Reposting question re: Malwarebytes and Webroot issue.


Userlevel 1
I uploaded a screenshot that doesn't appear so i deleted the previous thread.
 
I am getting a pop up from malwarebytes that i do not understand. i'll type it out.
 
Malwarebytes Anti-Malware
Malicious Website Blocked
Domaine: click.watchjmp.com
IP: 54.67.85.144
Type: Outbound
Process: C:Program FilesWebrootWRSA.exe
 
Will someone please explain what is going on here.
 
Thanks very much.
 
 

15 replies

Userlevel 7
Hi Athalwolf
 
Welcome to the Community Forums.
 
Have checked out the site in question over at BrightCloud.com (Webroot's reputation service) which reveals:
 


 
whihc would seem to suggest that MBAM is correct and that the site is best avoided.
 
So what I am wondering if this is a case of MBAM detecting WSA detecting or checking the site in question, i.e., a potential 'conflict' between the two applications?
 
Regards, Baldrick
Userlevel 1
Morning Baldrick,
 
Thanks for replying.
While i did not go directly to BrighCloud.Com (thanks for that info btw) I googled click.watchjmp.com and looked through several pages of search results. There were some warnings but typically there would be posts from other folks who had similar issues but surprisingly there were none to be found.
 
I am not attemtping to go to the website rather i get the Malwarebytes warning pop -up at random times and while at safe websites I often go to like Reddit or Audiokarma. This just started happening about a week ago. i have not installed any new software or downloaded any movies or music or programs. My Malwarebytes Pro is updated and a Threat Scan comes up with 0 threats.
 
I do not understand why the Process is WebrootWRSA.exe but admittedly this stuff is not my forte. 
 
Userlevel 7
Hi Athalwolf
 
Yes, this does seem a little strange...as I said the only thing that I can think of is MBAM reacting to what WSA is doing.
 
You could try adding the file WRSA.exe to the Exclusion section in MBAM, and see if that stops the popups...doing so should be safe as you know what WRSA.exe is.
 
If that does not help then I would Open a Support Ticket to let the Support Team know/investigate further to see if they can work out what is happening.
 
Either way do post back to let us know how you get on with this...all such feedback is very useful to use going forward and lookiing to help other Community members.
 
Regards, Baldrick
Userlevel 1
Thanks very much. I will follow your instructions.
 
Have a great day!
Userlevel 7
Hi Athalwolf
 
You are most welcome...:D
 
Please do come back and let us know how this pans out for you.
 
Regards, Baldrick
Userlevel 1
You bet!
Userlevel 7
Cheers, much appreciated. :D
Userlevel 1
The folks at Malwarebytes seem to think it is a false positive and advised me to report it in their False Positive Thread.
 
Here is a link to my original post should you like to see their thoughts : https://forums.malwarebytes.org/topic/181903-malwarebytes-and-webroot-question/
 
Here is a link to the False Positive thread: https://forums.malwarebytes.org/topic/181915-546785144/
 
 
Userlevel 7
Hi Athalwolf
 
Thanks for the update. Well, until the FP is sorted at the MBAM end I would add the file to the MBAM Exclusion list...just to make sure. ;)
 
Regards, Baldrick
Userlevel 1
I'll do that now Baldrick. Thanks
Userlevel 1
Uh maybe I won't yet lol.
 
You said,'You could try adding the file WRSA.exe to the Exclusion section in MBAM, and see if that stops the popups...doing so should be safe as you know what WRSA.exe is.'
 
I don't have a clue what WRSA.exe is. I thought it was Webroot. 
Userlevel 7
Hi Athalwolf
 
WRSA.exe is the actual Webroot SecureAnywhere executable that runs on yo9ur system and provides the core protection. This is what is starts on boot up and then runs on your system as per the below (view via the Task Manager) so it is quite safe to add to the Exclusions section of MBAM:
 


 
Apologies for the confusion and not making this clearer for you.
 
Regards, Baldrick
Userlevel 1
No worries. The staff at Malwarebytes will respond to the False Positive thread probably tomorrow I'm told.
Userlevel 7
Badge +56
@ wrote:
Hi Athalwolf
 
Welcome to the Community Forums.
 
Have checked out the site in question over at BrightCloud.com (Webroot's reputation service) which reveals:
 


 
whihc would seem to suggest that MBAM is correct and that the site is best avoided.
 
So what I am wondering if this is a case of MBAM detecting WSA detecting or checking the site in question, i.e., a potential 'conflict' between the two applications?
 
Regards, Baldrick
Yes your right WRSA.exe is the main process so that would be involved with the Web Filter checking the site!
 
Daniel 😉
Userlevel 7
Badge +56
I also replied at the Malwarebytes Forum: https://forums.malwarebytes.org/topic/181903-malwarebytes-and-webroot-question/?do=findComment&comment=1034730
 
Thanks,
 
Daniel 😉

Reply