  • 20 March 2019
Hey all

I'm back testing it alongside ninja rmm and I'm testing it in a VM against our current offering which is Bitdefender GZ. I think webroot may work out a bit cheaper.

So far I can see its a lot lighter, instant install and uninstall.

I managed to get both VMs ransomed using some test malware. How does webroot journal restore work? I heard it can reverse the encryption and virus damage some how? That would be a big positive.

Still a bit apprehensive after the two big hiccups this year resulting webroot killing machines (when we trialled it last it deleted a DNS dll file on two of the machines)

How does webroot journal restore work? I heard it can reverse the encryption and virus damage some how?

Here's an explanation I gave some time back:

"To put it simply, Webroot has three classifications for files: not only Good or Bad, but also Unknown. All files that Webroot does not "know", it automatically classes as Unknown. It treats all Unknown files as suspicious and journals all and every change they make to your system and files. (It also gives them only restricted privileges so that, for example, they are unable to steal your private data.) If and when an Unknown file is determined to be Bad, every change that it has made to your system and/or files is "rolled back", that is to say, reversed to the state in which it was before those malicious changes were made. Thus, for example, files encrypted by ransomware are decrypted."

Here is the link to the original post.

I added this proviso—and reassurance:

"I believe there have been rare instances where this process has not worked. A good backup procedure (ideally, imaging of disk if possible) is therefore prudent and advisable as a second line of defence in the (unlikely) event that this fails you.

"As a note of reassurance, I have been running Webroot SecureAnywhere, and previously its legacy product Prevx, for almost 11 years now (EDIT: now more than 12) and, quite unlike other security products I have used, it has never yet failed me."

Oh, and for the more technically minded, see this:
