• 0

What happens if Webroot SecureAnywhere misses a virus?


Question



In this video Webroot purposely infect a machine running Webroot SecureAnywhere. They even disable the behaviour shield to replicate what would happen if a threat was missed and it executed on your PC.

We estimate there to be somewhere in the region of 50,000 new strains of malware every single day, so it's frankly impossible for the legacy signature-based approaches to keep up with the vast volume of threats.

Webroot SecureAnywhere adopts a new cloud-driven approach, ensuring that users always have access the the latest security "definitions" without needing to download any updates. This, coupled with a 700Kb agent, ensures optimal performance and enhanced security.

Webroot also recognise that the ever-rising volume of malware means that they'll miss threats, too. While they do have industry leading detection rates (See: http://www.av-test.o...er/mayjun-2012/) they have introduced unique protection against information-stealing malware, so even if they do miss something, the data that you really care about cannot be tampered with.

Recommended Posts

  • 0

Hello,

Not to complain about AV-Test, since this is more of a general issue facing all testers, but as I am sure you are aware, in any kind of sample set containing files not specifically verified by a human being there can be files which are incorrectly identified as malicious code when, in fact, they do not contain any executable code at all, or contain code that does not perform a threatening action, even though the behavior may initially be diagnosed as malicious (for example, a license key mechanism that injects the key into a runtime executable or library). While rare, reports of "false 'false positives'" can occur in tests involving samples, and investigating and balancing out those cases can be labor-intensive for both the tester and the testee.

Regards,

Aryeh Goretsky

Hi Yorak,

I would certainly be happy to work with you to personally address your false positive issues.

The problem with video reviews is that they can only over show the results of a sample-set which is statistically insignificant. Will we generate false positives? Absolutely, but I'd also like to think that our cloud-powered heuristics should generate less false positives versus the traditional approach.

Let's take a look at the latest AV-Test results: http://www.av-test.o...rt_no%5D=121849 (I hate these tests in general, but that's a whole other topic!)

Out of a sample of 661,176 we generated 4 false positives. Eset NOD32 generated 1 false positive out of the same sample, but they also missed a lot more threats, so it's always a bit of a trade-off.

As our community has grown, the quality of our security intelligence has improved, so we've seen a massive decline in the number of false positives compared to the early days.

Give it another whirl and if you still have problems send your keycode to wfletcher[at]webroot.com and I'll take a look for you.

  • 0

I haven't tried Webroot nor do I know anyone personally that runs it. I've been using Nod 32 for many of years. I get great results with Nod 32 overall but am not adverse to switching to Webroot.

What advantages does Webroot have over Nod 32, specifically in the real-time protection?

Gimme a key and I'll give you a cookie. :D

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

  • 0

Hello,

Not to complain about AV-Test, since this is more of a general issue facing all testers, but as I am sure you are aware, in any kind of sample set containing files not specifically verified by a human being there can be files which are incorrectly identified as malicious code when, in fact, they do not contain any executable code at all, or contain code that does not perform a threatening action, even though the behavior may initially be diagnosed as malicious (for example, a license key mechanism that injects the key into a runtime executable or library). While rare, reports of "false 'false positives'" can occur in tests involving samples, and investigating and balancing out those cases can be labor-intensive for both the tester and the testee.

Regards,

Aryeh Goretsky

Hi Goretsky,

I completely agree.

In my opinion, these tests are not representative of reality, but they can be useful as long as the reader understands the data. I remember a few months ago we absolutely bombed one of these tests because we generated hundreds of false positives. The tester installed us on a machine with thousands of infections and we (rightfully, in my opinion) automatically ramped up the heuristics to maximum, so we started to treat every file on the PC with maximum suspicion. Of course we generated lots of false positives and they trashed the product! In the real world, if one of our customers installed us on a machine with thousands of infections, the last thing they'll be concerned about is a false positive! Not to mention it would be pretty much impossible to get a PC into that state with Webroot SecureAnywhere installed!

One of the biggest problems I have with these tests is that the testers have to manually update the signature definitions before testing their sample malware. In the real-world, we don't get the luxury of updating our definitions the second before an infection strikes. With ~50,000 new threats every day, there's a huge window of exposure between updates which is not accounted for in the tests.

The 0-day tests they perform are also very weak. They tend to scan the virus and if the security vendor fails to detect it, the virus will be executed. If the virus is then running in memory, the security vendor is assumed to have failed. They don't take into consideration the monitoring capability of Webroot SecureAnywhere and the fact that the endpoint is protected from the threat, even though it's running (as you can see in the video in the OP).

