<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PC infected in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33363#M1347</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the section security in monitoring indicates that there are two infected computers and 31 others that are probably infected. the antivirus is correctly activated but I do not understand why the posts could be infected?&lt;BR /&gt;I ran kaspersky antivirus but nothing was detected. so then and protect the machines with CP?&lt;/P&gt;&lt;P&gt;what is the difference between prevent and detect in the blade control and how can delet infected information in .InfectedHostsLogs?&lt;/P&gt;&lt;P&gt;pictures:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63411_infec1.PNG" style="width: 620px; height: 172px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63412_infec.PNG" style="width: 620px; height: 258px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Mar 2018 16:10:07 GMT</pubDate>
    <dc:creator>junior_kakou</dc:creator>
    <dc:date>2018-03-02T16:10:07Z</dc:date>
    <item>
      <title>PC infected</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33363#M1347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the section security in monitoring indicates that there are two infected computers and 31 others that are probably infected. the antivirus is correctly activated but I do not understand why the posts could be infected?&lt;BR /&gt;I ran kaspersky antivirus but nothing was detected. so then and protect the machines with CP?&lt;/P&gt;&lt;P&gt;what is the difference between prevent and detect in the blade control and how can delet infected information in .InfectedHostsLogs?&lt;/P&gt;&lt;P&gt;pictures:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63411_infec1.PNG" style="width: 620px; height: 172px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63412_infec.PNG" style="width: 620px; height: 258px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33363#M1347</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2018-03-02T16:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: PC infected</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33364#M1348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you've shown in the screenshot, it appears the machines in question accessed sites that are known to contain malware, which generally would only happen in one of two situations:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The PC has some malicious software loaded on it (e.g. because it was infected with malware)&lt;/LI&gt;&lt;LI&gt;It's a false positive&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You'd have to look closer into the logs to find out what site they accessed.&lt;/P&gt;&lt;P&gt;There are certain Anti-Bot protections that can only be "detected" due to the small number of packets involved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Mar 2018 02:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33364#M1348</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-03T02:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: PC infected</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33365#M1349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prevents means a session has been broken off prematurely by the firewall.&lt;/P&gt;&lt;P&gt;Detect means it just saw something suspicious but it was not stopped by the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Botnet activity could just be a DNS query that point to a suspected host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a rule of thumb I find these overviews a bit confusing. Just get into the relevant logs and see what details you get there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 08:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PC-infected/m-p/33365#M1349</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-03-05T08:55:32Z</dc:date>
    </item>
  </channel>
</rss>

