<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9177585147335162418</id><updated>2011-07-22T03:10:11.198+08:00</updated><category term='Graduates'/><category term='OSCE'/><category term='WorryFree'/><category term='NVW'/><category term='the training'/><category term='tda'/><category term='Advisory/Alert'/><category term='info sharing'/><category term='IMSS'/><category term='Get-together'/><category term='Tools'/><category term='TMCM'/><category term='ScanMail'/><category term='Class Photo'/><category term='IWSS/IWSVA'/><category term='Server Protect'/><title type='text'>TCSE community - from ACAPacific</title><subtitle type='html'>I am the instructor for Trend Certified Security Expert (TCSE) training. Along the way, I will share with you some information that could be useful for your day to day job. Happy Supporting Trend Micro!!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default?start-index=101&amp;max-results=100'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>150</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3081438674627525879</id><published>2010-06-08T11:27:00.002+08:00</published><updated>2010-06-08T11:39:56.228+08:00</updated><title type='text'>My last day with ACA</title><content type='html'>Hi All,&lt;br /&gt;&lt;br /&gt;I am sorry to inform you starting from tomorrow, I will no longer be part of ACA. With a heavy heart, I'm leaving this TCSE community blog that I have created since 2008.&lt;br /&gt;&lt;br /&gt;Hope our paths cross again. Happy Supporting  Trend!&lt;br /&gt;&lt;br /&gt;Rgds,&lt;br /&gt;TheInstructor&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3081438674627525879?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3081438674627525879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3081438674627525879' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3081438674627525879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3081438674627525879'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/06/my-last-day-with-aca.html' title='My last day with ACA'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4146041747058044737</id><published>2010-04-14T17:01:00.002+08:00</published><updated>2010-04-14T17:14:17.031+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='info sharing'/><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Malware log analysis</title><content type='html'>Q: I was analyzing the 30 days malware log file and found hundreds of "BKDR_Generic.DIT" and "TROJ_Generic.DIT" which stated questionable action result - Passed Potential Security Risk. I am sure that I have already enabled Generic Detection by adding few lines in the ofcscan.ini. Anything to worry about?&lt;br /&gt;&lt;br /&gt;A: You have done the right thing by enabling generic detection. The purpose of this detection is to make us aware that there is a certain file that is posing some threats. There is a big possibility that this is malicious file. We are just letting it pass because we do not have still an enhanced clean pattern for that one. If we quarantine or delete that file, it is very risky. Why? It is because the file could be a system file or a .dll file that is an important file on Windows. If we quarantine/delete it, there is a chance that your Windows will hang or even BSOD.&lt;br /&gt;&lt;br /&gt;The moment you are aware of such generic virus. The next step is to collect them. Compress the files using WinZip and put a password: virus. Send the sample files to us and we will create an enhanced pattern file for you. Also, it will be much better if you use our SIC Tool to further analyze your system for other infections. Then send the sic logs and suspect.zip. Furthermore, send the Virus logs for us to know who are being infected and find the PC that is the one infecting the system.&lt;br /&gt;&lt;br /&gt;I hope this helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4146041747058044737?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4146041747058044737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4146041747058044737' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4146041747058044737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4146041747058044737'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/04/malware-log-analysis.html' title='Malware log analysis'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1188261506783828191</id><published>2010-04-13T17:07:00.002+08:00</published><updated>2010-04-13T17:09:56.013+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>March 2010 Class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-8ljvkq1hYo/S8Q0vG9BPVI/AAAAAAAAAOM/w0cSW57HDhc/s1600/IMG_5283.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 229px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/S8Q0vG9BPVI/AAAAAAAAAOM/w0cSW57HDhc/s320/IMG_5283.JPG" alt="" id="BLOGGER_PHOTO_ID_5459546632204926290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Fellow attendees for March 2010 class. From left is Ms Ong, Wan, Elson, Chin, myself and Raj.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1188261506783828191?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1188261506783828191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1188261506783828191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1188261506783828191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1188261506783828191'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/04/march-2010-class.html' title='March 2010 Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/S8Q0vG9BPVI/AAAAAAAAAOM/w0cSW57HDhc/s72-c/IMG_5283.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7243537267593937691</id><published>2010-04-13T11:27:00.002+08:00</published><updated>2010-04-13T12:07:03.423+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>IMSS 7.1 - some fine tuning steps</title><content type='html'>q. You might get 550 Access denied - Invalid HELO name from receiving domain (certain domain only) What fine tuning need to be done?&lt;br /&gt;&lt;br /&gt;a. There are few things that you can check. First, verify that your MX record has reverse MX  record. Some receiving domain will check for this and if you don't comply you will be rejected.&lt;br /&gt;&lt;br /&gt;Please refer below for configuration that you might want to fine tune:&lt;br /&gt;&lt;br /&gt;1. http://esupport.trendmicro.com/Pages/Receiving-mail-server-replies-with-504-5.5.2-machinename-Helo-command.aspx&lt;br /&gt;&lt;br /&gt;2. http://esupport.trendmicro.com/pages/Bogus-HELO-name-used-and-HELO-command-rejected-errors-appear-on-outbou.aspx&lt;br /&gt;&lt;br /&gt;3. http://esupport.trendmicro.com/pages/InterScan-Messaging-Security-Suite-IMSS-for-70-Windows-is-unable-to-de.aspx&lt;br /&gt;&lt;br /&gt;If you have tried all, but still the problem persist do escalate and make sure you attach together tsmtpd.ini, log.imss and tsmtpd.log in debug mode.&lt;br /&gt;&lt;br /&gt;Note: To enable debug you can use CDT else login to IMSS web console Choose Logs &gt; Settings from the menu. Application log level option change to "debug". Replicate the issue. Don't forget to disable the debug option once done.&lt;br /&gt;&lt;br /&gt;Reference link for basic info and troubleshooting:&lt;br /&gt;http://esupport.trendmicro.com/Pages/IMSS-70-Windows-basic-info-and-troubleshooting-guide.aspx#P25_1130&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7243537267593937691?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7243537267593937691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7243537267593937691' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7243537267593937691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7243537267593937691'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/04/imss-71-some-fine-tuning-steps.html' title='IMSS 7.1 - some fine tuning steps'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6449898805934239647</id><published>2010-04-12T12:07:00.001+08:00</published><updated>2010-04-12T12:08:43.615+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE SP1 ; found encrypted as the action in malware log</title><content type='html'>q: I found "encrypted" as the result action in malware log for OSCE 10 with SP1 &lt;br /&gt;&lt;br /&gt;a: This is is a new feature in OfficeScan 10, where the virus logs will show an "encrypted" result. The "Encrypted" result happens when the Scan Engine (VSAPI) is unable to take action (quarantine, delete, rename) on a malware. Instead, the OfficeScan client will just encrypt the malware.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6449898805934239647?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6449898805934239647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6449898805934239647' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6449898805934239647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6449898805934239647'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/04/osce-sp1-found-encrypted-as-action-in.html' title='OSCE SP1 ; found encrypted as the action in malware log'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-716590898463251455</id><published>2010-03-26T12:30:00.002+08:00</published><updated>2010-03-26T14:02:57.654+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Missing mail log entry for IMSS 7.0</title><content type='html'>When you want to trace a mail, you normally will query Message Tracking and put in the sender or recipient name. Let say you tried that and no relevant log entry appear. &lt;br /&gt;&lt;br /&gt;You might want to try and query the log file itself. Locate Log folder in IMSS installation folder. Look for file with the name 'mailtrace.log.########'. The # indicates the date.&lt;br /&gt;&lt;br /&gt;Probably there is a problem to upload the logs to database.&lt;br /&gt;You might also want to do the following to rectify this issue:&lt;br /&gt;1. Stop all IMSS related services&lt;br /&gt;2. Backup mail_trace_bookmark file which can be found in Program Files\Trend Micro\IMSS\bin by renaming it.&lt;br /&gt;3. Restart all IMSS related services&lt;br /&gt;Note: This should generate new bookmark&lt;br /&gt;4. Install the latest patch (if applicable)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-716590898463251455?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/716590898463251455/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=716590898463251455' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/716590898463251455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/716590898463251455'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/missing-mail-log-entry-for-imss-70.html' title='Missing mail log entry for IMSS 7.0'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-473757981410133892</id><published>2010-03-19T16:43:00.002+08:00</published><updated>2010-03-19T16:50:30.064+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NVW'/><title type='text'>To drop or reject the packets?</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/S6M6Tti3FkI/AAAAAAAAAOE/TLOhN0H03WA/s1600-h/nvw2500.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 187px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/S6M6Tti3FkI/AAAAAAAAAOE/TLOhN0H03WA/s400/nvw2500.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5450264084366169666" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Before you decide which action to enforce on your clients, perhaps you need to understand the effect of doing it.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Drop&lt;/strong&gt; will drop the packet without response &lt;br /&gt;&lt;strong&gt;Reject&lt;/strong&gt; will reject packet but with response that the packet has been rejected (ICMP unreachable equivalent send to the source)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-473757981410133892?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/473757981410133892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=473757981410133892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/473757981410133892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/473757981410133892'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/to-drop-or-reject-packets.html' title='To drop or reject the packets?'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/S6M6Tti3FkI/AAAAAAAAAOE/TLOhN0H03WA/s72-c/nvw2500.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3399546318201182532</id><published>2010-03-19T16:41:00.002+08:00</published><updated>2010-03-19T16:43:16.210+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>IMSVA sizing</title><content type='html'>q: How many mailboxes can IMSVA handle?&lt;br /&gt;a: It doesn't count by mailboxes in sizing the IMSVA. I have checked with Trend Micro TAM (Technical Account Manager) that 50,000 msg/hr is a good number.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3399546318201182532?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3399546318201182532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3399546318201182532' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3399546318201182532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3399546318201182532'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/imsva-sizing.html' title='IMSVA sizing'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1793567849553722128</id><published>2010-03-19T16:00:00.003+08:00</published><updated>2010-03-19T16:40:36.884+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE 10 client with smart scan method</title><content type='html'>I hope this answers you (you know who you are) :-)&lt;br /&gt;&lt;br /&gt;If your OSCE 10 client is using smart scan method, you can view the following from component version when you right click the OSCE client icon in system tray.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/S6Mvjrrj2KI/AAAAAAAAAN0/D77Ad9xwD7k/s1600-h/osce10.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 282px; height: 320px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/S6Mvjrrj2KI/AAAAAAAAAN0/D77Ad9xwD7k/s320/osce10.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5450252264115787938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Notice there is no conventional pattern file version (lpt$vpn###)&lt;br /&gt;&lt;br /&gt;Refer below for the view from OSCE web console. It will show either conventional pattern file or smart scan agent pattern.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-8ljvkq1hYo/S6M4IdoLBBI/AAAAAAAAAN8/m2fPYgb-5uI/s1600-h/osce+server.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 291px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/S6M4IdoLBBI/AAAAAAAAAN8/m2fPYgb-5uI/s400/osce+server.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5450261692091663378" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1793567849553722128?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1793567849553722128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1793567849553722128' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1793567849553722128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1793567849553722128'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/osce-10-client-with-smart-scan-method.html' title='OSCE 10 client with smart scan method'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/S6Mvjrrj2KI/AAAAAAAAAN0/D77Ad9xwD7k/s72-c/osce10.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6254570418364405930</id><published>2010-03-11T16:07:00.001+08:00</published><updated>2010-03-11T16:08:30.564+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tda'/><title type='text'>Prep for TDA POC</title><content type='html'>Threat Discovery Appliance (TDA) is part of Trend Micro &lt;a href="http://apac.trendmicro.com/apac/solutions/enterprise/security-solutions/threat-management/"&gt;Threat Management Services&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Find hidden malware before it steals data and damages your network...read more to know. :-)&lt;br /&gt;&lt;br /&gt;Checklist(once identified where to deploy):&lt;br /&gt;- at least 2 ports; management and data port  (onboard NIC is for management port)&lt;br /&gt;- IP address, subnet mask, default gateway and DNS configuration&lt;br /&gt;- Product activation code for POC&lt;br /&gt;- Time setting&lt;br /&gt;- proxy information required for product activation and log/report generation&lt;br /&gt;- Registered Services ; DNS, SMTP, FTP, PROXY&lt;br /&gt;- list of network segments / VLANS&lt;br /&gt;&lt;br /&gt;to access the web console;&lt;br /&gt;&lt;br /&gt;https://tda_ipaddress&lt;br /&gt;&lt;br /&gt;to check the port mirroring correctly configured / data successfully mirrored&lt;br /&gt;&lt;br /&gt;Login to the web console then open another browser then go to the following URL;&lt;br /&gt;&lt;br /&gt;https://tda_ipaddress/html/kmod_main.html&lt;br /&gt;note: look for syn_conntrack more than 500&lt;br /&gt;&lt;br /&gt;https://tda_ipaddress/html/rdqa.htm&lt;br /&gt;note:look for ATOP to see the bandwidth should be in Mbps or Kbps&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6254570418364405930?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6254570418364405930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6254570418364405930' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6254570418364405930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6254570418364405930'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/prep-for-tda-poc.html' title='Prep for TDA POC'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1360440673171668415</id><published>2010-03-11T00:36:00.000+08:00</published><updated>2010-03-11T00:36:00.912+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Query on IMSVA</title><content type='html'>IMSVA (InterScan Messaging Security Virtual Appliance)&lt;br /&gt;Q:How many users can it support?&lt;br /&gt;A:The sizing is not based on users. Literally, IMSVA can take up to 50,000 msg/hr&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://us.trendmicro.com/imperia/md/content/us/pdf/products/enterprise/interscanwebsecurityappliance/iwsva_datasheet_090804.pdf"&gt;here&lt;/a&gt; for Datasheet&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1360440673171668415?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1360440673171668415/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1360440673171668415' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1360440673171668415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1360440673171668415'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/03/query-on-imsva.html' title='Query on IMSVA'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-674995097805682401</id><published>2010-02-22T14:14:00.002+08:00</published><updated>2010-02-22T14:21:38.521+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Install Patch 5 for OSCE 8 to support for Windows 7 clients</title><content type='html'>On 22 January, 2010 Trend Micro has published Trend Micro OfficeScan 8.0 Service Pack 1 &lt;a href="http://www.trendmicro.com/ftp/products/patches/OSCE_80_Win_SP1_Patch5_en.exe"&gt;Patch 5&lt;/a&gt; - Build 3510.&lt;br /&gt;&lt;br /&gt;Refer to the &lt;a href="http://www.trendmicro.com/ftp/documentation/readme/OSCE80_Win_SP1_Patch_5_en_readme.txt"&gt;ReadMe&lt;/a&gt; file regarding this patch. One of it is to support for installation on Windows 7 client.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-8ljvkq1hYo/S4IiSyYmRcI/AAAAAAAAANs/XrdjfD7U5NM/s1600-h/patch5.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 154px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/S4IiSyYmRcI/AAAAAAAAANs/XrdjfD7U5NM/s400/patch5.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5440949005974914498" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-674995097805682401?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/674995097805682401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=674995097805682401' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/674995097805682401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/674995097805682401'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/02/install-patch-5-for-osce-8-to-support.html' title='Install Patch 5 for OSCE 8 to support for Windows 7 clients'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-8ljvkq1hYo/S4IiSyYmRcI/AAAAAAAAANs/XrdjfD7U5NM/s72-c/patch5.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-211913532902050379</id><published>2010-01-20T10:55:00.002+08:00</published><updated>2010-01-20T10:57:20.522+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>virus log from OSCE 10 client</title><content type='html'>q: Where to obtain the physical file of the virus log from your client pc?&lt;br /&gt;a: go to the officescan client installation, look for MISC folder. The content is all logs related ; virus log, spyware log&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-211913532902050379?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/211913532902050379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=211913532902050379' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/211913532902050379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/211913532902050379'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/01/virus-log-from-osce-10-client.html' title='virus log from OSCE 10 client'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5833049788224033888</id><published>2010-01-19T17:15:00.001+08:00</published><updated>2010-01-19T17:18:49.907+08:00</updated><title type='text'>Upgrade your OSCE 8 to OSCE 10 using client packager</title><content type='html'>If you want to create the new packager that can upgrade the existing client to the ver 8 without uninstallation of the client.&lt;br /&gt;&lt;br /&gt;There are options which you can modify on the OSCE server’s ofcscan.ini to allow upgrade.  &lt;br /&gt;&lt;br /&gt;To modify "ofcscan.ini" on the OfficeScan server's "\PCCSRV" folder, then create the client package:&lt;br /&gt;&lt;br /&gt;  On the "INI_CLIENT_SETUP_SECTION" section:&lt;br /&gt;&lt;br /&gt;  BypassServerChecking=1 ,&lt;br /&gt;&lt;br /&gt;    which allows the MSI/exe package can be installed on any OfficeScan client computers, even they are not managed by the package packed server.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;  BypassUpgradePrivilegeChecking=1 ,&lt;br /&gt;&lt;br /&gt;    which allows the MSI/exe package can perform client programs upgrade, even the client is configured as it cannot upgrade programs or hot fixes from the server.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;You may need to revert back to the original settings once the packager is created.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5833049788224033888?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5833049788224033888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5833049788224033888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5833049788224033888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5833049788224033888'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/01/upgrade-your-osce-8-to-osce-10-using.html' title='Upgrade your OSCE 8 to OSCE 10 using client packager'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7143353669530978118</id><published>2010-01-19T14:53:00.003+08:00</published><updated>2010-01-19T15:18:50.844+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ScanMail'/><title type='text'>SMEX 10 is here..</title><content type='html'>You can refer the details from here:&lt;br /&gt;http://www.trendmicro.com/download/product.asp?productid=8&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;what's new?&lt;/strong&gt;-Supports Microsoft Exchange Server 2010&lt;br /&gt;-Microsoft Active Directory (AD) Integration&lt;br /&gt; can create policy and assign to AD users&lt;br /&gt;- Role Based Access&lt;br /&gt;multiple admin access to different areas in the web console&lt;br /&gt;-Event Tracking in Logs&lt;br /&gt;since multiple admin can access the web console, thus the needs to track the activity for each administrator&lt;br /&gt;-Installation enhancement&lt;br /&gt;-IPv6 support&lt;br /&gt;-Includes Web Reputation Filter&lt;br /&gt;to check the URL from within the email content agaist the web reputation database. This is separate from SPS offering.&lt;br /&gt;-Resource management&lt;br /&gt;allow for tuning CPU resources during scanning&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Upgrade checklist&lt;/strong&gt;&lt;br /&gt;- Server specs&lt;br /&gt;2GB RAM, 10GB free disk space&lt;br /&gt;- Software requirements&lt;br /&gt;Also support Windows 2008 server, Exchange 2010&lt;br /&gt;- Credentials requirements &lt;br /&gt;Local admin&lt;br /&gt;- Activation Code&lt;br /&gt;- Housekeeping of the current logs&lt;br /&gt;Delete older logs. Verify the folder ..\Smex\log is at minimum size.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note: &lt;br /&gt;1. no restart of MS Exchange is required. Relatively no downtime to the email system&lt;br /&gt;2. if no issues, the upgrade will complete in 30 minutes&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7143353669530978118?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7143353669530978118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7143353669530978118' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7143353669530978118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7143353669530978118'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2010/01/smex-10-is-here.html' title='SMEX 10 is here..'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6933719907966833804</id><published>2009-12-21T11:37:00.002+08:00</published><updated>2009-12-21T11:41:54.025+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NVW'/><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>List of ports when using NVW and TMCM</title><content type='html'>A customer asked, what ports to allow since he deploys two units of NVW the NVW registered to TMCM in the network.&lt;br /&gt;&lt;br /&gt;Ports used by NVW and TMCM to communicate:&lt;br /&gt;&lt;br /&gt;1. TCP &lt;span style="font-weight:bold;"&gt;80&lt;/span&gt; Listening/Outbound (HTTP)&lt;br /&gt;2. TCP &lt;span style="font-weight:bold;"&gt;443&lt;/span&gt; Listening/Outbound (HTTPS)&lt;br /&gt;3. UDP &lt;span style="font-weight:bold;"&gt;10323&lt;/span&gt; (Inbound)&lt;br /&gt;4. UDP &lt;span style="font-weight:bold;"&gt;514&lt;/span&gt; Outbound (Syslog)&lt;br /&gt;&lt;br /&gt;Ports used by NVW and protected machines to communicate:&lt;br /&gt;&lt;br /&gt;1. TCP &lt;span style="font-weight:bold;"&gt;20901-2&lt;/span&gt; Listening &amp; TCP &lt;span style="font-weight:bold;"&gt;20903&lt;/span&gt; Interprocess (Damage Cleanup Services). This is also used by Vulnerability Assessment&lt;br /&gt;&lt;br /&gt;2. UDP &lt;span style="font-weight:bold;"&gt;123&lt;/span&gt; (Inbound). Port used by the Trend Micro Network Time Protocol. It is also used by Network VirusWall to synchronize time with the TMCM server.