Trend Micro Control Manager 5.0 Managing Clients and Groups @ NC State Joe_Wells@ncsu.edu
Background (people) Roles for Malware client deployments Neal McCorkle – OIT Security Tim Gurganus – OIT Security Joe Wells – OIT Systems and Hosted Services Ed Lee – OIT Learning Space Support
Background (Malware product line) Trend Micro Products in use: OfficeScan 8.0 for Windows Control Manager 5.0 ServerProtect (NetWare / Linux) Web Threat Protection for Desktops Web Threat Protection for Servers Damage Cleanup Services
Trend Micro’s free products TrendMicro Housecall http://www.trendsecure.com/portal/en-US/tools/security_tools/ TrendMicro™ HijackThis http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download TrendMicro sysclean (NCSU bundled) http://www.ncsu.edu/antivirus/files/sysclean.exe TrendMicro TMVS (who’s running TMOS) http://www.ncsu.edu/antivirus/files/utilities/TMVS.zip
Key points to the workshop Background Client review Dashboard Portal to OS vs CM Searching within OS Clients and “Domains” Logs from groups Settings CM Ad Hoc Queries CM Reports CM Templates Contact & listserv Q/A
Obtaining the TMOS client (campus)
TMOS Client “Update Now” akin to running SAV LiveUpdate Services (automatic): tmlisten, ntrtscan Processes: ntrtscan, pccntmon, tmlisten, tmproxy, {random name in %TEMP%} with “Scottish Terrier”-like icon as OfcDog application TMOS icon’s status indicator: http://oit.ncsu.edu/antivirus/officescan-status-icons
Client Review Version. GUID. Parent. Firewall ports & communications: TCP 21264 and TCP 8080 for general client communications. TCP 443 and 4343 for administrative interaction; TCP 139, 1025 & 1026: AD Login
Trend Micro Officescan Local Console
Dashboard Getting there: Restrictions: https://avcm.ncsu.edu/WebApp/login.aspx Restrictions: IE only, due to ActiveX coding. Campus and VPN address range only.
Portal to OfficeScan parent vs Control Manager Layout of services AVCM - Control Manager. AV08 and AV09 – “On-Campus” parents. AV05, AV06 and AV07 – Off-Campus parents.
Portal to AV0? Searching for your client PCs. What is a Domain and how to use them. Moving clients to Domains. Moving clients to other TMOS servers (use Port 8080) Logs from Domains. Settings for Domains.
Control Manager Ad Hoc Queries. Reports. Templates.
Contact and communications Durpal site: http://xteams.oit.ncsu.edu/antivirus Mj2 email list: antivirusadmin Remedy: OIT_ANTIVIRUS Trend Micro Help and documents: http://esupport.trendmicro.com/enterprise/default.aspx Joe_wells@ncsu.edu