PC Tools ThreatFire 3.5
Solid free protection supplements your existing antivirus
- Blocks brand-new threats, monitors system activity
- Occasional PC lockups
ThreatFire adds a worthwhile layer of security for your computer. Even more impressively, it's free.
Your current antivirus program may offer plenty of protection, but new, unknown threats still could slip through. That's where PC Tools' ThreatFire comes in. Now in version 3.5, this free utility adds an extra layer of protection to the security software you already have. It blocks an impressive number of threats through behaviour-based analysis. As can sometimes happen with security tools, however, it caused some system lockups in our testing.
The new edition of this popular free security program, released in May, adds an on-demand signature-based scanner, a mostly just-for-fun world map that shows detected threats, and a useful system-activity monitor that provides a good deal of information on the programs and services running on your PC.
To identify a malware threat based on a positive signature match--which is still the primary method that most antivirus programs use — a lab must first obtain a sample of the malware and create a full signature for it. It that window of time, before a signature is available, your machine could be infected with the virus. By contrast, proactive detection such as behavioural analysis can detect and block brand-new threats without signatures, thereby providing immediate protection. Most antivirus programs supplement signature scanners with some type of proactive detection, but not all are as effective as ThreatFire.
In independent tests conducted for PC World by AV-Test.org, a German security-program testing operation, ThreatFire's performance was outstanding. It correctly identified 18 of 20 new, relatively unknown malware samples by looking purely at factors such as where the program came from, what changes it made to files or the system Registry, and whether the program attempted to send information to the Internet. It successfully blocked 17 of those 18 (one sample stopped ThreatFire before the block could occur), and it successfully cleaned 16 of those blocked (it left part of one infection behind).
What's more, ThreatFire didn't register any false alarms in AV-Test.org's run-throughs; this is a definite plus, since proactive, non-signature protection is often prone to false alarms.
Version 3.5 adds PC Tools' signature-based scanner, formerly available only in the $US30-per-year Pro version. Since it isn't real-time protection, it won't scan every new saved file, so you will need to schedule it or activate the scan manually. The free version also requires that you keep its community features (which send anonymous detection info to PC Tools) enabled in order to continue receiving no-cost updates; doing so improves threat detection for all users, and there's no good reason to disable it. The Pro 3.5 version allows you to disable the feature, but unless you're running a business, you have no need to shell out for Pro. The free version of ThreatFire 3.5 is for home use.
The anonymous detection data also provides info for the utility's new Threat Detection display. Red dots on a global map show infection points for selected malware and adware threats.
Though the map is interesting, the new system-activity monitor is more useful. For the programs and services that are currently running, the monitor displays in-depth background info, such as the author, the command line, a list of open windows and modules, and other details for all processes. You can stop a process, or kick off a Google search for more information on it, with a right-click on the process name.
Other changes in 3.5 include better default options for handling alerts. For one thing, you can now instruct the tool to automatically quarantine, allow, or prompt whenever it encounters a suspected threat or potentially unwanted program (known threats are always quarantined). This version of ThreatFire also has improved master boot record scanning.
While you don't have to pay for ThreatFire, installing it entails another kind of cost. The lightweight ThreatFire service and system tray process didn't noticeably impact our test system while we surfed the Web and performed common tasks, and together they used less than 10MB of system memory. But security programs by nature have to reach far into your PC, and as a result they can often conflict with other software and cause trouble. In our tests on one heavily used PC with a wide range of installed programs and utilities, the computer locked up each time we attempted to run an on-demand scan using ThreatFire's signature scanner. You don't need to run the signature scanner to get ThreatFire's worthwhile behavioral protection, but such lockups are a good example of why you should be careful about installing too many security extras.
ThreatFire's thorough behavioral protection provides a worthwhile additional layer of security, particularly for shared or other at-risk PCs. It's all the more impressive for being free. As always, however, be careful about loading your computer down with security programs.
Join the Good Gear Guide newsletter!
Most Popular Reviews
- 1 2016 Ford Mustang EcoBoost review
- 2 Synology DS216+ Review
- 3 Review: TCL C1 series 4K TV
- 4 Tech21 Evo Xplorer iPhone case review
- 5 LG 55EG960T OLED UHD TV
Latest News Articles
- What Microsoft is taking away from Windows 10 in the Anniversary Update
- PowerDVD 16 gains 360-degree video playback: Here's how it works
- Microsoft will miss its one billion Windows 10 device target
- Google is working to make every website viewable in VR
- Twitter's new stickers are more useful than Snapchat
GGG Evaluation Team
First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.
- FTJava Tech Lead - Full StackNSW
- CCSenior Technology Specialist - Back-end Java/JEENSW
- FTTandem/NonStop Technical ConsultantWA
- CCSenior Java DeveloperVIC
- FTSenior Full Stack .Net DeveloperNSW
- FTDB2 Systems ProgrammerWA
- CCContract Systems Analyst (JAVA/J2EE/SQL) 160902/SA/812Asia
- CCStorage / Server EngineerNSW
- FTUnix Systems AdministratorNSW
- CCChange ManagerNSW
- FTFull Stack Application Developer - IoT projectsVIC
- CCSAP ABAP DeveloperNSW
- CCWebmaster content managementACT
- CCSr. SQL Server DBANSW
- FTPrincipal Business Consultant- Wealth ManagementNSW
- FTSenior Test Analyst | End to End TestingNSW
- FTApplication AdministratorACT
- CCContract Systems Analyst (CISCO/Firewall/Network) 160819/SA/423Asia
- CCSQL Database Administrator - DBANSW
- FTSAP BASIS HANA ConsultantNSW
- CCBusiness Analyst / SalesforceNSW
- FTBusiness AnalystACT
- CCEmail Production SpecialistNSW
- CCSAP ArchitectSA
- CCJunior/Intermediate Drupal web developer - APS Level 4/5 equiACT