Skip to main content
Solved

W32.Trojan.Gen. False Positive Fix - April 24


Did this help you find an answer to your question?
Show first post

289 replies

  • Fresh Face
  • 4 replies
  • April 26, 2017
That is the one focused for MSPs... I'm not a MSP.  

akim
Forum|alt.badge.img+35
  • Retired Webrooter
  • 831 replies
  • April 26, 2017
@ we will get a letter for our SMBs shortly and post a link to it here.

@
 
Do we know how long it will take them to respond to support tickets for the Utillity?

Forum|alt.badge.img+48
  • Author
  • Retired Webrooter
  • 1550 replies
  • April 26, 2017
It is not our intention to be deceptive. We want to work with customers still being affected by this issue on an individual level to make sure that the issue is completely resolved.
 
If those customers and partners can notify us via a support ticket, that is the fastest way for us to identify and assist them. We are happy to submit a ticket on your behalf if that would be helpful. 

@
 
Can you tell us as MSP's officially what is the plan for this utility? Do we need to run it on every client? Or just infected clients? what about clients we seem to have fixed and stabalized?
 
Just trying to make a plan of attack for our team. Thanks for any input you can give. Also how long before support ticket gets answered?
 
Appreciate all that you guys are doing.

Forum|alt.badge.img+48
  • Author
  • Retired Webrooter
  • 1550 replies
  • April 26, 2017
@ Just talked with support and we're seeing an average response time of one hour. 

But I am over an hour already...... Can you respond on other questions? I also posted those to the ticket as well. Just wanting some clarification.

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
Hi When you get the tool from support, plan to push it out to your endpoints and it will execute automatically. It will restore files from this incident to their original locations. So you should plan to use a script or your RMM tool to push it to endpoints. 
Mike

@
 
All endpoints or just the effected ones? We lucked out on some clients and have not had the issue, others we have manually fixed and some still struggling.
 
Thanks

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
Just the affected ones will benefit from the tool because its specifically designed to move the affected files back into the right folders. 
Mike

@ Would it be ok if we run it on all machines though? We aren't certain which are afffected or not so it would be a hassle to sort through thousands to figure out which are affected if we could just run it everywhere without any issues.

Is there a full explaination as to what this "Fix" does?

It moves the quarantined files back into their proper folders, what about systems which we've manually restored quarantined files already but the agent is unresponsive to the cloud?

What else does this fix do?

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
I hear you. There is not a problem deploying across both affected and unaffected machines.
Mike

@
 
If this tool is an .exe file and hosted at a url, wouldn't it be easy enough to actually use the webroot console to "download and run a file" from the 'Agent Commands option - Advanced' in the endpoints list rather than using a separate interface? Seems like Webroot employees would recommend that over using a script or RMM tool to push it to endpoints. One to one contact in the interface that is affected would be much easier for the person fixing the problem.

I have used the "Download and run a file" with great success with shared google drive files (with direct download link conversion). However, it doesn't work if you select a full page of hosts and check the 'send to all pages' option. It also doesn't work with an .msi file. I use msi2exe to convert the file.

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
Yes you can deploy the tool using the Download and Run a File agent command from the WSA console or by using any other deployment method that you may use.
Mike

  • 1 reply
  • April 26, 2017
I requested the "fix" through the already-open ticket.  The response can be summarized by "We would like to schedule an appointment to call you, during which a member of the Webroot Advanced Malware Removal Team will provide remote assistance on the affected computer."  It appears that Webroot wants me to be on the phone with their support engineers for several days deploying this to all of our machines.

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
Hi No, we dont want to hang on the phone with your team while you use it. They want to understand (quickly) if the person requesitng the tool is confident in his abiltiy to just run with it. You know some people ask for tools like this who dont actually know what theyre doing. So you will be given access to download it very quickly once you connect with support.
Mike

  • 1 reply
  • April 26, 2017
Is anyone else having issues with files upwards of 20GB being created from this, filling up hard drive space?

MSP Update:
 
So far I am seeing good success with this utility. have only run into 3 workstations so far that are not working.
 
I am not getting console commands to run at this time still... hoping that gets resolved as well>??

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
@ Here's the document that customers can share with their management team. 

Forum|alt.badge.img+4
  • New Voice
  • 9 replies
  • April 26, 2017
Hello. I ran the tool on one of the infected machines, it disabled my Webroot. How do we know when the fix is done? After 10 minutes I enabled Webroot again and it ran a scan and the file that was falsely identified was once again found as a threat, I allowed it ... but I feel like I'm still not back to normal. I even had support (and myself), whitelist that file and folder in my console. 
 
I have around 350 endpoints, it took out 3 security cameras and quoting software, and then some facebook pages. This has caused a lot of headaches and I've only had a few issues. Can't imagine if it would have taken out servers and all my workstations. I'm still not feeling very confident with Webroot now, and to make matters worse my Account Rep never replies to my e-mails. 

  • Retired Webrooter
  • 24 replies
  • April 26, 2017
Please contact support. They can address your issues with you. 
Mike

Forum|alt.badge.img+48
  • Author
  • Retired Webrooter
  • 1550 replies
  • April 26, 2017
@ One possible reason why you're experiencing this would be if the system were low on drive space when the issue happened. I'd recommend talking with support and submitting a ticket so that they can further assist you. https://www.webroot.com/us/en/about/contact-us 
 
Thanks!

akim
Forum|alt.badge.img+35
  • Retired Webrooter
  • 831 replies
  • April 26, 2017
@, I spoke with our support team and asked our SEs to reach out to you. Can you please let us know if your case was resolved?

Forum|alt.badge.img+4
  • New Voice
  • 9 replies
  • April 26, 2017
Shane C. and Sarah M. reached out and were both great and answered lots of my questions. Thank you!!!

Reply