New Update Trend Micro home products version 17.9

Trend Micro
44 Replies 9,128 Views
Well, I tried 2 samples. The first one was missed, only an injection attempt (using ZwWriteVirtualMemory which is very well known to be associated with code injection) was blocked. So malware wasn’t allowed to inject, but the original file was running in memory.

Second sample I tried, I appended bytes to it.
First of all, the inventors of the TLSH don’t make proper use of it, few new bytes voided TM detection.
Secondly, executing the sample produced no detections or blocks.

Both samples were realistically downloaded, nothing was tested from desktop.

For both, there was the New File Warning (maybe it can be counted as user-dependent).

However, from my very long-standing tests of McAfee, executables are not a problem for it. Neither are some small, incremental changes to the file.
 
Well, I tried 2 samples. The first one was missed, only an injection attempt (using ZwWriteVirtualMemory which is very well known to be associated with code injection) was blocked. So malware wasn’t allowed to inject, but the original file was running in memory.

Second sample I tried, I appended bytes to it.
First of all, the inventors of the TLSH don’t make proper use of it, few new bytes voided TM detection.
Secondly, executing the sample produced no detections or blocks.

Both samples were realistically downloaded, nothing was tested from desktop.

For both, there was the New File Warning (maybe it can be counted as user-dependent).

However, from my very long-standing tests of McAfee, executables are not a problem for it.
Would a "normal" user user come up against that though, in the normal "I visit approximately 10-15 known sites a day" as is my case, and am only downloading Mullvad exe., Trend Micro.exe, NPE.exe, etc. type of files?
 
Would a "normal" user user come up against that though, in the normal "I visit approximately 10-15 known sites a day" as is my case, and am only downloading Mullvad exe., Trend Micro.exe, NPE.exe, etc. type of files?
I don’t think it will be a problem for you, but these small details paint bigger pictures… if you know what I mean. Appending these bytes also tests the static analysis as it produces a “low prevalence” file.
 
Of gaps and holes where things could go downhill more easily, compared to McAfee, Norton, Kaspersky etc.?
Exactly, a few other things about Trend design which I don’t really understand:

New malware hashes collected in a pattern: Instead of immediately adding classified malware hashes to a massive cloud database, Trend Micro adds them to a pattern updated every 4 hours. This causes additional delays. Trend Micro also regularly cleans this pattern.

A change of a single byte voids the detection and restarts the whole collect-classify-update process.

Behavioural blocking very often just terminates without performing proper remediation. I went and checked the logs (there are more logs in addition to the history on the UI) to find out that the offending sample performing injection was classified as “suspicious” but for some reason was given a “silent pass”. Why???

I can only classify these as “little design hiccups”.

It’s just not the way I like things done 🤷🏻‍♂️

Hence I am developing my own remediation and detection toolkit that goes very deep when remediating (even deleting empty folders, sibling files, scheduled tasks and so on).

Probably for many users it won’t be a problem.
 
Just found the release notes for 17.9 on the Japanese site: サポート情報 : トレンドマイクロ.

I must say I am a little disappointed. No new protection features.

1760126782151.png
 
Just found the release notes for 17.9 on the Japanese site: サポート情報 : トレンドマイクロ.

I must say I am a little disappointed. No new protection features.

View attachment 291802
VSAPI and ATSE 25 are implemented. These have separate release notes. But from what I saw (could be due to some false positives mitigation or performance enhancements) 25 performs worse than 24. Overall, very disappointing. And there won’t be a new engine till May next year.

The UI is faster and more animated on a positive note. The “add more devices” icon now has shine added to it. But protection doesn’t shine.
 
Well, I tried 2 samples. The first one was missed, only an injection attempt (using ZwWriteVirtualMemory which is very well known to be associated with code injection) was blocked. So malware wasn’t allowed to inject, but the original file was running in memory.

Second sample I tried, I appended bytes to it.
First of all, the inventors of the TLSH don’t make proper use of it, few new bytes voided TM detection.
Secondly, executing the sample produced no detections or blocks.

Both samples were realistically downloaded, nothing was tested from desktop.

For both, there was the New File Warning (maybe it can be counted as user-dependent).

