Skip to main content
Hi! Today I checked my monitored processes after a windows update and saw that a process named "SearchUI.exe" was being monitored. I calculated the hash of the program and looked it up on Webroot's site and VirusTotal. VT said 0/68 detected and Webroot's site said that the determination was good. Why is it being monitored if Webroot knows that it is good? Here's an image showing it.

 



 

Thanks, Anthony.
Did you try a scan or two and check after to see if it's still being Monitored? If it is please Submit a Support Ticket and ask them to look into it for you to see why! It could be a communication issue from the WSA client to the Cloud but they would know.

 



 

HTH,
In the scan log it shows as good for me [g]! https://docs.webroot.com/us/en/home/wsa_pc_userguide/wsa_pc_userguide.htm#UsingReportsAndViewers/SavingScanLogs.htm%3FTocPath%3DUsing%2520Reports%2520and%2520Viewers%7C_____1

 

Some legitimate files are not included in this log

[g] c:windowssystemappsmicrosoft.windows.cortana_cw5n1h2txyewysearchui.exe [SHA256: 2D878B022ADF849A3EF5350F57D99E09C5C31C5491C6AB470C627E3646860A22] [MD5: B047F60A8E079A0A0D166F353762B378] [Flags: 10191000.13769]
Alright, after scanning it wasn't monitored. Thank you for the help!
@ wrote:

Alright, after scanning it wasn't monitored. Thank you for the help!

Great to hear! ;)

 

Cheers,

Reply