<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dealing with a malware infection issue in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/143198#M5306</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we have recently been using the EPS 86.20 Client.&lt;BR /&gt;In order to test the correct functionality of the virus protection, we downloaded the EICAR test virus.&lt;BR /&gt;The EPS detects the malware but takes no action. In this case, the file should be quarantined if a cure cannot be performed.&lt;BR /&gt;The file remains on the computer and can be run.&lt;BR /&gt;The infection status is Untreated and the file has not been Quarantined.&lt;BR /&gt;The same problem occurs with Riskware as well.&lt;/P&gt;&lt;P&gt;Why isn't the malware moved to quarantine?&lt;BR /&gt;Does Checkpoint have a best-practice setting here?&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screen1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15628i805E6B4381CC6BD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="screen1.png" alt="screen1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screen2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15629iBCCE7DB6F9F9E625/image-size/medium?v=v2&amp;amp;px=400" role="button" title="screen2.PNG" alt="screen2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 08:42:14 GMT</pubDate>
    <dc:creator>m25487</dc:creator>
    <dc:date>2022-03-08T08:42:14Z</dc:date>
    <item>
      <title>Dealing with a malware infection issue</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/143198#M5306</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we have recently been using the EPS 86.20 Client.&lt;BR /&gt;In order to test the correct functionality of the virus protection, we downloaded the EICAR test virus.&lt;BR /&gt;The EPS detects the malware but takes no action. In this case, the file should be quarantined if a cure cannot be performed.&lt;BR /&gt;The file remains on the computer and can be run.&lt;BR /&gt;The infection status is Untreated and the file has not been Quarantined.&lt;BR /&gt;The same problem occurs with Riskware as well.&lt;/P&gt;&lt;P&gt;Why isn't the malware moved to quarantine?&lt;BR /&gt;Does Checkpoint have a best-practice setting here?&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screen1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15628i805E6B4381CC6BD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="screen1.png" alt="screen1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screen2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15629iBCCE7DB6F9F9E625/image-size/medium?v=v2&amp;amp;px=400" role="button" title="screen2.PNG" alt="screen2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 08:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/143198#M5306</guid>
      <dc:creator>m25487</dc:creator>
      <dc:date>2022-03-08T08:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with a malware infection issue</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/143300#M5325</link>
      <description>&lt;P&gt;General best practices are covered in sk154052, but doesn't appear to get this specific for Anti-malware.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35245"&gt;@jcortez&lt;/a&gt;&amp;nbsp;Any thoughts on the quarantine behaviour, other than a client who's policy was changed and not up to date?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 01:44:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/143300#M5325</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-09T01:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with a malware infection issue</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/144045#M5384</link>
      <description>&lt;P&gt;I have now found the solution to the problem.&lt;BR /&gt;Forensics Analysis Model: I have now set the "Quarantine"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;setting here. The setting "Nothing" was previously stored here.&lt;BR /&gt;According to File Reputation, the file is now being quarantined.&lt;BR /&gt;However, the "Untreated" message in the Anti-Malware Blade remains "Cleaned Failed"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="check1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15751i3EBDE10A396AC2EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="check1.png" alt="check1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 13:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Dealing-with-a-malware-infection-issue/m-p/144045#M5384</guid>
      <dc:creator>m25487</dc:creator>
      <dc:date>2022-03-17T13:49:27Z</dc:date>
    </item>
  </channel>
</rss>

