With Webroot SecureAnywhere Internet Security Complete... is Malwarebytes Anti Exploit recommended?


Userlevel 3
Badge +7
With Webroot SecureAnywhere Internet Security Complete... is Malwarebytes Anti Exploit recommended for PREVENTION of Exploits and Zero Day Attacks ??? Thank you in advance for a prompt and detailed response. ~ Alan

19 replies

Userlevel 7
Badge +62
Hello abrandt
 
Welcome to the Webroot Community,
 
As ? states here: "Really IMHO it's not needed as WSA will protect you from any payloads from any exploit and WSA has the Journaling and Rollback feature in case it's not known also the payload would have to run to do anything so it's best to keep all applications updated and let WSA do what it does best keep you and your private information safe!"
 
See this Video: https://community.webroot.com/t5/Webroot-Education/What-Happens-if-Webroot-quot-Misses-quot-a-Virus/...
 
  Also more videos of Webroot capabilities.
 


 

 
 
Userlevel 7
Badge +56
Hello,
 
There's nothing wrong with having a layered approach to one's security and as Sherry said WSA doesn't look for exploits because there are so many but WSA looks for the malicious payload they try to download and I said try to! If you feel that you need MAE and it works well for you great, personally I don't use it and feel I don't have the need for an Anti-Exploit.
 
HTH,
 
Daniel 😉
Userlevel 3
Badge +7
Hello, Sherry: Appreciate your response... however I may have found results contrary to your assertion. I ran Malwarebytes Anti-Malware after scan with Webroot SecureAnywhere Internet Security Complete and Optimization Utility and MBAM displayed the following results. Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, AKA Domain Database, 2015.6.12.1, 2015.9.11.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Rootkit Database, 2015.7.1.1, 2016.5.27.1, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Remediation Database, 2015.7.1.2, 2016.5.25.1, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, IP Database, 2015.6.12.1, 2016.6.14.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Domain Database, 2015.6.12.1, 2016.6.14.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, AKA IP Database, 2015.6.12.1, 2015.9.11.2, Update, 6/14/2016 8:13 AM, SYSTEM, ABRANDT-PC, Manual, program, 2.1.8.1057, 2.2.1.0, Update, 6/14/2016 8:13 AM, SYSTEM, ABRANDT-PC, Manual, Malware Database, 2015.7.1.5, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.5.27.1, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, IP Database, 2016.2.8.1, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Remediation Database, 2016.2.12.1, 2016.5.25.1, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Domain Database, 2016.2.16.8, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Malware Database, 2016.2.16.6, 2016.6.14.2, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Starting, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Started, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Starting, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Started, Scan, 6/14/2016 11:29 AM, SYSTEM, ABRANDT-PC, Manual, Start:6/14/2016 8:23 AM, Duration:3 hr 3 min 37 sec, Threat Scan, Completed, 1 Malware Detection, 28 Non-Malware Detections, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Starting, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Started, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Starting, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Started, (end) I am not very please with the above intrusions... and apparent lack of protection from both Webroot and SuperAntiSpyware. Comments from Power-Users would be much appreciated. Thank you, ~ Alan
Userlevel 7
Badge +56
It's best to ask one of Webroot's finest Threat Researchers to answer your question ? as IMO MBAM finds many non-threats and wants to delete them.
 
? can you post a scan log from MBAM?
 
Thanks,
 
Daniel 😉
Userlevel 7
Much agree with you, Daniel...MBAM can be some what 'enthusiastic' as to what it classes as a threat. ;) Nothing wrong with that other than it can give the wrong impression as to the state of 'cleanliness' of one's system.
Userlevel 7
Badge +35
 
We sometimes see MBAM detect remnants of infections that we already removed in logs like those, but  it is difficult to say if anything was actually missed without seeing the logs.
 
-Dan
Userlevel 3
Badge +7
Daniel: I did POST mbam results above... but this forum completely removed formatting. I do NOT see a LINK that support uploading an attach. Thank you. ~ Alan
Userlevel 7
Badge +56
When you save a MBAM scan log do it in a Text File, this is what it should look like as yours doesn't give any info.
 
