ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Webroot folder in Program Data is ~48GB!!!

    IT Discussion
    4
    22
    5.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RojoLocoR
      RojoLoco
      last edited by

      Ok, @Nic , today's 6 million dollar question is a 2-parter:

      1. Why is my WRData folder so huge? (it's all 1 file, db9598db.db)

      2. Can I delete that file?

      1 Reply Last reply Reply Quote 1
      • NicN
        Nic
        last edited by

        Probably a process is getting monitored. It saves a record of all changes when that is happening, in case it need to roll back. Check the processes being watched to see if any are in monitored status.

        Yes you can delete the folder and it will get recreated.

        JaredBuschJ RojoLocoR 2 Replies Last reply Reply Quote 1
        • JaredBuschJ
          JaredBusch @Nic
          last edited by

          @Nic said:

          Probably a process is getting monitored. It saves a record of all changes when that is happening, in case it need to roll back. Check the processes being watched to see if any are in monitored status.

          Yes you can delete the folder and it will get recreated.

          In that case I would be scared that something is doing something bad.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            have you been hit by crypto something?
            for your sake I hope not.. but at the same time.. if yes... then Webroot is currently saving you.

            RojoLocoR 1 Reply Last reply Reply Quote 0
            • RojoLocoR
              RojoLoco @Nic
              last edited by

              @Nic The whole folder? Also, what would be getting monitored that is so huge? I've only been running SW network monitor on that box.

              1 Reply Last reply Reply Quote 0
              • DashrenderD
                Dashrender
                last edited by

                in the case of something like cryptoware - webroot would be making a backup copy of all encrypted files before it allows the virus to encrypt them.

                1 Reply Last reply Reply Quote 0
                • NicN
                  Nic
                  last edited by

                  typically it's something innocuous that we haven't seen before, and it doesn't need to be monitored. If you recognize the process and know it is good then go ahead and whitelist it. If you aren't sure support would be happy to take a look at it.

                  1 Reply Last reply Reply Quote 1
                  • RojoLocoR
                    RojoLoco @Dashrender
                    last edited by

                    @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

                    DashrenderD 1 Reply Last reply Reply Quote 0
                    • NicN
                      Nic
                      last edited by

                      It could be the network monitor itself that we haven't seen before - post a snapshot of the processes within Webroot and we can take a look.

                      1 Reply Last reply Reply Quote 1
                      • DashrenderD
                        Dashrender
                        last edited by

                        @Nic how does he find out what process is being monitored?

                        RojoLocoR 1 Reply Last reply Reply Quote 0
                        • RojoLocoR
                          RojoLoco @Dashrender
                          last edited by

                          @Dashrender my ? exactly

                          1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @RojoLoco
                            last edited by

                            @RojoLoco said:

                            @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

                            In that case, @nic is probably right - webroot just doesn't know the process and it's probably just being cautious.

                            1 Reply Last reply Reply Quote 0
                            • NicN
                              Nic
                              last edited by

                              Is this business or consumer version?

                              RojoLocoR 1 Reply Last reply Reply Quote 0
                              • RojoLocoR
                                RojoLoco @Nic
                                last edited by

                                @Nic Biz endpoint

                                1 Reply Last reply Reply Quote 0
                                • NicN
                                  Nic
                                  last edited by

                                  actually it's the same for both, my bad. Click on the gear symbol next to PC Security, then click Block/Allow Files and see what is listed there. Anything with the radio button in the Monitor column is being monitored and needs to be set to either Block or Allow.

                                  RojoLocoR 1 Reply Last reply Reply Quote 0
                                  • RojoLocoR
                                    RojoLoco @Nic
                                    last edited by

                                    @Nic where is that on the console? I have the endpoints locked down, no settings available on the local machine.

                                    1 Reply Last reply Reply Quote 0
                                    • NicN
                                      Nic
                                      last edited by

                                      You can do a report for "All Undetermined Software Seen" and that should show you if anything is being monitored. Then you can do an override for it on the Override tab.

                                      RojoLocoR 1 Reply Last reply Reply Quote 1
                                      • NicN
                                        Nic
                                        last edited by

                                        Actually if you zoom in on an undetermined software from the report it has the override button there to make it easier.

                                        1 Reply Last reply Reply Quote 0
                                        • RojoLocoR
                                          RojoLoco @Nic
                                          last edited by

                                          @Nic ok that report revealed the issue.... like 6 gazillion instances of our own software, source code, patches, etc. This was a development machine before, and all those database instances are busy clogging up the works. Overrides on the way. Thanks for your help!

                                          1 Reply Last reply Reply Quote 0
                                          • NicN
                                            Nic
                                            last edited by

                                            Ah that makes sense. One think you can do now is exclude folders, so if you just want to exclude the folders that you put your builds into, that should take care of future versions. Otherwise you'll have to keep whitelisting them as they get created.

                                            RojoLocoR 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post