Discussion:
Trend Micro Officescan for Win2k strange behaviour
Marco Monicelli
2004-07-14 09:28:24 UTC
Permalink
Hello List!

I've noticed the following "weird" behaviour of the Trend Micro Officescan
client vers. 5.58 update to pattern 1.936.00 Engine 7.100 for WinXP/2k/NT:

The AV client is protected for unloading the Realtime Scan agent prompting
for a password (which I don't know of course). Moreover I have NOT admin
rights which allows me to perform a full system scan but not to unload the
client and/or the realtime protection.
Playing with the "net" command on a DOS prompt, I found out that the AV
launches itself and the realtime prot as services automatically. Then I
tried to stop the services with the simple command

net stop "OfficeScanNT Listener"
net stop "OfficeScanNT RealTime Scan"

Guess what? The two services have been successfully stopped from my system.

What do you guys think of this? Should I advise the AV Company of this or
this is normal behaviour?

Tnx for feedback.

Ciao

Marco Monicelli
MARCEGAGLIA SPA
Automotive Sales Department
Stainless Steel Division
Tel. +39 0376 685369
Fax. +39 0376 685625
email: ***@marcegaglia.com
Seth Hall
2004-07-16 00:09:49 UTC
Permalink
This post might be inappropriate. Click to display it.
3APA3A
2004-07-16 09:12:08 UTC
Permalink
Dear Marco Monicelli,

--Wednesday, July 14, 2004, 1:28:24 PM, you wrote to ***@securityfocus.com:

MM> Playing with the "net" command on a DOS prompt, I found out that the AV

...

MM> net stop "OfficeScanNT Listener"
MM> net stop "OfficeScanNT RealTime Scan"

It's bug of any automated system. It's documented as "Kiddie with
elevated privileges can make any protection unusable". Windows is very
vulnerable to this problem.
--
~/ZARAZA
Ну а теперь, Уильям, хорошенько поразмыслите над данным письмом. (Твен)
Loading...