Threatfire false positives ?

Discussion in 'malware problems & news' started by damian666, Apr 9, 2008.

Thread Status:
Not open for further replies.
  1. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    If ThreatFire gives a prompt on a program that is not malicious (default setting 3), is it considered a false positive? Should FP be reported to PC Tools?
     
  2. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    I think so.
     
  3. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Yes, please.
     
  4. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    I think so too, but you have to do it the old-fashioned way, there is no "report f/p" function in ThreatFire.
     
  5. Hairy Coo

    Hairy Coo Registered Member

    Joined:
    Oct 19, 2007
    Posts:
    1,486
    Location:
    Northern Beaches
    The best way probably would be to turn on Community Protection,which would assist in having FPs placed on the TF whitelist.
    Settings-general-community protection-can always be turned off
     
  6. KDNeese

    KDNeese Registered Member

    Joined:
    Dec 16, 2005
    Posts:
    236
    Just for info:

    wextract.exe is a process associated with the operating system, not malware.

    interop.shell32.dll is associated somehow with MS NET Framework, not malware.

    I couldn't find any info on the other one.
     
  7. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    That is the essence which makes whitelist apps so very dependable and trustworthy IMO.

    Many other apps leave a user with a degree of uncertainty and HIPS is a big uncertainty for any unfamilair with their system and even some who are, but take a strictly whitelist application for security and it more or less inventories ALL your apps deemed safe and then when enabled no others are allowed period, that is if AE is on guard.

    With ThreatFire theres still room for uncertainty in my estimation but maybe they'll get more aggressive in that regards at some point in the future. Right now in it's present form theres some areas that don't secure my confidence as well as an AE, Deep Freeze, or FD-ISR to name a few that do although these are very different purposed methods.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.