Should I Install ThreatFire?

One of my nerdy friends told me that I should install a program called Threat Fire because it can do things that my anti-virus program can’t do. Is this true and should I install it? – Samantha

When it comes to protecting your computer from viruses and other malware (malicious software), there are two approaches to guarding your computer in the anti-virus arena: signature-based and behavior-based.

The most common programs use “signature-based” scanners that look for known signatures of malicious code in any file that is being scanned. Most of the name-brand anti-virus programs on the market (Norton, McAfee, CA, AVG, Panda, Webroot, etc.) are signature-based scanners.

Signature-based anti-virus programs are very good at detecting malware because they are looking for the known signs at the code level for known malicious software. The hole in the signature-based scheme is that new threats can’t be detected until the infectious code has been discovered and added to the “signature” file of the anti-virus program (which is why it is so critical that you keep your anti-virus program up-to-date.)

This is also why anti-virus software can’t always protect you from infections, especially when opening file attachments or manually downloading “free” software, because new threats have to infect systems before they become known.

Once the new threat has been identified, the ‘race is on’ to update the detection signature file and get it out to all the users before they come in contact with the new infection.

In the past, new vulnerabilities would be discovered and we would start to see exploits appear a couple of months later. This gave the anti-virus companies ample time to create updated signature files and get them out to their users.

Today, it is very common to see “zero-day” exploits, which means as soon as a new vulnerability in any operating system or software program is discovered some bonehead on the Internet has written malicious code to take advantage of the hole the same day that the exploit was discovered.

In general, you shouldn’t run two signature-based anti-virus programs on the same system because they will detect each other as potential threats and can cause various other system maladies (more is not better, in this case.)

The latest type of anti-virus protection is based on behavior-based scanners that look for specific types of behavior that are common with malicious software programs. This behavior-based approach has a better chance of catching unknown threats that a signature-based scanner would not be able to detect until it was updated with the signature information.

The down side to behavior-based programs is that you’re more likely to get “false-positives” on legitimate programs that you do want to have running on your system.

ThreatFire is a free behavior-based anti-virus program from the folks at PC Tools that can be added as an additional layer to systems that are already running a signature-based anti-virus program.

I would not recommend running it on its own and I would not recommend adding it to a computer that is already infected or is on a dial-up connection or that’s experiencing performance issues. ThreatFire’s value comes from proactive protection against future threats, not current infections.

Generally speaking, if you have a signature-based anti-virus and you are very careful about what files you open and what websites you visit (heaven help all of you with teenagers in your house!) you will be just fine.

If you decide to add ThreatFire for additional protection, make sure your computer is completely clear of any malware before adding it (or any security software for that matter) or you could stand the chance of causing system lockups or reduced system performance as a result of the existing condition of your computer.

Ken Colburn
President of Data Doctors Computer Services, Host of the award-winning Computer Corner radio show, and Author of Computer Q&A in the East Valley Tribune newspapers.

Article Written by

  • tAz

    Threatfire + Comodo Personal Firewall + (cough) Windows Defender = Fortress :)

    Been running this combo on Vista HP for quite a while and it rocks. Lower mem overhead than any “All-In-One” Internet Security Suite out there.

    Being a heuristic scanner you do get the occassional unexpected alert when installing “trustworthy” applications but then you can make an educated guess as to why this is so ie installing the sensitive areas of the registry or systemroot.

    Hasn’t let me down yet. PCTools themselves recommend running it along side their own Spyware Doctor but I have not found this to be necessary.

    cheers,
    tAz

  • harold subido

    very clear explanation..
    thank you very much for sharing…