When you launch unknown applications: display a pop-up message

This will increase the security, so the user will be notified in advance


It will be more convenient, the user will know that in system is running suspicious process




At the moment the user doesn't receive notification of monitoring active process



Identity Shield Enhancements

by Silver VIP on ‎01-27-2015 08:16 AM

Can we have two separate lists, Protect and Allow/Deny, to the Identity Shield as some have said that they would like to Protect an App but they also want to be able to Allow or Deny an App from seeing Protected Data. I can see the benefit of this option myself and other Advanced users.




Daniel :smileywink:

Block All Bundled Software

by Silver VIP ‎10-07-2014 11:48 AM - edited ‎10-07-2014 11:55 AM

We get a lot of questions/issues/complaints around PUA's.  They are one of the most irritating things.  WSA blocks many of them, but for a variety of reasons not all.  Specifically PUA's that are bundled with other software, are not hidden, have an opt out ability, are not currently blocked by Webroot.


Would it be possible to add a feature that the end user can choose when installing new software to block ALL bundled software?  That would:


1) Be an active choice by the user to block the bundles


2) Reduce vastly the number of PUA issues that we see


3) Keep things quite legal.


4) Help keep Webroot above and beyone the competition.  :smileyhappy:


I've had some conversations with folks internally about this, and it's a thorny issue.  Having a separate category for "technically legal but still unwanted" would require massive infrastructure changes, and categorizing them as bad would open up a legal can of worms.  I'm still pushing for the latter, and I'll update you guys when I have some news.

scan/optimize USB drives

by New Voice dhintz on ‎02-22-2015 06:55 PM

include menu options for enabling stands and optimizing of USB memory and peripheral hard drives

You can already scan external drives.  As far as optimization, that only really makes sense on your OS drive. 

New Webroot PDF User Guide Versions

by Silver VIP on ‎10-21-2014 10:56 AM


I would like to put in an Idea Exchange suggestion for  new PDF's User Guides. The most recent is this Webroot Management  from June of 2013


Also this Webroot PDF User Guide for PC from April 2013


And to push the bar here for a Mac PDF?


This would be a great asset for Webroot Consumers and for leading the OP's to a knowlegable way to print or copy information from these newer updated Webroot Manuals.


Can this be done from the Webroot staff of Editors?


 These PDFs are on Goodle Search.


This will be a tremendous help to all of the Webroot users searching the Web.


Does anyone else have any thoughts to add to this? Which are greatly welcomed!



Thank you,


Prevent Pre-checked installs of PUAs

by Sr. Community Leader on ‎10-19-2014 10:03 AM

PROBLEM: Additional, and likely unwanted extra software which appears (often pre-checked) during installations of various and even common softwares.
This extra software offered may appear at first glance as benign, and nothing to worry about, but the sad reality is that its main intention is to generate income for its developers and promoters, and in some instances may cause considerable problems for unwitting, innocent users.

Of course what we are referring to are known as PUAs (Potentially Unwanted Applications) aka PUPs, and there is a request and Idea posted here:
But it may be asking for something not quite possible, for different reasons.

So maybe a slightly different idea might be more feasible:

SUGGESTION: That WSA could have the added capability to allow users greater control of these "extra softwares" which arrive pre-checked, in that users could have a setting added to WSA to refuse these pre-checked, potential PUAs.


Resizable user interface / search options in lists

by Community Guide dtouch ‎11-22-2014 02:57 AM - edited ‎11-22-2014 03:08 AM

As I keep on using WSA, more and more programs gets added to the lists, namely Application Protection lists under Identity Protection. This feature often blocks programs like MailBird and Product key activation window of many programs and I have to manually allow these programs to copy text. While this feature makes it more secure and I have no issue manually configuring them, as time goes the list grows and it becomes a painful task to scroll down the tiny window and find the required entry. I am now talking about scrolling down through more than 100 entries. I am sure some many users have way more.


