عيد ميلاد مجيد, 聖誕節快樂, Maligayang Pasko, Hyvää Joulua, Joyeux Noël, Frohe Weihnachten, Καλά Χριστούγεννα, חג מולד שמח, मेरी क्रिसमस, Selamat Hari Natal, Buon Natale, メリークリスマス, Selamat Hari Krismas, God jul, کریسمس مبارک, С Рождеством, Feliz Navidad, Mutlu Noeller, کرسمس, Nathar Puthu Varuda Valthukkal, Geseende Kerfees en 'n gelukkige nuwe jaar, Miet puou yan dhiedh Banyda tene Yin, Wesołych Świąt
And of course!!!!
MERRY CHRISTMAS!!!
Keep safe over there holiday period... keep in mind the reason for the season and where possible hang out with your families... There are a lot of resellers out there who are workaholics... take a break! Give yourself and your family a Christmas Present this year! TIME!
Talk to you all in the new year.
Kieran
Welcome
**Please note: This is an INFORMAL blog, and I will attempt to add information to it on a reasonably regular basis**
Please maintain your current support paths for any post-sale technical queries:
Partner Support Hotline - 1800 094 155
Support Email - support@trendmicro.com.au
Thursday, December 23, 2010
A product well worth considering!!!
I have been speaking with a lot of customers over this past year who are dealing with information confidentiality issues, privacy breaches and general loss of intellectual property - either by malicious or accidental activity.
Trend Micro has just released the latest version of our Data Loss Prevention Production (v5.5)
You can download it from here:
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&clkval=347&lang_loc=1
Trend Micro has just released the latest version of our Data Loss Prevention Production (v5.5)
You can download it from here:
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&clkval=347&lang_loc=1
Data Loss Prevention delivers a network and endpoint-based data loss prevention (DLP) solution, combined with a workflow-navigation engine that makes it easier to identify, track, and secure your business-critical data. Plus, it reduces cost and complexity with high performance, fast deployment, and your choice of form factors. Your data is protected—whether online or offline—across email, webmail, social media, IM, Skype, Windows File Share, CDs, USB drives, ActiveSync, and other common threat vectors.
This is also now combined with a Network agent which is able to detect sentive data being transferred within the network without the needs for an installed agent - so perfect for environments which have a lot of contractors.
You can get the network monitoring agent from:
Some of the new features of DLP v5.5 are:
· Centralized Management for both DLP Endpoint and DLP Network Monitor
· Data Stealing Malware Detection
· Enhanced Dashboard and new reporting options
· Policy-based white/black list
· Improved log management for backup, purge and restoring
· Forensic data encryption
· New Data Discovery Actions
· Remote Crawler Enhancements
· Improved Log query filtering
· Policy Deployment Status
· Tree-view support for Endpoint Selection
· Popup Alert for Device Control
· Password protection for uninstall
· Additional True-file type support
Like I said... very worthwhile having a look at it.
More info at:
and a great demo video at:
Tuesday, November 30, 2010
Trend Aquires Mobile Armor to add EndPoint Encryption!
Here's is something to keep your eye's on!
Trend have just announced the agreement to acquire a complementary endpoint encryption company which rounds out Trend's data protection story and strengthens our competitive position in endpoint security.
Mobile Armor, based in St. Louis/Missouri/USA, provides one of the industry’s most secure, manageable, and easy-to-use data encryption solutions. Their full-disk, file/folder, and removable media encryption offerings make it simple to protect all data on desktops, laptops, tablets and removable media including USB thumb drives, CD/DVDs, and SD Cards.
Mobile Armor products are deployed in hundreds of organizations including blue-chip companies in healthcare and financial services as well as substantial implementation across the government sector. Mobile Armor’s product line has earned an impressive list of validations including FIPS 140-2 Level 2 and 3, and Common Criteria Evaluation Assurance Level 4+ (EAL-4+) Certification in final review.
For more information regarding the acquisition, please check out http://us.trendmicro.com/us/partners/strategic-partners/mobile-armor/index.html or the Mobile Armor website at http://www.mobilearmor.com/.
Trend have just announced the agreement to acquire a complementary endpoint encryption company which rounds out Trend's data protection story and strengthens our competitive position in endpoint security.
Mobile Armor, based in St. Louis/Missouri/USA, provides one of the industry’s most secure, manageable, and easy-to-use data encryption solutions. Their full-disk, file/folder, and removable media encryption offerings make it simple to protect all data on desktops, laptops, tablets and removable media including USB thumb drives, CD/DVDs, and SD Cards.