Thanks,
 
Daniel ;)
 
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2016-06-15
Scan Time: 1:24 PM
Logfile: MBAM scan log.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.06.15.04
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: Daniel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 415148
Time Elapsed: 10 min, 49 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)

(end)
Userlevel 3
Badge +7
Howdy, Daniel: I did copy into Notepad... and then c&p here... however formatting not preserved again. What are you doing that preserves lines? Positively, ~ Alan
Userlevel 7
Badge +56
@ wrote:
Howdy, Daniel: Appreciate your **explicit** instructions ! Here we go... does NOT appear to be nearly as menacing as when I first bug-eyed at it! Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, AKA Domain Database, 2015.6.12.1, 2015.9.11.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Rootkit Database, 2015.7.1.1, 2016.5.27.1, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Remediation Database, 2015.7.1.2, 2016.5.25.1, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, IP Database, 2015.6.12.1, 2016.6.14.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, Domain Database, 2015.6.12.1, 2016.6.14.2, Update, 6/14/2016 8:12 AM, SYSTEM, ABRANDT-PC, Manual, AKA IP Database, 2015.6.12.1, 2015.9.11.2, Update, 6/14/2016 8:13 AM, SYSTEM, ABRANDT-PC, Manual, program, 2.1.8.1057, 2.2.1.0, Update, 6/14/2016 8:13 AM, SYSTEM, ABRANDT-PC, Manual, Malware Database, 2015.7.1.5, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.5.27.1, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, IP Database, 2016.2.8.1, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Remediation Database, 2016.2.12.1, 2016.5.25.1, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Domain Database, 2016.2.16.8, 2016.6.14.2, Update, 6/14/2016 8:16 AM, SYSTEM, ABRANDT-PC, Manual, Malware Database, 2016.2.16.6, 2016.6.14.2, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Starting, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Started, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Starting, Protection, 6/14/2016 8:18 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Started, Scan, 6/14/2016 11:29 AM, SYSTEM, ABRANDT-PC, Manual, Start:6/14/2016 8:23 AM, Duration:3 hr 3 min 37 sec, >>> Threat Scan, Completed, **1 Malware Detection**, 28 Non-Malware Detections, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Starting, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malware Protection, Started, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Starting, Protection, 6/14/2016 11:36 AM, SYSTEM, ABRANDT-PC, Protection, Malicious Website Protection, Started, (end) Much appreciate your attention... looks like all is well after all !!! LOL! Positively, ~ Alan
Can you post the info from the Quarantine log? I just did a Threat Scan and mine only took
 
Time Elapsed: 10 min, 49 sec
 
I wonder why yours took 3 hours, 3 minutes and 37 seconds?
 

Userlevel 7
Badge +56
I did another Threat Scan and clicked copy to Clipboard and pasted here and it posted fine??
 
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2016-06-15
Scan Time: 3:36 PM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.06.15.05
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: Daniel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 415128
Time Elapsed: 10 min, 1 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)

(end)
Userlevel 3
Badge +7
Daniel: I think because I am a new member... I do not have rights to post an image... and text formatting is removed upon publishing... so I have upload a PRINT SCREEN to Evernote so that you can view. Thank you much. ~ Alan http://www.evernote.com/l/ANbABinpm55BiZkBUD9n0V_Vf7yYTkrm-7o/
Userlevel 7
Badge +56
Hello Alan,
 
Yes most if not all are PUP's or Webroot calls them PUA's so see here to learn more: https://community.webroot.com/t5/Techie-KB/How-to-Remove-Potentially-Unwanted-Applications/ta-p/40744 which are not malicious!
 
Thanks,
 
Daniel ;)
 

Userlevel 3
Badge +7
How does one identy the PUAs from this list?
Nothing looks **obvious** to me.  ;)
 
BTW - I changed my setting to Rich Text (default) which opened the formatting bar up top and ability to upload images... was not there before.
 
Thx.
 
~ Alan
Userlevel 7
Badge +56
From the MBAM log it says PUP in front so it's the same as PUA's! You can post pictures we have to approve them!
 
https://en.wikipedia.org/wiki/Potentially_unwanted_program
 


 
 
Userlevel 3
Badge +7
Dan:
 
Appreciate.
 
Will take this issue to the MBAM forum for assistance.
 
Thank you,
 
~ Alan  :)
Userlevel 7
Badge +56
It's not and issue it's just MBAM is more aggressive on PUP's and PUA's nothing more! Also WSA is very good at them as well and as you seen I didn't have any and the reason why is I watch what I install and from who, also I watch every step during installation looking for Unwanted added Programs. download .com is one of the worse places for adding Unwanted add-ons to programs. One more time they are not malicious in any way but just Unwanted so just be careful when installing software.
 
Thanks,
 
Daniel 😉
Userlevel 3
Badge +7
Howdy, Daniel:
 
You PUA point is understood.
 
My point is:
 
  • MBAM does not ID the PUA and LOCATION to faciliate effective removal
 
Thank you,
 
~ Alan
Userlevel 7
Badge +56
Hi Alan,
 
I'm sorry I don't understand what your trying to say? Just to let you know I'm an Expert over the the MBAM Community so I know how there programs work so I'm just offering my advice as it's easy to get PUA's see here from this Adobe Flash Update: https://community.webroot.com/t5/Security-Industry-News/Adobe-Flash-Player-22-0-0-192-Adobe-AIR-22-0-0-153/m-p/258062#M27352
 
Thanks,
 
Daniel 😉

Reply