&lt;br /&gt;&lt;br /&gt;3. UDP &lt;span style="font-weight:bold;"&gt;10323&lt;/span&gt; (Inbound). Default Heartbeat Port of TMCM for MCP-based agents. Heartbeats will indicate to the TMCM server that an agent is active.&lt;br /&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;5088 &lt;/span&gt;- Peagent&lt;br /&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;5091&lt;/span&gt; - Threat management agent. You can also modify this port in NVW console &gt; Policy enforcement &gt; TMAgent settings.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6933719907966833804?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6933719907966833804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6933719907966833804' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6933719907966833804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6933719907966833804'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/12/list-of-ports-when-using-nvw-and-tmcm.html' title='List of ports when using NVW and TMCM'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4560139408748483340</id><published>2009-12-21T11:33:00.002+08:00</published><updated>2009-12-21T11:36:59.296+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Protect'/><title type='text'>SPNT only on single processor?</title><content type='html'>I have read up the Student TextBook of Trend MIcro Server Protect Certification Training course. Refer to page 62 of the book it says &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"Note: ServerProtect works only on single-processor servers.&lt;br /&gt;When you try to run ServerProtect on a multiprocessor server, a warning appears on the console screen, and the application does not start. "&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Please note that the statement above is true for "older version" of SPNT 5.5. &lt;span style="font-weight:bold;"&gt;However with the release of newer version, SPNT 5.58, 5.7 and 5.8, dual processor is NOW supported.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4560139408748483340?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4560139408748483340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4560139408748483340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4560139408748483340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4560139408748483340'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/12/spnt-only-on-single-processor.html' title='SPNT only on single processor?'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1652950365817236187</id><published>2009-12-08T14:41:00.002+08:00</published><updated>2009-12-08T14:46:08.270+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>IMSS 7.1 - an upgrade from IMSS 7.0</title><content type='html'>Becareful when you inplace upgrade 7.0 to 7.1. It works for me. All the required settings still preserved. However, the IMSS is set to open relay!&lt;br /&gt;You have to remove 0.0.0.0 from IMSS console &gt; Administration &gt; SMTP Routing &gt; Message Rule&gt; Permitted Senders of Relayed Mail.&lt;br /&gt;&lt;br /&gt;Test out to telnet IMSS potr 25 and run mail from and rcpt to command to verify that it is now closed relay.&lt;br /&gt;&lt;br /&gt;good luck!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1652950365817236187?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1652950365817236187/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1652950365817236187' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1652950365817236187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1652950365817236187'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/12/imss-71-upgrade-from-imss-70.html' title='IMSS 7.1 - an upgrade from IMSS 7.0'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-9103348086034303065</id><published>2009-11-23T10:28:00.002+08:00</published><updated>2009-11-23T10:31:31.547+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Utilpolicy for IMSS for Linux</title><content type='html'>I posted earlier on this tool &lt;a href="http://tcse-trendmicro.blogspot.com/2009/07/replicating-imss-70-policy-and.html"&gt;here.&lt;/a&gt; It has got a linux version as well. Let me know if you need it. :-)&lt;br /&gt;&lt;br /&gt;utilPolicy.tar.gz is a tool to import/export the following &lt;br /&gt;   settings:&lt;br /&gt;   1. UI-&gt;Policy &lt;br /&gt;      &gt; Policy List&lt;br /&gt;      &gt; Scanning Exceptions&lt;br /&gt;      &gt; Internal Addresses&lt;br /&gt;   2. UI-&gt;IP Filtering&lt;br /&gt;      &gt; Overview--enable/disable IP Filtering&lt;br /&gt;      &gt; Rules&lt;br /&gt;      &gt; NRS&lt;br /&gt;      &gt; Approved List&lt;br /&gt;      &gt; Blocked List&lt;br /&gt;      &gt; Suspicious IP&lt;br /&gt;   3. Reports&lt;br /&gt;      &gt; Settings--of scheduled reports&lt;br /&gt;   4. Logs&lt;br /&gt;      &gt; Settings&lt;br /&gt;   5. Quarantine &amp; Archive&lt;br /&gt;      &gt; Settings (Qurantine &amp; Archive)&lt;br /&gt;   6. Administrator&lt;br /&gt;      &gt; Updates&lt;br /&gt;        &gt; Schedule&lt;br /&gt;        &gt; Source&lt;br /&gt;      &gt; Notifications&lt;br /&gt;        &gt; Events&lt;br /&gt;        &gt; Delivery Settings&lt;br /&gt;        &gt; Web EUQ Digest&lt;br /&gt;      &gt; IMSS Configuration&lt;br /&gt;        &gt; Connections&lt;br /&gt;          &gt; Components&lt;br /&gt;          &gt; LDAP &lt;br /&gt;          &gt; POP3&lt;br /&gt;          &gt; TMCM Server&lt;br /&gt;      &gt; SMTP Routing&lt;br /&gt;        &gt; SMTP&lt;br /&gt;        &gt; Connections&lt;br /&gt;        &gt; Message Rule&lt;br /&gt;        &gt; Domain-based Delivery&lt;br /&gt;   7. User Quarantine Access&lt;br /&gt;      &gt; Select LDAP groups to enable access&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-9103348086034303065?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/9103348086034303065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=9103348086034303065' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/9103348086034303065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/9103348086034303065'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/utilpolicy-for-imss-for-linux.html' title='Utilpolicy for IMSS for Linux'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-760325597520692268</id><published>2009-11-17T16:52:00.005+08:00</published><updated>2009-11-23T10:28:16.745+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>proxy pac and IWSS</title><content type='html'>Question:&lt;br /&gt;How can we configure users to point to IWSS via "Automatic Proxy Configuration"?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;1. Have a proxy.pac script ready. You can refer to this basic script.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_OuiiIFDG79s/SwJnOs95epI/AAAAAAAACCY/fxoXfP6r2WA/s1600/pp2.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 102px;" src="http://4.bp.blogspot.com/_OuiiIFDG79s/SwJnOs95epI/AAAAAAAACCY/fxoXfP6r2WA/s400/pp2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5404996005084625554" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;note:192.168.1.86 is your IWSS IP address andport 8080 is the proxy port&lt;br /&gt;&lt;br /&gt;2.Publish proxy.pac in your web server. Make sure your web server recognize the .pac extension by adding in the MIME type to the HTTP Header.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_OuiiIFDG79s/SwJnOpTYufI/AAAAAAAACCQ/vI_2f1VEa7E/s1600/pp1.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 140px;" src="http://3.bp.blogspot.com/_OuiiIFDG79s/SwJnOpTYufI/AAAAAAAACCQ/vI_2f1VEa7E/s400/pp1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5404996004101011954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_OuiiIFDG79s/SwJnO_m2sCI/AAAAAAAACCg/9zSsh15VIQc/s1600/pp3.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 280px;" src="http://2.bp.blogspot.com/_OuiiIFDG79s/SwJnO_m2sCI/AAAAAAAACCg/9zSsh15VIQc/s400/pp3.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5404996010088247330" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. Specify your user's browser with the configuration&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_OuiiIFDG79s/SwJnPD_Ez3I/AAAAAAAACCo/UFFX8vDw4wc/s1600/pp4.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 317px; height: 400px;" src="http://1.bp.blogspot.com/_OuiiIFDG79s/SwJnPD_Ez3I/AAAAAAAACCo/UFFX8vDw4wc/s400/pp4.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5404996011263577970" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_OuiiIFDG79s/SwJnO_m2sCI/AAAAAAAACCg/9zSsh15VIQc/s1600/pp3.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 280px;" src="http://2.bp.blogspot.com/_OuiiIFDG79s/SwJnO_m2sCI/AAAAAAAACCg/9zSsh15VIQc/s400/pp3.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5404996010088247330" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Remark:&lt;br /&gt;Do feedback on the performance and capability of this configuration. Do you experience any drop in connections?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-760325597520692268?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/760325597520692268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=760325597520692268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/760325597520692268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/760325597520692268'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/proxy-pax-and-iwss.html' title='proxy pac and IWSS'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_OuiiIFDG79s/SwJnOs95epI/AAAAAAAACCY/fxoXfP6r2WA/s72-c/pp2.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5844830036518581096</id><published>2009-11-12T13:51:00.004+08:00</published><updated>2009-11-23T10:35:13.693+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>What is 'Infection source'?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_OuiiIFDG79s/SvujIdSwXlI/AAAAAAAACAQ/JaHKN-2UupY/s1600-h/1.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 88px;" src="http://3.bp.blogspot.com/_OuiiIFDG79s/SvujIdSwXlI/AAAAAAAACAQ/JaHKN-2UupY/s400/1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5403091543658618450" /&gt;&lt;/a&gt;&lt;br /&gt;You can see this from your OfficeScan virus logs.&lt;br /&gt;&lt;br /&gt;You may not have the Infection Source if the infection is of trojan, generic malware or backdoor. Most cases in worm typically network worm you will have Infection Source information. Some virus detection doesn't have Infection Source if the infection is local meaning it is not coming from a remote computer. Also, it doesn't require scanning of mapped drives to check or detect infection source since the detection of infection source is based on the NET SESSION on the local computer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For example, if User A accesses a virus infected share on User B's machine, User B will become listed in the Infected Sources list.&lt;br /&gt;&lt;br /&gt;If there are no sources on the private network sharing malware, then nothing will be shown.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5844830036518581096?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5844830036518581096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5844830036518581096' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5844830036518581096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5844830036518581096'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/what-is-infection-source.html' title='What is &apos;Infection source&apos;?'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_OuiiIFDG79s/SvujIdSwXlI/AAAAAAAACAQ/JaHKN-2UupY/s72-c/1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1142918760664550727</id><published>2009-11-11T15:19:00.003+08:00</published><updated>2009-11-11T15:24:19.722+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>Manual or scheduled update failed</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Issue:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The client was not able to update the pattern of their TMCM 5.0. An error "Unable to create sub directory" appeared which can be seen from the command tracking.&lt;br /&gt;&lt;br /&gt;CDT logs captured and findings as follows:&lt;br /&gt;&lt;br /&gt;Err 20091030 22:48:08 5620 4436 HttpConnection: Socket connect fail Err 20091030 22:48:08 5620 4436 TmDownloader: Connection fail when try to open resource Inf 20091030 22:48:08 5620 4436 Re-downloaded (3) times Err 20091030 22:48:08 5620 4436 Downloader returns: 4 Err 20091030 22:48:09 5620 4436 can not get required server info file Inf 20091030 22:48:09 5620 4436 Cleanning Temp dir [D:\Program Files\Trend Micro\Control Manager\AU_Data\&lt;br /&gt;                                AU_Temp\5620_4436] Inf 20091030 22:48:09 5620 4436 UpdateManager endwith 28 (1c0002): ActiveUpdate was unable to connect to&lt;br /&gt;                                the network. Please verify that the network connection is functional, and&lt;br /&gt;                                then try again.&lt;br /&gt;Inf 20091030 22:48:09 5620 4436 End TmuUpdateEx()&lt;br /&gt;------------------------------&lt;br /&gt;Inf 20091030 22:48:09 5620 4436 release context for thread: 4436 Err 20091030 22:48:09 5620 4896 Delete Temp dir fail.&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 Cleanning Temp dir [D:\Program Files\Trend Micro\Control Manager\AU_Data\&lt;br /&gt;                                AU_Temp\5620_4896] Inf 20091030 22:48:09 5620 4896 UpdateManager endwith 16 (100000): ActiveUpdate was unable to complete the&lt;br /&gt;                                requested file operation. Please try again. If the problem persists,&lt;br /&gt;                                contact your Trend Micro technical support provider.&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 End TmuDuplicateEx()&lt;br /&gt;------------------------------&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 release context for thread: 4896&lt;br /&gt;------------------------------&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 new context for thread: 4896&lt;br /&gt;------------------------------&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 Set key[KeptPatternMaxCount] value[14] Inf 20091030 22:48:09 5620 4896 TmuSetPropertyEx returned [TRUE]&lt;br /&gt;------------------------------&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 Start TmuDuplicateEx() Err 20091030 22:48:09 5620 4896 Delete Temp dir fail.&lt;br /&gt;Inf 20091030 22:48:09 5620 4896 Cleanning Temp dir [D:\Program Files\Trend Micro\Control Manager\AU_Data\&lt;br /&gt;                                AU_Temp\5620_4896] Inf 20091030 22:48:09 5620 4896 UpdateManager endwith 16 (100000): ActiveUpdate was unable to complete the&lt;br /&gt;                                requested file operation. Please try again. If the problem persists,&lt;br /&gt;                                contact your Trend Micro technical support provider.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Answer:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The issue was possibly on the network side of the client, kindly chek if they were using a proxy on TMCM server.&lt;br /&gt;&lt;br /&gt;After checking the proxy setting kindly advice the client to delete all the contents of \Program Files\Trend Micro\Control Manager\AU_Data and try to do again a manual update. &lt;br /&gt;&lt;br /&gt;Note: Some of the files are locked and can't be deleted. It was when the Trend MIcro Control Manager service was stopped, then only a complete deletion can be done&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1142918760664550727?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1142918760664550727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1142918760664550727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1142918760664550727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1142918760664550727'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/issue-client-was-not-able-to-update.html' title='Manual or scheduled update failed'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-243665783753045677</id><published>2009-11-11T15:17:00.001+08:00</published><updated>2009-11-11T15:18:59.437+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE 8.0 and Windows 7</title><content type='html'>Question:&lt;br /&gt;&lt;br /&gt;I have OSCE 8.0 installed in my environment. Is there any patch available to support for Windows 7 client OS?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;No. You have to upgrade to version 10 in order to support Windows 7. If your license is still valid, you are entitled for free upgrade.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-243665783753045677?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/243665783753045677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=243665783753045677' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/243665783753045677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/243665783753045677'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/osce-80-and-windows-7.html' title='OSCE 8.0 and Windows 7'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1320608355203998636</id><published>2009-11-11T11:58:00.003+08:00</published><updated>2009-11-11T15:17:46.714+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='info sharing'/><title type='text'>DOWNAD and recycler folder</title><content type='html'>I read from &lt;a href="http://blog.trendmicro.com/downadconficker-turns-1yr/"&gt;Trend Micro Blog&lt;/a&gt; about DOWNAD/Conficker. Some interesting note to highlight since recent visit to a customer place I happened to see the virus log and they were few entries with infected path detected in Recycler folder.&lt;br /&gt;&lt;br /&gt;"In January of this year, a few security websites and media outlets reported a wave of detections of another DOWNAD variant.&lt;br /&gt;&lt;br /&gt;This variant first sent exploit packets for a Microsoft Server Service Vulnerability to every machine on the network and to several randomly selected targets over the Internet. It then &lt;span style="font-style:italic;"&gt;dropped a copy of itself in the Recycler folder &lt;/span&gt;of all available removable and network drives and created an obfuscated autorun.inf file on these drives so it can execute every time a user browsed a network folder or removable drive without actually clicking on the file. It then enumerated the available servers on the network and, using this information, gathered a list of user accounts on the machines."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;What is Recycler Folder and How to remove it&lt;/span&gt;&lt;br /&gt;A good reading material from &lt;a href="http://techsalsa.com/what-is-recycler-folder-and-how-to-remove-it/"&gt;Tech Salsa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you have used Windows for quite some time now then you must have seen this folder called RECYCLER. But many people don’t know what this folder is and what is it doing in the drive?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_OuiiIFDG79s/Svo5n2-SlFI/AAAAAAAACAI/4Dzaei5028w/s1600-h/recycler.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 110px; height: 44px;" src="http://2.bp.blogspot.com/_OuiiIFDG79s/Svo5n2-SlFI/AAAAAAAACAI/4Dzaei5028w/s400/recycler.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5402694059918791762" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;What is Recycler folder?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Recycler folder is used only on NTFS partitions and is referred to as a location where all the deleted files go after they have been deleted by the user. Now you may be wondering if it contains the deleted files then why we have the Recycle Bin.&lt;br /&gt;&lt;br /&gt;When a file is deleted it goes to the Recycle Bin but when the Recycle Bin is emptied, the files are stored in this Recycler folder. This is the reason why we can still restore the deleted data in the Windows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Difference between Recycle Bin and Recycler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Recycle Bin stores the file that are deleted from the computer until it is emptied completely whereas the Recycler folder contains a Recycle Bin for each user that logs on to the computer. (MS article)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Recycled Folder&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is something different than the Recycler folder as Recycled is same as Recycle Bin. That is both Recycled and Recycle Bin are just two different names for the same memory location.&lt;br /&gt;&lt;span style="font-style:italic;"&gt;&lt;br /&gt;How to delete Recycler Folder&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Recycler is a read only folder and that is why it gave error if you tried to delete it. To view the folder, go to Tools -&gt; Folder Options -&gt; View tab and uncheck the option of Hide Protected operating System Files.&lt;br /&gt;&lt;br /&gt;Now just right click on the folder, go to Properties and &lt;span style="font-weight:bold;"&gt;unselect the option of Read Only.&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt; Now it can be deleted.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Recycler Virus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There has been identified a virus with the same name that is Recycler.exe which should not be confused with the Recycler folder.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1320608355203998636?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1320608355203998636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1320608355203998636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1320608355203998636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1320608355203998636'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/blog-post.html' title='DOWNAD and recycler folder'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_OuiiIFDG79s/Svo5n2-SlFI/AAAAAAAACAI/4Dzaei5028w/s72-c/recycler.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4468181271423443530</id><published>2009-11-02T14:31:00.002+08:00</published><updated>2009-11-02T14:34:54.623+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>Scan Engine version 9.0 is almost here!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-8ljvkq1hYo/Su589iyVP5I/AAAAAAAAANk/xLZADq4wk7I/s1600-h/trend.bmp"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 97px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/Su589iyVP5I/AAAAAAAAANk/xLZADq4wk7I/s400/trend.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5399390400015581074" /&gt;&lt;/a&gt;&lt;br /&gt;Scan Engine 9.000 ActiveUpdate (AU) Upload &lt;br /&gt; October 30, 2009&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Details&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;On November 16, 2009 (US PST), Trend Micro will upload Scan Engine (VSAPI) 9.000 to the ActiveUpdate (AU) server.  &lt;br /&gt;&lt;br /&gt;Trend Micro will release VSAPI 9.000 on these products :&lt;br /&gt;&lt;br /&gt;Ø  OfficeScan&lt;br /&gt;Ø  Client Server Messaging Suite / Client Server Suite&lt;br /&gt;Ø  Worry Free Business Security&lt;br /&gt;Ø  ServerProtect for NT&lt;br /&gt;Ø  Trend Micro Control Manager&lt;br /&gt;&lt;br /&gt;Scan Engine 9.000 includes the following enhancements / features :&lt;br /&gt;Ø  Support for the detection of files that contain known PDF exploits&lt;br /&gt;Ø  Support for shellcode detection&lt;br /&gt;Ø  Recognition of the following additional file types:&lt;br /&gt;   o    Flash Video (FLV)&lt;br /&gt;   o    Microsoft Document Imaging (MDI)&lt;br /&gt;   o    Moving Picture Experts Group (MPEG)&lt;br /&gt;   o    QuickTime (MOV)&lt;br /&gt;   o    RIFF&lt;br /&gt;   o    SITX&lt;br /&gt;   o    ZIP64&lt;br /&gt;Ø  Support for the detection of exploits to Microsoft Office vulnerabilities&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Recommended Action&lt;/span&gt;&lt;br /&gt;Trend Micro recommends that you update your scan engine to provide protection against the latest threats.&lt;br /&gt;&lt;br /&gt;For customers who want to test VSAPI 9.000 on selected clients, please download VSAPI 9.000 &lt;br /&gt;&lt;br /&gt;For 32-bit VSAPI at&lt;br /&gt;http://officescan-p.pre-opr-au.trendmicro.com/activeupdate/engine/engv90kd.zip&lt;br /&gt;&lt;br /&gt;For IA 64-bit VSAPI at&lt;br /&gt;http://officescan-p.pre-opr-au.trendmicro.com/activeupdate/engine/engv90_ia64_ntkd.zip&lt;br /&gt;&lt;br /&gt;For AMD 64-bit VSAPI at&lt;br /&gt;http://officescan-p.pre-opr-au.trendmicro.com/activeupdate/engine/engv90_amd64_ntkd.zip&lt;br /&gt;&lt;br /&gt;Manual instructions on how to apply the scan engine can be found at http://esupport.trendmicro.com/enterprise/default.aspx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4468181271423443530?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4468181271423443530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4468181271423443530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4468181271423443530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4468181271423443530'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/scan-engine-version-90-is-almost-here.html' title='Scan Engine version 9.0 is almost here!'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/Su589iyVP5I/AAAAAAAAANk/xLZADq4wk7I/s72-c/trend.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8086949619962411071</id><published>2009-11-02T11:51:00.002+08:00</published><updated>2009-11-02T11:54:36.308+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WorryFree'/><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Support for Windows 7, both OSCE and WFBS</title><content type='html'>Please install Service Pack 1 for your OSCE 10 and WFBS in order to support for Windows 7 Operating System.&lt;br /&gt;&lt;br /&gt;Refer here:&lt;br /&gt;&lt;a href="http://www.trendmicro.com/ftp/documentation/readme/OSCE_10_WIN_EN_ServicePack1_Readme.TXT"&gt;OSCE&lt;/a&gt;&lt;a href="http://www.trendmicro.com/ftp/documentation/readme/WFBS-A%206.0%20SP1_Readme.htm"&gt;&lt;br /&gt;WFBS&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8086949619962411071?