Solved

Webroot Threats in Mobile Android


Userlevel 7
Badge +57
Is anyone having continuous threats popping up with Webroot Mobile Security? I just had to reset my Samsung Note 8 this morning and I'm getting this Threat from Outlook. False positives perhaps?



icon

Best answer by freydrew 23 April 2019, 06:05

If you use Webroot on an Android phone and see multiple ‘infected file’ notifications, please upgrade to version 5.5.5 from the Google Play Store.

Once you’re running the latest version, additional steps may need to be taken:

1) If you quarantined the affected apps, resolve by:
a. Following the steps to restore apps from quarantine in the attached doc. Each app must be un-quarantined separately.

2) If you did not quarantine or uninstall the affected apps, resolve by:
a. Waiting until after 11pm MST April 22, 2019 as this will allow the app cache to clear automatically. After this time, no new notifications relating to this issue will occur.

3) If you uninstalled apps identified as infected, resolve by:
a. Re-installing any apps that were deleted by downloading the latest version from the Google Play Store.

We appreciate your patience on this. If you have any questions, feel free to open a customer support ticket at support.webroot.com.
View original

28 replies

Badge +1

Looks like the problem is back. I have the same base.app detection with Viber today.

It says: Unclassified. Webroot has determined this app is malicious

Userlevel 7
Hi ,

i reinstall my Webroot , yes it is latest version .

yesterday i sent some malware for webroot and now detected their , but again can not Quarantine or deleted threats.

yesterday i deleted threat file manually .

Regards ,

Amir

It would be best if you contacted support and tell them so they can look into it for you. Webroot Customer Service
Userlevel 7
Badge +35
Hi ,

i reinstall my Webroot , yes it is latest version .

yesterday i sent some malware for webroot and now detected their , but again can not Quarantine or deleted threats.

yesterday i deleted threat file manually .

Regards ,

Amir
Userlevel 7
now I have same problem.

my webroot is update and latest version. find some malware , but can not Quarantine or deleted threats !!!

why ?!

Amir

What version do you have installed?

Would it be this one? https://play.google.com/store/apps/details?id=com.webroot.security&hl=en

Current Version
5.5.5.38787

I'm on a Beta which is version: 5.5.7.42602 and don't see any issues?

Thanks,
Userlevel 7
Badge +35
now I have same problem.

my webroot is update and latest version. find some malware , but can not Quarantine or deleted threats !!!

why ?!

Amir
Badge +2
I just opened a support ticket for com.skype.raider

So far, webroot still considers Skype as malicious
Badge +1
I opened a support ticket and they told me that they are aware of the problem. They said several false positives were sent out for android applications and that the problem would be fixed shortly. They said that within the hour the problem would be fixed. As of right now, webroot is scanning and shows no threats. So everything looks good on my end. I just restarted my device and re- opened webroot and the problem went away. So I'm not sure what they did or if the app is fixed now. I'm still getting an app icon notification for webroot though.

Edit: The app has crashed on me several times after the false positives went away. And the app icon badge still shows that there is a notification. What is this notification? Probably another glitch

Edit #2 : If I press and hold the app icon it shows in the notification window that I am protected and that no problem are detected. So I guess the #1 badge icon is simply to show you that you are protected? It didn't show a notification before all these problems started...
Badge +2
Having the exact same issue with com.skype.raider base.apk
Today is the 23rd way past the time specified by freydrew

Feels like Webroot team is making big move lately, introducing much regression. Before I was suffering from Scan out of Date... and now this.. 😞
Userlevel 7
Badge +48
If you use Webroot on an Android phone and see multiple ‘infected file’ notifications, please upgrade to version 5.5.5 from the Google Play Store.

Once you’re running the latest version, additional steps may need to be taken:

1) If you quarantined the affected apps, resolve by:
a. Following the steps to restore apps from quarantine in the attached doc. Each app must be un-quarantined separately.

2) If you did not quarantine or uninstall the affected apps, resolve by:
a. Waiting until after 11pm MST April 22, 2019 as this will allow the app cache to clear automatically. After this time, no new notifications relating to this issue will occur.

3) If you uninstalled apps identified as infected, resolve by:
a. Re-installing any apps that were deleted by downloading the latest version from the Google Play Store.

We appreciate your patience on this. If you have any questions, feel free to open a customer support ticket at support.webroot.com.
Badge +3
I received 18 virus threats. I have never had any threat before. My story is as above. Hard to use phone, as screen keeps going back to red tinted

warning screen.
Userlevel 7
Badge +57
Hello Webrooters,

I uninstalled and reinstalled Webroot Mobile and I'm not getting anymore threats so far. Which is worth a try. I left the Beta and now using the released version.
Badge +1
com.skype.raider on my LG Aristo 2 plus also showing as a trojan.
Badge +1
Sorry - me again - I use a J7 and have the new, "fixed", 5.5.5 version.
Badge +1
Same here - seems my camera, live wallpaper app, and a game (I have used for 5 years) are threats to be removed, but I am unable to do so and get error code _1010. This is really getting old.
Userlevel 3
Badge +9
Definitions must have been updated. Rescanning my Nokia phone now gives the result "You are protected, no problems detected".

Edit: Samsung keyguardwallpaperupdater is still being detected.
Badge +2
Note 9 is all trojan and I removed normal apps like duckduck go and grub hub and many others thinking they were trojans and it of course couldn't remove Phone and all of the core android applications
Badge +1
The same thing is happening on my samsung tab S3. I started the device and ran a scan, and then it identified the google maps app as a threat. It showed com.google.android.apps.base.apk as a trojan. And then right after I restarted again it showed the keyguard wallpaper updater as a threat (keyguardwallpaperupdator.apk). I have malwarebytes and its not picking anything up. Must be a false positive.
Userlevel 7
Badge +36
We are aware of the situation and are working to address it. We will keep this thread updated as we know more.
Userlevel 1
Badge +1
@ordervine
Don't think phone specific, I'm using Huawei Mate Se.
More than likely, something with last virus definitions update.
Userlevel 1
Badge +1
I submitted a ticket to Webroot's customer service with the app that my copy of Webroot was detecting and the mobile logs. They just replied back to me saying that they corrected the definition. I rescanned my phone, and it's not hitting the false positive anymore. So submitting tickets seems to work.
Badge +1
Same for me Samsung Note 9 - 32 items none of which can be quarantined or removed
Looks like all are Samsung based controls. Threats notices appeared after I clicked on a valid telephone number on a website. So not sure if these are false positives or real Trojan. Installed Avast and it found zero threats????
Userlevel 1
Badge +1
Yep. False positives everywhere. 5.5.5.38787, Android.

Uber, Walmart, The Weather Channel, Google Pay, Shazam, PlayStation, SimpliSafe, Atom Tickets

All listed as Trojans or unspecified threats. Uninstalled Webroot until the issue resolves. Getting way too many warnings, my phone was getting bombarded with them.
Userlevel 1
Badge +1
I'm having the same issue. It's detecting Outlook for Android as a trojan, with the same SHA1 hash as Ssherjj's in the picture above.
Userlevel 7
Badge +57
Thanks as well @Stvhorn for that information..hoping this gets taken care of soon.

@freydrew can you check this out?
Userlevel 1
Badge +1
just started happening to me too. Identified 5 apps on my google fi nexus 6p as threats including outlook, google fi app, joann fabrics, and united airlines

Reply