Mobile Armor products are deployed in hundreds of organizations including blue-chip companies in healthcare and financial services as well as substantial implementation across the government sector. Mobile Armor’s product line has earned an impressive list of validations including FIPS 140-2 Level 2 and 3, and Common Criteria Evaluation Assurance Level 4+ (EAL-4+) Certification in final review.
For more information regarding the acquisition, please check out http://us.trendmicro.com/us/partners/strategic-partners/mobile-armor/index.html or the Mobile Armor website at http://www.mobilearmor.com/.
Worry-Free Business Security 7.0 Critical Patch B1357
Details:
Note: Critical Patch Build 1357 includes fix 1347. For more information please refer to the 1357 readme file
After applying the critical patch, the following happen:
The solution list above will be also included in the next major Worry-Free Business Security 7 release package.
Solution link:
The following issue may occurs after customer install WFBS7.0:
- Users may get ESENT event ID 490 in the Application Event Log after the Security Agent is installed.
- Performance issues may occur when saving Microsoft Office files on a 64-bit server shared network drive. This often happens when saving excel files.
- The WFBS 7.0 server may slow down the performance of some servers after a few weeks.
To resolve these issues, please install Worry-Free Business Security 7.0 Critical Patch Build 1357.
Note: Critical Patch Build 1357 includes fix 1347. For more information please refer to the 1357 readme file
After applying the critical patch, the following happen:
- The ESENT event ID 490 will no longer occur. ESENT will be able to open the catroot database files as normal.
- Performance becomes normal when saving files on 64-bit server shared network drives.
- The Worry-Free Business Security Server releases unused resources to enhance system performance.
The solution list above will be also included in the next major Worry-Free Business Security 7 release package.
Solution link:
http://esupport.trendmicro.com/pages/Worry-Free-Business-security-70-servers-may-slow-down-after-a-few-weeks.aspx
Tuesday, November 16, 2010
Don't Forget about Silent Installs!
I was just dealing with this question from a reseller, and thought it might be of interest to the wider community.
If you review the Install Guide - at page 95 (Chapter 3 Page 33) you will find information pertaining to recording a silent or unattended install script file.
Have a great day everyone!
Kieran
If you review the Install Guide - at page 95 (Chapter 3 Page 33) you will find information pertaining to recording a silent or unattended install script file.
Have a great day everyone!
Kieran
Tuesday, November 2, 2010
Worry Free Business Security V7.0 is on the Download Page!!
Go grab it people!!
DOWNLOAD IT
#### HERE ####
For those of you who have been under a rock on Mars, there have been a few enhancements to the product:
1. Mac support in WF Advanced
2. DLP lite functionality in the Messaging Security Agent for WF Advanced
3. USB and Network Share Access Control
4. URL Filtering Blacklist customisation
5. Web Reputation scanning in emails through the Messaging Security Agent.
There have been a number of GUI enhancements as well, but a SIGNIFICANT performance improvments as well.
So go on... don't just sit there... download it and install and play!
Please post comments on your experiences and you thoughts.
I trust everyone is enjoying the last couple of months of the year.
Talk to you all again soon.
Kieran
DOWNLOAD IT
#### HERE ####
For those of you who have been under a rock on Mars, there have been a few enhancements to the product:
1. Mac support in WF Advanced
2. DLP lite functionality in the Messaging Security Agent for WF Advanced
3. USB and Network Share Access Control
4. URL Filtering Blacklist customisation
5. Web Reputation scanning in emails through the Messaging Security Agent.
There have been a number of GUI enhancements as well, but a SIGNIFICANT performance improvments as well.
So go on... don't just sit there... download it and install and play!
Please post comments on your experiences and you thoughts.
I trust everyone is enjoying the last couple of months of the year.
Talk to you all again soon.
Kieran
Wednesday, October 6, 2010
Mac Users are completely safe...
...Well... That's what the Apple using community have been misled to believe.
Two new malware for Mac OS X were recently discovered. Even though there are indeed relatively fewer Mac malware compared with Windows, many Mac users who still believe they are somehow magically immune from attacks may run the risk of encountering any of these two...
Read on at the Trend Micro Malware Blog.
Not One but Two New OS X Malware
When you are done there... check out Trend Micro's solution Trend Micro Security for Mac which will be included in version 7.0 of Worry Free Business Security Advanced
Two new malware for Mac OS X were recently discovered. Even though there are indeed relatively fewer Mac malware compared with Windows, many Mac users who still believe they are somehow magically immune from attacks may run the risk of encountering any of these two...
Read on at the Trend Micro Malware Blog.
Not One but Two New OS X Malware
When you are done there... check out Trend Micro's solution Trend Micro Security for Mac which will be included in version 7.0 of Worry Free Business Security Advanced
Thursday, September 23, 2010
WFBS V7.0 Beta - EXTENDED!
