Author Topic: Has anybody used ThreatFire v4.5.0.17 the latest  (Read 21096 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #30 on: June 07, 2009, 10:33:50 AM »
ThreatFire shows in Security Center only if you enable it to do so in its settings.
ThreatFire shows in Security Center only if you enable it to do so in its settings.
As you'll see from the screen shot, that's not the case in Windows 7.  :)

Click image to enlarge

Windows 7 is still in beta and ThreatFire also doesn't officially support this OS (yet). So i see no problem. That feature works fine in XP and Vista.

it's behavior blocker
For instance... what?
Which is suspicious for it?

Um, malware? I thought you understand the concept of behavior analyzers and blockers.
Behavior blockers track what every program does and if they detect behavior that is common for malware, they prevent it, rollback the changes and alert the user. So if something tries to add itself into system folder, add system entry, starts listening to specific ports and tries contacting IRC server, behavior blocker will most probably jump on it.

The good is that behavior blockers are basically immune to packers and crypters and provide excellent 0-day protection without regular updates. The only downside is that they aren't exactly effective against Fake AV's where you just need signature detection.
Visit my webpage Angry Sheep Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #31 on: June 07, 2009, 11:10:42 AM »
Thanks RejZor.
The best things in life are free.

Offline George Yves

  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 4095
  • Help you I can
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #32 on: June 07, 2009, 11:33:23 AM »
I want to "add a spoon of tar in a jar of honey".

ThreatFire sees two types of threats: unknown (not in its db) and known (already in its db). When TF detects an unknown threat its user can define - either to allow or to deny and quarantine; when it detects a known threat, it quarantines the threat immediately and only inform the user that so and so was detected and quarantined. But what should the user do if any TF's "known threat" appears to be a false positive?

For example, I have ClamWin Portable on USB that I use when on a business trip. Before every trip I update ClamWin's database and I tried to do so after I installed TF. I failed to update the database this time. ThreatFire detected freshclam.exe (the program in ClamWin that updates its db) and immediately quarantined it as a "known threat" - Worm.Win32.AutoRun.ahep.

I went to PortableApps.com forum and read there that freshclam.exe should be put on whitelist. But as I have said - "known threats" can't be allowed in TF. Then I went to PCTool's forum and tried to register there and report this FP - I was prompted that the registration letter was send to my e-mail and my account would be activated after I click on a link in it. Three days have passed and I got no confirmation letter. I tried three different e-mails with the same result - no letters. So now if I want to update ClamWin I should suspend TF.
May the FOSS be with you!

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #33 on: June 07, 2009, 11:55:56 AM »
Actually thats not the case anymore for version 4.5. This version is not using signatures anymore, except signatures for behavioral part (so they can update behavior rules on the fly).
Visit my webpage Angry Sheep Blog

Offline George Yves

  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 4095
  • Help you I can
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #34 on: June 07, 2009, 12:23:22 PM »
Actually thats not the case anymore for version 4.5. This version is not using signatures anymore, except signatures for behavioral part (so they can update behavior rules on the fly).
And what? Why I can't get the confirmation e-mail? Why I can't freshclam.exe and other FP on their whitelist?
May the FOSS be with you!

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3695
  • If at first you don’t succeed; call it version 1.0
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #35 on: June 07, 2009, 12:37:28 PM »
I have a slightly different opinion concerning this.
In the event of a FP, most software can be configured to offer the user an option to ignore it.
Not so with the version of TF I use: the options are "quarantine", or "quarantine and notify". That's it. (No option to just "kill the process", or "ask me what to do".
Which makes the FP issue a deal breaker for a lot of would-be users. Has been talked about at length on the PCTools forum, the company appear not open in the slightest to changing the options.
Windows 10,Windows Firewall,Firefox w/Adblock.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48542
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #36 on: June 07, 2009, 04:51:40 PM »
Actually thats not the case anymore for version 4.5. This version is not using signatures anymore, except signatures for behavioral part (so they can update behavior rules on the fly).
And what? Why I can't get the confirmation e-mail? Why I can't freshclam.exe and other FP on their whitelist?
Try again and this time check your spam folder. Their reply to you is probably in there.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline George Yves

  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 4095
  • Help you I can
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #37 on: June 07, 2009, 06:25:15 PM »
Try again and this time check your spam folder. Their reply to you is probably in there.
I have been checking my e-mail addresses for three days already - no letters from TF forum. I went back to the forum - all my accounts are still awaiting confirmation.

I gave them 3 addresses (one at mail.ru and two at gmail.com) and got 0 responses. Could anybody help me to get in touch with TF forum administration?

==============

Oh, at last! I gave them the fourth address and got the confirmation. But all the three previous mailboxes are still empty.
« Last Edit: June 07, 2009, 08:00:35 PM by George Yves »
May the FOSS be with you!

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #38 on: June 07, 2009, 07:18:25 PM »
They are not exactly active on weekends...
Visit my webpage Angry Sheep Blog

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #39 on: June 08, 2009, 11:00:05 AM »
Hi all,

I've decided to install threatfire onto my PC ;) after a while when I was fixing my friend PC.
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #40 on: June 08, 2009, 01:43:23 PM »
Three days have passed and I got no confirmation letter. I tried three different e-mails with the same result - no letters.


If you're waiting on PC Tools, (rather than ex-Novatix in the US) they won't be back on deck until AM on Tuesday June 9 AEST (GMT+10) due to holiday Monday.
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #41 on: June 08, 2009, 01:52:51 PM »
Hi SpeedyPC,

In ThreatFire you have various options: allowed, denied, quarantined. If you have something allowed and regret that you can remove that item - those items there. If something was denied, you can restore,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

silvertones

  • Guest
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #42 on: June 08, 2009, 02:01:50 PM »
They've dropped support for Windows 2000 which I run. Version 4.5 will not work. They refuse to do anything about it.

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #43 on: June 08, 2009, 02:27:16 PM »
Hi SpeedyPC,

In ThreatFire you have various options: allowed, denied, quarantined. If you have something allowed and regret that you can remove that item - those items there. If something was denied, you can restore,

polonus

Thanks for the heads up polonus as I'm learning a bit more about threatfire ;)
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: Has anybody used ThreatFire v4.5.0.17 the latest
« Reply #44 on: June 08, 2009, 02:37:21 PM »
Drhayden1 on that screen shot picture as I can see you are using XP, may I ask what software addon did you used those icons layout at the top of your OS screen cause I like it looks really cool ;D
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip