Trend Micro Office Scan blocks uploads as malicious

Questions and Answers : Windows : Trend Micro Office Scan blocks uploads as malicious
Message board moderation

To post messages, you must log in.

AuthorMessage
bill

Send message
Joined: 6 Jan 00
Posts: 4
Credit: 402,746
RAC: 0
United States
Message 866102 - Posted: 16 Feb 2009, 13:30:30 UTC

Our University uses Trend Micro Office Scan and in the last few weeks it keeps blocking boinc uploads as High Risk Malicious. Any idea on how to avoid this? The example is astropulse but I believe it has also been seti. No problem at home where I use a different application.

Trend Micro Web Reputation - Feedback Submission Form
URL*: http://boinc2.ssl.berkeley.edu.nyud.net/sah/download_fanout/coral/astropulse_5.03_windows_intelx86.exe
Current rating: This URL is currently listed as malicious.

Trend Micro Web Reputation Query - Online System
Type a website in the field below to:
• Check its reputation ranking/score
• Submit feedback about a certain website
Complete website*:
Only HTTP and HTTPS are supported. (e.g., http://www.trendmicro.com)
Web reputation result: This URL is currently listed as malicious.
ID: 866102 · Report as offensive
Profile arkayn
Volunteer tester
Avatar

Send message
Joined: 14 May 99
Posts: 4438
Credit: 55,006,323
RAC: 0
United States
Message 866143 - Posted: 16 Feb 2009, 15:49:17 UTC

It is flagging it because they have it on a round robin server instead of straight off the normal server. SETI does it with all new application releases to relieve the pressure on the normal server.

http://boinc2.ssl.berkeley.edu.nyud.net

The key is the bolded part, Trend Micro thinks that the it is malicious because of the URL redirect.

try this one as a direct download and then install it manually.

http://boinc2.ssl.berkeley.edu/sah/download_fanout/astropulse_5.03_windows_intelx86.exe

ID: 866143 · Report as offensive
bill

Send message
Joined: 6 Jan 00
Posts: 4
Credit: 402,746
RAC: 0
United States
Message 866181 - Posted: 16 Feb 2009, 18:11:08 UTC - in response to Message 866143.  


Trend Micro OfficeScan Event




URL Blocked



Apparently the system adds the same info to the URL and gives me the same block. I tried it by clicking the link, typing the link, and copying to text file and then copy/paste the link.

The URL that you are attempting to access is a potential security risk. Trend Micro OfficeScan has blocked this URL in keeping with network security policy.

URL: http://boinc2.ssl.berkeley.edu.nyud.net/sah/download_fanout/coral/astropulse_5.03_windows_intelx86.exe








ID: 866181 · Report as offensive
Profile arkayn
Volunteer tester
Avatar

Send message
Joined: 14 May 99
Posts: 4438
Credit: 55,006,323
RAC: 0
United States
Message 866199 - Posted: 16 Feb 2009, 19:08:52 UTC

I just went into the file server and clicking on the link it redirects to the other server as well.

Usually you have to wait for a week before they remove the redirect or talk the campus IT personnel into adding the url to the approved list(like that will happen).

ID: 866199 · Report as offensive
bill

Send message
Joined: 6 Jan 00
Posts: 4
Credit: 402,746
RAC: 0
United States
Message 869060 - Posted: 24 Feb 2009, 16:33:43 UTC

Suddenly today 2 Astropulse tasks downloaded through the Office Scan. I have no idea - maybe they accepted my request citing the NSF funding etc for Boinc.
ID: 869060 · Report as offensive
Aurora Borealis
Volunteer tester
Avatar

Send message
Joined: 14 Jan 01
Posts: 3075
Credit: 5,631,463
RAC: 0
Canada
Message 869064 - Posted: 24 Feb 2009, 16:45:47 UTC - in response to Message 869060.  

Suddenly today 2 Astropulse tasks downloaded through the Office Scan. I have no idea - maybe they accepted my request citing the NSF funding etc for Boinc.

More likely. Seti turned off the redirect temporarily to stop the DOS effect on the servers.
ID: 869064 · Report as offensive
Profile arkayn
Volunteer tester
Avatar

Send message
Joined: 14 May 99
Posts: 4438
Credit: 55,006,323
RAC: 0
United States
Message 869174 - Posted: 25 Feb 2009, 1:46:10 UTC - in response to Message 869060.  

They turned off the coral cache yesterday morning to help the server overload problem.

ID: 869174 · Report as offensive
John McLeod VII
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 15 Jul 99
Posts: 24806
Credit: 790,712
RAC: 0
United States
Message 869195 - Posted: 25 Feb 2009, 3:02:17 UTC - in response to Message 869174.  

They turned off the coral cache yesterday morning to help the server overload problem.

The Coral Cache was supposed to help with bandwidth problems, but too many ISPs and firewalls block redirected downloads, causing more usage of bandwidth instead of less bandwidth usage.


BOINC WIKI
ID: 869195 · Report as offensive

Questions and Answers : Windows : Trend Micro Office Scan blocks uploads as malicious


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.