Idea: Make WSA UI window resizable or an option for fullscreen, so that the list expands and it will be easy for us to go though it. Also add a search option to search for the required entry.



No current plans to change the UI in this regard.  If that list is overly long we do recommend contacting support to get applications whitelisted in our database so that you don't have to manage them manually on your end.

Hi ,


i suggestion when user use locate Device feature , do not lock device .


Thanks ,




More control of Personalised Security Report

by Silver VIP ‎03-15-2014 05:23 AM - edited ‎03-19-2014 04:44 PM

Have noticed  in the Fora that there have been a number of users reporting dissatisfaction at the way that the Personalised Security Report is notified and the control that they have over how it interacts with their systems/themselves, etc.


As a result I am starting a feature request to try to capture this centrally as this is really the place for such views to reside if change is to have a chance of being achieved IMHO.


So common issues that users feel that they need rectified are:


1. Seeing the notification message on every login.  


Suggested that that the frequency should be much more limited (maybe only show the message once per month and that the prompt should disappear by itself if not interacted with by the user after so many seconds.  As it is, the prompt only goes away if you click on "Learn More" (which opens the web page with the stats) or the "X" in the upper right (which closes the window).


So extrapolating from this the conclusion to draw here is the provision of user definable parameters for (i) number of prompts to be shown & interval (in secs) before stopping & (ii) time after which prompt/notification will auto disappear if not responded too.


2. Ability to turn off notification


User defined setting that allows the user to decide whether they are interested in even receiving sucha report, and therefore associated notification (not that I can understand why one would not want too...:smileywink:)


3. Control to be provided via My Account/Web Console


And one of my own, given the above:


Provision of the above above suggested settings to be handled as another option in the Web Console, very much in the same way as control of the Advanced Settings can be handled that way.  Believe that as the deployment of the report "is controlled by the backend rather than the agent" to quote JoeJ, it makes sense for any new user settings that may be provided to also effectively reside at the backend rather than the client.


Well, I hope that provides a suitable starter for further comments by those who want to make them so that we can see if the feature (which I personally like) can be enhanced.


So please post & comment away, folks...:smileyvery-happy:


EDIT: To add point 4. (from David's comments below)


Provision of the ability to be able to view the latest/last Report published "On Demand".  Suggestion is the addition of a permanent tool or option, to access this, under the Utilities, Reports tab.  Thanks, David...a very good one!






Just heard back that this one is under consideration by the product management team. I'll update when they've made a determination.

Webroot Community App

by Community Expert Advisor ams963 on ‎07-24-2014 06:18 PM



It would be great if there was a Webroot Community app for smartphones, tablets and pcs (Win 8/8.1 Metro apps). It would let direct and smooth access to our Community instead of browsers. It could also have an option for all the sweeptakes and contests arranged by Webroot.

I'll have to investigate whether Lithium has anything like this.  They are doing a new version of the mobile website, but not sure if they have a separate app or not.



As I understand it, the Web Threat Shield blocks sites based on a reputation score, and sites that are believed to be new are automatically given a low reputation score -- so any new site is automatically blocked. The problem is that in the user interface, when a site is blocked, the user is not told whether it is blocked because there is actual evidence of real threats or simply because the site is believed to be new. The result is that users will be frightened away from any relatively new site, even if they have personal knowledge of its reputation (i.e., they might assume that evidence of an actual threat has been detected on the site). This problem is exaccerbated by the fact that Webroot apparently has no reliable way of determining the age of a site, so a site that has been around a long time but simply isn't yet in the Webroot database will be considered new and therefore a threat.

Instead, why not give users more information and let them decide? Rather than giving a new site a low reputation score and scaring users into thinking it is likely to contain threats, instead provide a message like the following:

Webroot does not have any information about the reputation of this website. It may be a relatively new website or an older website that is not popular enough for us to have encountered it before. You may be comfortable using this website if you have personal knowledge of its reputation, but otherwise we suggest you proceed with caution.

