HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Opening Windows Live Mail gave a Shell Code alert.

    Erik, I will send you a PM with the details.
     
  2. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    I get the same thing, every time I open WLM from IE11 I get a alert/crash, I had to uninstall!!
     
  3. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    No need to uninstall, although you could go back to build 171 / 172. I've temporarily removed the mitigations on WLM until I hear from Erik.
     
  4. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    Right im rolling back to 171
     
  5. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    I got a similar BadUSB Alert with a wireless mouse receiver, so should be the same cause.
     
  6. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    Also same thing here...
     
  7. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
    I had an alert about a new microsoft keyboard detected and shell code alert!

    Win 8 x32
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    I've found just disabling Load Library mitigations stops the Shell Code alert when opening WLM.
     
  9. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    The BadUSB got a different algorithm. So upgrading triggers the BadUSB alert. Fresh install does not. Just click Allow once and you are done. I will have a look to see if we can improve on this upgrade.
     
  10. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    CryptoGuard is suppose to trigger because AxCrypt overwrites the file with random data which totally looks like encryption. If you use these tools, disable CryptoGuard temporarily.
     
  11. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    The Shellcode mitigation is indeed under Load Library (as stated in the changelog). I was expecting several FPs because this is a new feature. I will push out an update today or tomorrow to address. Thanks for reporting :thumb:
     
  12. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    This is expected as CryptoGuard prevents mass file encryption. Using secure delete tools that first encrypt before deleting files triggers CryptoGuard. Temporary disable CryptoGuard before using tools that perform encryption before deletion like secure erasers.
     
  13. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Alert Windows Mail 2012 v16.4 with build 177/W7 64 bits.

    hmpalert.jpg .
     
  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
     
  15. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Thanks for info Krusty ;)
     
  16. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    No encryption fly-out with an (un)sandboxed IE11 and build 177 (W7 64 bits). I see a green IE11 fly out.

    Edit: no problems with the encryption fly-out with an (un)sandboxed Firefox 37.0.
     
    Last edited: Apr 1, 2015
  17. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
  18. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    Snap7.jpg HitmanPro.Alert 3.0.34 build 177 Release Candidate alert with wallmast.exe 4.0a
     
  19. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    I would not know which one to target for hackers. This, I think nobody knows. Or do you?
     
  20. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    I would now try to enable IAT filtering but disable Control Flow Integrity (ROP)
     
  21. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    Thank you! Perfect!
     
  22. PallMall

    PallMall Guest

    Reporting on latest HitmanPro.Alert 3.0.30.177 RC :

    1- At reboot after update from HitmanPro.Alert 3.0.30.172 and before login, HMP.Alert informed me that a new USB keyboard had been detected (there is no new USB keyboard and no new USB device whatever engaged). Of course I accepted.
    2- Issue with xmplay.exe remains (Control-Flow Integrity), none when that mitigation only for xmplay.exe only, disabled.
     
  23. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    Did you add a desktop wallpaper utility manually to HitmanPro.Alert? Why?
    Do not randomly apply exploit mitigations to software that are not internet-facing. You can run into issues like this, especially with software that is built for Windows 98, NT, ME, 2000 and XP. You can disable Enforce DEP if you insist on running this software on your 64-bit Windows 7 machine.
     
  24. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Hey Mark,

    Erik posted build 177 yet your signature has a link to build 176? ;)
     
  25. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    W7-x64, Uninstall hpa172 + clean install hpa177, hp240, IE11, FireFox 37.0, FireFox-nightly-x64 40.1a, Outlook-2003,.....

    Running without problems, no BadUSB issues, I am not using Windows Live Mail (WLM).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.