cruelsister
Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
roflmfaoI also have no clue as to why that Pic was dropped, unless it is some sort of arcane Asian BlackHat mating ritual. I was going to open the Picture up but as her hair is more lustrous than mine I decided not to.
I don't think the malware should have a routine in webroot to have a rollback, i was a webroot fan in my younger ages, every app in monitoring mode gets all of its actions recorded, many times some samples use some unique things that webroot rollback can not do anything. After all i believe webroot is now one of the weakest av's. Their way in confronting the malwares is not logical. So many false positive(the one you said i had that plus some ip services of Windows!). Even their cloud responses really late to the threat, other products are much faster.A Webroot employee advised somewhere to wait at least 4 hours for rollback of malicious system changes; if the system is not rolled-back within 4 hours it is probably not going to happen.
I cannot say "Webroot advises" since the above is to be found nowhere in official Webroot documentation.
Webroot does rollback some encryption.
It appears that rollback of encryption is dependent upon whether or not Webroot has a rollback routine for the specific ransomware.
Someone posted somewhere here on MT that they waited 96 hours and there was no rollback of encryption.
To find out more go searching for these infos on Webroot's Reddit and elsewhere online. The "4 hour" advice is straight out of the mouth of (was posted by) a Webroot employee. I can't remember where I read it.
Anyway... this sort of thing can be avoided by setting heuristics to "Block any file that is not specifically whitelisted." With that setting you will probably be surprised to discover that System32 and SysWOW64 files are not in the Webroot database and will be monitored\blocked (dependent upon settings).
Try it for yourself... anyone can confirm this fact.
I don't think the malware should have a routine in webroot to have a rollback, i was a webroot fan in my younger ages, every app in monitoring mode gets all of its actions recorded, many times some samples use some unique things that webroot rollback can not do anything. After all i believe webroot is now one of the weakest av's. Their way in confronting the malwares is not logical. So many false positive(the one you said i had that plus some ip services of Windows!). Even their cloud responses really late to the threat, other products are much faster.
Why would CS stop at that when she doesn't stop at breaking security software just because someone had hair with more metallic properties?D.R- I also have no clue as to why that Pic was dropped, unless it is some sort of arcane Asian BlackHat mating ritual. I was going to open the Picture up but as her hair is more lustrous than mine I decided not to.
It would be nice if somebody ever tested the manual rollback options. (Don't know if it would work or not.)
Control active processes, stop all untrusted, re-scan.