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8086949619962411071/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8086949619962411071' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8086949619962411071'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8086949619962411071'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/11/support-for-windows-7-both-osce-and.html' title='Support for Windows 7, both OSCE and WFBS'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6353500830853276644</id><published>2009-10-28T11:41:00.004+08:00</published><updated>2009-10-28T11:55:05.136+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Activating your OSCE 10 with superkey</title><content type='html'>Issue:&lt;br /&gt;I have my paper license with the following description:&lt;br /&gt;OfficeScan Superkey (AV+SW+DC+FW)English ver 10.x&lt;br /&gt;&lt;br /&gt;I'm upgrading my OSCE 8 to OSCE 10. During the installation wizard, I put in the superkey for the first item which is for antivirus module only. refer below screen shot.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_OuiiIFDG79s/Sue-JvVA-FI/AAAAAAAAB-g/eMMC9N2bE-U/s1600-h/osce1.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_OuiiIFDG79s/Sue-JvVA-FI/AAAAAAAAB-g/eMMC9N2bE-U/s400/osce1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5397491752959539282" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Once upgrade is done, from the web console Administration &gt; Product License under License Information table I can see that "Antivirus for Desktop" and "Antivirus for Servers" both in grace period. The other services "Web Reputation and Anti-Spyware for desktops", "Web Reputation and Anti-Spyware for Servers" and "Damage Cleanup Services" shown as not activated.&lt;br /&gt;&lt;br /&gt;What went wrong?&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Login to the web console. Click on Administration &gt; Product License. Choose the services for which you want to activate or refresh the license information.&lt;br /&gt;There are two things here:&lt;br /&gt;&lt;br /&gt;1. For License appear as in grace period or expired despite the license just renewed. This is because you have to update information upon renewing the license. This will allow for the OSCE server to sync with the License Server for the new expiry date, license seats number and other relevant information. Refer to below screen shot. You will have to click on the "Update Information" button.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_OuiiIFDG79s/Sue_z67jHvI/AAAAAAAAB-o/S-FQ0zJmAk8/s1600-h/osce2.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 152px;" src="http://4.bp.blogspot.com/_OuiiIFDG79s/Sue_z67jHvI/AAAAAAAAB-o/S-FQ0zJmAk8/s400/osce2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5397493577140084466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. Activating Web Reputation and Damage Cleanup Services for OSCE 10 is actually by using the same key. Hence the name SuperKey. Don't forget to click on the "Update Information" button once you are done.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6353500830853276644?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6353500830853276644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6353500830853276644' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6353500830853276644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6353500830853276644'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/activating-your-osce-10-with-superkey.html' title='Activating your OSCE 10 with superkey'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_OuiiIFDG79s/Sue-JvVA-FI/AAAAAAAAB-g/eMMC9N2bE-U/s72-c/osce1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1988199090686567537</id><published>2009-10-26T15:21:00.002+08:00</published><updated>2009-10-26T15:29:17.383+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>How to set a fixed amount of memory (Enterprise Manager)</title><content type='html'>Issue:&lt;br /&gt;If using SQL Server on the same system as the TMCM server, and you notice that memory utilization is quite high most of the time occupied with SQL related processes. Probably, you need to set a fixed amount of memory (Enterprise Manager)approximately two-thirds of the total memory for TMCM server.&lt;br /&gt;&lt;br /&gt;Suggestion:&lt;br /&gt;To set a fixed amount of memory&lt;br /&gt;&lt;br /&gt;   1. Expand a server group.&lt;br /&gt;&lt;br /&gt;   2. Right-click a server, and then click Properties.&lt;br /&gt;&lt;br /&gt;   3. Click the Memory tab.&lt;br /&gt;&lt;br /&gt;   4. Click Use a fixed memory size (MB), and then position the fixed memory slider.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1988199090686567537?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1988199090686567537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1988199090686567537' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1988199090686567537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1988199090686567537'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/how-to-set-fixed-amount-of-memory.html' title='How to set a fixed amount of memory (Enterprise Manager)'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7023467988684511704</id><published>2009-10-23T16:19:00.001+08:00</published><updated>2009-10-23T16:28:34.605+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>malformed email</title><content type='html'>Issue:&lt;br /&gt;I have IMSA 7.0 Patch 1. Recently, one of my email is quarantined which can be seen from the web console with the reason "malformed". I noticed from the mail, it has about ~70 image attachments which are the company logo/symbol in that particular mail. I believe that is the reason for the "malformed" issue.&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;&lt;br /&gt;Malformed email is quarantined in IMSA due to the following rules setting: &lt;br /&gt;&lt;br /&gt;1. Maximum number of entities allowed in each mail message ( usually Maximum attachment or embedded item) &lt;br /&gt;               LimitEntities = 64 &lt;br /&gt;&lt;br /&gt;2. Maximum number of parameters allowed in each header field ( You can change this field to CC and BCC field as well) &lt;br /&gt;               LimitHeaderParams=100 &lt;br /&gt;&lt;br /&gt;3. Maximum number of header fields allowed in each entity &lt;br /&gt;               LimitHeaders=500 &lt;br /&gt;&lt;br /&gt;You will have to edit this setting.&lt;br /&gt;&lt;br /&gt;Access the hyperterminal console and log in as root. Locate the following imss.ini file located in /opt/trend/imss/config/ directory.&lt;br /&gt;Change the value of the following parameters to the maximum value needed:&lt;br /&gt; LimitEntities&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;http://esupport.trendmicro.com/Pages/Frequently-Asked-Questions-FAQ-about-the-mail-transfer-agent-MTA-of-In.aspx&lt;br /&gt;http://esupport.trendmicro.com/7/What-is-malformed-email-and-how-to-avoid-it.aspx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7023467988684511704?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7023467988684511704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7023467988684511704' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7023467988684511704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7023467988684511704'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/malformed-email.html' title='malformed email'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1316652250208270236</id><published>2009-10-23T16:14:00.001+08:00</published><updated>2009-10-23T16:17:36.839+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>Approving youtube.com</title><content type='html'>Issue:&lt;br /&gt;Customer installed IWSS 3.1 on Windows 2003 svr. They enabled the URL filtering and block access to Streaming Media / MP3 category. However, they want to approve www.youtube.com.&lt;br /&gt;&lt;br /&gt;I have tried to add in youtube* and *youtube* in the approved URL list. But the youtube page doesn't appear correctly. Some of the page elements are missing. What's wrong.&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;Please try to add the following in the HTTP&gt; URL Filtering &gt; Settings &gt; Approve URL List &lt;br /&gt;&lt;br /&gt;- Choose URL keyword and enter the following string&lt;br /&gt;&lt;br /&gt;ytimg.com&lt;br /&gt;youtube.com&lt;br /&gt;&lt;br /&gt;Note: Actual strings shown after adding them is as follows:&lt;br /&gt;&lt;br /&gt;*ytimg.com*&lt;br /&gt;* youtube.com*&lt;br /&gt;&lt;br /&gt;Please be informed that youtube has to retrieve files from different servers which are hosted under youtube.com and ytimg.com. The thumbnails/pictures are usually stored under ytimg.com while the actual flv files are located on servers under youtube.com. One example is the “v21.lscache2.c.youtube.com”. The retrieval of the files depends on the current location of the browser requesting the site and depends on which server hosts the requested files.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1316652250208270236?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1316652250208270236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1316652250208270236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1316652250208270236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1316652250208270236'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/approving-youtubecom.html' title='Approving youtube.com'/><author><name>mumof2heroes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/-XdOOFukK9c8/Tv6XXH5mn8I/AAAAAAAAC6g/TaHKeZawc5g/s220/IMG_0515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1197711454524094143</id><published>2009-10-20T12:46:00.000+08:00</published><updated>2009-10-20T12:47:27.883+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Procedure to reimage IMSA</title><content type='html'>1.1. Backup current config: http://www.trendmicro.com/ftp/documentation/guides/IMSA7.0_SP1_AG.pdf (Page: 93)&lt;br /&gt;&lt;br /&gt;1.2. Save the config file after re-imaging IMSA&lt;br /&gt;&lt;br /&gt;1.3. Instruction on how to rescue (re-image) can be found in Page 165. You need to download the Solution CD using this link: http://www.trendmicro.com/ftp/products/imsa/IMSA_7.0_Solution_CD.zip&lt;br /&gt;&lt;br /&gt;Thanks Law!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1197711454524094143?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1197711454524094143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1197711454524094143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1197711454524094143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1197711454524094143'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/procedure-to-reimage-imsa.html' title='Procedure to reimage IMSA'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8324450650991165199</id><published>2009-10-14T16:54:00.005+08:00</published><updated>2009-11-25T22:36:13.812+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>Database optimization for TMCM 3.0</title><content type='html'>Issue:&lt;br /&gt;I have customer installed the old TMCM version 3.0 on MSDE database (free database version one that is bundled in TMCM installer). I will have to perform database performance optimization for Expert on Guard (EoG) service activation. How do I go about and do it?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;You will have to have Query Analyzer. For free tool, you can download one from &lt;a href="http://www.albahari.com/QueryExpress.exe"&gt;here&lt;/a&gt;. Connect to the database and execute the following commands.&lt;br /&gt;Copy and paste it in the Query Analyzer: &lt;br /&gt;--------- copied start below this line ------------------------------------- &lt;br /&gt;use db_ControlManager; &lt;br /&gt;runcate table tb_InValidLog; &lt;br /&gt;delete tb_DeployCommandTracking; &lt;br /&gt;delete tb_tvcscommandlist; &lt;br /&gt;delete tb_tvcsCommandTaskqueue; &lt;br /&gt;delete tb_registeredproductlist where RPL_TotalCount&lt;=0; &lt;br /&gt;update tb_registeredproductlist set RPL_ProductInfoState=0 where RPL_ProductInfo&lt;br /&gt;Backup log db_controlamanger with truncate_only; &lt;br /&gt;DBCC shrinkDatabase(db_controlmanager); &lt;br /&gt;--------- copied end this line ------------------------------------------------ &lt;br /&gt;&lt;br /&gt;note: dbcontrolmanager.mdf is variable - typically is the name of your TMCM database.&lt;br /&gt;Verify that the command executed successfully. &lt;br /&gt;&lt;br /&gt;I hope it helps!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8324450650991165199?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8324450650991165199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8324450650991165199' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8324450650991165199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8324450650991165199'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/database-optimization-for-tmcm-30.html' title='Database optimization for TMCM 3.0'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6553685185206323387</id><published>2009-10-14T16:26:00.002+08:00</published><updated>2009-10-14T16:29:46.246+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WorryFree'/><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Worry Free installed on Apache Web Server</title><content type='html'>Issue/concern:&lt;br /&gt;A customer installed Worry Free on Apache Web Server rather than IIS. Now, he is concern since he is going to patch the Apache whether it will affect the Worry Free web console installation. Is there anything to backup?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;&lt;br /&gt;Well actually nothing to backup on WFBS just make sure you have an apache backup. Just incase you need to revert back. Check the apache update’s roll back procedure as well if thre’s any.&lt;br /&gt;&lt;br /&gt;On our documentation we can support Apache ver 2.0.63 or later. As long as you are on the range I see no harm.&lt;br /&gt;&lt;br /&gt;Allow me to put some of my thoughts into this, although apache is nice and stable Web server we only included it in the package if a client with limited machineries would like to install the product on a non windows server class OS. I suggest you use IIS instead.&lt;br /&gt;&lt;br /&gt;Note: you might want to consider backup httpd.conf, c:\etc. For more infor you may google around. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6553685185206323387?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6553685185206323387/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6553685185206323387' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6553685185206323387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6553685185206323387'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/worry-free-installed-on-apache-web.html' title='Worry Free installed on Apache Web Server'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6212036524558369960</id><published>2009-10-09T16:34:00.003+08:00</published><updated>2009-10-09T16:51:52.318+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NVW'/><title type='text'>CDI for NVWe2500</title><content type='html'>Issue:&lt;br /&gt;A customer reported that her NVWe2500 unit is not able to update either manual or scheduled. Clicking on the update button will take almost forever to come out with the page.&lt;br /&gt;&lt;br /&gt;Normally the Available Version column should indicate the latest component version but since the problem occur, she only see N/A as the description.&lt;br /&gt;&lt;br /&gt;How to run CDI to further troubleshoot on this issue?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;The Case Diagnostic Information (CDI) gathers information for diagnostic and debugging purposes. Trend Micro can use this information to diagnose problems and issues with NVWe. You can collect the CDI by clicking on the Administration menu, then the Tools link, and then the download link. The Tools pane will appear.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-8ljvkq1hYo/Ss75dpzCf1I/AAAAAAAAANU/28_Z73pefyQ/s1600-h/nvw1.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 88px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/Ss75dpzCf1I/AAAAAAAAANU/28_Z73pefyQ/s400/nvw1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5390520091840511826" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Save the file to your computer and then send it to Trend Support for further investigation. We cannot open the file as it is encrypted. It can only be read by their service engineering group.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-8ljvkq1hYo/Ss75ecXoEhI/AAAAAAAAANc/QLNGxpAWQFY/s1600-h/nvw2.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 298px; height: 215px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/Ss75ecXoEhI/AAAAAAAAANc/QLNGxpAWQFY/s400/nvw2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5390520105415741970" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6212036524558369960?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6212036524558369960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6212036524558369960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6212036524558369960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6212036524558369960'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/cdi-for-nvwe2500.html' title='CDI for NVWe2500'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-8ljvkq1hYo/Ss75dpzCf1I/AAAAAAAAANU/28_Z73pefyQ/s72-c/nvw1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5649290117669431005</id><published>2009-10-06T16:50:00.002+08:00</published><updated>2009-10-06T16:56:45.245+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>iCrcPtnDP log file</title><content type='html'>Issue:&lt;br /&gt;Customer installed OSCE 10, with smart scan scanning method.&lt;br /&gt;Recently, he found out that in this particular folder .\PCCSRV\log folder there are many logs by the name iCrcPtnDPxxxxxx.log (e.g. iCrcPtnDP647700.log). If this continues they are worried that it might used up the HDD space a lot. &lt;br /&gt;&lt;br /&gt;Is this log important?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;This log is just icrc pattern update logs (server smart scan). It is safe to just delete the log from time to time.&lt;br /&gt;&lt;br /&gt;I hope it helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5649290117669431005?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5649290117669431005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5649290117669431005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5649290117669431005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5649290117669431005'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/icrcptndp-log-file.html' title='iCrcPtnDP log file'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6129887777032866031</id><published>2009-10-02T16:35:00.003+08:00</published><updated>2009-10-02T16:36:57.250+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>Trend Micro Anti-Malware Ranked #1 in Real-World Online Testing</title><content type='html'>http://us.trendmicro.com/us/trendwatch/core-technologies/competitive-benchmarks/index.html&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SsW7izD43uI/AAAAAAAAANM/nxpfjuaQlKA/s1600-h/trend%231.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 251px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SsW7izD43uI/AAAAAAAAANM/nxpfjuaQlKA/s400/trend%231.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5387918735715131106" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6129887777032866031?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6129887777032866031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6129887777032866031' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6129887777032866031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6129887777032866031'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/10/trend-micro-anti-malware-ranked-1-in.html' title='Trend Micro Anti-Malware Ranked #1 in Real-World Online Testing'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SsW7izD43uI/AAAAAAAAANM/nxpfjuaQlKA/s72-c/trend%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5775399120248238964</id><published>2009-09-28T10:13:00.003+08:00</published><updated>2009-09-28T10:17:55.268+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>spam pattern update failed</title><content type='html'>Problem:&lt;br /&gt;My customer reported that he can't perform update for the spam pattern of IMSS 7.0 Linux&lt;br /&gt;&lt;br /&gt;Refer below information:&lt;br /&gt;1. What was the current build of their IMSS 7.0&lt;br /&gt;* Make it sure that the latest patch was already been applied.&lt;br /&gt;  &lt;strong&gt;Linux_1633&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;2. What was the last changes made before the issue occured?&lt;br /&gt;&lt;strong&gt;No changes made&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;3. Are they running another program on the same IMSS server where the database is utilized?&lt;br /&gt;&lt;strong&gt;No&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;4. What is the specs of the server and how many mails are they processing.&lt;br /&gt;&lt;strong&gt;Power Edge 6800 Server (Linux RedHat Enterprise) 2nd Dual Core Xeon Processor 7120M, 4MB L3 Cache. 3.00 GHz, 800 FSB 146GB hardrive 4Gb DDR2 RAM&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Attached also the screen shot of the error message. Please find the attached CDT log uploaded at ftp://ftp.myatsc.net/UPLOAD/ACA/&lt;br /&gt;MATRADE folder.&lt;br /&gt;&lt;br /&gt;Reply from Support:&lt;br /&gt;1. Since the build is 1633 (GM) please download and install the latest service pack and patch: http://www.trendmicro.com/download/product.asp?productid=12&lt;br /&gt;&lt;br /&gt;2. Now if issue persists after that step 1, do the following:&lt;br /&gt;       - root# mv /opt/trend/imss/temp /opt/trend/imss/temp_090509&lt;br /&gt;       - root# mkdir /opt/trend/imss/temp&lt;br /&gt;       - root# chown -R imss:imss /opt/trend/imss/temp&lt;br /&gt;       - root# mv /opt/trend/imss/lib/AU_Temp /opt/trend/imss/lib/AU_Temp_090509&lt;br /&gt;       - root# mv /opt/trend/imss/lib/AU_Cache /opt/trend/imss/lib/AU_Cache_090509&lt;br /&gt;       - root# mv /opt/trend/imss/lib/download /opt/trend/imss/lib/download_090509&lt;br /&gt;       - root# chown -R imss:imss /opt/trend/imss/lib/AU_Temp /opt/trend/imss/lib/AU_Cache /opt/trend/imss/lib/download&lt;br /&gt;&lt;br /&gt;3. If issue still persists, do the following:&lt;br /&gt;       - Look and open the file: /opt/trend/imss/lib/aucfg.ini&lt;br /&gt;       - Change the debug_level from 5 to "-1" without quotes&lt;br /&gt;       - Save the changes and do this command: root# /opt/trend/imss/bin/script/S99IMSS restart&lt;br /&gt;       - Enable debug log in UI =&gt; Log =&gt; Settings =&gt; Debug&lt;br /&gt;       - Reproduce the issue by clicking the Update in the Summary Page of IMSS for components to be updated or wait for the time the scheduled update to be triggered (screenshot please)&lt;br /&gt;       - Collect the following logs&lt;br /&gt;              1. All logs inside this folder with same timestamp of the replication: /opt/trend/imss/log/*&lt;br /&gt;              2. Get this file: /opt/trend/imss/lib/AU_Log/TmuDump.txt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5775399120248238964?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5775399120248238964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5775399120248238964' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5775399120248238964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5775399120248238964'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/09/spam-pattern-update-failed.html' title='spam pattern update failed'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3893089992352752828</id><published>2009-09-28T10:01:00.002+08:00</published><updated>2009-09-28T10:06:07.231+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>patch 1 for sp1 installation problem on IMSA</title><content type='html'>1. Did the client already update the IMSA for SP1 prior to patch 1?&lt;br /&gt;2. If yes and this happens, we need to ask the client to collect some logs to analyze&lt;br /&gt;       a. Connect the pc to IMSA to the CLI (command line) via SSH&lt;br /&gt;       b. Go to $IMSA_Home/cdt&lt;br /&gt;       c. Open the cdt.ini and check SilentMode=1 is set to zero "0"&lt;br /&gt;           bash-3.0# cd /opt/trend/imss/cdt&lt;br /&gt;           bash-3.0# vi cdt.ini&lt;br /&gt;       d. Save the changes and run it. bash-3.0# ./cdt&lt;br /&gt;       e. Select All Events and once the CDT is running, replicate the patch installation.&lt;br /&gt;       f. Once the issue occurs, allow CDT to continue running for about 5 mins more.  Afterwards, stop CDT and collect the CDT logs.  Move the CDT*.zip to /tmp folder and using UI console, export the logs/CDT.  Otherwise, you can try the following to move the logs out from the IMSA.&lt;br /&gt;&lt;br /&gt;Transferring files to / from IMSA&lt;br /&gt;&lt;br /&gt;=======&lt;br /&gt;Using FTP&lt;br /&gt;=======&lt;br /&gt;Use the ncftp FTP client to access the external FTP servers (in our case you can upload it here ftp.trend.com.au; user: xxxx and pass: yyyy) and exchange files. The command-line arguments must include username, password and the port number if it is not 21:&lt;br /&gt;&lt;br /&gt;bash-3.00# ncftp -u &lt;Username&gt; -p &lt;Password&gt; -P 2121 10.13.130.253 NcFTP 3.1.9 (Mar 24, 2005) by Mike Gleason (http://www.NcFTP.com/contact/).&lt;br /&gt;Connecting to 10.13.130.253...&lt;br /&gt;transfer Microsoft FTP Service (Version 5.0).&lt;br /&gt;Logging in...&lt;br /&gt;User training logged in.&lt;br /&gt;Logged in to 10.13.130.253.&lt;br /&gt;ncftp / &gt;&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;bash-3.00# cd /tmp&lt;br /&gt;bash-3.00# ncftp -u xxxx -p yyyyy ftp.trend.com.au NcFTP 3.1.9 (Mar 24, 2005) by Mike Gleason (http://www.NcFTP.com/contact/).&lt;br /&gt;Connecting to ...&lt;br /&gt;transfer Microsoft FTP Service (Version 5.0).&lt;br /&gt;Logging in...&lt;br /&gt;User training logged in.&lt;br /&gt;Logged in.&lt;br /&gt;ncftp / &gt;cd _asiasupport/upload/logs/1-1-271644771&lt;br /&gt;ncftp &gt; put &lt;name of files we need to upload&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;=======&lt;br /&gt;Using the NFS Client&lt;br /&gt;=======&lt;br /&gt;Using the NFS client from the shell allows one to set up a remote filesystem to which files can be copied:&lt;br /&gt;&lt;br /&gt;mount -t nfs -o nolock 10.13.9.186:/data /mnt&lt;br /&gt;&lt;br /&gt;Note: Since there is no locking daemon available on IMSA, you have to tell the mount command to not use locking.