Great news for people who did not get a chance to participate in the inital WFBS7 beta program.
We are extending the beta cycle an additional 6 weeks and will be releasing Worry-Free Business Security 7.0 Phase 2 beta build September 21st, 2010. Phase 2 Beta Program Schedule: Register here if you haven't already.
Phase 2 build resolves issues identified in Phase 1 including high resource usage and connectivity problems with the Client Security Agent (CSA) on both desktops and server platforms.
Thank you to those who participated in Phase 1 for your patience working with us and providing valuable information which helped identify the issues with the product. We continue to seek your feedback and suggestions to make certain we cover all aspects of Worry-Free Business Security and ensure stability of the product.
October 20th, 2010 Phase 2 build validation
October 25th, 2010 WFBS 7 beta program ends
October 29th, 2010 GM
General Release will be early November
(All dates subject to change)
https://www.trendbeta.com/
Some of the new features include:
New Features
http://wfbs7beta.trendmicro.com/
We are extending the beta cycle an additional 6 weeks and will be releasing Worry-Free Business Security 7.0 Phase 2 beta build September 21st, 2010. Phase 2 Beta Program Schedule: Register here if you haven't already.
Phase 2 build resolves issues identified in Phase 1 including high resource usage and connectivity problems with the Client Security Agent (CSA) on both desktops and server platforms.
Thank you to those who participated in Phase 1 for your patience working with us and providing valuable information which helped identify the issues with the product. We continue to seek your feedback and suggestions to make certain we cover all aspects of Worry-Free Business Security and ensure stability of the product.
September 21st , 2010 Phase 2 beta build available for download
October 20th, 2010 Phase 2 build validation
October 25th, 2010 WFBS 7 beta program ends
October 29th, 2010 GM
General Release will be early November
(All dates subject to change)
https://www.trendbeta.com/
Some of the new features include:
New Features
- ScanMail for Exchange 10 integration
- Data Loss Prevention
- Device Access Control
- Uniclient + AMSP
- Macintosh Support
- New customized installation and deployment
http://wfbs7beta.trendmicro.com/
Critical Issue - WFBS Produces Excessive Policy Violations
We have a hot issue right now with WFBS and an AEGIS (Behaviour Monitoring Engine) update causing excessive amounts of Policy Violations. Trend Micro Engineering teams have released a critical patch to address the root cause of this issue.
The issue was caused by new AEGIS update driver. From our testing, SP3 does not seem to be affected so, the decision has been made to not deploy this to ActiveUpdate, but instead encourage affected customers to either apply the critical patch or SP3. The critical update is in effect the rolledback AEGIS driver. This is because we don’t want to affect those customers already on SP3 and keep them on the new driver.
There have been isolated cases where environments with SP3 applied have been affected - however a reboot of the end-point has resolved the issue 100% of the time.
Please reference the below KB for any customers / partners affected by this that might contact yourself. Support teams are also handling the incoming customer cases
http://esupport.trendmicro.com/4/Behavior-Monitoring-blocks-the-TMBMSRVexe-process.aspx
Customers who are using WFBS 6.0 Service Pack 1 or Service Pack 2 may get "Unauthorized changes blocked" messages for the TMBSRV.exe process. The following message will appear on the client machine:
Unauthorized changes blocked!
Client/Server Security Agent has blocked the following programs to protect your computer. To unblock the programs, contact your administrator.
In the WFBS console, the customers are also getting an excessive Policy Violation of Behavior Monitoring due to the TMBSRV.exe process:
Solution:
________________________________________
To address the problem, please apply Critical Patch Build 3221. You can download it from the following links.
Alternatively, you can also update SP1 or SP2 to SP3. The installation packages and documentation can be found below:
WFBS 6.0 Advanced SP3 English
WFBS 6.0 Standard SP3 English
The issue was caused by new AEGIS update driver. From our testing, SP3 does not seem to be affected so, the decision has been made to not deploy this to ActiveUpdate, but instead encourage affected customers to either apply the critical patch or SP3. The critical update is in effect the rolledback AEGIS driver. This is because we don’t want to affect those customers already on SP3 and keep them on the new driver.
There have been isolated cases where environments with SP3 applied have been affected - however a reboot of the end-point has resolved the issue 100% of the time.
Please reference the below KB for any customers / partners affected by this that might contact yourself. Support teams are also handling the incoming customer cases
http://esupport.trendmicro.com/4/Behavior-Monitoring-blocks-the-TMBMSRVexe-process.aspx
Customers who are using WFBS 6.0 Service Pack 1 or Service Pack 2 may get "Unauthorized changes blocked" messages for the TMBSRV.exe process. The following message will appear on the client machine:
Unauthorized changes blocked!
