on how to install SQL Server 2016 SP1 Express manually.
Agent Installation, Upgrade, and Uninstallation
If you create a login script in Active Directory and then log on as administrator on an endpoint running Windows Vista Home, Server 2008, 7, 8, or Server 2012, the OfficeScan agent cannot be installed to the endpoint and the message that displays states that the account used is not an administrator account.
The ServerProtect Normal Server Migration tool is unable to:
To resolve these issues, open Registry Editor on the Normal Server and Information Server and add following registry key:
The administrator will not be able to remotely install the OfficeScan agent to Windows 7 x86 platforms without enabling the default administrator account. To resolve this issue:
Note: Enable the Remote Registry service on the Windows 7 machine. By default, Windows 7 machines disable this feature.
Option A: Use the domain administrator account to remotely install OfficeScan XG agents to Windows 7 machines.
Option B: Use the default administrator account:
Upgrade may fail if using an MSI package to upgrade an OfficeScan agent that was originally installed also using an MSI package. Perform the following steps:
Before moving OfficeScan agents from an existing OfficeScan XG server, you must install OfficeScan XG Critical Patch 1737 on the source OfficeScan server to ensure that the OfficeScan agents can properly report to the target OfficeScan XG Service Pack 1 server.
Note: If you are upgrading the OfficeScan XG server to OfficeScan XG Service Pack 1 directly, you do not need to apply the Critical Patch.
A Microsoft Hyper-V virtual machine might not be able to start if the host endpoint has OfficeScan agent installed. This is because the OfficeScan agent and Hyper-V virtual machine access the same Hyper-V xml file, which causes file access violation. As a workaround:
Turn off file mapping scan by modifying the TmFilter/TmxpFilter registry value.
To turn off file mapping:
On the server computer, open ofcscan.ini under the \PCCSRV folder.
Modify the following setting under [Global Setting]: UseMapping=0
On the web console, go to Agents > Global Agent Settings and click Save to deploy the setting to all agents.
The following registry information is added after the deployment completes:
Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSApiNt\Parameters
In a Citrix environment, when the OfficeScan agent detects a security risk during a particular user session, the notification message for the security risk displays on all active user sessions.
Security risk can be any of the following:
Users are unable to collapse the agent management tree menu items on the User Account - Step 3 Define Agent Tree Menu screen when configuring User Accounts on Windows 8.1 and Windows Server 2012 R2 platforms running Internet Explorer 11. To resolve this issue:
Install the Internet Explorer 11 hotfix from the Microsoft Windows Update site: http://support.microsoft.com/kb/2884101/en-us.
After expanding the menu items when creating or modifying a User Role or User Account, you cannot collapse the menu items again in Internet Explorer 11.
To resolve this issue for 32-bit platforms, install the following Internet Explorer security update:
http://www.microsoft.com/en-us/download/details.aspx?id=40717
To resolve this issue for 64-bit platforms, install the following Internet Explorer security update:
http://www.microsoft.com/en-us/download/details.aspx?id=40716
On the web console's Update Summary screen (Updates > Summary), the Behavior Monitoring Configuration Pattern, Policy Enforcement Pattern, and Digital Signature Pattern do not appear correctly due to JavaScript caching. To resolve this issue:
Clear the browser cache to update the component names.
When the security level on a Citrix server is medium or high, perform the following steps:
For Windows Server 2003 platforms hosting VMware agents, incoming packets to a VMware agent endpoint are dropped if the host machine has the OfficeScan agent installed.
Workaround (for all agents):
On the server computer, open ofcscan.ini under the \PCCSRV folder.
Add the following setting under [Global Setting]: EnableGlobalPfwBypassRule=1
On the web console, go to Agents > Global Agent Settings and click Save to deploy the setting to all agents.
Workaround (for specific agents):
Add the following registry value:
Key: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
For x64 endpoints: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432\TrendMicro\PC-cillinNTCorp\CurrentVersion\PFW
If you enable the option Check HTTPS URLs in a Web Reputation policy:
Agents can browse blocked sites if using Juniper Networks VPN and proxy servers to connect to the Internet. To resolve this issue:
After upgrading, the Web Reputation Services is unavailable until the Web Blocking List is fully updated. To resolve this issue, go to Smart Protection > Smart Protection Sources and select a secondary Smart Protection Server for agents to use until the Web Blocking List has completed the update.
Note: OfficeScan begins updating the Web Blocking List immediately after the server upgrades.
Cloud Synchronization Channel Support
Virtual Desktop Infrastructure
There are several tools included in this version. Refer to the OfficeScan server Help for instructions on how to use them. The tool folders are located under \PCCSRV\Admin\Utility.
The following are the permissions for the OfficeScan folders:
| Directory/User | Administrator | Everyone | IUser _<Server Name> | System | Network Service | 
| \PCCSRV | Full control | RX | N/A | Full control | N/A | 
| \PCCSRV\Download | Full control | R | R | Full control | N/A | 
| \PCCSRV\HTTPDB | Full control | N/A | N/A | N/A | N/A | 
| \PCCSRV\Log | Full control | N/A | N/A | Full control | N/A | 
| \PCCSRV\Private | Full control | N/A | N/A | Full control | RX | 
| \PCCSRV\Temp | Full control | N/A | RWXD | N/A | RWXD | 
| \PCCSRV\Virus | Full control | N/A | RW (Special Access) | N/A | N/A | 
| \PCCSRV\Web | Full control | N/A | R | Full control | N/A | 
| \PCCSRV\Web\Cgi | Full control | N/A | RX | N/A | N/A | 
| \PCCSRV\Web_OSCE\Web_console | Full control | RX | N/A | Full control | N/A | 
| \PCCSRV\Web_OSCE\Web_console\HTML\ClientInstall | Full control | N/A | RWXD | N/A | N/A | 
| \PCCSRV\Web_OSCE\Web_console\RemoteInstallCGI | Full control | N/A | RWXD | N/A | N/A | 
A license to the Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, Maintenance must be renewed on an annual basis at Trend Micro's then-current Maintenance fees.
You can contact Trend Micro via fax, phone, and email, or visit us at http://www.trendmicro.com.
Evaluation copies of Trend Micro products can be downloaded from our website.
Global Mailing Address/Telephone numbers
For global contact information in the Asia/Pacific region, Australia and New Zealand, Europe, Latin America, and Canada, refer to http://www.trendmicro.com/en/about/overview.htm.
The Trend Micro "About Us" screen displays. Click the appropriate link in the "Contact Us" section of the screen.
Note: This information is subject to change without notice.
Trend Micro Incorporated, a global leader in Internet content security and threat management, aims to create a world safe for the exchange of digital information for businesses and consumers. A pioneer in server-based antivirus with over 20 years experience, we deliver top-ranked security that fits our customers' needs, stops new threats faster, and protects data in physical, virtualized and cloud environments. Powered by the Trend Micro™ Smart Protection Network™ infrastructure, our industry-leading cloud-computing security technology and products stop threats where they emerge, on the Internet, and are supported by 1,000+ threat intelligence experts around the globe. For additional information, visit http://www.trendmicro.com.
Copyright 2017, Trend Micro Incorporated. All rights reserved. Trend Micro, the t-ball logo and OfficeScan are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other product or company names may be trademarks or registered trademarks of their owners.
Information about your license agreement with Trend Micro can be viewed at http://us.trendmicro.com/us/about/company/user_license_agreements/.
License Attributions can be viewed from the OfficeScan web console.