&lt;br /&gt;&lt;br /&gt;These files can then be accessed from non-IMSA devices (Linux, Windows, etc.) that have an NFS client.  In other words, in windows machine, create a folder and have it shared (Everyone with Read &amp; Write).  Example.  I have a machine 10.0.0.1 and I created IMSA folder and shared it so if I access it using windows, it is like: \\10.0.0.1\imsa&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3893089992352752828?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3893089992352752828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3893089992352752828' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3893089992352752828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3893089992352752828'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/09/patch-1-for-sp1-installation-problem-on.html' title='patch 1 for sp1 installation problem on IMSA'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7996025300996335458</id><published>2009-09-11T15:13:00.002+08:00</published><updated>2009-09-11T15:18:55.901+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>NRS activation problem for IMSS 5.7</title><content type='html'>&lt;strong&gt;Problem:&lt;/strong&gt;&lt;br /&gt;My customer is still using IMSS 5.7 build 1121 on Windows 2000. No plan to upgrade yet since the hardware is of low specs. Recently he activated the NRS. Upon saving the changes, refer below for message that he received:&lt;br /&gt;&lt;br /&gt;-------------------------------------------&lt;br /&gt;The configuration changes have been saved.&lt;br /&gt;&lt;br /&gt;However, local DNS server seemed not responding to DNS A-record query for Network Reputation initialization test in time and timed out. As a result, Network Reputation during scan may not be functioning properly. Although mail flow will still continue, it is recommended to follow manual's instructions to troubleshoot, reconfigure and tune local DNS server before fully utilizing this feature.&lt;br /&gt;&lt;br /&gt;Some possible reasons may lead to this testing failure are listed here as reference and please refer to manuals for further information:&lt;br /&gt;&lt;br /&gt;1. Local DNS server can not respond to A record query.&lt;br /&gt;&lt;br /&gt;2. Local DNS server can not look up its root DNS server for sub-domains of a.mail-abuse.com.&lt;br /&gt;&lt;br /&gt;3. Slow response from local DNS server and/or intermittent networking connectivity for outgoing DNS queries.&lt;br /&gt;&lt;br /&gt;-------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Solution:&lt;/strong&gt;&lt;br /&gt;Do the following;&lt;br /&gt;&lt;br /&gt;1)  Stop all IMSS services.&lt;br /&gt;&lt;br /&gt;2)  Look in the IMSS folder then backup and delete  the following files.&lt;br /&gt;&lt;br /&gt;     licenseprofile3.dat is for NAS&lt;br /&gt;     licenseprofile4.dat is for RBL+&lt;br /&gt;&lt;br /&gt;     You might night not have both files. Just delete these two files if you see them.&lt;br /&gt;&lt;br /&gt;3)  Restart all  IMSS services&lt;br /&gt;&lt;br /&gt;4)  Enter the NRS Activation Code again.&lt;br /&gt;&lt;br /&gt;     Open the GUI and click 'Configuration'&lt;br /&gt;     Under 'Configuration', click 'Product Licenses'&lt;br /&gt;     Under 'Network Reputation Services', click 'View license details'&lt;br /&gt;     Enter the NRS Activation Code.&lt;br /&gt;&lt;br /&gt;     Under 'Configuration', select 'Network Reputation'&lt;br /&gt;     Check the box next to 'Enable Network Reputation Service'&lt;br /&gt;     Under 'Action:', select 'Default intelligent action'&lt;br /&gt;     Click 'Save'&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7996025300996335458?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7996025300996335458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7996025300996335458' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7996025300996335458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7996025300996335458'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/09/nrs-activation-problem-for-imss-57.html' title='NRS activation problem for IMSS 5.7'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8173191477491588087</id><published>2009-09-11T12:58:00.002+08:00</published><updated>2009-09-11T13:02:12.902+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Improving the performance of OfficeScan related clients agents</title><content type='html'>You notice poor performance from any of the following:&lt;br /&gt;OfficeScan 7.0 / 7.3 / 8.0 / 10 client&lt;br /&gt;Client Server Messaging Security for SMB (CSM) 3.x Agent&lt;br /&gt;Worry-Free Business Security (WFBS) Standard / Advanced Agent&lt;br /&gt;&lt;br /&gt;Please refer to this &lt;a href="http://esupport.trendmicro.com/Pages/Improving-the-performance-of-OfficeScan-related-clients-agents.aspx"&gt;knowledge base&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;1. As a workaround, disable the TSC.exe process from starting at startup&lt;br /&gt;2. If the issue persists, delay the RealTimeScan process from starting at startup&lt;br /&gt;3. If the issue still persists, resize the "PagedPoolSize" registry key&lt;br /&gt;4. If this does not work, run the &lt;a href="http://www.trendmicro.com/download/product.asp?productid=25"&gt;Case Diagnostic Tool (CDT)&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8173191477491588087?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8173191477491588087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8173191477491588087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8173191477491588087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8173191477491588087'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/09/improving-performance-of-officescan.html' title='Improving the performance of OfficeScan related clients agents'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1456726255568563901</id><published>2009-09-04T14:26:00.002+08:00</published><updated>2009-09-04T14:33:08.955+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>List of endpoint security software that OSCE automatically uninstalls</title><content type='html'>This is related to old entry with the topic &lt;a href="http://tcse-trendmicro.blogspot.com/2009/06/removal-of-other-antivirus-product.html"&gt;'Removal of antivirus product during OSCE installation'.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I came across the below note while reading the Student Textbook for OSCE 10, TCSE course. Thought of sharing it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;"If Trend Micro or third-party endpoint security programs are installed on the computer, check if OfficeScan can automatically uninstall the software and replace it with the OfficeScan client. For a list of endpoint security software that OfficeScan automatically uninstalls, open the following files in {installation path}\PCCSRV\Admin. You can open these files with a text editor like Notepad. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;tmuninst.ptn  &lt;br /&gt;tmuninst_as.ptn  &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If the software on the target computer is not included in the list, manually uninstall it first. "&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1456726255568563901?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1456726255568563901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1456726255568563901' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1456726255568563901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1456726255568563901'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/09/list-of-endpoint-security-software-that.html' title='List of endpoint security software that OSCE automatically uninstalls'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4625353291341374410</id><published>2009-08-27T14:46:00.002+08:00</published><updated>2009-09-02T14:33:39.399+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>problem in updating your IMSS for linux?</title><content type='html'>look for tmudumpt.txt file located in  /opt/trend/imss/lib/AU_Log/TmuDump.txt&lt;br /&gt;You should have some indication. If it looks garbage to you, send it to Trend Support.&lt;br /&gt;&lt;br /&gt;You might want to run Case Diagnostic Tool as well. Type /opt/trend/imss/cdt/cdt&lt;br /&gt;Case Diagnostic GUI will prompt up. Follow through the wizard. &lt;br /&gt;&lt;br /&gt;Collect the log/folder and submit to &lt;a href="http://esupport.trendmicro.com/SRFMain.aspx"&gt;Trend Support.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4625353291341374410?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4625353291341374410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4625353291341374410' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4625353291341374410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4625353291341374410'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/08/problem-in-updating-your-imss-for-linux.html' title='problem in updating your IMSS for linux?'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3455740970429476633</id><published>2009-08-12T12:03:00.003+08:00</published><updated>2009-08-12T12:12:27.230+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>August Class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SoI_xk-QxnI/AAAAAAAAANE/t6AtdOhJD7E/s1600-h/classAug09.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 268px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SoI_xk-QxnI/AAAAAAAAANE/t6AtdOhJD7E/s400/classAug09.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5368923826750015090" /&gt;&lt;/a&gt;&lt;br /&gt;From left is Nizam, Shahril, Sha, Arniza, Rosdi, Duvell, Bernard, Yatim and Helmi.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3455740970429476633?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3455740970429476633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3455740970429476633' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3455740970429476633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3455740970429476633'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/08/august-class.html' title='August Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SoI_xk-QxnI/AAAAAAAAANE/t6AtdOhJD7E/s72-c/classAug09.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4673325859948141967</id><published>2009-08-12T11:56:00.003+08:00</published><updated>2009-08-12T12:03:16.090+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ScanMail'/><title type='text'>ScanMail for Domino 3.0 gets update from TMCM 5.0</title><content type='html'>By default your SMD will get the update from Trend Micro ActiveUpdate in the Internet. However, you can specify other Internet update source, namely TMCM.&lt;br /&gt;key in "http://&lt;tmcm_ip_or_fqdn&gt;/TVCSDownload/activeupdate"&lt;br /&gt;as the Internet update source.&lt;br /&gt;&lt;br /&gt;By default also, your SMD will try to do secure update by means of going through https. So most likely that your update will fail if your URL for TMCM is http based. So make sure you add in the following:&lt;br /&gt;&lt;br /&gt;Option I. Use the following command inside the server console:&lt;br /&gt;      set conf DisableSecureUpdate=1&lt;br /&gt;The server does not need to restart when this option is used.&lt;br /&gt;&lt;br /&gt;Option II. Follow these steps:&lt;br /&gt;      1. Open the notes.ini file.&lt;br /&gt;      2. Add the DisableSecureUpdate=1 entry as another line inside the notes.ini file. Make sure the last line of file is empty.&lt;br /&gt;      3. Save the file and restart the Domino server service.&lt;br /&gt;&lt;br /&gt;Monitor the success of updates from the Domino server console.&lt;br /&gt;&lt;br /&gt;Hope it helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4673325859948141967?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4673325859948141967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4673325859948141967' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4673325859948141967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4673325859948141967'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/08/scanmail-for-domino-30-gets-update-from.html' title='ScanMail for Domino 3.0 gets update from TMCM 5.0'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1338459027743492500</id><published>2009-08-04T16:19:00.000+08:00</published><updated>2009-08-04T16:20:50.510+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>IWSS unable to do schedule update after license expire</title><content type='html'>Solution:&lt;br /&gt;Recreate the scheduled task using createatasktool.exe downloaded from&lt;br /&gt;&lt;br /&gt;http://solutionfile.trendmicro.com/solutionfile/25483/en/createatasktool.zip&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1338459027743492500?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1338459027743492500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1338459027743492500' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1338459027743492500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1338459027743492500'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/08/iwss-unable-to-do-schedule-update-after.html' title='IWSS unable to do schedule update after license expire'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4823226118364543080</id><published>2009-07-29T09:32:00.001+08:00</published><updated>2009-07-29T09:35:05.604+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>IMSS 7.0 and IWSS 3.1 on the same server machine</title><content type='html'>Issue:&lt;br /&gt;When running both IMSS 7.0 and IWSS 3.1 on the same server machine, I notice once the IWSS console service is up, the IMSS console service cannot start and same goes the other way. Is there any workaround for this?&lt;br /&gt;&lt;br /&gt;Workaround:&lt;br /&gt;Please note, it is &lt;span style="font-weight:bold;"&gt;not recommended&lt;/span&gt; to install both on the same machine. &lt;br /&gt;It is because both tomcat is using same port 8005 to start the service. You need change the port on either IMSS or IWSS tomcat.&lt;br /&gt;&lt;br /&gt;Please do EITHER of the two steps below:&lt;br /&gt;A) On IMSS,&lt;br /&gt;1) Go to &lt;IMSS_Folder&gt;\ui\adminUI\conf&lt;br /&gt;2) Edit the file server.xml&lt;br /&gt;3) Search for "8005"&lt;br /&gt;4) Replace it with available port such as "8006"&lt;br /&gt;5) Save&lt;br /&gt;6) Start "Trend Micro IMSS Web Console" service&lt;br /&gt;&lt;br /&gt;OR &lt;br /&gt;&lt;br /&gt;B) On IWSS&lt;br /&gt;1) Go to &lt;IWSS_Folder&gt;\ui\adminUI\conf&lt;br /&gt;2) Edit the file server.xml&lt;br /&gt;3) Search for "8005"&lt;br /&gt;4) Replace it with available port such as "8006"&lt;br /&gt;5) Save&lt;br /&gt;6) Start "Trend Micro Interscan Web Security Suite Console" service&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4823226118364543080?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4823226118364543080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4823226118364543080' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4823226118364543080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4823226118364543080'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/imss-70-and-iwss-31-on-same-server.html' title='IMSS 7.0 and IWSS 3.1 on the same server machine'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6139965468687187460</id><published>2009-07-23T13:19:00.004+08:00</published><updated>2009-07-23T13:31:09.709+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE 8.0 hotfix 3300</title><content type='html'>&lt;strong&gt;Overview of this hotfix release&lt;/strong&gt;&lt;br /&gt;enables the OSCE client to control access to external devices. e.g to disable the autorun feature for USB device&lt;br /&gt;&lt;br /&gt;note: &lt;br /&gt;- you will not be able to run the hotfix, if it detects your OSCE build doesn't meet the requirement&lt;br /&gt;- supported only on 32bit platforms&lt;br /&gt;- please perform the post installation configuration.&lt;br /&gt;- the device access control feature (DAC) applies to all clients.&lt;br /&gt;- OSCE client will not report unauthorized access logs to the OSCE server. However, user can look for the logs locally in the client machine located at ../Trend Micro/BM/Log&lt;br /&gt;&lt;br /&gt;where to get the hotfix?&lt;br /&gt;you may request it from &lt;a href="http://esupport.trendmicro.com/SRFMain.aspx"&gt;Trend Support&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;suggestion for post installation configuration (modify and add to ofcscan.ini). This parameter will just enable the disabling autorun for USB devices.&lt;br /&gt;&lt;br /&gt;########################start####################################&lt;br /&gt;[Global Setting]&lt;br /&gt;EnableAEGIS=1&lt;br /&gt;CheckMountPointInterval=300&lt;br /&gt;&lt;br /&gt;[AEGIS_DACPolicy]&lt;br /&gt;&lt;br /&gt;#PolicyId0=D001 - Device Access Control On Plug in devices (USB)&lt;br /&gt;#PolicyId0=D002 - Device Access Control On CD/DVD&lt;br /&gt;#PolicyId0=D003 - Device Access Control On FLOPPY&lt;br /&gt;#PolicyId0=D004 - Device Access Control On Network Resource&lt;br /&gt;#PolicyId0=D005 - Block AutoRun function on USB devices&lt;br /&gt;&lt;br /&gt;# v=0 (disable), 1 (enable)&lt;br /&gt;# w=0 (no pop up), 1 (allow pop up)&lt;br /&gt;# x=0 (pass), 2 (deny access), 4 (Read Only), 5 (Read &amp; Write only), 6 (Read &amp; Execute only)&lt;br /&gt;# y=0 (pass), 2 (deny access)&lt;br /&gt;# z=0 (disable), 1 (enable)&lt;br /&gt;&lt;br /&gt;Count=5&lt;br /&gt;&lt;br /&gt;Enable=1&lt;br /&gt;PopAlert=0           &lt;br /&gt;&lt;br /&gt;PolicyId0=D001 &lt;br /&gt;&lt;br /&gt;Action0=5&lt;br /&gt;Enable0=0&lt;br /&gt;&lt;br /&gt;PolicyId1=D002 &lt;br /&gt;&lt;br /&gt;Action1=0&lt;br /&gt;Enable1=0&lt;br /&gt;&lt;br /&gt;PolicyId2=D003&lt;br /&gt;&lt;br /&gt;Action2=0&lt;br /&gt;Enable2=0&lt;br /&gt;&lt;br /&gt;PolicyId3=D004&lt;br /&gt;&lt;br /&gt;Action3=0&lt;br /&gt;Enable3=0&lt;br /&gt;&lt;br /&gt;PolicyId4=D005&lt;br /&gt;&lt;br /&gt;Action4=2&lt;br /&gt;Enable4=1&lt;br /&gt;&lt;br /&gt;########################end####################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6139965468687187460?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6139965468687187460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6139965468687187460' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6139965468687187460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6139965468687187460'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/osce-80-hotfix-3300.html' title='OSCE 8.0 hotfix 3300'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2827878799451411336</id><published>2009-07-23T11:33:00.002+08:00</published><updated>2009-07-23T11:55:39.504+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>replicating imss 7.0 policy and configuration</title><content type='html'>issue:&lt;br /&gt;existing imss 7.0 server behaving funny and we suspect that it's going to crash soon. We actually prepare another server with the same IP address and hostname then start to install IMSS 7.0. Now, how do we replicate the settings on existing server to the newly installed server?&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;Use utilpolicy ( you can ask from Trend Support or myself for a copy). It's not published in the KB (ASFAIK). The tool will backup policies and IMSS settings. It doesn't matter if the database user name and password different from the earlier server settings.&lt;br /&gt;&lt;br /&gt;Overview of the tool&lt;br /&gt;+++++++++++++++++++++&lt;br /&gt;utilPolicy.exe is a simple tool to import/export policy rules and internal addresses using SQL script. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How to use the tool&lt;br /&gt;+++++++++++++++++++++++++&lt;br /&gt;Run to corresponding command line.&lt;br /&gt; a. To export the policy rules and internal addresses:&lt;br /&gt;  utilPolicy.exe -e %exported_file_name%&lt;br /&gt;  example: "utilPolicy -e policy.txt"&lt;br /&gt;&lt;br /&gt; b. To import the policy rules and internal addresses:&lt;br /&gt;  utilPolicy.exe -i %exported_file_name%&lt;br /&gt;   example: "utilPolicy -i Policy.txt"&lt;br /&gt;&lt;br /&gt;3. Restart the IMSS Policy Service.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2827878799451411336?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2827878799451411336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2827878799451411336' title='18 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2827878799451411336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2827878799451411336'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/replicating-imss-70-policy-and.html' title='replicating imss 7.0 policy and configuration'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>18</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8790667754766750738</id><published>2009-07-17T11:50:00.009+08:00</published><updated>2009-07-17T12:36:41.317+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>IWSS 3.1 backup and restore</title><content type='html'>You will need SQL Management Express if you don't want to go through the hassle of doing it from the command prompt.&lt;br /&gt;&lt;br /&gt;Download and Install Microsoft SQL Server Management Studio Express&lt;br /&gt;http://www.microsoft.com/downloadS/details.aspx?familyid=C243A5AE-4BD1-4E3D-94B8-5A0F62BF7796&amp;displaylang=en#filelist&lt;br /&gt;&lt;br /&gt;note: I installed IWSS 3.1 with the database SQL 2005 Express bundled in the installation. Database name is iwss3. Don't lose the sa password! :-)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;To backup&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-8ljvkq1hYo/Sl_30t_cOQI/AAAAAAAAAL8/FB_8k_Rq12w/s1600-h/iwss1.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 176px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/Sl_30t_cOQI/AAAAAAAAAL8/FB_8k_Rq12w/s320/iwss1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5359274566665124098" /&gt;&lt;/a&gt;&lt;br /&gt;1. Click the database name&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-8ljvkq1hYo/Sl_4ODOHOuI/AAAAAAAAAME/EYscRlgcR3Q/s1600-h/iwss2.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 167px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/Sl_4ODOHOuI/AAAAAAAAAME/EYscRlgcR3Q/s320/iwss2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5359275001860537058" /&gt;&lt;/a&gt;&lt;br /&gt;2. Then click tasks&gt; backup&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/Sl_6xdX0t9I/AAAAAAAAAMc/Y8Pw9dcvZQw/s1600-h/iwss3.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 278px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/Sl_6xdX0t9I/AAAAAAAAAMc/Y8Pw9dcvZQw/s320/iwss3.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5359277809199265746" /&gt;&lt;/a&gt;&lt;br /&gt;3. Choose where you want to store the backup file and click OK&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-8ljvkq1hYo/Sl_83Odj9DI/AAAAAAAAAMs/Qpiu44dPHoo/s1600-h/iwss4.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 251px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/Sl_83Odj9DI/AAAAAAAAAMs/Qpiu44dPHoo/s320/iwss4.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5359280107299271730" /&gt;&lt;/a&gt;&lt;br /&gt;4. To restore, follow the earlier steps 1,2 in the above but this time click restore. Click OK to continue to restore.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To see the space of your database, do the following like in the screen capture:&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-8ljvkq1hYo/Sl_-AIJieUI/AAAAAAAAAM0/ABbYMBXytz8/s1600-h/iwss5.JPG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 222px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/Sl_-AIJieUI/AAAAAAAAAM0/ABbYMBXytz8/s320/iwss5.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5359281359735126338" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8790667754766750738?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8790667754766750738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8790667754766750738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8790667754766750738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8790667754766750738'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/iwss-31-backup-and-restore.html' title='IWSS 3.1 backup and restore'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/Sl_30t_cOQI/AAAAAAAAAL8/FB_8k_Rq12w/s72-c/iwss1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6374704407851741846</id><published>2009-07-14T14:43:00.001+08:00</published><updated>2009-07-14T14:45:35.344+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE 8.0 SSO login frm TMCM 3.5</title><content type='html'>issue:&lt;br /&gt;My customer installed TMCM 3.5 and OSCE 8.0. OSCE 8.0 is currently registered to TMCM 3.5 as one of the agents.&lt;br /&gt;&lt;br /&gt;OSCE web console url is non-ssl based. When try to access OSCE console from TMCM, TMCM will actually refer to ssl based of the OSCE url and result in broken link since OSCE is actually published at http://&lt;OSCE&gt; instead of https://&lt;osce&gt;&lt;br /&gt;&lt;br /&gt;How can this be fixed? User wants to SSO to OSCE console from TMCM 3.5. But her OSCE is http based where as TMCM trying to reach to https based of the URL.&lt;br /&gt;&lt;br /&gt;SOlution:&lt;br /&gt;Regarding this, kindly perform the following to have the Officescan run on HTTPS:&lt;br /&gt;&lt;br /&gt;1. Unregister Officescan from TMCM and delete the entity as well on the TMCM directory tree &lt;br /&gt;&lt;br /&gt;2. On the Officescan server open a command prompt and go to the following folder&lt;br /&gt;&lt;br /&gt;C:\Program Files\Trend Micro\Officescan\PCCSRV\&lt;br /&gt;&lt;br /&gt;3. Run the following command&lt;br /&gt;&lt;br /&gt;svrsvcsetup -enablessl&lt;br /&gt;&lt;br /&gt;4. Kindly check if you can now access  the Officescan console using HTTPS &lt;br /&gt;&lt;br /&gt;5. Register it now to TMCM &lt;br /&gt;&lt;br /&gt;6. Kindly check if you can now peform SSO onto TMCM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6374704407851741846?