Client/Server Security Agent has blocked the following programs to protect your computer. To unblock the programs, contact your administrator.
In the WFBS console, the customers are also getting an excessive Policy Violation of Behavior Monitoring due to the TMBSRV.exe process:
Solution:
________________________________________
To address the problem, please apply Critical Patch Build 3221. You can download it from the following links.
Alternatively, you can also update SP1 or SP2 to SP3. The installation packages and documentation can be found below:
WFBS 6.0 Advanced SP3 English
WFBS 6.0 Standard SP3 English
Friday, July 23, 2010
LNK Vulnerability is bigger than just USB keys.
Hi there everyone.
I trust this update finds you all well and you are looking forward to a great weekend.
My I offer a piece of advice for this weekend?
AVOID "LNK" FILES LIKE THE PLAGUE!
I was drafting the previous post regarding the fact that a USB key no longer requires an autorun file to perform an infection, but it seems that is now only one small part of the over all issue.
One of our newer staffers here at Trend in Sydney has many security qualification, and certifications, including many industry regulatory compliance advisory certifications as a result of his time with Visa Europe. As a result of all this knowledge he was able to craft some impromptu internal demonstrations for us to show us the extent and possibilities that this particular vulnerability presents.
Needless to say the outcome is concerning.
Without even so much as a double click, he had complete control of a demo-lab machine remotely, executing commands without hindrance.
As a result of a wonderful flaw in Microsoft a number of articles need to be viewed.
Microsoft Security Advisory - Temporary "Fix It For Me" tool This will be superseded by the patch that Microsoft eventually releases.
Microsoft Security Response Center
Information about the vulnerability
Trend Updates as a result of related Malware
Guys, just be aware - a LNK file can be propagated via any number of vectors. A web site, an email a USB, and as a result of the way this vulnerability works the user does not need to interact with the LNK file at all. As a result of Windows rendering the LNK file icon, the contents are executed to perform the exploit. And as you know an LNK file can point to ANYTHING and in this case, ANY type of exploit!
Be careful, and keep a keen eye out for the impending Microsoft fix since this is going to be the most effective way to protect your customers.
Have a great weekend!
I trust this update finds you all well and you are looking forward to a great weekend.
My I offer a piece of advice for this weekend?
AVOID "LNK" FILES LIKE THE PLAGUE!
I was drafting the previous post regarding the fact that a USB key no longer requires an autorun file to perform an infection, but it seems that is now only one small part of the over all issue.
One of our newer staffers here at Trend in Sydney has many security qualification, and certifications, including many industry regulatory compliance advisory certifications as a result of his time with Visa Europe. As a result of all this knowledge he was able to craft some impromptu internal demonstrations for us to show us the extent and possibilities that this particular vulnerability presents.
Needless to say the outcome is concerning.
Without even so much as a double click, he had complete control of a demo-lab machine remotely, executing commands without hindrance.
As a result of a wonderful flaw in Microsoft a number of articles need to be viewed.
Microsoft Security Advisory - Temporary "Fix It For Me" tool This will be superseded by the patch that Microsoft eventually releases.
Microsoft Security Response Center
Information about the vulnerability
Trend Updates as a result of related Malware
Guys, just be aware - a LNK file can be propagated via any number of vectors. A web site, an email a USB, and as a result of the way this vulnerability works the user does not need to interact with the LNK file at all. As a result of Windows rendering the LNK file icon, the contents are executed to perform the exploit. And as you know an LNK file can point to ANYTHING and in this case, ANY type of exploit!
Be careful, and keep a keen eye out for the impending Microsoft fix since this is going to be the most effective way to protect your customers.
Have a great weekend!
No AUTORUN.INF needed for USB infection!!
New Malware Distribution Technique For USB via MS Vulnerability
Please be aware that there is a new vulnerability in the way Microsoft handles shortcut (.LNK) files in external drives. This is currently being exploited by malicious code for new propagation techniques related to external devices such as USB keys.
By having a shortcut (.LNK) file on the removable drive, this simply needs to be viewed (not executed) to automatically execute malicious code. In other words, just by plugging in a USB key and opening the root folder would trigger the infection.
References:
MS Security Advisory:
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://www.securecomputing.net.au/News/220266,microsoft-looks-into-malware-spreading-via-usb.aspx
Trend Micro Malware Blogs and Virus Information:
http://blog.trendmicro.com/usb-worm-exploits-windows-shortcut-vulnerability/
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_STUXNET.A&Vsect=T
There are actually a number of components to the malware which we detect as:
WORM_STUXNET.A – The malicious files themselves
LNK_STUXNET.A – The malicious .LNK file to execute the files.
RTKT_STUXNET.A – Rootkit component.
How can Trend Micro protect against this?
