Hi
drragostea,
I'll predicate my remarks by stating that I am no expert when it comes to Runtime Environment protocols and the applets/activeX components to which they tend to serve as "container".
You are probably right when observing: "something may be going on that I am not aware of."
However, it probably has much more to do with the developing relationships between Sun Micro Systems, JAVA, Runtime Environments and the various online utilities such as Trend Micro, Symantec, MalwareBytes, Panda, Avir, Kaspersky and others…. than it has to do with your own machine.
Running online scanners has historically been a headache. Sometimes the application would load and run the very first time after accepting ActiveX, and sometimes it would take multiple times to install the ActiveX, whether or not the application eventually loaded and scanned your machine.
There are few "time wasters" that have frustrated me more than attempting to run an online scan, only to eventually declare defeat and then go search out another scan utility. It has been especially frustrating, because when one has the need to run an online scan, one is already frustrated and suspicious of nearly everything about the machine, the net, and whatever may be producing an aberrant computing behavior.
Even if I am specifically wrong in my next speculation, it would make intuitive sense to consider.
Anti-malware scans are some of the most frequently accessed sites.
People accessing online scans have all varieties of OS/application/data/and potentially malware, installed on their machines.
Therefore it is highly important to make correct and secure "handshakes" (and containers) between people's machines and online scans.
So for the sake of "hypothetical" argument, let's suppose that last time you ran TrendMicro online, all went well.
Minutes, days, or weeks later you found need to run TrendMicro again on the same machine, or on a different machine, or on the same machine whose configuration had changed, whether or not your login changed.
Now throw into the mix, that TrendMicro will most likely have updated its database and heuristic engines.
So now what your machine (and the JAVA containers presently being used) will "see" is an entirely different download and engine executable when running an online scan this time, than what it just saw last time.
Imagine, if you will, the tremendous and frequent work that Sun Java has had to do to create "application containers" just for folks to run an online scan whenever they decide to do so. The updates, check-sums, and modifications would have to be an enormous task, just to keep current.
In the present circumstance, Sun Micro has an ongoing-good working relationship with Trend Micro, Symantec, MalwareBytes, Panda, Avir, Kaspersky and others, such that Sun Micro may have devised methods to "share" the certification and check-sum burden with the trusted application owners.
Thus, TrendMicro may have a proprietary access permission structure with JAVA Sun, so that TrendMicro can do some internal verification/certification of updates, etc. and run with special privilege with respect to the "Rules" that would otherwise be applied diligently in the cases of various lesser known or even home-made JAVA applets/ActiveX components.
The above is "simply how I think about" the circumstance into which you inquire.
I have no hard data, nor any source from which I am drawing.
However, here is a Sun Micro discussion of the Rules and their applications:
http://java.sun.com/blueprints/qanda/ejb_t…strictions.html
Hope this helps.
As for experts who may read this, I stand ready to be corrected as necessary.
Best Regards,
Doug