ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Webroot folder in Program Data is ~48GB!!!

    Scheduled Pinned Locked Moved IT Discussion
    22 Posts 4 Posters 5.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      have you been hit by crypto something?
      for your sake I hope not.. but at the same time.. if yes... then Webroot is currently saving you.

      RojoLocoR 1 Reply Last reply Reply Quote 0
      • RojoLocoR
        RojoLoco @Nic
        last edited by

        @Nic The whole folder? Also, what would be getting monitored that is so huge? I've only been running SW network monitor on that box.

        1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender
          last edited by

          in the case of something like cryptoware - webroot would be making a backup copy of all encrypted files before it allows the virus to encrypt them.

          1 Reply Last reply Reply Quote 0
          • NicN
            Nic
            last edited by

            typically it's something innocuous that we haven't seen before, and it doesn't need to be monitored. If you recognize the process and know it is good then go ahead and whitelist it. If you aren't sure support would be happy to take a look at it.

            1 Reply Last reply Reply Quote 1
            • RojoLocoR
              RojoLoco @Dashrender
              last edited by

              @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

              DashrenderD 1 Reply Last reply Reply Quote 0
              • NicN
                Nic
                last edited by

                It could be the network monitor itself that we haven't seen before - post a snapshot of the processes within Webroot and we can take a look.

                1 Reply Last reply Reply Quote 1
                • DashrenderD
                  Dashrender
                  last edited by

                  @Nic how does he find out what process is being monitored?

                  RojoLocoR 1 Reply Last reply Reply Quote 0
                  • RojoLocoR
                    RojoLoco @Dashrender
                    last edited by

                    @Dashrender my ? exactly

                    1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @RojoLoco
                      last edited by

                      @RojoLoco said:

                      @Dashrender practicallt impossible on this machine. It has been off for 3 days, before that no email or browsing, just a headless workstation for testing GIS map stuff.

                      In that case, @nic is probably right - webroot just doesn't know the process and it's probably just being cautious.

                      1 Reply Last reply Reply Quote 0
                      • NicN
                        Nic
                        last edited by

                        Is this business or consumer version?

                        RojoLocoR 1 Reply Last reply Reply Quote 0
                        • RojoLocoR
                          RojoLoco @Nic
                          last edited by

                          @Nic Biz endpoint

                          1 Reply Last reply Reply Quote 0
                          • NicN
                            Nic
                            last edited by

                            actually it's the same for both, my bad. Click on the gear symbol next to PC Security, then click Block/Allow Files and see what is listed there. Anything with the radio button in the Monitor column is being monitored and needs to be set to either Block or Allow.

                            RojoLocoR 1 Reply Last reply Reply Quote 0
                            • RojoLocoR
                              RojoLoco @Nic
                              last edited by

                              @Nic where is that on the console? I have the endpoints locked down, no settings available on the local machine.

                              1 Reply Last reply Reply Quote 0
                              • NicN
                                Nic
                                last edited by

                                You can do a report for "All Undetermined Software Seen" and that should show you if anything is being monitored. Then you can do an override for it on the Override tab.

                                RojoLocoR 1 Reply Last reply Reply Quote 1
                                • NicN
                                  Nic
                                  last edited by

                                  Actually if you zoom in on an undetermined software from the report it has the override button there to make it easier.

                                  1 Reply Last reply Reply Quote 0
                                  • RojoLocoR
                                    RojoLoco @Nic
                                    last edited by

                                    @Nic ok that report revealed the issue.... like 6 gazillion instances of our own software, source code, patches, etc. This was a development machine before, and all those database instances are busy clogging up the works. Overrides on the way. Thanks for your help!

                                    1 Reply Last reply Reply Quote 0
                                    • NicN
                                      Nic
                                      last edited by

                                      Ah that makes sense. One think you can do now is exclude folders, so if you just want to exclude the folders that you put your builds into, that should take care of future versions. Otherwise you'll have to keep whitelisting them as they get created.

                                      RojoLocoR 1 Reply Last reply Reply Quote 0
                                      • RojoLocoR
                                        RojoLoco @Nic
                                        last edited by

                                        @Nic I've been trying to stay on top of that stuff, but they can build faster than I can make exclusions.

                                        1 Reply Last reply Reply Quote 0
                                        • NicN
                                          Nic
                                          last edited by

                                          Yeah just exclude the whole folder that they do their dev work in and that should take care of it.

                                          1 Reply Last reply Reply Quote 2
                                          • 1
                                          • 2
                                          • 1 / 2
                                          • First post
                                            Last post