We already have a virus signature file available to detect the initial malware.
Please be aware that there is a new vulnerability in the way Microsoft handles shortcut (.LNK) files in external drives. This is currently being exploited by malicious code for new propagation techniques related to external devices such as USB keys.
By having a shortcut (.LNK) file on the removable drive, this simply needs to be viewed (not executed) to automatically execute malicious code. In other words, just by plugging in a USB key and opening the root folder would trigger the infection.
References:
MS Security Advisory:
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://www.securecomputing.net.au/News/220266,microsoft-looks-into-malware-spreading-via-usb.aspx
Trend Micro Malware Blogs and Virus Information:
http://blog.trendmicro.com/usb-worm-exploits-windows-shortcut-vulnerability/
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_STUXNET.A&Vsect=T
There are actually a number of components to the malware which we detect as:
WORM_STUXNET.A – The malicious files themselves
LNK_STUXNET.A – The malicious .LNK file to execute the files.
RTKT_STUXNET.A – Rootkit component.
How can Trend Micro protect against this?
We already have a virus signature file available to detect the initial malware.
Thursday, July 15, 2010
Whoops, we did it again!
hmmm lame title... sorry about that! :)
I trust everyone is enjoying their week so far. Down hill run from here on the week and the month!
We topped the NSS labs report again!
Now, those of you who have seen me speak, you will be very aware of my opinion's of other lab-tests, and comparisons. Even when Trend comes out on top of these.
NSS has always been a bit of a shining beacon in this arena though. They are the equivalent of Choice magazine - taking completely unbiased, unsponsored view points to provide their subscribers with the best possible and most untainted information available. See below a screen shot of their website.
Here is a portion of the outcomes this report showed.
This table is anonymised at the request of NSS - but the results are pretty obvious. Trend are the fastest to respond with a time of 4.62 hours - the next quickest are our British friends lagging by a full 12 hours, and it only gets worse from there. Our 2 major competitors scored around the 30 and 45 hour marks - I'll leave the rest to you to interpret.
And there are three words which are the reason for this success. Smart Protection Network.
I wonder if you are noticing a theme here so far with my blogs??
You can find out some more information on this report here.
Signing off... Kieran
I trust everyone is enjoying their week so far. Down hill run from here on the week and the month!
We topped the NSS labs report again!
Now, those of you who have seen me speak, you will be very aware of my opinion's of other lab-tests, and comparisons. Even when Trend comes out on top of these.
NSS has always been a bit of a shining beacon in this arena though. They are the equivalent of Choice magazine - taking completely unbiased, unsponsored view points to provide their subscribers with the best possible and most untainted information available. See below a screen shot of their website.
Here is a portion of the outcomes this report showed.
This table shows blocking mechanisms at download and at execution on the system.
This is the total time in hours to block a previously undetected Malicious URL.
And there are three words which are the reason for this success. Smart Protection Network.
I wonder if you are noticing a theme here so far with my blogs??
You can find out some more information on this report here.
Signing off... Kieran
Monday, July 12, 2010
Another Gem from the keyboard of Wayne Small
Are you planning on installing WFBS v6?
Do you have field engineers who like pictures?
Do you generally install WFBS without changing anything from defaults?
Wayne has just released his lastest publication to make your reselling life easier!
WFBS 6.0 Visual Guide
This is a great step-by-step field guide which will be well worth forking over a few bucks for.
Have a great week everyone!
Do you have field engineers who like pictures?
Do you generally install WFBS without changing anything from defaults?
Wayne has just released his lastest publication to make your reselling life easier!
WFBS 6.0 Visual Guide
This is a great step-by-step field guide which will be well worth forking over a few bucks for.
Have a great week everyone!
Tuesday, July 6, 2010
Latest information to combat Fake AV
Fake AV has been one of the most challenging malware families I have encountered in a long time.
A friend of mine recently had an encounter with a FakeAV variant. Her son had been using the computer, and her updated free-AVG had no idea the malware had infiltrated or was present. Even though there were many pop-ups appearing asking her to pay for the "Security Software" which had detected Trojans on her machine (classic indicator of a FakeAV "RansomWare").
Eventually it was a simple matter of removing a single registry run key in safe-mode and submitting the related file to our labs for further analysis (which we were able to identify immediately).
We were actually a little disappointed that this variant seemed so easy to remove. We thought it was all over... we were wrong!!
The pop-ups had ceased. It was like looking at a still pond. Smooth surface, but plenty of activity happening underneath!
I installed Trend Micro Titanium on her Netbook, which immediately started detecting Web Threats! Granted, we were not detecting a local file-based infection at that stage - BUT it was blocking the malware's connection home. This malware will try to connect home to either get an updated malware components, or send sensitive information back "home". Our Virus Research labs filled in the gaps with the file-based infection response.
