<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove ransomware pos infection in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24018#M3465</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Maybe worth to have a look here:&amp;nbsp;&lt;A href="https://www.nomoreransom.org/en/index.html" rel="nofollow noopener noreferrer" target="_blank"&gt;https://www.nomoreransom.org/en/index.html&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;Also this post is useful&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2363" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2363&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2019 09:12:07 GMT</pubDate>
    <dc:creator>Markusevc</dc:creator>
    <dc:date>2019-06-21T09:12:07Z</dc:date>
    <item>
      <title>How to remove ransomware pos infection</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24015#M3462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear colleagues,&lt;/P&gt;&lt;P&gt;We have a company in angola that got Ransomware and as expected had no backup. They contacted me asking for help to solve the problem.&lt;/P&gt;&lt;P&gt;Do we have any way to solve a post-infection with the end point?&lt;/P&gt;&lt;P&gt;We could sell, install the endpoint to remove the threat, but would it install with the infected machine?&lt;/P&gt;&lt;P&gt;As far as I know, after infecting if encrypted the files were already ... the only solution would be to remove the ransonware and protect it from happening any more.&lt;/P&gt;&lt;P&gt;What is the recommendation to clean the machines before installing the endpoint?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Jan 2019 14:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24015#M3462</guid>
      <dc:creator>Cipriano</dc:creator>
      <dc:date>2019-01-13T14:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove ransomware pos infection</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24016#M3463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, if the machine was already infected and the files were encrypted before Sandblast Agent was installed, there is nothing we can do in order to restore the encrypted files.&lt;/P&gt;&lt;P&gt;The best way would be to reimage the machine, and install the endpoint protection afterwards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Gal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Jan 2019 15:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24016#M3463</guid>
      <dc:creator>Gal_Carmeli</dc:creator>
      <dc:date>2019-01-13T15:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove ransomware pos infection</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24017#M3464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of ransomware was it? There are few decryptors out there based on leaked or reverse engineered by the researchers which can help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 10:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24017#M3464</guid>
      <dc:creator>Marcel_Afrahim</dc:creator>
      <dc:date>2019-01-27T10:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove ransomware pos infection</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24018#M3465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Maybe worth to have a look here:&amp;nbsp;&lt;A href="https://www.nomoreransom.org/en/index.html" rel="nofollow noopener noreferrer" target="_blank"&gt;https://www.nomoreransom.org/en/index.html&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;Also this post is useful&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2363" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2363&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:12:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-remove-ransomware-pos-infection/m-p/24018#M3465</guid>
      <dc:creator>Markusevc</dc:creator>
      <dc:date>2019-06-21T09:12:07Z</dc:date>
    </item>
  </channel>
</rss>

