> Source: [sk163658](https://support.checkpoint.com/results/sk/sk163658)

# sk163658 - A host is reported by the SMB appliance as "infected" or "possibly infected" even though it was scanned and protected by an Endpoint protection

| Property | Value |
|----------|-------|
| Solution ID | sk163658 |
| Date Created | 2019-12-31 |
| Last Modified | 2022-07-21 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800, 910 |

## Symptoms

- The SMB appliance detects and blocks a malicious activity of a host and reports it as "`infected`" or "`possibly infected`". However, the host was scanned and protected by an Endpoint protection (Check Point or a 3rd party agent) which did not find or block any malicious activity.

## Cause

The above symptom can be caused by the following causes:

1. The host tried to access a malicious site or download a malicious file, and as a result, the SMB appliance blocked that connection. Therefore, no malicious packets arrived at the host to be found.
2. The malicious activity, which the SMB appliance blocked, might have been a False-Positive.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