< soap_box >
(I hope this doesn't sound like Marketing fluff.) This really highlights the true power of what the Smart Protection Network means in real-life scenarios. It's not only for the major enterprises - its also for the "average-Joe" home user, who effectively is the most vulnerable user of all! Plus the information provided from this ultra-vulnerable source also contributes to protecting our large corporate customers, and visa-versa.
PLEASE enable Web Threat Protection (Web Reputation) in all your Trend Micro installs. PLEASE enable Email Reputation and Smart Scanning (File Reputation) were applicable too.
Another thing that is highlighted is that you certainly get what you pay for when installing a "Free" Anti-Malware product, and unfortunately this was installed by a person from one of the franchise computer services companies who should really have known better!
< /soap_box >
Anyway. I trust you will enjoy having a read through this whitepaper which aims to educate users on how FakeAV gets onto their machines, and best to protect themselves from it happening in the first place!
Have a great rest of the week everyone!
Regs
Kieran
A friend of mine recently had an encounter with a FakeAV variant. Her son had been using the computer, and her updated free-AVG had no idea the malware had infiltrated or was present. Even though there were many pop-ups appearing asking her to pay for the "Security Software" which had detected Trojans on her machine (classic indicator of a FakeAV "RansomWare").
Eventually it was a simple matter of removing a single registry run key in safe-mode and submitting the related file to our labs for further analysis (which we were able to identify immediately).
We were actually a little disappointed that this variant seemed so easy to remove. We thought it was all over... we were wrong!!
The pop-ups had ceased. It was like looking at a still pond. Smooth surface, but plenty of activity happening underneath!
I installed Trend Micro Titanium on her Netbook, which immediately started detecting Web Threats! Granted, we were not detecting a local file-based infection at that stage - BUT it was blocking the malware's connection home. This malware will try to connect home to either get an updated malware components, or send sensitive information back "home". Our Virus Research labs filled in the gaps with the file-based infection response.
< soap_box >
(I hope this doesn't sound like Marketing fluff.) This really highlights the true power of what the Smart Protection Network means in real-life scenarios. It's not only for the major enterprises - its also for the "average-Joe" home user, who effectively is the most vulnerable user of all! Plus the information provided from this ultra-vulnerable source also contributes to protecting our large corporate customers, and visa-versa.
PLEASE enable Web Threat Protection (Web Reputation) in all your Trend Micro installs. PLEASE enable Email Reputation and Smart Scanning (File Reputation) were applicable too.
Another thing that is highlighted is that you certainly get what you pay for when installing a "Free" Anti-Malware product, and unfortunately this was installed by a person from one of the franchise computer services companies who should really have known better!
< /soap_box >
Anyway. I trust you will enjoy having a read through this whitepaper which aims to educate users on how FakeAV gets onto their machines, and best to protect themselves from it happening in the first place!
Have a great rest of the week everyone!
Regs
Kieran
Thursday, July 1, 2010
Beware of Tab-Jacking or Tabnapping!!
I just came across an interesting article detailing a new phishing threat mechanism.
http://uk.biz.yahoo.com/07062010/389/tab-napping-new-online-scam.html
The general message appears to be that now we need to check that the URL we typed in originally is still there if we utilise a number of tabs and come back to a previously opened tab.
As per usual - this is something that Web Threat Protection in our Smart Protection Network will serve to protect Trend Micro users from.
http://uk.biz.yahoo.com/07062010/389/tab-napping-new-online-scam.html
The general message appears to be that now we need to check that the URL we typed in originally is still there if we utilise a number of tabs and come back to a previously opened tab.
As per usual - this is something that Web Threat Protection in our Smart Protection Network will serve to protect Trend Micro users from.
Thursday, June 17, 2010
Worry Free Business Security V7.0 Beta!
WFBS v7.0 beta registration is now OPEN!!
Following is the schedule for the beta program. So you can register now.
There is even going to be an introductory product demonstration prior to the code release. Something I have not personally seen the beta team do previously.
Visit here to register for the WFBS beta program, or for your beta account if you don't already have one.
Talk to you all soon.
Kieran
Following is the schedule for the beta program. So you can register now.
There is even going to be an introductory product demonstration prior to the code release. Something I have not personally seen the beta team do previously.
