We started getting the following Application Events on our Trend OfficeScan servers, mixed 2003 and 2008
Event Fault:
EVENT LOG Application
EVENT TYPE Warning
SOURCE Trend OfficeScan Server
CATEGORY System
EVENT ID 900
USERNAME NT AUTHORITY\SYSTEM
COMPUTERNAME BIMJHBFP
DATE / TIME 2/20/2012 6:23:17 AM
MESSAGE Error Message: The digital signature of the following file is invalid. OfficeScan server has renamed the file to prevent OfficeScan file danamge.
C:\Program Files\Trend Micro\OfficeScan\PCCSRV\pccnt\COMMON\DWIoTrapNT.dll
RESOLUTION: [From Trend Micro]
Short:
As a workaround for this issue , you may disable check of digital signature on the files on the officescan server.
1. Set “CheckDigitalSignatureForHotfix” to ‘0’ in …\PCCSRV\ofcscan.ini
2. Stop OfficeScan Master Service
3. Rename “DWIoTrapNT.dll_Invalid” to “DWIoTrapNT.dll”
4. Start OfficeScan Master Service
Full:
This message is to inform you that the solution for Service Request ID 1-365450963 has been delivered.
SR Solution: Officescan server is designed to enumerate client files (a pre-defined list hardcoded in codes) and check digital signatures of the files and if any file has invalid digital signature or no digital signature, it will Rename/move the corrupt files.
The reported issue is caused by 10.6 GM DWIoTrapNT.dll’s digital signature is invalid. The Code signing certificate for this file expired on 16/02/2012 . Hence Officescan server renames it to *._invalid.
The issue is currently being handled by the product developement team and will be fixed by a hotfix to be released soon.
ETA for the related hotfix is 29-Feb , 2012
As a workaround for this issue , you may disable check of digital signature on the files on the officescan server.
1. Set “CheckDigitalSignatureForHotfix” to ‘0’ in …\PCCSRV\ofcscan.ini
2. Stop OfficeScan Master Service
3. Rename “DWIoTrapNT.dll_Invalid” to “DWIoTrapNT.dll”
4. Start OfficeScan Master Service
5. Deploy OSCE client
Once the hotfix is available and installed , you may enable the above feature again.