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6374704407851741846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6374704407851741846' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6374704407851741846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6374704407851741846'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/osce-80-sso-login-frm-tmcm-35.html' title='OSCE 8.0 SSO login frm TMCM 3.5'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2279711464349930759</id><published>2009-07-08T21:10:00.001+08:00</published><updated>2009-07-08T21:11:49.196+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>TREND MICRO MALWARE ADVISORY - Zero day security exploit in Microsoft Video streaming ActiveX control MsVidCtl</title><content type='html'>Topic: MPEG2TuneRequest Exploit Leads to KILLAV Malware&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Details:&lt;br /&gt;Earlier today, TrendLabs has been alerted of a zero-day exploit in Microsoft Video streaming ActiveX control MsVidCtl (Advisory 972890). Around 967 Chinese websites are reported to be infected by a malicious script that leads users to successive redirections and lands them to download a JPG file containing the exploit. Trend Micro detects it as JS_DLOADER.BD.  &lt;br /&gt;&lt;br /&gt;Upon successful exploitation, the script downloads another malware detected as WORM_KILLAV.AI. This malware disables and terminates AV processes, and drops other malware on the affected system. &lt;br /&gt;&lt;br /&gt;Affected Software&lt;br /&gt;Windows XP Service Pack 2 and Windows XP Service Pack 3&lt;br /&gt;Windows XP Professional x64 Edition Service Pack 2&lt;br /&gt;Windows Server 2003 Service Pack 2&lt;br /&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;br /&gt;Windows Server 2003 with SP2 for Itanium-based Systems _______________________________________________________________________________&lt;br /&gt;&lt;br /&gt; Recommended Action&lt;br /&gt;·         Update your AV products to current CPR 6.252.03 or higher&lt;br /&gt;_______________________________________________________________________________&lt;br /&gt;&lt;br /&gt;Detection&lt;br /&gt;Trend Micro JS_DLOADER.BD and WORM_KILLAV.AI with current CPR 6.252.03 or higher:&lt;br /&gt;http://www.trendmicro.com/download/pattern-cpr.asp&lt;br /&gt;Malicious URLs: are currently being block by WRS&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2279711464349930759?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2279711464349930759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2279711464349930759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2279711464349930759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2279711464349930759'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/trend-micro-malware-advisory-zero-day.html' title='TREND MICRO MALWARE ADVISORY - Zero day security exploit in Microsoft Video streaming ActiveX control MsVidCtl'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2522395346322564502</id><published>2009-07-08T21:05:00.003+08:00</published><updated>2009-07-08T21:09:16.946+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE SSO from TMCM 3.5</title><content type='html'>problem:&lt;br /&gt;My customer installed TMCM 3.5 and OSCE 8.0 where OSCE 8.0 is currently registered to TMCM 3.5 as one of the agents.&lt;br /&gt;&lt;br /&gt;OSCE web console url is non-ssl based. When try to access OSCE console from TMCM, TMCM will actually refer to ssl based of the OSCE url and result in broken link since OSCE is actually published at http://&lt;OSCE&gt; instead of https://&lt;osce&gt;&lt;br /&gt;&lt;br /&gt;How can this be fixed? User wants to SSO to OSCE console from TMCM 3.5. But her OSCE is http based where as TMCM trying to reach to https based of the URL.&lt;br /&gt;&lt;br /&gt;answer:&lt;br /&gt;Regarding this, kindly perform the following to have the Officescan run on HTTPS:&lt;br /&gt;&lt;br /&gt;1. Unregister Officescan from TMCM adn delete teh entuty as well on the TMCM directory tree 2. On the Officescan server open a command prompt and go to the following folder&lt;br /&gt;&lt;br /&gt;C:\Program Files\Trend Micro\Officescan\PCCSRV\&lt;br /&gt;&lt;br /&gt;3. Run the following command&lt;br /&gt;&lt;br /&gt;svrsvcsetup -enablessl&lt;br /&gt;&lt;br /&gt;4. Kindly check if you can now access  the Officescan console using HTTPS 5. Register it now to TMCM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2522395346322564502?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2522395346322564502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2522395346322564502' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2522395346322564502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2522395346322564502'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/osce-sso-from-tmcm-35.html' title='OSCE SSO from TMCM 3.5'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5225142022641247666</id><published>2009-07-08T20:59:00.003+08:00</published><updated>2009-07-08T21:05:33.368+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>Train the Trainer @ ACA SG</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SlSZLisqq0I/AAAAAAAAAL0/BFfbKpSXE5o/s1600-h/GEDC0143.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SlSZLisqq0I/AAAAAAAAAL0/BFfbKpSXE5o/s320/GEDC0143.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5356074280422124354" /&gt;&lt;/a&gt;&lt;br /&gt;Thanks Brian for the photo. He's the instructor. The one wearing green shirt and tie.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5225142022641247666?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5225142022641247666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5225142022641247666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5225142022641247666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5225142022641247666'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/07/train-trainer-aca-sg.html' title='Train the Trainer @ ACA SG'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SlSZLisqq0I/AAAAAAAAAL0/BFfbKpSXE5o/s72-c/GEDC0143.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-21777855383752698</id><published>2009-06-29T09:39:00.001+08:00</published><updated>2009-07-29T09:43:08.356+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>June class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-8ljvkq1hYo/Sm-o8L1ccDI/AAAAAAAAAM8/oH-OKnibVHk/s1600-h/juneclass.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 228px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/Sm-o8L1ccDI/AAAAAAAAAM8/oH-OKnibVHk/s320/juneclass.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5363691433144119346" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;16th June until 19th June.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-21777855383752698?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/21777855383752698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=21777855383752698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/21777855383752698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/21777855383752698'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/june-class.html' title='June class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-8ljvkq1hYo/Sm-o8L1ccDI/AAAAAAAAAM8/oH-OKnibVHk/s72-c/juneclass.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6851630880028431042</id><published>2009-06-12T17:32:00.002+08:00</published><updated>2009-06-12T17:51:20.261+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>Description on few terms in TMCM 5.0 report</title><content type='html'>Question:&lt;br /&gt;I need a description on report by TMCM 5. I need this information to present the report for management.&lt;br /&gt;&lt;br /&gt;- Description for Unique Infection Destination Count &amp; Unique Infection Source Count.&lt;br /&gt;- Description for N/A.&lt;br /&gt;- Description for Unique Infection Destination Count &amp; Unique Virus/Malware Count.&lt;br /&gt;- Description for Unique Infection Source Count &amp; Unique Virus/Malware Count.&lt;br /&gt;- Description for No action, N/A, Unable to delete file &amp; File passed.&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;&lt;br /&gt;The &lt;strong&gt;Unique Infection Destination Count &amp; Unique Infection Source Count&lt;/strong&gt; is just same as Infection Destination Count &amp; Infection Source Count. There's a word "Unique" because of Log Aggregation which is the new feature in TMCM 5.0 version. This means that the logs has already been sorted out. Like for example: Instead of logging 10 malware detection for same infection source and same malware, TMCM will only log this once. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;"NA"&lt;/strong&gt; means that the infection source is blank. If you will check the virus logs from OSCE server, there are rows which the Infection Source is blank. This is the NA in TMCM reports. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;No Action&lt;/strong&gt; - Some files require further investigation to determine whether they are infected with a virus or other instance of malware. To mitigate the impact of potential false positives, OfficeScan will temporarily take no action on certain suspicious files. After Trend Micro determines the correct status of the file, the scan action will be adjusted accordingly. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;File passed&lt;/strong&gt; - These are the detection scanned by Heurisitic scanning in which the file is tagged as suspicious. Since this is not yet included in the pattern file, OfficeScan will set the action to pass to prevent false-positive detection &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Unable to delete&lt;/strong&gt; - these are the malcious files in which OfficeScan cannot delete the file because it is locked for some reason. &lt;br /&gt;&lt;br /&gt;Hope these information helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6851630880028431042?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6851630880028431042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6851630880028431042' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6851630880028431042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6851630880028431042'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/description-on-few-terms-in-tmcm-50.html' title='Description on few terms in TMCM 5.0 report'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4172888853863245621</id><published>2009-06-12T17:28:00.002+08:00</published><updated>2009-06-12T17:31:40.764+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Removal of other antivirus product brand during OSCE installation</title><content type='html'>Question:&lt;br /&gt;Will OSCE installer, automatically remove Microsoft Forefront?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;It will not automatically remove Microsoft Forefront anti-virus software.&lt;br /&gt;I would suggest for you to manually uninstall the  Microsoft Forefront antivirus and after that, kindly install the OfficeScan anti-virus software.&lt;br /&gt;&lt;br /&gt;Actually, when OfficeScan client is installed, it automatically removes the following products first:&lt;br /&gt;&lt;br /&gt;1.      Authentium(TM) Command AntiVirus for Windows Enterprise 4.9x&lt;br /&gt;2.      Computer Associates (CA) eTrust(TM) Antivirus 8.1.655&lt;br /&gt;3.      eScan(TM) for Windows 8.0.653.1&lt;br /&gt;4.      ESET(TM) NOD32(TM) Antivirus build 3.0.642&lt;br /&gt;5.      ESET(TM) NOD32(TM) Antivirus 3.0.667.0&lt;br /&gt;6.      Kaspersky(TM) Anti-Virus 6.0.3.837&lt;br /&gt;7.      McAfee(TM) Total Protection&lt;br /&gt;8.      McAfee ePolicy Agent 3.6.0.574&lt;br /&gt;9.      McAfee VirusScan Enterprise 8.7.0.570&lt;br /&gt;10.     Norman(TM) Virus Control 5.99.0600&lt;br /&gt;11.     Symantec(TM) 11.0.780.1109 Endpoint Protection&lt;br /&gt;12.     Symantec 11.0.2010.25 Endpoint Protection MR 2&lt;br /&gt;13.     Symantec Endpoint Protection 11.0.3001.2224&lt;br /&gt;14.     Symantec Endpoint Protection 11.0.4000.2295&lt;br /&gt;15.     Symantec 11.0.4000.2295 Endpoint Protection 64-bit Edition&lt;br /&gt;&lt;br /&gt;Hope this info helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4172888853863245621?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4172888853863245621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4172888853863245621' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4172888853863245621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4172888853863245621'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/removal-of-other-antivirus-product.html' title='Removal of other antivirus product brand during OSCE installation'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4250675676126860522</id><published>2009-06-09T17:51:00.002+08:00</published><updated>2009-06-09T18:01:02.239+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>Worm Neeris family exploits the same vulnerability MS08-067</title><content type='html'>If you haven't patched with &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;MS08-067 &lt;/a&gt; which is KB958644, you better take the action now! Not only DOWNAD, you are also susceptible for attack by &lt;a href="http://www.google.com.my/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fthreatinfo.trendmicro.com%2Fvinfo%2Fvirusencyclo%2Fdefault5.asp%3FVName%3DWORM_NEERIS.A&amp;ei=tTIuSsybGciAkQWema2QCg&amp;usg=AFQjCNFVtc8uwJOMLiMk0e4VOpN9qrgGFw"&gt;neeris&lt;/a&gt; family..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4250675676126860522?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4250675676126860522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4250675676126860522' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4250675676126860522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4250675676126860522'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/worm-neeris-family-exploits-same.html' title='Worm Neeris family exploits the same vulnerability MS08-067'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4545212989199972446</id><published>2009-06-09T17:48:00.001+08:00</published><updated>2009-06-09T17:51:05.717+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE patch installation failed!</title><content type='html'>Question:&lt;br /&gt;I have tried to install few patches for a customer's OSCE server which runs on x64 Windows 2003 server. The error is "Installation Failed!". One of the patches, OSCE_80_WinSP1_Patch2. It's just rollback and the build number from web console &gt; about still shows version 3013. Even after server reboot.&lt;br /&gt;&lt;br /&gt;What went wrong? Need your advice. Attached is the tmpatch.log&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;Here is the analysis of the tmpatch.log (***note that it might vary depends on the case)&lt;br /&gt;&lt;br /&gt;The patch installation failed because some files cannot be replaced.&lt;br /&gt;&lt;br /&gt;Error Log:&lt;br /&gt;----------------------------&lt;br /&gt;[2009-06-08:16:05:26][cgiRecvFile.exe : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\pftB~tmp\FileGroup9\cgiRecvFile.exe-&gt;C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\Web_OSCE\Web\CGI\cgiRecvFile.exe fail]&lt;br /&gt;Fail.&lt;br /&gt;----------------------------&lt;br /&gt;&lt;br /&gt;From the log above, the installation failed because the installer is unable to replace the file 'cgiRecvFile.exe'.&lt;br /&gt;&lt;br /&gt;Try doing the following:&lt;br /&gt;&lt;br /&gt;1. Stop OfficeScan service&lt;br /&gt;2. Rename cgiRecvFile.exe to cgiRecvFile.exe.bak&lt;br /&gt;&lt;br /&gt;**This file can be found on C:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\Web_OSCE\Web\CGI\&lt;br /&gt;&lt;br /&gt;3. Then try to install the patch again.&lt;br /&gt;&lt;br /&gt;If problem persist, please check the updated tmpatch.log!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4545212989199972446?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4545212989199972446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4545212989199972446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4545212989199972446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4545212989199972446'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/osce-patch-installation-failed.html' title='OSCE patch installation failed!'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-912159797255207999</id><published>2009-06-03T11:24:00.002+08:00</published><updated>2009-06-03T11:30:38.872+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Questions on IMSS event logs</title><content type='html'>Questions:&lt;br /&gt;Currently, we found a lot of errors from Trend Micro Interscan Messaging Security Suite (IMSS).&lt;br /&gt;&lt;strong&gt;1. What are these errors about?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;-----------------error#1----------------------&lt;br /&gt;2009/05/23 00:15:50 GMT+08:00&lt;br /&gt;&lt;strong&gt;Write socket FAIL!&lt;/strong&gt;2009/05/23 00:15:50 GMT+08:00&lt;br /&gt;D1B55AA6-934D-4BF7-AE5F-D8DD6AA7489E&lt;br /&gt;ERROR:  id, WRITE ERROR AT 2232&lt;br /&gt;2009/05/23 00:15:50 GMT+08:00&lt;br /&gt;D1B55AA6-934D-4BF7-AE5F-D8DD6AA7489E&lt;br /&gt;&gt;&gt; .\r\n&lt;br /&gt;&lt;br /&gt;2009/05/23 00:16:40 GMT+08:00&lt;br /&gt;ERROR:  &lt;strong&gt;Downstream server close the connection, the reason maybe excess downstream mail size limit or local disk is full.&lt;/strong&gt; &lt;Return code=64&gt;&lt;br /&gt;2009/05/23 00:16:40 GMT+08:00&lt;br /&gt;CA273A4C-5244-4507-9DF1-B6B030B495DA&lt;br /&gt;ERROR:  id, WRITE ERROR AT 1528&lt;br /&gt;2009/05/23 00:16:40 GMT+08:00&lt;br /&gt;CA273A4C-5244-4507-9DF1-B6B030B495DA&lt;br /&gt;&gt;&gt; .\r\n&lt;br /&gt;&lt;br /&gt;-----------------end error#1----------------------&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Where can we configure the period of expiry for the email?&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;3. Does IMSS notify the user if the message has expired?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;-----------------error#2----------------------&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;f0208a7b-afa8-4e8f-b434-88fe441a1ee7&lt;br /&gt;Push email into &lt;retry queue&gt; OK&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;BAD MAIL FROM &lt;abc@def.com.my&gt;, &lt;strong&gt;Unable to deliver message to&lt;/strong&gt; &lt;jkl@mlk.gov.my&gt;.&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;ca273a4c-5244-4507-9df1-b6b030b495da&lt;br /&gt;Push email into &lt;delivery queue&gt; OK&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;CA273A4C-5244-4507-9DF1-B6B030B495DA&lt;br /&gt;ERROR:  AF file expired&lt;c:\program files\trend\imss\ISNTSMTP\mqueue\ca273a4c-5244-4507-9df1-b6b030b495da.AF&gt;&lt;br /&gt;&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;CA273A4C-5244-4507-9DF1-B6B030B495DA&lt;br /&gt;ERROR:  ERROR DELIVERING MAIL - TIMESTAMP AND REASON HAS BEEN UPDATED IN AF FILE&lt;br /&gt;2009/05/23 00:24:39 GMT+08:00&lt;br /&gt;CA273A4C-5244-4507-9DF1-B6B030B495DA&lt;br /&gt;ERROR:  MDA finish, delivery fail since &lt;This message has expired&gt;, spend &lt;4299633&gt; ms. eMail is deleted&lt;br /&gt;&lt;br /&gt;-----------------end error#2----------------------&lt;br /&gt;&lt;br /&gt;Answers:&lt;br /&gt;&lt;br /&gt;1. The possible reasons for this issue are: &lt;br /&gt;• Issues with the downstream server (e.g. filter settings for attachments) &lt;br /&gt;• Insufficient space in the local hard drive where IMSS is installed &lt;br /&gt;• Compatibility issues with the Gigabit Ethernet Network Interface Card (NIC) &lt;br /&gt;&lt;br /&gt;The WRITE ERROR occurs because these required resources for writing data are not available. To resolve the issue, do either of these options: &lt;br /&gt;• Modify the IsntSmtp.ini file &lt;br /&gt;• If IMSS is installed in the local hard drive, make sure that 500 MB (minimum required free disk space) is available for mail storage &lt;br /&gt;• Ensure compatibility if using a Gigabit Ethernet NIC &lt;br /&gt;&lt;br /&gt;Modify the IsntSmtp.ini file: &lt;br /&gt;a. Open the ..\IMSS\IsntSmtp.ini file. &lt;br /&gt;b. Add the following parameter under the “[Delivery-Advanced]” section: "Transfer827=yes" &lt;br /&gt;c. Save the changes. &lt;br /&gt;&lt;br /&gt;Ensure compatibility if using a Gigabit Ethernet NIC: &lt;br /&gt;a. Upgrade the NIC driver or downgrade to a 100 MBPS network card. &lt;br /&gt;b. If using either a half-duplex or full duplex setting, change the switch from one setting to the other by configuring the port switch. &lt;br /&gt;&lt;br /&gt;2. Where can we configure the period of expiry for the email? &lt;br /&gt;==&gt; You can configure it through: &lt;br /&gt;a. IMSS console &gt; Configuration &gt; SMTP Routing &gt; Delivery &gt; Advance &lt;br /&gt;b. Check 'Maximum retry period' value. This is the period of expiry for the mail. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Does IMSS notify the user if the message has expired? &lt;br /&gt;==&gt; By default, IMSS will send NDR notification to senders if the mail/s were not successfully sent. &lt;br /&gt;You can check this settings also in &lt;IMSS&gt;\ISNTSmtp.ini:&lt;br /&gt;&lt;br /&gt;Delivery-Advanced] &lt;br /&gt;MaximumHopCount=15 &lt;br /&gt;MasqueradeDomain= &lt;br /&gt;DisableReceivedHeader=no &lt;br /&gt;DNSAuthoritativeBitCheck=no&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-912159797255207999?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/912159797255207999/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=912159797255207999' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/912159797255207999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/912159797255207999'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/questions-on-imss-event-logs.html' title='Questions on IMSS event logs'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2505822716505751707</id><published>2009-06-03T11:20:00.002+08:00</published><updated>2009-06-03T11:22:59.403+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ScanMail'/><title type='text'>Question on ScanMail for Lotus Domino</title><content type='html'>Question:&lt;br /&gt;Does ScanMail for Domino supports clusters on different platform? i.e. Linux and Windows.&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;Yes, SMD supports cluster on different platform. As long as Domino nodes are clustered, SMD can support it. Take note that Domino is not platform dependent then as well as with Scanmail (SMD). This will only replicate the database. &lt;br /&gt;&lt;br /&gt;More details will be updated soon....Wait up!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2505822716505751707?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2505822716505751707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2505822716505751707' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2505822716505751707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2505822716505751707'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/question-on-scanmail-for-lotus-domino.html' title='Question on ScanMail for Lotus Domino'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-463034504713412769</id><published>2009-06-03T11:15:00.002+08:00</published><updated>2009-06-03T11:19:10.107+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Protect'/><title type='text'>Can SPNT 5.7 Information Server manages SPNT 5.58 Normal server</title><content type='html'>Question:&lt;br /&gt;Can Server Protect 5.7 Information server manages 5.58 Normal server?&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;SPNT 5.7 should manage Normal Server with its same version. If customer's Normal server is 5.58 then they should upgrade it to 5.7 version. SPNT 5.7 version also works with 32-bit platform. You may refer to the &lt;a href="http://www.trendmicro.com/download/product.asp?productid=17"&gt;README&lt;/a&gt;: &lt;br /&gt;&lt;br /&gt;---------------------from read me--------------------------------&lt;br /&gt;What's New &lt;br /&gt;1. Supports both 32-bit and 64-bit operating system platforms &lt;br /&gt;-----------------------------------------------------------------&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-463034504713412769?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/463034504713412769/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=463034504713412769' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/463034504713412769'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/463034504713412769'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/06/can-spnt-57-information-server-manages.html' title='Can SPNT 5.7 Information Server manages SPNT 5.58 Normal server'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6806096983837316400</id><published>2009-05-20T15:32:00.002+08:00</published><updated>2009-05-20T15:43:34.440+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>IDS-SYN flood in the OSCE firewall log</title><content type='html'>Question/Concern/Inquiry:&lt;br /&gt;Hi, I received this OfficeScan logs from my customer asking why there are lots of entries on IDS-SYN flood. How to fix this? Is it because of the machine is infected or not properly patch? Please help to clarify.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-8ljvkq1hYo/ShO0ZcINm6I/AAAAAAAAALs/7t0NqrItsjE/s1600-h/firewallog.bmp"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/ShO0ZcINm6I/AAAAAAAAALs/7t0NqrItsjE/s320/firewallog.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5337808332504538018" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;click for larger image&gt;&lt;br /&gt;Solution/Recommendation:&lt;br /&gt;Two hosts use a SYN FLOOD packet to "shake hands" before establishing a TCP connection. During an attempt to connect, some of the target machine’s resources, such as the memory, may be in use so it does accept the request. &lt;br /&gt;&lt;br /&gt;Some attacks take advantage of this TCP feature to flood the target machine with requests that it cannot process. These are called half-open sessions and is a type of Denial of Service (DoS) attack. The connection count between 172.16.1.13 and 168.168.1.186 exceed the default value 64,and this trigger the &lt;span style="font-weight:bold;"&gt;SYNFLOOD IDS&lt;/span&gt; filter. &lt;br /&gt;&lt;br /&gt;This is a design specification because of the default SynfloodHalpOpen count is set to 64, if the connection count exceed, IDS rules will be trigged. You can check with the administrators of the company to check why it is sending TCP flood connections by using packet capture (wireshark). &lt;br /&gt;&lt;br /&gt;We can also change OSCE Client setting to enlarge the SYNFLOOD halfopen count to workaround: Find the following key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmcfw\Parameters\ IdsSynFloodHalfOpen (DWORD): Default 64 IdsSynFloodSynPerSec (DWORD): Default 4 Change IdsSynFloodHalfOpen to 256 If they still encounter a problem, change IdsSynFloodHalfOpen to 512 &lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6806096983837316400?