- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Dealing with a malware infection issue
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dealing with a malware infection issue
Hello,
we have recently been using the EPS 86.20 Client.
In order to test the correct functionality of the virus protection, we downloaded the EICAR test virus.
The EPS detects the malware but takes no action. In this case, the file should be quarantined if a cure cannot be performed.
The file remains on the computer and can be run.
The infection status is Untreated and the file has not been Quarantined.
The same problem occurs with Riskware as well.
Why isn't the malware moved to quarantine?
Does Checkpoint have a best-practice setting here?
Thanks for your answers.
- Labels:
-
Threat Emulation
-
Threat Extraction
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have now found the solution to the problem.
Forensics Analysis Model: I have now set the "Quarantine"
setting here. The setting "Nothing" was previously stored here.
According to File Reputation, the file is now being quarantined.
However, the "Untreated" message in the Anti-Malware Blade remains "Cleaned Failed"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
General best practices are covered in sk154052, but doesn't appear to get this specific for Anti-malware.
@jcortez Any thoughts on the quarantine behaviour, other than a client who's policy was changed and not up to date?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have now found the solution to the problem.
Forensics Analysis Model: I have now set the "Quarantine"
setting here. The setting "Nothing" was previously stored here.
According to File Reputation, the file is now being quarantined.
However, the "Untreated" message in the Anti-Malware Blade remains "Cleaned Failed"
