Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Troubleshooting Event Monitoring false detections

    • Updated:
    • 20 Sep 2018
    • Product/Version:
    • OfficeScan 11.0
    • OfficeScan XG.All
    • Platform:
    • N/A N/A
Summary

Learn what to do when events being monitored are triggered by non-malicious applications.

Details
Public

Event Monitoring provides a more generic approach to protecting against unauthorized software and malware attacks. It monitors system areas for certain events, allowing administrators to regulate programs that trigger such events.

These are the events that can be monitored:

  • Duplicated System File
  • Hosts File Modification
  • Suspicious Behavior
  • New Internet Explorer Plugin
  • Internet Explorer Setting Modification
  • Security Policy Modification
  • Program Library Injection
  • Shell Modification
  • New Service
  • System File Modification
  • Firewall Policy Modification
  • System Process Modification
  • New Startup Program

For more information regarding the events and the actions, please visit our Online Help article on Event Monitoring.

Events being triggered by non-malicious applications are perfectly normal. For example, if a user installs an application that creates a startup entry, it will trigger the event New Startup Program provided that the application is not yet on our whitelist.

When this happens, you can add the application to Behavior Monitoring Exception List or submit it to us for whitelisting. Please refer to KB 1115668 for the steps.

Premium
Internal
Rating:
Category:
Remove a Malware / Virus
Solution Id:
1121086
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.