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6806096983837316400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6806096983837316400' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6806096983837316400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6806096983837316400'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/05/ids-syn-flood-in-osce-firewall-log.html' title='IDS-SYN flood in the OSCE firewall log'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/ShO0ZcINm6I/AAAAAAAAALs/7t0NqrItsjE/s72-c/firewallog.bmp' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5278679147440315638</id><published>2009-05-20T15:14:00.003+08:00</published><updated>2009-05-20T15:22:15.898+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>May Class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-8ljvkq1hYo/ShOuESvlqsI/AAAAAAAAALk/mrbu6AEZ_xM/s1600-h/DSC_1475.jpg"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/ShOuESvlqsI/AAAAAAAAALk/mrbu6AEZ_xM/s320/DSC_1475.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5337801372138318530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The class was conducted from 12-15th May. Quite a big class this time around.&lt;br /&gt;From left is Mr Chung, Anthony,Najib,Faizal,Shahrul,myself,Azrin,Rohaizat and Ganesh.&lt;br /&gt;&lt;br /&gt;Wishing you guys best of luck for the coming exam. ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5278679147440315638?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5278679147440315638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5278679147440315638' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5278679147440315638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5278679147440315638'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/05/may-class.html' title='May Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/ShOuESvlqsI/AAAAAAAAALk/mrbu6AEZ_xM/s72-c/DSC_1475.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6069449791595362487</id><published>2009-05-19T15:23:00.000+08:00</published><updated>2009-05-20T15:30:33.689+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Mail queue issue</title><content type='html'>Question/Concern/Inquiry:&lt;br /&gt;A customer reported his IMSS 7.0 has got problem with the mail queue issue. He started to notice this problem since early last week. The delivery queue could grow up to thousands. REstart the SMTP service will decrease the queue number but after a while it will grow again.&lt;br /&gt;&lt;br /&gt;I notice the following error in System Event log since the date that my customer noticed of the problem.&lt;br /&gt;"April 20, 2009 8:00:10 PM,abcmail,Mail Sender processing folder C:\Program Files\Trend Micro\IMSS\queue\reprocess: Smtp server responded error with:"&lt;br /&gt;&lt;br /&gt;Solution/Recommendation:&lt;br /&gt;Based on your message, you have a queuing issue. This was caused by the DNS, policy and the network connection problem. In the logs; == April 24, 2009 11:42:23 AM,abcmail,Mail Sender processing folder C:\Program Files\Trend Micro\IMSS\queue\reprocess: Smtp server responded error with:&lt;br /&gt;April 24, 2009 11:44:34 AM,abcmail,IMSS Daemon is stopped April 24, 2009 11:45:08 AM,abcmail,IMSS Daemon Service starts running .....&lt;br /&gt;April 24, 2009 11:45:25 AM,abcmail,Mail Sender processing folder C:\Program Files\Trend Micro\IMSS\queue\reprocessbig: Smtp server responded error with: 421 Internal configuration error April 24, 2009 11:45:25 AM,abcmail,Mail Sender processing folder C:\Program Files\Trend Micro\IMSS\queue\reprocess: Smtp server responded error with: 421 Internal configuration error April 24, 2009 11:48:39 AM,abcmail,IMSS Daemon is stopped April 24, 2009 11:48:51 AM,abcmail,IMSS Daemon Service starts running .....&lt;br /&gt;April 24, 2009 11:49:15 AM,abcmail,Mail Sender processing folder C:\Program Files\Trend Micro\IMSS\queue\reprocessbig: Smtp server responded error with: 552 Message exceeds fixed maximum message size ==&lt;br /&gt;&lt;br /&gt;You have a lot of messages queued in \IMSS\queue\reprocess. It only happens when;&lt;br /&gt;* Administrator requested reprocessing of the quarantined mail&lt;br /&gt;* When the action "Change recipient to" is performed&lt;br /&gt;* When the action "Send notifications" is performed and is configured to attach the original mail&lt;br /&gt;&lt;br /&gt;To isolate the issue, do the following:&lt;br /&gt;1. Do you have a policy (for example SPAM policy) which has an action "change recipient"? Do you have also an action of "send notifications"? Or do you have a frequest "reprocess" on the quarantined messages like "resend"?&lt;br /&gt;2. If you have a lot of messages in \IMSS\queue\reprocess folder, do these:&lt;br /&gt;  a. Stop IMSS services&lt;br /&gt;  b. Rename the \IMSS\queue\reprocess folder (for example, reprocess_old) c. Create a new one (for example, reprocess under \IMSS\queue\) and restart the IMSS services&lt;br /&gt;&lt;br /&gt;3. Please try increasing the following values on imss.ini to improve the performance of the scanner:&lt;br /&gt;&lt;br /&gt;=======================&lt;br /&gt;proc_max_worker_proc=25&lt;br /&gt;proc_thread_per_proc=15&lt;br /&gt;=======================&lt;br /&gt;&lt;br /&gt;Save the changes and then restart the IMSS services and see if the problem will still persist.&lt;br /&gt;&lt;br /&gt;4. Please check in tsmtpd.ini and set IdleWaitingSecond to "60". See below:&lt;br /&gt;&lt;br /&gt;FROM&lt;br /&gt;==&lt;br /&gt;# 9.2&lt;br /&gt;# SMTP client session timeout (seconds).&lt;br /&gt;# If server does not respond for timeout period, then close session.&lt;br /&gt;# Recommended maximum = 60 (to avoid wasting time on dead mails) # #IdleWaitingSecond=30 ==&lt;br /&gt;&lt;br /&gt;TO&lt;br /&gt;==&lt;br /&gt;# 9.2&lt;br /&gt;# SMTP client session timeout (seconds).&lt;br /&gt;# If server does not respond for timeout period, then close session.&lt;br /&gt;# Recommended maximum = 60 (to avoid wasting time on dead mails) # IdleWaitingSecond=60 ==&lt;br /&gt;&lt;br /&gt;Save the file and restart IMSS SMTP service&lt;br /&gt;&lt;br /&gt;5. Also, move files under /mque/resend/ to mque/outbox/pool then, a. Restart "Trend Micro IMSS SMTP Service.&lt;br /&gt;b. Observe for few minutes&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6069449791595362487?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6069449791595362487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6069449791595362487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6069449791595362487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6069449791595362487'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/05/mail-queue-issue.html' title='Mail queue issue'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3164836295688081537</id><published>2009-05-18T09:18:00.000+08:00</published><updated>2009-05-20T09:20:40.107+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>OSCE 10 is here!</title><content type='html'>The OfficeScan 10.0 GM build 1068R1 was posted on the Trend Micro website on May 15th as scheduled. This GA build is the same as the one that was uploaded to the Beta FTP server for all Beta participants to download. &lt;br /&gt;&lt;br /&gt;Note: Due to an issue with the original OfficeScan 10.0 GA product package available for download from the Trend site early on May 15th, you may have encountered the following error when trying to install OfficeScan 10.0.&lt;br /&gt;&lt;br /&gt;“Program too big to fit in memory"&lt;br /&gt;&lt;br /&gt;This issue has now been resolved. If you encountered this error please download the current package from the Trend website. &lt;br /&gt;&lt;br /&gt;http://www.trendmicro.com/download/product.asp?productid=5&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3164836295688081537?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3164836295688081537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3164836295688081537' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3164836295688081537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3164836295688081537'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/05/osce-10-is-here.html' title='OSCE 10 is here!'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5629114885995316077</id><published>2009-05-07T14:52:00.003+08:00</published><updated>2009-05-07T15:09:02.887+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Protect'/><title type='text'>Installing Server Protect for EMC Celerra</title><content type='html'>Make sure you read the &lt;a href="http://www.trendmicro.com/ftp/documentation/guides/spemc558gsg.pdf"&gt;Getting Started Guide&lt;/a&gt; and the &lt;a href="http://www.trendmicro.com/ftp/documentation/readme/readme-spemc558.txt"&gt;ReadMe&lt;/a&gt; file.&lt;br /&gt;&lt;br /&gt;Points worth highlighting here will be the preinstallation tasks. Make sure it's ready before you plan for your visit to do the installation.&lt;br /&gt;&lt;br /&gt;1. Make sure the EMC Celerra of supported version&lt;br /&gt;2. AV user Account and Antivirus Group configured&lt;br /&gt;3. CAVA already installed&lt;br /&gt;4. Servers met the specified requirement&lt;br /&gt;&lt;br /&gt;The installation is just the same like the Server Protect for NT. However, make sure the target server is not installed with OfficeScan nor other antivirus software that's doing protection for the server. This is because, it will conflict with Server Protect Normal. Refer to this &lt;a href="http://esupport.trendmicro.com/pages/Can-the-OfficeScan-7.x-server-component-and-ServerProtect-for-Microsof.aspx"&gt;knowledge base&lt;/a&gt;.&lt;br /&gt;If both running, the worst case is neither OSCE nor Server Protect will detect the infection. &lt;br /&gt;&lt;br /&gt;Once installed, you need to test the scanning with the &lt;a href="http://www.eicar.org/download/eicar.com.txt"&gt;Eicar&lt;/a&gt; test file. Try to download the file from the Internet will prompt you that 'access is denied'. That's just the simple notification you will receive. You will need to test the CAVA working or not by copying the test file into the mapped drive at the EMC box. The same error message should appear.&lt;br /&gt;&lt;br /&gt;Verify the infection from the management console at the scan result menu.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5629114885995316077?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5629114885995316077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5629114885995316077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5629114885995316077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5629114885995316077'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/05/installing-server-protect-for-emc.html' title='Installing Server Protect for EMC Celerra'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6949896294551974807</id><published>2009-04-27T10:40:00.000+08:00</published><updated>2009-04-27T10:42:29.738+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>Encountered an error while trying to download certain filev ia IWSVA/IWSS</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SfUbhi-1FTI/AAAAAAAAALc/sQT_Tn27Jhc/s1600-h/iwsserror.bmp"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 115px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SfUbhi-1FTI/AAAAAAAAALc/sQT_Tn27Jhc/s400/iwsserror.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5329195997202814258" /&gt;&lt;/a&gt;&lt;br /&gt;Question/Concern/Inquiry:&lt;br /&gt;Based on your email, you had encountered an error while trying to download certain filev ia IWSVA.&lt;br /&gt;&lt;br /&gt;I had check the screenshot that you had sent and found out that the error occured was caused by popup blocker. Most if the new browser had a built in popup blocker if you were going to look on your Browser the popup to download the file had been blocked.&lt;br /&gt;&lt;br /&gt;To resolve this issue you can do the following;&lt;br /&gt;&lt;br /&gt;1. Log in to your IWSVA.&lt;br /&gt;2. Click HTTP&gt;HTTP SCAN&gt;Policies&lt;br /&gt;3. At the right pane click the Virus Scan Global Policy 4. Click the Virus Scan Rule tab.&lt;br /&gt;5. Under Large File Hnadling Choose Deffered Scanning.&lt;br /&gt;6. Click Save.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6949896294551974807?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6949896294551974807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6949896294551974807' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6949896294551974807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6949896294551974807'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/encountered-error-while-trying-to.html' title='Encountered an error while trying to download certain filev ia IWSVA/IWSS'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SfUbhi-1FTI/AAAAAAAAALc/sQT_Tn27Jhc/s72-c/iwsserror.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1889565933961391595</id><published>2009-04-23T09:57:00.002+08:00</published><updated>2009-04-23T10:04:06.183+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NVW'/><title type='text'>Network Viruswall to exclude mobile device from assessment</title><content type='html'>Question:&lt;br /&gt;Saril of NRE asked me on how to exclude mobile devices from assessment by Network Viruswall.&lt;br /&gt;&lt;br /&gt;Answer:&lt;br /&gt;To exclude smart phones/PDA from being assessed by Network Viruswall you can either;&lt;br /&gt;&lt;br /&gt;1. Add in the smart phones/PDA IP address or MAC Address in the Global Exception List&lt;br /&gt;2. Tick option to "Disable endpoint detection for non-windows Operating Systems" in the Network Viruswall console &gt; Policy Enforcement &gt; Policies.&lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1889565933961391595?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1889565933961391595/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1889565933961391595' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1889565933961391595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1889565933961391595'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/network-viruswall-to-exclude-mobile.html' title='Network Viruswall to exclude mobile device from assessment'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4002234749717201663</id><published>2009-04-23T09:37:00.002+08:00</published><updated>2009-04-23T09:55:20.509+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NVW'/><title type='text'>Manually delete PEAgent for Network Viruswall</title><content type='html'>Question/Concern/Inquiry:&lt;br /&gt;Based on your message, you moved the NVWe and would like to re-deploy the PE agent. During uninstallation of PE Agent at vista machine, you encounter the following error whenever try to remove the PE Agent via Add/Remove Program .."..another installation is in progress.." If we try to use self installer i.e. peagent_config.exe we will receive the same error too.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Solution/Recommendation:&lt;br /&gt;&lt;br /&gt;Please follow the steps below to manually uninstall the PE Agent to these machine:&lt;br /&gt;&lt;br /&gt;1. On System Tray, right click PEAgent icon, then click "Uninstall Real-Time Scan".&lt;br /&gt;2. Right click PEAgent icon, then click Exit.&lt;br /&gt;3. Run command "\%WinDir%\PEAgent\PEAgent.exe /delete".&lt;br /&gt;4. Delete the folder \%WinDir%\PEAgent.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4002234749717201663?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4002234749717201663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4002234749717201663' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4002234749717201663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4002234749717201663'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/manually-delete-peagent-for-network.html' title='Manually delete PEAgent for Network Viruswall'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1443566373604997146</id><published>2009-04-13T10:14:00.003+08:00</published><updated>2009-04-13T10:17:47.774+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>April Class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-8ljvkq1hYo/SeKgSm-OpTI/AAAAAAAAALU/brx2IlKa7d4/s1600-h/DSC_1052.jpg"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 268px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/SeKgSm-OpTI/AAAAAAAAALU/brx2IlKa7d4/s400/DSC_1052.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5323993951064991026" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This month class was conducted from 7th to 10th April. Three participants ; Henny from HP Singapore, Fariz from Felda Prodata and Azizan from Sapura Synergy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1443566373604997146?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1443566373604997146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1443566373604997146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1443566373604997146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1443566373604997146'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/april-class.html' title='April Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-8ljvkq1hYo/SeKgSm-OpTI/AAAAAAAAALU/brx2IlKa7d4/s72-c/DSC_1052.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8668202201877390453</id><published>2009-04-10T17:48:00.003+08:00</published><updated>2009-04-10T17:50:51.284+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>[Trend Micro Advisory] NEW WORM_DOWNAD.E/Conficker Variant</title><content type='html'>NEW WORM_DOWNAD.E/Conficker Variant&lt;br /&gt; 04/09/2009 &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This is a pro-active notification that Trend Micro received a new sample of DOWNAD and named it as WORM_DOWNAD.E Trend Micro has flagged this worm as noteworthy due to the increased potential for damage, and propagation. Including its ability to propagate via the Server service vulnerability. &lt;br /&gt;&lt;br /&gt;Please visit Trend Micro’s DOWNAD Information page for the latest information:&lt;br /&gt;http://us.trendmicro.com/us/threats/conficker-worm/ &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Arrival&lt;/strong&gt;&lt;br /&gt;This worm may be downloaded unknowingly by a user when visiting malicious Web sites.&lt;br /&gt;&lt;br /&gt;This worm executes only after meeting any of the following trigger condition: &lt;br /&gt;Any day before May 3, 2009&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Propagation Routine&lt;/strong&gt;&lt;br /&gt;This worm propagates by taking advantage of a vulnerability discovered in certain Microsoft operating systems that could allow remote code execution if an affected system received a specially crafted RPC request, which also contains a shellcode. &lt;br /&gt;&lt;br /&gt;This worm also attempts to propagate via the same vulnerability through the internet using external IP addresses by checking if the system is directly connected to the internet. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Other Details&lt;/strong&gt;&lt;br /&gt;This worm creates the temporary file in %System%/0{Random}.tmp which is a SYS file and is detected by Trend Micro as TROJ_DOWNAD.E. It then creates a service using this temporary file, thus the malicious routines of this malware are also exhibited in the system. After creating the service, the temporary file is deleted.&lt;br /&gt;&lt;br /&gt;It then patches %System%\drivers\tcpip.sys in memory to modify the limitation of TCP maximum half-connection attempts number. After doing this, the created driver service is unloaded and deleted, leaving no trace in the registry.&lt;br /&gt;&lt;br /&gt;It creates a thread that opens a random port to communicate with a remote computer. This worm also creates the following mutex “Global\{Random}” to ensure that only one instance of itself is running in memory: &lt;br /&gt;&lt;br /&gt;_________________________________________________________________________________&lt;br /&gt;&lt;br /&gt;Trend Micro Solutions&lt;br /&gt;·VSAPI Pattern - Since OPR 5.953.00&lt;br /&gt;·Intellitrap pattern - detected as PAK_Generic.001&lt;br /&gt;·Damage Cleanup Template   -  DCT OPR 1026&lt;br /&gt;_________________________________________________________________________________&lt;br /&gt;&lt;br /&gt;DOWNAD/Conficker Best Practices&lt;br /&gt;1. Patch Windows systems with the MS08-067  &lt;br /&gt;2. Verify OfficeScan Client Edition is up to date and proper sttings&lt;br /&gt;http://esupport.trendmicro.com/pages/How-to-configure-Trend-Micro-products-for-best-protection-against-malw.aspx &lt;br /&gt;3. Follow recommended solutions and protection&lt;br /&gt;&lt;br /&gt;http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=Sn &lt;br /&gt;_________________________________________________________________________________&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8668202201877390453?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8668202201877390453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8668202201877390453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8668202201877390453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8668202201877390453'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/trend-micro-advisory-new.html' title='[Trend Micro Advisory] NEW WORM_DOWNAD.E/Conficker Variant'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3334542471467755885</id><published>2009-04-08T16:58:00.003+08:00</published><updated>2009-04-08T17:00:42.909+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Protect'/><title type='text'>SPNT 5.7 is not for Windows 2003 server 32 bit</title><content type='html'>Your concern as spoken over the phone as follows:&lt;br /&gt;ServerProtect 5.58 installed on Windows 2003 server has problem to update with the latest component (scan engine and pattern file). It’s a fresh installation and you faced this problem since last week.&lt;br /&gt;&lt;br /&gt;Information required:&lt;br /&gt;&lt;br /&gt;Please forward to me tmudump.txt file (you can perform a search in C:\Program Files\Trend\Sprotect folder) &lt;br /&gt;Screen shot of the error message (I’ve record down in text, however if I need to escalate this to Trend Support a screen shot will help) &lt;br /&gt;Have you installed the latest patch for your ServerProtect 5.58? http://www.trendmicro.com/ftp/products/patches/spnt_558_win_en_patch7.exe &lt;br /&gt;Screen shot of the update page screen. ( I want to see the current component version) &lt;br /&gt;Please forward to me server.ini file from spntshare directory. &lt;br /&gt;&lt;br /&gt;Feedback from customer:&lt;br /&gt;She actually installed SPNT 5.7 on Windows 2003 32 bit. I asked her to remove SPNT 5.7 and install SPNT 5.58 instead. That solved the problem not able to update the scan engine and pattern file.&lt;br /&gt;&lt;br /&gt;Another case is solved.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3334542471467755885?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3334542471467755885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3334542471467755885' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3334542471467755885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3334542471467755885'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/spnt-57-is-not-for-windows-2003-server.html' title='SPNT 5.7 is not for Windows 2003 server 32 bit'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3403094111156808214</id><published>2009-04-07T16:00:00.000+08:00</published><updated>2009-04-08T17:05:45.983+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>Removing spyware from "exclusion list" in your IWSS</title><content type='html'>If you add spyware into the exclusion list, it will no longer detected as spyware the next time around. Until you remove the entry from SPYWAREEXCEPTIONLIST.INI by default located in your IWSS installation folder.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3403094111156808214?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3403094111156808214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3403094111156808214' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3403094111156808214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3403094111156808214'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/removing-spyware-from-exclusion-list-in.html' title='Removing spyware from &quot;exclusion list&quot; in your IWSS'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-59981000037951720</id><published>2009-04-06T14:03:00.001+08:00</published><updated>2009-04-06T14:04:41.925+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>very simple test that's available at the Conficker Working Group's site.</title><content type='html'>Do you want to check if you are infected with Conficker or Downad worm family? Verify from this test site &lt;a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html"&gt;Conficker Eye Chart&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-59981000037951720?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/59981000037951720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=59981000037951720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/59981000037951720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/59981000037951720'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/very-simple-test-thats-available-at.html' title='very simple test that&apos;s available at the Conficker Working Group&apos;s site.'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-676692252646512710</id><published>2009-04-06T10:30:00.003+08:00</published><updated>2009-04-06T10:44:35.748+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>TMCM 3.5 security logs</title><content type='html'>Concern&lt;br /&gt;+++++++++&lt;br /&gt;Hello, I have customer asking me why at his TMCM, he can see the result for unsuccessful entry. Whereas, when he digged the OSCE log for the day there was nothing related being found, Further looking at the TMCM log, it is found that the time the log was generated at entity was back 8 months. Whereas the time received from entity show yesterday date. My question is why it is taking long time for the OSCE to send the logs to TMCM? Please explain in what condition that this things happen. How to remedy. I will attach together tmcm and officescan log for yesterday. If you look at the Tmcm log, look at the first and second column. Some are of the same day differs only 1 hour which is acceptable. but some are few months different. Should you need more info, please let me know.