A message like that would provide a sufficient warning without misleading users into thinking an actual threat has been identified on a site with which they are already comfortable. If several users choose to unblock the site and proceed, you might then use that information to bump up the site's reputation and stop blocking the site altogether.

Note, this request is motivated by a recent negative Webroot experience with a site that I maintain. The site is for a small local church, so it is not widely popular and was therefore not known to Webroot. One of our church members recently reported that the site was blocked by Webroot and showed me the message indicating that the site was deemed to have a high likelihood of containing threats. Despite the fact that she knows the site and has been to it many times before, she assumed a real threat had been detected. And despite the fact that I am the creator and maintainer of the site, when I saw the warning message, I too thought perhaps some real threat had been detected. Upon further investigation, I learned that no specific threats had been detected, and that Webroot was blocking the site merely because it thought the site was new. The problem is that the site is not new -- it has been up for a full three years.

I believe Webroot is doing its customers a disservice by misleading them into thinking sites they already know and trust have been determined to have real threats, when in reality Webroot simply has zero information about the site. If you have no information about a site, simply tell the user that, and let the user decide what to do based on their personal knowledge of the site.

Good suggestion - we've entered into our database for dev's consideration.

[Using Google Chrome on Windows 7 and Windows 8]


When we use Google Chrome to visit an HTTPS website, Chrome shows us a padlock to the left of the URL.


Usually we see a Green Padlock, like on the websites for facebook, gmail, twitter, and this one (  The green padlock is a native part of Chrome.  You see that icon when you go to a website where every element on the webpage (images, javascript, etc) is local to the secured SSL server.


Sometimes, though we see a gray-padlock-with-yellow-triangle.  The gray-padlock-with-yellow-triangle is also a native part of Chrome.  You can see that icon when you go to a website that is SSL secure, but, say, embeds an image or banner or something from another server that isn't SSL secure.



The issue is that users never see any green padlocks when Webroot Filtering Extension is enabled.  The extension acts as "something on the page that's embedded from another server".  Thus, a user can never tell the difference between a 100% secured website and once that's only partially secure.  In other words, the extension reports a false-negative for every legit HTTPS website.


Padlock Issue


Since I own and run an insurance website, I would very much like users to see the green padlock on my site.  But if they have Webroot Filtering enabled, they'll only see the partially-secure gay-and-yellow icon... and it looks like it's my company's fault that we're not 100% secure.


I want to be clear about this, the issue is not how secure the extension really is... but how secure my website appears to Webroot users.  Right now, this extension makes my website appear untrustworthy.



What I'd like to see from Webroot:

- fix the problem, or...

- add a note to the gray padlock for safe sites (like mine) explaining that the website is actually safe, or...

- upon the extension being enabled (and whenever a browser is launched) make a splash page that educates the user about how they will never see green padlocks again and why (user can disable the splash page in preferences), or...

- take down the extension and do an update that force-disables the extension until it's repaired, or...

- remove the part of the extension that is causing the problem (perhaps put that part into a second, separate extension that can be optionally enabled)



If it cannot be fixed, Webroot at least needs to do something to educate its users about why they never see green padlocks anymore.



Some ideas on what to investigate in fixing this bug:

page 1

page 2





There is more on this issue on the forum here:


Also, I had previously filed a support ticket regarding this issue on Oct 25, 2013 18:04.



Kind regards,


I checked in with our support escalation team and they're looking into it.

Pre checked bundles

by Frequent Voice on ‎11-18-2014 09:45 AM

 Having looked through this subject, my own thought is that it would be easier from a programming and legal perspective to simply have WR uncheck the boxes and flag up to the user to check that is what they require.


Or am I being a little naive here?



connect/disconnect toggle

by dgkh on ‎02-05-2015 11:46 AM

Webroot lacks a toggle internet connection on or off button. 

