Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Diego_Vigano
Participant
Jump to solution

Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Hi,

yesterday, during automatic scheduled update, a protection named "Trojan.Win32.Password-Unencrypted.A" was installed blocking all http connection.

As a workaround I change the protection from "prevent" to "detect".

Now, I can't find the protection in my database nor in the wiki, what's happened? How can I know if hte protection was retired?

kr,

Diego

1 Solution

Accepted Solutions
Diego_Vigano
Participant

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

View solution in original post

0 Kudos
13 Replies
Omer_Shliva
Employee
Employee
 
0 Kudos
jgaikwad
Explorer

Having this same issue today and was stumped when I couldnt find the protection at all.  Guessing I just need to reinstall policy and it will be fixed.

0 Kudos
miguel
Participant

This impacted our network greatly as well. Will be opening a ticket to get a RCA. In the meantime, any details that can be shared here how this could have happened?

0 Kudos
Diego_Vigano
Participant

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

0 Kudos
Omer_Shliva
Employee
Employee
 
0 Kudos
Diego_Vigano
Participant

I can't because now the protection is not in the list, anyway as in the samples below, i searched for the protection and changed Prevent to detect:

bot.jpg

0 Kudos
miguel
Participant

The action taken was "Redirect", I'm happy to share screenshot privately, I have support case number if you want.

phuocle
Explorer

I get the same problem. How can we solve this?

0 Kudos
RickLin
Advisor
Advisor

If you search and can find it, just change the Protection action from Prevent to Detect base on your Threat Prevention Profile.

Remember to install Threat Prevention policy to apply it.

It work for my customer at Monday.

1.png

0 Kudos
TP_Master
Employee
Employee

Hi all,

After getting reports of issues with this protection it was removed from the Anti-Bot package, hence the fact you can't see it now when searching. Anyway it will not return in its current form.

 

HTH

Diego_Vigano
Participant
All,
I showed the solution in my first post (change the protection to "detect"), I rather wondered why it was not present in the Anti-BOT wiki on this link https://threatwiki.checkpoint.com/threatwiki/public.htm

I think it would be correct to flag it as a "retired" (similar as in the Microsoft's patches) and wrote something in the knowledgebase.
 
Consider that the impact on our company has been remarkable ...
0 Kudos
jboco
Explorer

Hi All,

I had the same issue last Monday, May 20th, 2019. But when I'm looking into the Protection list. I can't find it anymore?

Did anyone confirm if the protection has been retired?

KR

 

0 Kudos
Omer_Shliva
Employee
Employee

This protection is no longer part of the Anti-Bot dynamic package.

 

Omer Shliva | Team Leader, AB Research Protections and IPS/AB Customer Focus Team

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events