&lt;br /&gt;&lt;br /&gt;Suggested solution&lt;br /&gt;+++++++++++++++++++++&lt;br /&gt;"Generated at entity" means that the information log was generated at the OfficeScan. "Received from entity" means the the information log was received by Control Manager. From the log, it showed that OfficeScan generated the log on 6/9/2008 and was uploaded to Control Manager on 2/4/2009. There are several reasons for this kind of issue. Below are the possible reason: &lt;br /&gt;&lt;br /&gt;1. TMCM purged already the logs (depending on Purge settings) but the particular log is still on OfficeScan. &lt;br /&gt;2. The log was queued on OfficeScan. &lt;br /&gt;3. OfficeScan was offline during that time. &lt;br /&gt;&lt;br /&gt;We can adjust the polling of logs from Agent.ini file. Agent.ini normally located in ..OfficeScan\PCCSRV\CmAgent\ &lt;br /&gt;&lt;br /&gt;More details on parameter to edit, I'd recommend you submit to Trend Portal. Anyway the number indicated in agent.ini is in seconds.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-676692252646512710?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/676692252646512710/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=676692252646512710' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/676692252646512710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/676692252646512710'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/04/tmcm-35-security-logs.html' title='TMCM 3.5 security logs'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6145147181635583603</id><published>2009-03-31T12:09:00.002+08:00</published><updated>2009-04-06T10:45:14.324+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Backup your OSCE configuration before reinstallation or upgrade</title><content type='html'>Let say you need to remove your current OSCE server and perform a fresh install. What files to backup?&lt;br /&gt;&lt;br /&gt;1. HTTPDB folder&lt;br /&gt;2. PFW folder if you enable the firewall&lt;br /&gt;3. ofcscan.ini&lt;br /&gt;&lt;br /&gt;Make sure when you go through the wizard, you retain the older configuration of server client 5 digits communication port, web server configuration whether by IP address or hostname and the port number of the web server i.e. 8080, 80.&lt;br /&gt;&lt;br /&gt;I hope it helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6145147181635583603?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6145147181635583603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6145147181635583603' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6145147181635583603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6145147181635583603'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/03/backup-your-osce-configuration-before.html' title='Backup your OSCE configuration before reinstallation or upgrade'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3966207762584490293</id><published>2009-03-26T17:02:00.000+08:00</published><updated>2009-03-26T17:03:10.156+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>Squid cache on IWSVA 3.1</title><content type='html'>The default size limit of the entire cache is 588 MB (this is defined in the cache_dir parameter). The objects in the cache will be considered STALE after the following time:&lt;br /&gt;&lt;br /&gt;FTP – 10080 minutes or 7 days&lt;br /&gt;HTTP – 4320 minutes or 3 days&lt;br /&gt;&lt;br /&gt;This is defined by the refresh_pattern parameter. Refer to the squid.conf file for further details.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3966207762584490293?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3966207762584490293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3966207762584490293' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3966207762584490293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3966207762584490293'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/03/squid-cache-on-iwsva-31.html' title='Squid cache on IWSVA 3.1'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-4468435103053865990</id><published>2009-03-25T16:54:00.001+08:00</published><updated>2009-03-25T16:57:22.735+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><title type='text'>URL cache for IWSS/IWSVA3.1</title><content type='html'>IWSS/IWSVA 3.1 includes Web Reputation feature. This feature relies on DNS queries to Trend Micro data centers for each new URL request. Reputations are cached for a period of &lt;strong&gt;35 minutes &lt;/strong&gt;by default and new reputation requests for that URL are provided without the need for additional queries.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-4468435103053865990?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/4468435103053865990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=4468435103053865990' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4468435103053865990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/4468435103053865990'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/03/url-cache-for-iwssiwsva31.html' title='URL cache for IWSS/IWSVA3.1'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-501915511356169005</id><published>2009-03-23T10:32:00.004+08:00</published><updated>2009-04-06T10:45:43.884+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>March 2009 Class</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_-8ljvkq1hYo/Scb0_49O9uI/AAAAAAAAALM/Gjxcsm4bsyE/s1600-h/tcseMARCH.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 268px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/Scb0_49O9uI/AAAAAAAAALM/Gjxcsm4bsyE/s400/tcseMARCH.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316205788615603938" /&gt;&lt;/a&gt;&lt;br /&gt;From left is Ikhwal, Son, Dung, Sha, Hartini and Suhaini.&lt;br /&gt;Dung and Son from VietInBank. Ikhwal from one of the local partner. Hartini and Suhaini from TelBru.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-501915511356169005?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/501915511356169005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=501915511356169005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/501915511356169005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/501915511356169005'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/03/march-2009-class.html' title='March 2009 Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-8ljvkq1hYo/Scb0_49O9uI/AAAAAAAAALM/Gjxcsm4bsyE/s72-c/tcseMARCH.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-17629135572152082</id><published>2009-03-23T10:30:00.001+08:00</published><updated>2009-04-06T10:46:38.266+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>[Malware Advisory] WORM_Downad.KK - Activates on April Fool's Day</title><content type='html'>Dear All,&lt;br /&gt;&lt;br /&gt;We would like to inform you that we have received new updates from our Global Update Center.&lt;br /&gt;&lt;br /&gt;Topic: WORM_Downad.KK – Activates on April Fool’s Day&lt;br /&gt;&lt;br /&gt;Advisory Release Date: March 18, 2009&lt;br /&gt;&lt;br /&gt;Details&lt;br /&gt;&lt;br /&gt;Worm_downad had infected more than 15 million computers, making it one of the widespread infections in recent times.&lt;br /&gt;&lt;br /&gt;A new variant of worm_downad (aka Conficker) is expected to be launched on April Fool’s day.&lt;br /&gt;&lt;br /&gt;Trend Micro detects this new variant as worm_downad.kk. More information can be found at http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOWNAD.KK&amp;VSect=T. Trend Micro detects this malware starting with pattern file 5.885.00. &lt;br /&gt;&lt;br /&gt;Compared to the old variants, worm_downad.kk is more sophisticated. Here are a few of the payloads :&lt;br /&gt;&lt;br /&gt;·        Connects to various time servers to determine the current date and time. &lt;br /&gt;&lt;br /&gt;·        Register itself as a system service to ensure auto execution every startup. &lt;br /&gt;&lt;br /&gt;·        Deletes a registry key to prevent system startup in safe mode. &lt;br /&gt;&lt;br /&gt;·        Terminates security-related processes (i.e. procexp, regmon, autoruns, gmer etc.) &lt;br /&gt;&lt;br /&gt;·        Blocks access to security and antivirus websites. &lt;br /&gt;&lt;br /&gt;·        Generates 50,000 malicious URLs and attempts to connect to around 500 random generated URLs at a time. &lt;br /&gt;&lt;br /&gt;_______________________________________________________________________&lt;br /&gt;&lt;br /&gt;Recommended Action&lt;br /&gt;&lt;br /&gt;·        Enable Web Reputation Service &lt;br /&gt;&lt;br /&gt;·        Make sure that you have the latest virus definitions (at least pattern file 5.885.00) &lt;br /&gt;&lt;br /&gt;·        Run a FULL system scan to ensure that malware does not exist on your PC &lt;br /&gt;&lt;br /&gt;·        Apply MS 08-067&lt;br /&gt;&lt;br /&gt;·        Ensure strong password practice&lt;br /&gt;&lt;br /&gt;·        Disable autorun.inf for removeable devices&lt;br /&gt;&lt;br /&gt;·        For file sharing server, don’t share to everyone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-17629135572152082?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/17629135572152082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=17629135572152082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/17629135572152082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/17629135572152082'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/03/malware-advisory-wormdownadkk-activates.html' title='[Malware Advisory] WORM_Downad.KK - Activates on April Fool&apos;s Day'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-1632747009764599674</id><published>2009-02-25T17:14:00.002+08:00</published><updated>2009-04-06T10:46:23.262+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Protect'/><title type='text'>Server Protect NT Normal Server</title><content type='html'>Checklist for SPNT normal server installation:&lt;br /&gt;&lt;br /&gt;1. log in as administrator&lt;br /&gt;2. Verify if the target drive/directory is administrative shared from windows explorer \\servername\c$ try to create a text file. If allowed means we are okay to do the installation &lt;br /&gt;3. From Windows services (services.msc) verify that Remote Procedure Call (RPC) service and Remote Registry Services are started ; startup type automatically &lt;br /&gt;4. If the servers are hardened, please verify with the server owner/vendor with the problem that you face. By right, if you comply to #1-3 you should be able to install SPNT normal server successfully!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-1632747009764599674?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/1632747009764599674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=1632747009764599674' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1632747009764599674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/1632747009764599674'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/server-protect-nt-normal-server.html' title='Server Protect NT Normal Server'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-901765916196015917</id><published>2009-02-16T12:52:00.003+08:00</published><updated>2009-04-06T10:45:14.325+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Image Setup utility is not supported on Vista</title><content type='html'>When creating image, you can use the Image Setup Utility (imgsetup.exe). The Image Setup Utility helps you use the hard drive imaging technology to deploy the client. Run this tool after OSCE client is installed on the image and before the copies of the image is made. It will ask the OfficeScan client to regenerate a GUID once the image is loaded on new machines.&lt;br /&gt;&lt;br /&gt;In OfficeScan 8.0, the GUID is checked upon registration. Duplicate GUIDs are listed in the \pccsrv\chkguid.log file. Client listed in this file has a duplicate GUID. To force a client to generate a new one, you need to run Verify Connection from the management console. A scheduled Verify Connection may be set up to run once a day. Result of this Verify connection task can be found in \pccsrv\verconn.log file.&lt;br /&gt;&lt;br /&gt;This utility is however not supported on Vista&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-901765916196015917?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/901765916196015917/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=901765916196015917' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/901765916196015917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/901765916196015917'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/image-setup-utility-is-not-supported-on.html' title='Image Setup utility is not supported on Vista'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7523113876857172467</id><published>2009-02-12T17:58:00.005+08:00</published><updated>2009-04-06T10:46:58.681+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><title type='text'>Interpreting the X-header</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-8ljvkq1hYo/SZPzmwU0VgI/AAAAAAAAALE/Lqz0aFSsTcg/s1600-h/x-header.bmp"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 41px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/SZPzmwU0VgI/AAAAAAAAALE/Lqz0aFSsTcg/s400/x-header.bmp" alt="" id="BLOGGER_PHOTO_ID_5301849033478002178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What does the X-header means?&lt;br /&gt;++++++++++++++++++++++++&lt;br /&gt;&lt;br /&gt;The first line detailing the product in used which is IMSS version 7 and the spam pattern information as highlighted in green color.&lt;br /&gt;&lt;br /&gt;The second line indicates the spam score for the message is 12.814 whereas the detection threshold is 6.0. The value ‘1’ indicates it is detected as a spam.&lt;br /&gt;&lt;br /&gt;Report false-positives?&lt;br /&gt;+++++++++++++++++&lt;br /&gt;&lt;br /&gt;This can be done by following the steps below:&lt;br /&gt;a. Save the original copies of the spam emails received in *.msg or *.eml format.&lt;br /&gt;b. Put all the samples in a folder and compress/zip it with a password (example: novirus).&lt;br /&gt;c. Send the message to the following email addresses:&lt;br /&gt;&lt;br /&gt;Address false-positives to: false[at]support.trendmicro.com.&lt;br /&gt;&lt;br /&gt;Address false-negatives to: spam[at]support.trendmicro.com.&lt;br /&gt;&lt;br /&gt;Trend Micro Anti-spam engineer will fine tune their processes to avoid such incident from happening again.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7523113876857172467?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7523113876857172467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7523113876857172467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7523113876857172467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7523113876857172467'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/interpreting-x-header.html' title='Interpreting the X-header'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-8ljvkq1hYo/SZPzmwU0VgI/AAAAAAAAALE/Lqz0aFSsTcg/s72-c/x-header.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6279011637014186426</id><published>2009-02-10T09:41:00.003+08:00</published><updated>2009-04-06T10:47:13.340+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>Malware Advisory - [PE_VIRUX.A AWARENESS]</title><content type='html'>PE_VIRUX.A is a polymorphic file infector capable of infecting .exe and .scr files. This file infector may be downloaded unknowingly by a user when visiting malicious Web sites.&lt;br /&gt;&lt;br /&gt;For more information about this malware, please see the following link:&lt;br /&gt;&lt;br /&gt;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_VIRUX.A&lt;br /&gt;&lt;br /&gt;Solutions available:&lt;br /&gt;I. Trend Micro strongly recommends updating your pattern file to the latest OPR (Official Pattern Release).  OPR 5.821.00 already includes detection for PE_VIRUX.A.&lt;br /&gt;&lt;br /&gt;II. If in case your network is already experiencing infections from this malware, the following product settings are recommended:&lt;br /&gt;&lt;br /&gt;1. Set first product action to clean&lt;br /&gt;&lt;br /&gt;2. Set second product action to pass&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;note: Use a specific action for each virus/malware type&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can consider applying the preventive measures below:&lt;br /&gt;&lt;br /&gt;a. Download from trusted sites or sources only. Unknown sites will possibly direct the user’s browser to malicious websites to download scripts or executables that can infect machines.&lt;br /&gt;&lt;br /&gt;b. Make sure that downloaded or copied files are scanned by Trend Micro antivirus first before executing them.&lt;br /&gt;&lt;br /&gt;c. Ensure that OfficeScan Web Reputation Services is enabled and the security level is configured as “Medium”.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6279011637014186426?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6279011637014186426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6279011637014186426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6279011637014186426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6279011637014186426'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/malware-advisory-peviruxa-awareness.html' title='Malware Advisory - [PE_VIRUX.A AWARENESS]'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2162247355354360964</id><published>2009-02-06T11:43:00.002+08:00</published><updated>2009-04-06T11:03:03.847+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Bypass server checking for OSCE client packager</title><content type='html'>You might want to add in this parameter before creating the client packager if you want to execute the client packager off the corporate network where there is no connection back to the OfficeScan server. The impact if you don't have this parameter, your installation may stall or fail for the client packager installation keeps trying to check the OSCE server and failed to connect.&lt;br /&gt;&lt;br /&gt;Edit the following file.&lt;br /&gt;&lt;br /&gt;1. Open the ofcscan.ini file on the OfficeScan server (..\PCCSRV\ofcscan.ini)&lt;br /&gt;2. Under the header INI_CLIENT_SETUP_SECTION, add the BypassServerChecking=1 parameter.&lt;br /&gt;3. Save and close the file.&lt;br /&gt;4. Recreate the Client Packager setup file and deploy this to the clients.&lt;br /&gt;&lt;br /&gt;Hope it helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2162247355354360964?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2162247355354360964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2162247355354360964' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2162247355354360964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2162247355354360964'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/bypass-server-checking-for-osce-client.html' title='Bypass server checking for OSCE client packager'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-15878177180411762</id><published>2009-02-06T10:38:00.003+08:00</published><updated>2009-04-06T11:03:16.642+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Tool - autorun eater</title><content type='html'>&lt;span id="intelliTxt"&gt;Din and Hafizi shared with me about this tool that they deployed to their end users to avoid problem with the worm spreading via thumb drives.&lt;br /&gt;&lt;br /&gt;The tool is called &lt;a href="http://www.softpedia.com/get/Security/Secure-cleaning/Autorun-Eater.shtml"&gt;Autorun Eater.&lt;/a&gt; It will remove any suspicious 'autorun.inf' files even before the user attempts to access the drive. These files are auto-backup'ed in case of false positives. If you have OfficeScan already installed, it can work hand in hand. OfficeScan will detect the autorun.inf if only user access the drive. So, when you have autorun eater it is a proactive step.&lt;br /&gt;&lt;br /&gt;note: The tool produces a goat sound effect upon starting. You might want to turn off the volume.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-15878177180411762?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/15878177180411762/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=15878177180411762' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/15878177180411762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/15878177180411762'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/tool-autorun-eater.html' title='Tool - autorun eater'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5514803614275678963</id><published>2009-01-30T10:35:00.000+08:00</published><updated>2009-04-06T10:49:23.443+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>January class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-8ljvkq1hYo/SYuiFejDGwI/AAAAAAAAAK8/saQtnOD9Dik/s1600-h/jantcse.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 229px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/SYuiFejDGwI/AAAAAAAAAK8/saQtnOD9Dik/s320/jantcse.jpg" alt="" id="BLOGGER_PHOTO_ID_5299507601514633986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hafizi and Din from MOHA. Hopefully to see you both come here and sit for the TCSE exam! Good Luck. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5514803614275678963?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5514803614275678963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5514803614275678963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5514803614275678963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5514803614275678963'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/01/january-class.html' title='January class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-8ljvkq1hYo/SYuiFejDGwI/AAAAAAAAAK8/saQtnOD9Dik/s72-c/jantcse.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6080914249182425505</id><published>2009-01-23T09:13:00.003+08:00</published><updated>2009-04-06T10:51:39.770+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSCE'/><title type='text'>Analyzing your OSCE virus log for worm_downad</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SXkboqLJMpI/AAAAAAAAAKk/5WVKTmNGYGU/s1600-h/viruslog.bmp"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 80px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SXkboqLJMpI/AAAAAAAAAKk/5WVKTmNGYGU/s400/viruslog.bmp" alt="" id="BLOGGER_PHOTO_ID_5294293222280475282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Click for larger image&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you look at your OSCE virus log and found 'x' under column Infected file. That indicates the machine has not been patched with MS08-067.&lt;br /&gt;&lt;br /&gt;Further explanation:&lt;br /&gt;&lt;br /&gt;"If there is WORM_DOWNAD detection in IE temp folder + WORM_DOWAD detection in system folder for the file named x and real time scan able to delete the file means that malware is Propagatng via MS08‐067 and machines are still not patched with MS08‐067."&lt;br /&gt;&lt;br /&gt;Do you still fighting against this worm? Good Luck! I hope this information helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6080914249182425505?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6080914249182425505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6080914249182425505' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6080914249182425505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6080914249182425505'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/01/analyzing-your-osce-virus-log-for.html' title='Analyzing your OSCE virus log for worm_downad'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SXkboqLJMpI/AAAAAAAAAKk/5WVKTmNGYGU/s72-c/viruslog.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7082607296641295398</id><published>2009-01-15T15:04:00.000+08:00</published><updated>2009-04-06T10:49:23.443+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>January Class in Brunei</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_-8ljvkq1hYo/SYabeD80WqI/AAAAAAAAAK0/_P282VHwh2g/s1600-h/bruneiTCSE.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5298092952406743714" style="margin: 0px 10px 10px 0px; float: left; width: 320px; height: 214px;" alt="" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/SYabeD80WqI/AAAAAAAAAK0/_P282VHwh2g/s320/bruneiTCSE.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SYabePyiBhI/AAAAAAAAAKs/zBmZNea4JMY/s1600-h/BruneiTCSE2.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5298092955584824850" style="margin: 0px 10px 10px 0px; float: left; width: 320px; height: 214px;" alt="" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SYabePyiBhI/AAAAAAAAAKs/zBmZNea4JMY/s320/BruneiTCSE2.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Thanks to Syafiq for the photos. Yeah, you should apologize for the delay in sending me the photos! :-) Anyway, I had a fun time teaching all of you though I had to talk non-stop to finish up the syllabus in time. &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Good Luck for exams! Tell me the good news only. By the way, they are from Ministry of Foreign Affairs and Trade.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7082607296641295398?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7082607296641295398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7082607296641295398' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7082607296641295398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7082607296641295398'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/02/january-class-in-brunei.html' title='January Class in Brunei'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-8ljvkq1hYo/SYabeD80WqI/AAAAAAAAAK0/_P282VHwh2g/s72-c/bruneiTCSE.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7799383666354696443</id><published>2009-01-15T11:51:00.004+08:00</published><updated>2009-04-06T10:52:18.449+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>Installing MS SQL 2005 Express on other drives.</title><content type='html'>Let say this is for Trend Micro Control Manager 5.0. When you run the installation, you will have to choose the database selection. If you choose &lt;strong&gt;"Install Microsoft SQL Express",&lt;/strong&gt; the only thing that you can specify is the SA password. You can't choose the installation path for your database, hence the database will be installed to C:\ following the TMCM installation. &lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;If you need to install the database component on D drive for example, I would suggest that you run installation for MS SQL Express seperately. Look for SQLEXPR.exe from TMCM installation folder. You will go through the installation wizard. When you come to this screen, select Browse button to browse for the target installation path.