Most of the time I do not want to be connected. I want all traffic stopped but easily restarted when I am ready.

Not sure this makes sense for us, as we rely on the Internet to work.  You could just make a shortcut on your desktop to disable your ethernet/wireless connection and then re-enable it.

Webroot has 7 characters which happens to match US phone numbers. For ease of access, has someone considered reserving a paid or toll free number 932-7668 (WEB-ROOT)?


In the UK: +44 (0) 870  WEBROOT


Offhand I would think this would be a support number, but it could be used for sales I suppose.

The only button is "unblock" and thats not an optimum solution.



Currently in beta testing phase

Control inactive processes and journaling

by Community Expert Advisor explanoit ‎03-23-2014 09:41 AM - edited ‎03-23-2014 10:16 AM

A major oversight in the product is the inability to see the currently journaled applications or allow applications that may only run for an instant but nevertheless be monitored and restricted. Or they may never run again, potentially leaving very large journaling files.


Take for example a print driver installer. You launch it and run it but it doesn't fully install. You then launch it, go into Control Active Processes, allow the main installer, and try again. However, you look in the log and it is launching executables under it that never have a chance to show up in the Control Active Processes window. You never get a chance to allow them and your installation is impeded.


Webroot's response to this is to contact support to whitelist the files via the MD5s in submitted logs or to add a file via Block/Allow files. This is not an acceptable solution for power or home users. Power users should be given full status and control of their protection, and navigating temporary directories under appdata is not a reasonable task for home users to perform. In addition, in many cases files are extracted to a random temporary directory and immediately deleted. There may never be a chance for the normal user to ever manually allow them.


Webroot needs to implement a dialog where users can see a full listing of the data that Webroot is storing on their PC via journaling and the applications it has decided to monitor and restrict from performing fully. Your competitors that have their own centralized reputation engines allow this.


As an expert, I can work around these impediments. But I am in IT with experience on the product's philosophy, workings and Windows. This knowledge should not be required to control the fundamental design and operation of a product. And this is the most fundamental design. The journaling. This is a basic, core feature that should already be implemented.

keycode renewal

by mrt422 on ‎07-11-2014 12:19 PM

I manage 15 computers for my family who live all across the country. When their subscriptions expire, it would be nice to update their keycode directly from the web console. As it is now, all 15 machines need to be updated manually. This means I'll be emailing or phoning 15 people who may or may not have the skill to do this.

Future Linux support?

by Frequent Voice ‎02-09-2014 08:18 PM - edited ‎02-11-2014 02:58 PM

I plan to get one in the future so I would love it if (and so would others probably) if you could add av support for linux ubuntu.

Ubuntu is the most common out there and the easiest. (so I would expect a lot of people to get that one if any of them.) I am sure you could do a great job if you know enough about them. (which I am fairly certain wouldn't be hard for your team)


Thanks in advance :smileywink:


actually on second all of them, I may use gentoo though.


edit edit:  not that it matters but maybe mint. (I hear that even linux can get viruses hence why i would like webroot to support it.  if possible.)


Feel free to chime in if you think this is unnessescary or needed or for whatever reason you may have. (as long as its not harsh)

From comments made in various threads in the Community re. the Web Threat Shield and the associated URL Reputation Service, of which the following is a very recent example:


It has struck me that a useful feature to help the Threat Researchers at Webroot & Brightcloud, would be the capturing & transmission of information back to base, of when the user locally uses the 'Unblock' option to advance past the blocking webpage thrown up by the Web Threat Shield.


Whilst I am not suggesting that this is input directly into the URL reputation determination process, it may be worth considering whether the collection of such statistics would help Brightcloud spot sites that need to be investigated more closely because of a large number of local overrides...not only sites that are potentially popular or becoming so but which might also indicate that there is an issue with reputation, etc.


Just an idle tbought that may be of use going forward.








Top Kudoed Authors