The performance tests they perform can be very useful, though. :-)

  • 0

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

I don't know about that Will, I think it may be very entertaining.....

but I do agree, do your own homework on the product and pick the best one for you.

  • 0

Hi Goretsky,

The 0-day tests they perform are also very weak. They tend to scan the virus and if the security vendor fails to detect it, the virus will be executed. If the virus is then running in memory, the security vendor is assumed to have failed. They don't take into consideration the monitoring capability of Webroot SecureAnywhere and the fact that the endpoint is protected from the threat, even though it's running (as you can see in the video in the OP).

Complete success would be that it doesn't execute. If it doesn't execute it isn't taking up processor cycles. If it doesn't take processor cycles, it isn't going to take any part of it away from applications or other system processes. While the endpoint isn't going to allow the application/service to communication to the internet in essence it has failed to keep the machine clean and free from infection. It has given the end user the illusion that they are malware free because it stopped malware-x from communicating. So in my point of view it has failed from doing its job properly.

  • 0

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

Do you or could you offer a 30-day trial period? I see no option for this on your website.

  • 0

Do you or could you offer a 30-day trial period? I see no option for this on your website.

Here you go: http://www.webroot.com/En_US/consumer-trials.html

The home products are Webroot SecureAnywhere Complete, Essentials and Antivirus. The business product comes with a much more advanced management console.

  • 0

I've downloaded and am currently using your product, however I have one problem. Why is it I get no notification pop-up when an executable containing malicious code is blocked? I have to manually open the Webroot program and go to the quarantine to see this.

Every malicious test file that I've downloaded has been successfully blocked by Webroot, but I'd like be notified instantly of the block. I see no option in the settings to allow this to happen, am I overlooking it?

Thanks for your time.

  • 0

I've downloaded and am currently using your product, however I have one problem. Why is it I get no notification pop-up when an executable containing malicious code is blocked? I have to manually open the Webroot program and go to the quarantine to see this.

Every malicious test file that I've downloaded has been successfully blocked by Webroot, but I'd like be notified instantly of the block. I see no option in the settings to allow this to happen, am I overlooking it?

Thanks for your time.

Hi Marshall,

I'm just wondering if you may have downloaded our business product instead of the home user product(s)?

If the latter, I'll have a member of our consumer support team reach out to you, because you should be at least alerted by default.

  • 0

I have a comment on the video then I have a question.

Comment : Thank you for turning off Animations and fades during recording. Most people don't do that and it makes the machine feel sluggish so props for that.

Question

1) I really liked the rollback feature I saw in the video and have a question about it. What if it monitors an unknown file that the user installs. This unknown file is some sort of safe free word processor that the user uses. Then at some point in time the file is accidentally flagged as malware and the user goes to clean up the infection by following webroots instructions. Would all of the data the user created with that program be removed during the removal process?

If so, can you undo an undo?

Thanks

Adam.

  • Like 2
  • 0

I have a comment on the video then I have a question.

Comment : Thank you for turning off Animations and fades during recording. Most people don't do that and it makes the machine feel sluggish so props for that.

Question

1) I really liked the rollback feature I saw in the video and have a question about it. What if it monitors an unknown file that the user installs. This unknown file is some sort of safe free word processor that the user uses. Then at some point in time the file is accidentally flagged as malware and the user goes to clean up the infection by following webroots instructions. Would all of the data the user created with that program be removed during the removal process?

If so, can you undo an undo?

Thanks

Adam.

Hi warwagon,

I'll start by saying the scenario you describe should be super rare (and will probably never happen to you), but the answer is yes. All of the content that is removed by the journaling and rollback feature can be restored if needed.

In fact, you'll be able to see exactly what has been rolled-back in the quarantine section, so if you needed to restore a specific document you can do so.

Let me know if you have any more questions!

  • 0

I've experienced multiple issues, mainly the detection rates. I visit a lot of dodgy sites (those of you who are subscribers or mods know why) so I willingly subject myself to malicious content. I've been infected with multiple trojans and malware during my experience with webroot. Never did I have an infiltration when using Nod32 for the few years I've been using it.

I've since uninstalled Webroot and reinstalled Nod32 for peace of mind. Your cloud based AV is headed in the right direction, it just doesn't get the job done.