However, from my very long-standing tests of McAfee, executables are not a problem for it. Neither are some small, incremental changes to the file.
Have you tested the same two samples on Hypersensitive Mode? Any difference?
 
The number of findings I have reported to Trend… some have been acted on. All in all, an inconsistent product.
Honestly, I really like Trend Micro and it is one of the least bloated products out there. Its web protection is one of the best (especially phishing) . I'm sure it is not perfect but no other products are perfect either, so if it works for you then keep using it.

The antivirus market has lost it. Most products have become Malware themselves and I'm here talking about Avira and its alikes.

As for the technical details, I am not an expert and I'm sure you know better in that regard, so thank you again for your efforts.
 
I tested the new version of Trend Micro for a month. The detection was poor. I had hopes that the new behaviour blocker would protect the system better but alas...
Also the Trend Micro Toolbar extension is still not available in Firefox.

I like the UI and different modules. Feels light on the system and have some nice features.
 
VSAPI and ATSE 25 are implemented. These have separate release notes. But from what I saw (could be due to some false positives mitigation or performance enhancements) 25 performs worse than 24. Overall, very disappointing. And there won’t be a new engine till May next year.

The UI is faster and more animated on a positive note. The “add more devices” icon now has shine added to it. But protection doesn’t shine.

I tested the new version of Trend Micro for a month. The detection was poor. I had hopes that the new behaviour blocker would protect the system better but alas...
Also the Trend Micro Toolbar extension is still not available in Firefox.

I like the UI and different modules. Feels light on the system and have some nice features.

i.e. a "skinnable" Winamp player without the protection, what a shame.
 
TrendMicro Maximum Security provides a smooth and lightweight experience. My system always feels fast and responsive with it installed. One of the standout features is that after your first scan, TrendMicro marks safe files so they won’t be scanned again in the future. This makes subsequent full scans much quicker, as only new or changed files are checked. Additionally, TrendMicro offers solid protection with its behavior blocker and suspicious file detection. It's also an affordable option, with keys often available online at discounted prices. TrendMicro will allow you to key-stack. I would also suggest going through all the settings and setting them on high for maximum protection.

Screenshot 2026-02-21 191451.pngScreenshot 2026-02-21 191501.pngScreenshot 2026-02-21 191530.pngScreenshot 2026-02-21 191708.png
 
i really love trend but its antivirus skills are not on par with other av-s like norton avast or bidefender. there is something really obnoxious about them not really doing something. I still have licenses and uses them once in a while but my paranoid self does not feel safe also for the fact that they realy so heavily on the web detections
 
Trend is a lovely product but it needs to be updated to compete with the others (not the UI but the protection). And also fixing the bugs faster. It took ages for the new Firefox extension. The program is running smooth and have no bloatware such as VPN and other "crap" modules.

Since the new version there is an issue with the brower exploit module in combination with Firefox. It consumes a lot of CPU and memory.

1784752672160.png


The problem is the script scanning option.
1784752804978.png


On Windows 11 the folder shield option cannot select hidden folders such as AppData. I used that to protect additional folders. There is no problem on Windows 10 (extended support and LTRS version). I can bypass the bug with attrib -h "C:\Users\<profileName>\AppData", add the folders to the folder shield and restore the attritute option with attrib +h "C:\Users\<profileName>\AppData".

On the other hand it recent surprised me in a positive way. I tested some samples and Trend Micro did it very well compared to earlier this year.
 
I contacted Trend Micro about the 2 issues.

First the Firefox issue. The anwer:
"The websites you reported may be generating a high volume of script execution events that Trend Micro scans and evaluates against potential threats, which may be causing the performance issue. Solution: add the websites to the exception list." That is not a solution for me but a bypass. It is a bug because there are no issues with the same sites in Edge and Chrome.

Second about the folder shield. The answer:
"The hidden folders cannot be added to the folder shield. This is by design for the following reasons:
to prevent accidental shielding of critical system folders that are essential for your operating system and applications to function correctly.
to avoid performance issues that may arise from protecting deeply nested or heavily used system directories."
I can following their reasons but strange that it works on Windows 10 with the same Trend Micro version.

So Trend Micro is off the list for my new install base at the moment.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top