- June 14th, 2010 Registration (Go NOW! opens in a new window)
- July 26th, 2010 Product Demo via Webex
- July 28th, 2010 Beta Start - Download and Installation
- August 9th, 2010 Customer on-site visits
- Sept. 15th, 2010 Beta Program Closing
- Sept. 22nd, 2010 Beta Program Ends
- Scan Mail for Exchange v10 (SMEX10) technology integration
- Scan Mail for exchange is the stand-alone enterprise solution for Exchange Server. I don't know exactly how much of the technology will be integrated at the WF-Message Security Agent level, however some of the key enhancements to SMEX10 are:
- Exchange 2010 support
- Web Reputation Filter
- Data Loss Prevention Policies
- Resource (CPU) Management
- AD Integration & Role Based Access
- Data loss prevention
- This will be a "lite" version of our corporate DLP solution.
- A few pre-fabricated Loss Prevention Rules
- Device Access Control
- I expect this will be similar to what is currently in Officescan v10. That is, placing read/write/execute access at the device controller level.
- Uniclient + AMSP
- Uniclient and Anti-Malware Solution Platform are key components to lowering the overall footprint of WBFS. I have been told that the dev team behind the project have been set a VERY aggressive footprint reduction target.
- Macintosh Support
- FINALLY - we will be using the Plug-in architecture that was borrowed from the Officescan product! A Mac client will be enabled for use in the WFBS architecture.
- New customized installation and deployment
- This will be revealed at the webex demo on the 26th
Visit here to register for the WFBS beta program, or for your beta account if you don't already have one.
Talk to you all soon.
Kieran
Tuesday, June 8, 2010
WFBS 6 Service Pack 2 Best Practices!
Hi there guys.
See... this is the benefit of a blog over the email newsletter! Quick updates.
You'll find the document at:
TREND MICRO - Worry-Free Business Security 6.0 SP2 Best Practices Guide
Enjoy, and I trust this will help with any possible configuration questions.
regs
Kieran
See... this is the benefit of a blog over the email newsletter! Quick updates.
You'll find the document at:
TREND MICRO - Worry-Free Business Security 6.0 SP2 Best Practices Guide
Enjoy, and I trust this will help with any possible configuration questions.
regs
Kieran
Monday, May 31, 2010
Worry Free Business Security v6.0 SP2
SP2 stand-alone can be implemented directly onto a WFv6.x server install.
WFBS 6 SP2 repack can be installed directly onto WF5.x and below servers'
Now, what's new in Service Pack 2?
WFBS 6 SP2 repack can be installed directly onto WF5.x and below servers'
Now, what's new in Service Pack 2?
- Low-Impact Smart Scan Pattern Update Mechanism - To reduce the impact of updates to Security Server performance, certain resource-intensive processes have been moved to Trend Micro servers in the cloud.
- Adjustments to Behaviour Monitoring and the Firewall - for Performance Behaviour Monitoring is now disabled by default on Clients in server groups, while the Firewall remains disabled by default on all Clients and is now completely removed from the servers! Upgrading to Service Pack 2 automatically adjusts both features on all Clients in existing server groups.
- UNC Paths on Behaviour Monitoring Exception List - Protects end-points from programs that run from network folders.
- Cleanup Mechanism After Updates Disk Cleaner - cleanup tool removes remnant files automatically every time the Security Server updates. The tool can also be run manually to clean up the Security Server.
Other Enhancements
- Reduced frequency of security status reporting to Worry-Free Remote Manager to enhance performance
- Seat count threshold for displaying warnings on the Live Status screen has been changed to 100%.
- Wording changes on the Messaging Security Agent installation screen to cover User Access Control on Windows™ Small Business Server 2008
So, what does all this mean...
We had lots of feedback from you, the partner community regarding issues you had experienced with V5 and V6 of WFBS...
The main ones being
- Bloating - Install size getting too large
- Upgrade not being "worry free"
- Issues with the Message Security Agent (MSA) Install
- Default Config not providing optimal performance
We did some testing on SP2 internally. Some of you will be familiar with Anthony Edwards and his field services team. They are a dedicated, highly technical group of people. They were tasked with putting SP2 through the wringer to ensure it met our expectations for the local market. It passed with flying colours.
Addressing the specific issues mentioned above:
- The scope of the SP2 project was never to reduce the overall size of the product. This is a project which is currently being worked on for WF v7 - the good news with this is that they are going back to the drawing board and re-architecting the entire product to make is slick! I personally have high expectations from this project! We are setting ourselves lofty goals, and I think they will be achieved!
- Anthony and his team found the upgrade from v5, and v6 to v6 SP2 to be simply flawless! They were unable to generate any errors.
- The MSA too, installed flawlessly - they were not able to fault it, even when they tried!
- The performance of the default configuration has been greatly improved too - the issues seems to lie specifically with the firewall on the servers - SP2 removes the FW completely from the servers, and in doing so removes any perfmormance impact that was previously being encountered at the server level.
