The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Threatfire

    Discussion in 'Security and Anti-Virus Software' started by richarddd, May 4, 2008.

  1. richarddd

    richarddd Notebook Consultant

    Reputations:
    15
    Messages:
    208
    Likes Received:
    1
    Trophy Points:
    31
    Threatfire seems to silently interfere with some programs.

    I was having problems installing Ubuntu using wubi. I eventually figured out that TF was changing some of the installed files. With TF suspended it installed fine. I've also noticed that when I download files using GrabIt (a newsreader), TF changes the downloaded files. Again, suspending TF fixed the problem.

    I tried re-downloading and reinstalling TF, but that didn't help

    Anyone else?
     
  2. Gintoki

    Gintoki Notebook Prophet

    Reputations:
    2,886
    Messages:
    6,566
    Likes Received:
    0
    Trophy Points:
    205
    Threatfire is a behavioral based "Antivirus" that stops anything that looks shady, it isn't a bug it's how it's supposed to be.
     
  3. richarddd

    richarddd Notebook Consultant

    Reputations:
    15
    Messages:
    208
    Likes Received:
    1
    Trophy Points:
    31
    I had thought it would pop-up a window asking if I wanted to allow the behavior it regards as shady, rather than just messing up files without warning.
     
  4. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    What kind of files were changed by ThreatFire?
    Some .exe files or mp3's/videofiles and how did ThreatFire change the files?
    Have you contacted their support forum (PCTools) about the changes made, I'm sure they've got the answers if you are sure the downloaded data was harmless.
    Cheers.
     
  5. richarddd

    richarddd Notebook Consultant

    Reputations:
    15
    Messages:
    208
    Likes Received:
    1
    Trophy Points:
    31
    Wubi was creating a text file (menu.lst, a grub config file) that ThreatFire always made 0 bytes long. Given the number of users of Ubuntu and wubi, not to mention the open source nature, I seriously doubt there is anything dangerous.

    Downloaded files were without a doubt harmless. TF altered a few bytes of just about everything I downloaded with GrabIt.

    It's fine for TF to see something harmless as a threat. I just wish it would tell me first, rather than silently messing with files.

    I wrote a detailed message to TF tech support on the PCTools web site, clicked send and it brought me back to the initial page. I don't have the energy to retype.
     
  6. coolguy

    coolguy Notebook Prophet

    Reputations:
    805
    Messages:
    4,679
    Likes Received:
    12
    Trophy Points:
    106
    That's why I didn't install TF. I don't want to run into unnecessary problems. I also don't believe in behavorial blockers.
     
  7. richarddd

    richarddd Notebook Consultant

    Reputations:
    15
    Messages:
    208
    Likes Received:
    1
    Trophy Points:
    31
    As a follow-up, when I uninstalled TF, it gave me the opportunity to describe any problems I had. I filled out the form and gave my email address, but have not heard anything back.
     
  8. Gintoki

    Gintoki Notebook Prophet

    Reputations:
    2,886
    Messages:
    6,566
    Likes Received:
    0
    Trophy Points:
    205
    They receive a lot of emails daily so it may take a while to get a response.
     
  9. richarddd

    richarddd Notebook Consultant

    Reputations:
    15
    Messages:
    208
    Likes Received:
    1
    Trophy Points:
    31
    Even so, a week seems a long time. We shall see what happens.