HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,750
    Location:
    EU
    So far so good on Win7 Ult.(64)
    USB keyboard message is gone.
     
  2. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    German version still says "Tastaturschlag Verschlüsselung"

    There is no such word in german language. see: http://www.duden.de/suchen/dudenonline/Tastaturschlag

    As "Tastaturschlag Verschlüsselung" is to long anyway, my suggestion is: Tastatur Verschlüsselung
     
  3. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Build 178 is running great here. The issue with Shellcode alert when opening Windows Live Mail is resolved.

    Thanks. :thumb:
     
  4. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Build 178 and previous versions gave me an alert, when I started Color-Filters from NIK-Filter-Collection, within Photoshop-Elements 11.
    I had to disable IAT, to avoid alerts.

    http://abload.de/img/hmpalertagqll.jpg
     
  5. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    build 178 RC :)
     
  6. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    W7-x64, hp240, upgrade hpa 177 -> 178, FF 37.0, IE11,...

    No issues/problems at all.
     
  7. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    Thanks for the input. The German translation was done by a native German who is active in the computer security business (professionally) for many, many years. And yes, the word is not registered in the official German dictionary, a Google Search for "Tastaturschlag" returns over 2500 hits. Even though that's not many, I'm led to believe that the word is informally used by the German population.
    A Google Search for "Tastatur Verschlüsselung" returns about the same amount of hits. So, what to do?
    We'll leave if at is for the time being. If you have other remarks, let us know!
     
  8. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    Hi. I'm native german. It's no hard mistake, it's ok. "Tastatur Verschlüsselung" would be worser IMO. A solution could be "Tastaturanschlag Verschlüsselung" but the best (esp. in technical sence) is "Tastatureingaben Verschlüsselung". But maybe it is both to long?

    Background: Tastaturschlag or Tastaturanschlag is the hardware thing. (how easy or fast I can type with keyboard xy, how comfortably are the keys etc.) Tastatureingaben is what happens and what is encrypted by alert.

    Another thing in german translation, but also a small issue what is not completely wrong:

    "Schützt Anwendungen gegen aktuelle und zukünftige Angriffe anhand System-Schwachstellen"
    better would be
    "Schützt Anwendungen gegen aktuelle und zukünftige Angriffe durch System-Schwachstellen"
     
  9. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Confirmed fixed with 178 :)
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Now have RC 178 on all computers. Working great sofar.
     
  11. Surfright (circle) is so close to the German border (arrow), they could hire a native german translator who could go to office on his biccycle

    Untitled.png
     
  12. heikwith

    heikwith Registered Member

    Joined:
    Jul 29, 2002
    Posts:
    91
    HitmanProAlert3.0.35.178RC Attack intercepted Avantbrowser2015v12.5 build 10.jpg After update from 172RC to 178RC I got this.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    ROP Alerts with Firefox 37 on Youtube(FF now defaults to HTML5 video) in combination with Webroot SecureAnywhere, no alerts when Identity Shield is disabled.
     
  14. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    Turn off Load Library mitigation for Avant Browser. We'll look into it later. Thanks!
     
  15. PallMall

    PallMall Guest

    HMP.Alert 3 build178 RC running smooth on Firefox 37 / Win7.1 Premium x64
    USB keyboard message is gone.
    Problem with no issue is that it brings no information. Still, I won't say I'm sorry about that. Hmm...
     
  16. Man van het noorden

    Man van het noorden Registered Member

    Joined:
    Jun 26, 2014
    Posts:
    12
    Location:
    NL
    After installing build 178 (I came from build 172) I have problems with Thunderbird. When I start Thunderbird, the flyer appears but the interface never shows. In Task Manager I can see that the thunderbird.exe process is active (very active) and it stays that way using a lot of processor time. When I quit the process and try to start it again... the same thing happens but sometimes I'm lucky and the Thunderbird interface does appear and I can do my thing, but most of the time... nope. Only after disabling the 'Load Library' function for thunderbird.exe the issue seems really gone.
     
  17. PallMall

    PallMall Guest

    In what HitManPro.Alert "category" have you set Thunderbird? I've included Thunderbird within OFFICE (as advised elsewhere on this thread) and I've encountered no issue up to now.
     
  18. Man van het noorden

    Man van het noorden Registered Member

    Joined:
    Jun 26, 2014
    Posts:
    12
    Location:
    NL
    Yes Thunderbird is in the OFFICE category as the advice was. Do you have 'Load Library' enabled?
     
  19. PallMall

    PallMall Guest

    Yes, all mitigations are enabled here for Thunderbird set in OFFICE...
    The strange thing is that you've encountered the issue you describe above only with latest HMP.Alert 178 as I understand it.
    I guess you're aware of not having installed/modified any code related to Thunderbird since HMP.Alert 172?
    Otherwise your issue requires the developer's analysis ... I'm afraid I cannot dig any further than a basic, elementary approach.
     
  20. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  22. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    We will have a look at the issue. Thanks for reporting.
     
  23. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    We did hire a native translator.
     
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Mitigation DEP

    Platform 6.3.9600/x64 06_45
    PID 11808
    Application C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Description Google Chrome 41

    IP = 1C50B9C0, State = 0x1000, Type = 0x20000, Protect = 0x4

    Stack Trace
    # Address Module Location
    -- -------- ------------------------ ----------------------------------------
    1 2EE440BA (anonymous; chrome_child.dll)
    8b75fc MOV ESI, [EBP-0x4]
    83c404 ADD ESP, 0x4
    e92c000000 JMP 0x2ee440f1

    2 2EE4566A (anonymous; chrome_child.dll)
    3 2EE4EF62 (anonymous; chrome_child.dll)
    4 2EE4ECAC (anonymous; chrome_child.dll)
    5 2EE0A61B (anonymous; chrome_child.dll)
    6 2EE4F143 (anonymous; chrome_child.dll)
    7 2EE4ECAC (anonymous; chrome_child.dll)
    8 2EE0A61B (anonymous; chrome_child.dll)
    9 2EE4F143 (anonymous; chrome_child.dll)
    10 2EE4ECAC (anonymous; chrome_child.dll)
     
  25. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Protect = 0x4. This means that the page is not executable (0x4 = PAGE_READWRITE, compare to PAGE_EXECUTE_READWRITE).
    Are you running an old plugin?

    Do you get the message consistently?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.