ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Webroot folder in Program Data is ~48GB!!!

    Scheduled Pinned Locked Moved IT Discussion
    22 Posts 4 Posters 5.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @Nic
      last edited by

      @Nic said:

      Probably a process is getting monitored. It saves a record of all changes when that is happening, in case it need to roll back. Check the processes being watched to see if any are in monitored status.

      Yes you can delete the folder and it will get recreated.

      In that case I would be scared that something is doing something bad.

      1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender
        last edited by

        have you been hit by crypto something?
        for your sake I hope not.. but at the same time.. if yes... then Webroot is currently saving you.

        RojoLocoR 1 Reply Last reply Reply Quote 0
        • RojoLocoR
          RojoLoco @Nic
          last edited by

          @Nic The whole folder? Also, what would be getting monitored that is so huge? I've only been running SW network monitor on that box.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            in the case of something like cryptoware - webroot would be making a backup copy of all encrypted files before it allows the virus to encrypt them.

            1 Reply Last reply Reply Quote 0
            • NicN
              Nic
              last edited by

              typically it's something innocuous that we haven't seen before, and it doesn't need to be monitored. If you recognize the process and know it is good then go ahead and whitelist it. If you aren't sure support would be happy to take a look at it.

              1 Reply Last reply Reply Quote 1
              • RojoLocoR
                RojoLoco @Dashrender
                last edited by

                @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

                DashrenderD 1 Reply Last reply Reply Quote 0
                • NicN
                  Nic
                  last edited by

                  It could be the network monitor itself that we haven't seen before - post a snapshot of the processes within Webroot and we can take a look.

                  1 Reply Last reply Reply Quote 1
                  • DashrenderD
                    Dashrender
                    last edited by

                    @Nic how does he find out what process is being monitored?

                    RojoLocoR 1 Reply Last reply Reply Quote 0
                    • RojoLocoR
                      RojoLoco @Dashrender
                      last edited by

                      @Dashrender my ? exactly

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @RojoLoco
                        last edited by

                        @RojoLoco said:

                        @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

                        In that case, @nic is probably right - webroot just doesn't know the process and it's probably just being cautious.

                        1 Reply Last reply Reply Quote 0
                        • NicN
                          Nic
                          last edited by

                          Is this business or consumer version?

                          RojoLocoR 1 Reply Last reply Reply Quote 0
                          • RojoLocoR
                            RojoLoco @Nic
                            last edited by

                            @Nic Biz endpoint

                            1 Reply Last reply Reply Quote 0
                            • NicN
                              Nic
                              last edited by

                              actually it's the same for both, my bad. Click on the gear symbol next to PC Security, then click Block/Allow Files and see what is listed there. Anything with the radio button in the Monitor column is being monitored and needs to be set to either Block or Allow.

                              RojoLocoR 1 Reply Last reply Reply Quote 0
                              • RojoLocoR
                                RojoLoco @Nic
                                last edited by

                                @Nic where is that on the console? I have the endpoints locked down, no settings available on the local machine.

                                1 Reply Last reply Reply Quote 0
                                • NicN
                                  Nic
                                  last edited by

                                  You can do a report for "All Undetermined Software Seen" and that should show you if anything is being monitored. Then you can do an override for it on the Override tab.

                                  RojoLocoR 1 Reply Last reply Reply Quote 1
                                  • NicN
                                    Nic
                                    last edited by

                                    Actually if you zoom in on an undetermined software from the report it has the override button there to make it easier.

                                    1 Reply Last reply Reply Quote 0
                                    • RojoLocoR
                                      RojoLoco @Nic
                                      last edited by

                                      @Nic ok that report revealed the issue.... like 6 gazillion instances of our own software, source code, patches, etc. This was a development machine before, and all those database instances are busy clogging up the works. Overrides on the way. Thanks for your help!

                                      1 Reply Last reply Reply Quote 0
                                      • NicN
                                        Nic
                                        last edited by

                                        Ah that makes sense. One think you can do now is exclude folders, so if you just want to exclude the folders that you put your builds into, that should take care of future versions. Otherwise you'll have to keep whitelisting them as they get created.

                                        RojoLocoR 1 Reply Last reply Reply Quote 0
                                        • RojoLocoR
                                          RojoLoco @Nic
                                          last edited by

                                          @Nic I've been trying to stay on top of that stuff, but they can build faster than I can make exclusions.

                                          1 Reply Last reply Reply Quote 0
                                          • NicN
                                            Nic
                                            last edited by

                                            Yeah just exclude the whole folder that they do their dev work in and that should take care of it.

                                            1 Reply Last reply Reply Quote 2
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post