Trend Micro Antivirus

Topics: Technical Issues
Jan 17, 2015 at 5:58 PM
Edited Jan 17, 2015 at 5:59 PM
Reopened the issue:

New Info:
I have now done hell of a lot of testing on this issue.. Because I still have it.. I have a Verbatim Store N Go 1tb, encrypted (AES and Whirlpool hash). I can't mount it when the antivirus is running.. (trend micro worry free business security)

If I "kill" the AV, then it works and the drive get mounted perfect. But when it is running, it freezes..

So I'm sure that I have isolated it to be the Trend Micro AV whitch is the problem..

I hope it will narrow down the "window" of the problem.

Any one else using Trend Micro?
Jan 17, 2015 at 10:27 PM
Thank you for your update.

Unfortunately I don't think there is much that can be done from VeraCrypt side. As shown by the issue linked to Symantec product, some Antivirus tend to use some unsupported ways of handling things and when Microsoft pushes some obscure update, they start to have issues.
In case of Symantec, it was a BSOD so their engineers were forced to look at it and they admitted that this is their fault and they announced that they are working on a fix:

As a workaround, they asked users to mount volumes as readonly to avoid this issue. Can you please check if this has some effect in your case?

Of course, it can be very helpful if Trend Micro engineers could look at this issue since it will easy for them to pinpoint the origin of the freeze. Is it possible to open a ticket with them?

From my side, I don't have access to this Antivirus so i can't test or debug. Maybe since the PC freezes, there is some entry for this in Windows EventViewer. Can you please look and see if anything is logged when the freeze happens?

Jan 18, 2015 at 9:30 AM
After some testing, it sounds like it is the "same" problem as with Symantec. It works if it is mounted as "Read only". If I kill Trend Micro while I mount the drive "normaly", then it also works.

I will try contacting Trend Micro for a solution.

There is no "errors" in the "event log". The only thing is the "system was not shutdown normaly" - but ofcause, I "kill" the machine by taking the power :-)
Jan 18, 2015 at 8:03 PM
Thanks for taking the time to report and investigate this destrukt, very helpful.

Stay paranoid ! :)