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SW65iuSwODI/AAAAAAAAAJo/SDLMCGJaJE4/s1600-h/sqlExpress1.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5291370618400290866" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 295px" alt="" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SW65iuSwODI/AAAAAAAAAJo/SDLMCGJaJE4/s320/sqlExpress1.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_-8ljvkq1hYo/SW65it3XdXI/AAAAAAAAAJw/mpBRovOoIUw/s1600-h/sqlExpress2.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5291370618285421938" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 295px" alt="" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/SW65it3XdXI/AAAAAAAAAJw/mpBRovOoIUw/s320/sqlExpress2.JPG" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7799383666354696443?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7799383666354696443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7799383666354696443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7799383666354696443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7799383666354696443'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/01/installing-ms-sql-2005-express-on-other.html' title='Installing MS SQL 2005 Express on other drives.'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SW65iuSwODI/AAAAAAAAAJo/SDLMCGJaJE4/s72-c/sqlExpress1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5789330957882165380</id><published>2009-01-15T10:33:00.005+08:00</published><updated>2009-04-06T11:03:16.642+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Using GMER to detect rootkit malware</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_-8ljvkq1hYo/SW6llyEgXXI/AAAAAAAAAJg/iYyOspT2yeo/s1600-h/rootk.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5291348680721325426" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 270px" alt="" src="http://4.bp.blogspot.com/_-8ljvkq1hYo/SW6llyEgXXI/AAAAAAAAAJg/iYyOspT2yeo/s320/rootk.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;a href="http://www.gmer.net/files.php"&gt;GMER&lt;/a&gt; is a free tool which you can use to detect rootkit malware. DownAD is one of it. If you suspect that your machine is infected with a rootkit, you may want to run GMER. Item highlighted in red are the identified rootkit malware.&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;From the identification, you can do proper cleanup. Once done, you may need to rerun GMER to verify that the rootkit has been successfully removed.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5789330957882165380?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5789330957882165380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5789330957882165380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5789330957882165380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5789330957882165380'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/01/using-gmer-to-detect-rootkit-malware.html' title='Using GMER to detect rootkit malware'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-8ljvkq1hYo/SW6llyEgXXI/AAAAAAAAAJg/iYyOspT2yeo/s72-c/rootk.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7067790085216955855</id><published>2009-01-13T09:47:00.002+08:00</published><updated>2009-01-13T09:53:46.353+08:00</updated><title type='text'>Best Practice -  How to clean Worm_Downad.AD with OfficeScan</title><content type='html'>&lt;span style="color:#000000;"&gt;Trend Micro has seen an increase of Worm_Downad.AD infection or its variants.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;"&gt;Symptom&lt;br /&gt;· Users cannot login using their windows credentials because it is locked out&lt;br /&gt;· Increase traffic at port 445&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;"&gt;The following components are needed in order to completely clean the infected machines:&lt;br /&gt;·         Latest virus pattern file (lpt$vpn.xxx)&lt;br /&gt;·         Rootkit Common Module (RCM) 2.2.1016&lt;br /&gt;·         GeneriClean Technology&lt;br /&gt;·         Damage Cleanup Template (DCT) 1002&lt;br /&gt;·         Damage Cleanup Engine (DCE) &lt;a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/DCEv6.0.1169.zip"&gt;6.0.1169&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="color:#000000;"&gt;·         Scan engine (VSAPI) &lt;a href="http://www.trendmicro.com/download/engine.asp"&gt;8.911&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#000000;"&gt;·         Microsoft 08-67 patch&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;"&gt;&lt;strong&gt;Recommended Action&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;em&gt;Using OfficeScan (OSCE) 8.0&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/u&gt;1.  Apply MS08-67 patch -- &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx&lt;/a&gt;&lt;br /&gt;2.  Update now to ensure you have the latest components&lt;br /&gt;3.  Deploy the latest Damage Cleanup Engine (DCE) 6.0.1169 via OSCE server.  DCE 6.0.1169 can be downloaded at &lt;a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/DCEv6.0.1169.zip"&gt;http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/DCEv6.0.1169.zip&lt;/a&gt; &lt;br /&gt;Visit KB article for details -- &lt;a href="http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-124134"&gt;http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-124134&lt;/a&gt;&lt;br /&gt;4.  If VSAPI 8.911 is not yet uploaded to AU, apply VSAPI 8.911 to the OSCE server.  You can download the files at &lt;a href="http://www.trendmicro.com/download/engine.asp#prod_5"&gt;http://www.trendmicro.com/download/engine.asp#prod_5&lt;/a&gt;&lt;br /&gt;Visit KB article for details -- &lt;a href="http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-122633"&gt;http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-122633&lt;/a&gt;&lt;br /&gt;5.  Once all the update components are up-to-date, invoke a “scan now” from the OSCE server&lt;br /&gt;6.  Machines that are infected with Worm_Downad.AD or its variants requires a reboot to completely clean the machine.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;em&gt;Using OfficeScan (OSCE) 7.x&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;1.  Apply MS08-67 patch -- &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx&lt;/a&gt;&lt;br /&gt;2.  Update now to ensure you have the latest components&lt;br /&gt;3.  Deploy the latest Damage Cleanup Engine (DCE) 6.0.1169 via OSCE server.  DCE 6.0.1169 can be downloaded at &lt;a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/DCEv6.0.1169.zip"&gt;http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/DCEv6.0.1169.zip&lt;/a&gt; &lt;br /&gt;Visit KB article for details -- &lt;a href="http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-124134"&gt;http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-124134&lt;/a&gt;&lt;br /&gt;4.  Install Rootkit Common Module on each OSCE 7.x clients&lt;br /&gt;         a.  download the file (DTtool.zip) at FTP site&lt;br /&gt;         b.  extract and copy these files to the windows\system32\drivers folder&lt;br /&gt;                      Dttool.exe&lt;br /&gt;                      Tmcomm.inf&lt;br /&gt;                      Tmcomm.sys&lt;br /&gt;                      Tmengdrv.dll&lt;br /&gt;         c.  open command prompt and go to windows\system32\drivers and run&lt;br /&gt;                      Dttool.exe install&lt;br /&gt;                      Dttool.exe start&lt;br /&gt;5.  If VSAPI 8.911 is not yet uploaded to AU, apply VSAPI 8.911 to the OSCE server.  You can download the files at &lt;a href="http://www.trendmicro.com/download/engine.asp#prod_5"&gt;http://www.trendmicro.com/download/engine.asp#prod_5&lt;/a&gt;&lt;br /&gt;Visit KB article for details -- &lt;a href="http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-122633"&gt;http://esupport.trendmicro.com/support/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=PUB-en-122633&lt;/a&gt;&lt;br /&gt;6.  Once all the update components are up-to-date, invoke a “scan now” from the OSCE server&lt;br /&gt;7.  Machines that are infected with Worm_Downad.AD or its variants requires a reboot to completely clean the machine.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#000000;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7067790085216955855?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7067790085216955855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7067790085216955855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7067790085216955855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7067790085216955855'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2009/01/best-practice-how-to-clean-wormdownadad.html' title='Best Practice -  How to clean Worm_Downad.AD with OfficeScan'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-5389141689555110020</id><published>2008-12-26T11:33:00.004+08:00</published><updated>2009-04-06T10:52:26.660+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>Resetting TMCM 5.0 password</title><content type='html'>If you forgot your password to login to TMCM console, you can reset it. However, you cannot forget the username that you used to login (yes, there are people who forgot even the username). Please refer to the knowledge base solution ID: &lt;a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1038174&amp;amp;id=EN-1038174"&gt;1038174&lt;/a&gt; for resetting password via OSQL command line.&lt;br /&gt;&lt;br /&gt;If using osql command line doesn't help, you might want to try using this tool QTODBC. Let me know if you can't find the tool in the Internet. For those who are using licensed SQL server, probably you can use the SQL Enterprise Manager. Please refer to the knowledge base solution ID : &lt;a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1037073&amp;amp;id=EN-1037073"&gt;1037073&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-5389141689555110020?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/5389141689555110020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=5389141689555110020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5389141689555110020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/5389141689555110020'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/resetting-tmcm-50-password.html' title='Resetting TMCM 5.0 password'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-735758287018185578</id><published>2008-12-26T11:17:00.002+08:00</published><updated>2008-12-26T11:33:50.115+08:00</updated><title type='text'>Merry Xmas and Happy New Year</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-8ljvkq1hYo/SVRQaHdKNyI/AAAAAAAAAJQ/M7SU3WApKxA/s1600-h/Animated+Happy+New+Year2.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 264px;" src="http://1.bp.blogspot.com/_-8ljvkq1hYo/SVRQaHdKNyI/AAAAAAAAAJQ/M7SU3WApKxA/s320/Animated+Happy+New+Year2.gif" alt="" id="BLOGGER_PHOTO_ID_5283936672420607778" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hello all! The year is getting to the end where we will have to bid farewell to 2008 and welcome 2009. I hope everyone is enjoying the holidays! Merry Xmas and Happy New Year to all!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-735758287018185578?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/735758287018185578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=735758287018185578' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/735758287018185578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/735758287018185578'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/merry-xmas-and-happy-new-year.html' title='Merry Xmas and Happy New Year'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-8ljvkq1hYo/SVRQaHdKNyI/AAAAAAAAAJQ/M7SU3WApKxA/s72-c/Animated+Happy+New+Year2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-2706654005017049249</id><published>2008-12-23T09:36:00.003+08:00</published><updated>2009-04-06T10:52:43.271+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Send Large Files by Email</title><content type='html'>Often, Siclog or other logs that you need to submit to Support Engineer may grow to a large size that restricting you from attaching it via email. Alternative? You can upload it to an FTP site OR try this service offered by &lt;a href="http://www.yousendit.com/"&gt;You Send It.&lt;/a&gt; Other websites offering the same service are in &lt;a href="http://www.email-unlimited.com/stuff/send-huge-files.htm"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Upon uploading a file to the website, an email is        sent to the recipient, where they are given a link to download        the file. It's that easy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-2706654005017049249?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/2706654005017049249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=2706654005017049249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2706654005017049249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/2706654005017049249'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/send-large-files-by-email.html' title='Send Large Files by Email'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-8056403131169639093</id><published>2008-12-22T11:22:00.003+08:00</published><updated>2009-04-06T10:49:23.444+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Class Photo'/><title type='text'>December Class</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-8ljvkq1hYo/SU8ImRQgQCI/AAAAAAAAAJI/L_kU8QO-_60/s1600-h/dec_class1.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_-8ljvkq1hYo/SU8ImRQgQCI/AAAAAAAAAJI/L_kU8QO-_60/s320/dec_class1.jpg" alt="" id="BLOGGER_PHOTO_ID_5282450341489557538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Lyn and Wind are two kind ladies. :-) Thank you for being understanding. I am sorry that even &lt;a href="http://www.dimdim.com/"&gt;DimDim.com&lt;/a&gt; that time were not on my side when the 'conversion' server became unavailable to convert the powerpoint slides.&lt;br /&gt;&lt;br /&gt;Wish you all the best in the exam!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-8056403131169639093?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/8056403131169639093/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=8056403131169639093' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8056403131169639093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/8056403131169639093'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/december-class.html' title='December Class'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-8ljvkq1hYo/SU8ImRQgQCI/AAAAAAAAAJI/L_kU8QO-_60/s72-c/dec_class1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7940969579579175790</id><published>2008-12-19T09:06:00.005+08:00</published><updated>2009-04-06T10:55:22.429+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IMSS'/><category scheme='http://www.blogger.com/atom/ns#' term='IWSS/IWSVA'/><category scheme='http://www.blogger.com/atom/ns#' term='TMCM'/><title type='text'>MSDE/ SQL 2005 database installation</title><content type='html'>Something to take note when you install IWSS, IMSS or TMCM which require database component and your option is to install MSDE/SQL 2005 database, make sure the option for authentication is set to &lt;span style="font-weight: bold;"&gt;'SQL Server Authentication'.  &lt;/span&gt; If you are installing on existing SQL server, choose Mixed Authentication Mode.&lt;br /&gt;&lt;br /&gt;You may refer to this &lt;a href="http://support.microsoft.com/kb/322336"&gt;knowledge base&lt;/a&gt; from Microsoft website should you need to verify and change the system administrator password in MSDE or SQL Server 2005 Express Edition.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7940969579579175790?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7940969579579175790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7940969579579175790' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7940969579579175790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7940969579579175790'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/msde-sql-2005-database-installation.html' title='MSDE/ SQL 2005 database installation'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-7664343010884631728</id><published>2008-12-15T17:13:00.004+08:00</published><updated>2009-04-06T10:54:02.086+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Online Support System</title><content type='html'>You can say goodbye to the good ol' asia[at]support.trendmicro.com from now on. Please welcome to the new and updated online support system which can be reached &lt;a href="http://esupport.trendmicro.com/support/srf/questionentry.do"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;All support cases should be submitted through there and each cases  will be assigned with service request ID. Do provide your real email address in "Send Reply-To" field because the reply from Trend Support will be sent to this account.&lt;br /&gt;&lt;br /&gt;Happy Supporting Trend!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-7664343010884631728?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/7664343010884631728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=7664343010884631728' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7664343010884631728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/7664343010884631728'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/online-support-system.html' title='Online Support System'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-3126360311908804305</id><published>2008-12-12T14:18:00.005+08:00</published><updated>2009-04-06T11:01:06.673+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>Top Infectors for Asian countries</title><content type='html'>I handled a number of cases for the past few months regarding the spread of autorun malware via thumb drive. Thank you Azril for the latest malware sample, :p&lt;br /&gt;&lt;br /&gt;This statistic from Trend Micro researcher will give you some insights, do read it &lt;a href="http://blog.trendmicro.com/most-abused-infection-vector/"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-8ljvkq1hYo/SUIFFM1tcUI/AAAAAAAAAJA/OFtL9xN9o2I/s1600-h/statistic.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 52px;" src="http://2.bp.blogspot.com/_-8ljvkq1hYo/SUIFFM1tcUI/AAAAAAAAAJA/OFtL9xN9o2I/s400/statistic.png" alt="" id="BLOGGER_PHOTO_ID_5278787300135629122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If disabling the autorun feature is agreeable to the end users, you might want to consider deploying this &lt;a href="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VNAME=Disabling+the+Autorun+Feature+in+Windows&amp;amp;Page"&gt;tool.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-3126360311908804305?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/3126360311908804305/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=3126360311908804305' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3126360311908804305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/3126360311908804305'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/top-infectors-for-asian-countries.html' title='Top Infectors for Asian countries'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-8ljvkq1hYo/SUIFFM1tcUI/AAAAAAAAAJA/OFtL9xN9o2I/s72-c/statistic.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9177585147335162418.post-6425160817376941376</id><published>2008-12-12T09:58:00.002+08:00</published><updated>2009-04-06T11:01:36.571+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisory/Alert'/><title type='text'>JS_DLOAD.MD/IE7 0-day Exploit</title><content type='html'>&lt;table class="MsoNormalTable" style="width: 424.5pt;" width="566" border="0" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="padding: 0in;" valign="top"&gt; &lt;table class="MsoNormalTable" style="width: 457.1pt;" width="609" border="0" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="padding: 0in; width: 457.1pt;" valign="top" width="609"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;&lt;b&gt;&lt;span style="font-family:Verdana;font-size:85%;color:#cc0000;"&gt;&lt;span style="font-size: 10pt; color: rgb(204, 0, 0); font-family: Verdana;"&gt;Details&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/strong&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 0in; width: 457.1pt;" width="609"&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;On December 10, 2008  2:06pm (GMT +8) TrendLabs received a report stating t&lt;st1:personname st="on"&gt;ha&lt;/st1:personname&gt;t there is a zero day IE7 exploit discovered in a  China forum. The said toolkit was being sold in &lt;st1:place st="on"&gt;&lt;st1:country-region st="on"&gt;China&lt;/st1:country-region&gt;&lt;/st1:place&gt;  underground community. The exploit method used is a Heap Spray on SDHTML  t&lt;st1:personname st="on"&gt;ha&lt;/st1:personname&gt;t affects the following platform  :&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;Internet Explorer  7.0 (7.0.5730.13) &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;Windows XP / Windows  2003&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;color:#666666;"&gt;&lt;span style="font-size: 12pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;The  be&lt;st1:personname st="on"&gt;ha&lt;/st1:personname&gt;vior of the malware after exploit  is it will download/redirect to the following URL's wwwwyyyyy.cn and  qqqqttrr.cn&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;As of December 10,  2008 2:06PM (GMT +8) Microsoft does not &lt;st1:personname st="on"&gt;ha&lt;/st1:personname&gt;ve any patch on this exploit. &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 0in; width: 457.1pt;" valign="top" width="609"&gt; &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:Verdana;font-size:85%;color:#cc0000;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(204, 0, 0); font-family: Verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:Verdana;font-size:85%;color:#cc0000;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(204, 0, 0); font-family: Verdana;"&gt;Solution&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 0in; width: 457.1pt;" width="609"&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Times New Roman;font-size:85%;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 0in; width: 457.1pt;" width="609"&gt; &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;URL  FILTERING:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="font-weight: bold; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;Domain                                              &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;cc4y7.cn  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                                         &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;wwwwyyyyy.cn  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                             &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;qqqqttrr.cn  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                                      &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;www-onlinedown.com  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                      &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;hxxp://wieyou.com/iiee/explore.exe  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;hxxp://baidu.bbtu001.com  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;sllwrnm5.cn  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: 'Trebuchet MS';"&gt;{BLOCKED}&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;                            &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;color:#666666;"&gt;&lt;span style="font-size: 12pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;VSAPI:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="font-weight: bold; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;December 10, 2008  12:13:29 PM OPR 5.699.00 &lt;st1:personname st="on"&gt;ha&lt;/st1:personname&gt;s been  released including the following detections:&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;TROJ_GAMETHI.BPF&lt;br /&gt;TROJ_PATCH.KU&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;OPR:  5.701.00 is  already released&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;JS_DLOAD.MD&lt;br /&gt;TSPY_ONLINEG.EJH&lt;br /&gt;TSPY_ONLINEG.EJG&lt;br /&gt;TSPY_ONLINEG.EJG&lt;br /&gt;TSPY_ONLINEG.HAV&lt;br /&gt;TSPY_ONLINEG.EJG&lt;br /&gt;TSPY_ONLINEG.ADR&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;color:#666666;"&gt;&lt;span style="font-size: 12pt; color: rgb(102, 102, 102); font-family: Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;VIRUS  REPORT: &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:#666666;"&gt;&lt;span style="font-weight: bold; color: rgb(102, 102, 102); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-family:Arial;font-size:85%;color:#666666;"&gt;&lt;span style="font-size: 10pt; color: rgb(102, 102, 102); font-family: Arial;"&gt;More detailed  description of this malware can be found at the following  link:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:85%;color:black;"&gt;&lt;span style="font-size: 10pt; color: black; font-family: Arial;"&gt;&lt;a title="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_DLOAD.MD http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOAD%2EMD" href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOAD%2EMD"&gt;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOAD%2EMD&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;color:#333333;"&gt;&lt;span style="color: rgb(51, 51, 51); font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt; &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Times New Roman;font-size:100%;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9177585147335162418-6425160817376941376?l=tcse-trendmicro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tcse-trendmicro.blogspot.com/feeds/6425160817376941376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9177585147335162418&amp;postID=6425160817376941376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6425160817376941376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9177585147335162418/posts/default/6425160817376941376'/><link rel='alternate' type='text/html' href='http://tcse-trendmicro.blogspot.com/2008/12/jsdloadmdie7-0-day-exploit.html' title='JS_DLOAD.MD/IE7 0-day Exploit'/><author><name>Sha</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