  • 0

It's very light on resources, more so than Nod32. You never know it's there, including when the real-time protection doesn't notify you of a threat or infestation.. :D

Like I said, Webroot is headed in the right direction, but in terms of detection of viruses, it is sub-par.

  • 0

"Webroot SecureAnywhere adopts a new cloud-driven approach"

That's great and all...until malware kills your internet connection.

Also, is it just me or does the "article" read like an ad?

Panda Cloud Antivirus is actually fantastic. I'd pay for it, but I don't really care enough to change from MSE.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Save up to 87% on ChatPlayground AI lifetime subscriptions by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where for only a limited time, you can save up to 87% on ChatPlayground AI: lifetime subscriptions. ChatPlayground AI puts the world’s top AI models in one powerful interface, letting you enter a single prompt and instantly compare outputs from multiple models to choose the perfect response for your needs. Boost productivity and creativity with access to the latest AI giants like GPT-4o, Claude Sonnet 4, Gemini 1.5 Flash, DeepSeek V3, and dozens more — all in one window. Whether you’re chatting, coding, generating images, or refining prompts, ChatPlayground AI equips you with advanced tools like prompt engineering, image/PDF chat, saved conversations, and AI image creation, plus priority support to keep your workflow seamless. Access the world’s best AI models Side-by-Side Comparisons: Enter one prompt & instantly view results from multiple AI models to find the best output for your needs 40+ AI Models: Includes GPT-4o, Claude Sonnet 4, Gemini 1.5 Flash, DeepSeek V3, Llama, Perplexity, and many more Multi-Function Platform: Access AI for chat, image generation & coding all within a single interface Web Browser Extension: Offers a Chrome extension to seamlessly integrate the platform into your browsing workflow Boost productivity with powerful features ChatPlayground Interface: Designed for seamless AI model comparison in one window Prompt Engineering: Refine & optimize your prompts for better, more accurate responses Chat with Images & PDFs: Upload visuals and documents to get context-aware answers Saved Chat History: Keep track of past conversations for reference & ongoing projects AI Image Generation: Create high-quality visuals powered by top AI image models Priority Customer Support: Get faster assistance whenever you need it What you'll get with the Unlimited Plan Includes unlimited messages/month Built for prompt engineers, startups, and teams who run experiments nonstop Includes priority access to new features and future models Good to know Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: Desktop Max number of device(s): Unlimited Available to both NEW & Existing users Updates included A lifetime subscription to ChatPlayground AI (Unlimited Plan) normally costs $619, but you can pick it up for just $79 for a limited time - that represents a saving of $530 (87% off). Click the link below for more details, always check terms and specifications before making a purchase. Get this ChatPlayground AI (Unlimited) for $79 (was $619) There are also two other discounted plans to choose from. Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I like Tidal, but it still does not control devices from the mobile/app and still no surround support. And yeah re: above comment I still get a lot of network errors and I am on a 4/4 Gbit Fiber connection.
    • Aren`t "security features" and "AI model that can see your screen" a tad diametric!
    • Samsung, Amazon extend 990 PRO 2TB NVMe SSD deal beyond Prime Day 2026 by Sayan Sen Recently, we had Amazon's Prime Day 2026 sales wherein there were several great deals including on SSDs. One of those discounted components was the Samsung 990 PRO SSD as the 2TB variant of it was selling for $370, a very good price after a long time. Although that deal was supposed to expire today, Amazon has now extended that sale further (purchase link under the specs table down below). The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $400. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The technical specs of the Samsung 990 PRO 2TB are given in the table below: Specification Value Form Factor M.2 2280 Interface PCIe Gen 4.0 x4, NVMe 2.0 NAND Flash Samsung V-NAND TLC Controller Samsung In-house Controller Cache Memory Samsung 2GB Low Power DDR4 SDRAM Sequential Read Speed Up to 7,450 MB/s Sequential Write Speed Up to 6,900 MB/s Random Read (4KB, QD32) Up to 1,400,000 IOPS Random Write (4KB, QD32) Up to 1,550,000 IOPS Random Read (4KB, QD1) Up to 22,000 IOPS Random Write (4KB, QD1) Up to 80,000 IOPS Operating Temperature 0°C to 70°C Reliability (MTBF) 1.5 Million Hours Endurance 1,200 TBW (Total Bytes Written) Get it at the link below: Samsung 990 PRO SSD 2TB NVMe SSD (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      539
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!