So overall, WF6 SP2 addresses the majority of challenges experienced by our channel and customers. The results of the tests meets the expectations set from the SP. Some minor issues still require further investigation and troubleshooting outside the scope of concerns presented, and there are some issues which still need to be addressed which were not part of the scope of SP2.
I hope this has been informative for everone - and trust you all have a great week!
Learning Management System
Did you know that Trend Micro ANZ partners have access Trend Micro’s Online Training at http://trendmicro.CyberU.com
This site is a wonderful resource containing Sales Training and Level 1 and 2 technical training.
If you haven’t registered, do it now and have a look around – If you register as sales and pre-sales – you will gain access to all the appropriate certification/courses/exams.
If you have already registered, and do not have access, or your getting a bit lost on the site – call or email the Channel Management team on AU:1800 653 870 or NZ:0800 408 065 or channel_support@trendmicro.com.au
This site is a wonderful resource containing Sales Training and Level 1 and 2 technical training.
If you haven’t registered, do it now and have a look around – If you register as sales and pre-sales – you will gain access to all the appropriate certification/courses/exams.
If you have already registered, and do not have access, or your getting a bit lost on the site – call or email the Channel Management team on AU:1800 653 870 or NZ:0800 408 065 or channel_support@trendmicro.com.au
NSS Labs Report
FINALLY a TRUELY INDEPENDANT REPORT!!!!
If you are like me - you trust comparative reports as far as you can scrunch them up into a ball and throw them!
This report is different. Why? Because the testing company is different! NSS Labs is like the Choice magazine of the Global IT industry. They are not sponsored by the vendors they test. They are a customer led subscription service to enable their customers to make the best vendor agnostic decisions on specific topics.
NSS Labs compared leading endpoint security solutions using "real world" testing methods that go beyond simple detection to provide an unbiased report of security performance. These independent test results prove the Trend Micro’s Smart Protection Network provided the best protection. OfficeScan 10 ranked #1 in both socially engineered malware protection and "time to protect."
A snip from the report:
“During July and August, 2009 NSS Labs performed the industry’s most real-world test of anti-virus / endpoint protection suites against socially engineered malware. NSS Labs’ Live Testing measures products against the most current threats as a user would experience them: not against stale or questionable samples in a closed lab environment, like other tests. The results presented here are based upon empirically validated evidence gathered during 17 days of 24x7 testing, performed every 8 hours, over 59 discrete test runs, each one adding fresh new malware URLs. Each product was updated to the most current version available at the time testing began, and allowed access to the live Internet during the entire course of the test.”
Now – given the phenomenal results in Trend’s favour in this report - we have paid a big sum of money for people to gain free access to the report which would otherwise cost a couple of grand to access. – So click on this link as a stepping stone to NSS to access the report:
http://www.trendmicro.com/nss
Once there – there is a Consumer product report and a Corporate Product report.
Click on “Read the Report”
Fill in the First Name, Last name etc etc – and whammo! Access Granted!
USE THIS REPORT WHEN TALKING WITH YOUR CUSTOMERS!!!!
If you are like me - you trust comparative reports as far as you can scrunch them up into a ball and throw them!
This report is different. Why? Because the testing company is different! NSS Labs is like the Choice magazine of the Global IT industry. They are not sponsored by the vendors they test. They are a customer led subscription service to enable their customers to make the best vendor agnostic decisions on specific topics.
NSS Labs compared leading endpoint security solutions using "real world" testing methods that go beyond simple detection to provide an unbiased report of security performance. These independent test results prove the Trend Micro’s Smart Protection Network provided the best protection. OfficeScan 10 ranked #1 in both socially engineered malware protection and "time to protect."
A snip from the report:
“During July and August, 2009 NSS Labs performed the industry’s most real-world test of anti-virus / endpoint protection suites against socially engineered malware. NSS Labs’ Live Testing measures products against the most current threats as a user would experience them: not against stale or questionable samples in a closed lab environment, like other tests. The results presented here are based upon empirically validated evidence gathered during 17 days of 24x7 testing, performed every 8 hours, over 59 discrete test runs, each one adding fresh new malware URLs. Each product was updated to the most current version available at the time testing began, and allowed access to the live Internet during the entire course of the test.”
Now – given the phenomenal results in Trend’s favour in this report - we have paid a big sum of money for people to gain free access to the report which would otherwise cost a couple of grand to access. – So click on this link as a stepping stone to NSS to access the report:
http://www.trendmicro.com/nss
Once there – there is a Consumer product report and a Corporate Product report.
Click on “Read the Report”
Fill in the First Name, Last name etc etc – and whammo! Access Granted!
USE THIS REPORT WHEN TALKING WITH YOUR CUSTOMERS!!!!
Subscribe to:
Posts (Atom)




