Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #4251  
Old April 16th, 2012, 05:18 AM
LegioXGemina LegioXGemina is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 4
Thumbs up Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
The problem with these keys is that they are also used by the SpamBlockerUtility installed by Hotbar (as per here).

I've disabled the keys in our cloud so that they should no longer be listed.

Can you verify?

I did a rescan and the problem was solved. Thanks!
The registry keys previously reported as malware by HitmanPro were referred to the "Toolbar Whitelist" installed by GData Antivirus 2012?
Thanks again for your technical assistance!
__________________
Windows 7 X64, Comodo Firewall Defense+ 5.9, Gdata Antivirus 2012, Malwarebytes AntiMalware Pro 1.61, Zemana Antilogger 1.9.2.941 and HitmanPro 3.6.0 b152
  #4252  
Old April 16th, 2012, 07:22 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Have you the Files send them via E-Mail to you


Have you the Files from me
  #4253  
Old April 16th, 2012, 09:53 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Have you the Files from me
I have them. I will have a look at them shortly. Thanks!
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4254  
Old April 16th, 2012, 12:18 PM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
I have them. I will have a look at them shortly. Thanks!

Okay thank you very much for it.

Can you post your result of the Files, please
  #4255  
Old April 16th, 2012, 07:53 PM
Empath Empath is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 159
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
That's not good. Do you have som e rollback software installed? Maybe we can have a remote look (using our QuickSupport tool) to see whats going on?

I got it working. I used an image to return everything back to pre-renew status. Then, in frozen mode of TimeFreeze, I re-activated. Everything worked, so I exited frozen mode while preserving changes made.

Next time, I'll know to wait until it's ready to expire. It now says it'll expire a year from yesterday. I still had time on my previous license 'till the 11th of next month. I lost almost a month of paid use. That could be a situation worth addressing in future licensing.
  #4256  
Old April 17th, 2012, 03:48 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Okay thank you very much for it.

Can you post your result of the Files, please
I just confirmed that the cloud does not accept your mentioned files. I will have a look why the cloud is rejecting these. I assume because they are incomplete (just ~700 bytes each). But then I expect a different error.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4257  
Old April 18th, 2012, 09:35 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
I just confirmed that the cloud does not accept your mentioned files. I will have a look why the cloud is rejecting these. I assume because they are incomplete (just ~700 bytes each). But then I expect a different error.


Okay thank you very much for your Info about it check the Cloud for my Files and live me an ansäet for this
  #4258  
Old April 18th, 2012, 10:16 AM
Scott W's Avatar
Scott W Scott W is offline
Frequent Poster
 
Join Date: Sep 2008
Location: USA
Posts: 357
Default Re: Hitman Pro Support and Discussion Thread

Hi erik,

I just ran the current version in Compatible Disk Access Mode (per your advice to Rollback Rx users - so as not to be falsely alerted to a Bootkit) and Hitman reports snapshot.exe as suspicious. This is Drive Snapshot, which is totally trusted software!

Scott
__________________
My Security Blanket: MSE + PrivateFirewall + RollBack Rx + Shadow Defender ...and I backup with Drive Snapshot (just in case)!
  #4259  
Old April 18th, 2012, 10:28 AM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Scott W
Hi erik,

I just ran the current version in Compatible Disk Access Mode (per your advice to Rollback Rx users - so as not to be falsely alerted to a Bootkit) and Hitman reports snapshot.exe as suspicious. This is Drive Snapshot, which is totally trusted software!

Scott

I had it come up during a default scan a few days back, Scott, and reported it here as well as via the program. It hasn't come up since, however.
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★
  #4260  
Old April 18th, 2012, 03:26 PM
Function Function is offline
Regular Poster
 
Join Date: Feb 2012
Location: UK
Posts: 64
Default Re: Hitman Pro Support and Discussion Thread

http://i.imgur.com/iqOli.png

http://i.imgur.com/mY39Y.png

mbam.sys is a part of MalwareBytes Anti Malware

brnfilelock.sys is a part of Blueridge Appguard

SbieDrv.sys is a part of Sandboxie

nvlddmkm.sys is a part of Nvidia


The rest are all emulation software, they are run games. I forgot I even had them so I deleted them.

WinKawaks.exe was a emulator. I have deleted it before with Hitmanpro, the file is now gone but after the rootboot the scan always says its there.

I think its showing a few false positives for me.

I am using Rollback RX so I assume that the Master Boot Record is to do with that.

I am wondering if this is a problem between Hitman and Rollback RX snapshot system.

Currently going though all of my Snapshots to remove the emulation files to ensure its not a fault of Rollback RX.
  #4261  
Old April 18th, 2012, 03:32 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Function
http://i.imgur.com/iqOli.png

http://i.imgur.com/mY39Y.png

mbam.sys is a part of MalwareBytes Anti Malware

brnfilelock.sys is a part of Blueridge Appguard

SbieDrv.sys is a part of Sandboxie

nvlddmkm.sys is a part of Nvidia


The rest are all emulation software, they are run games. I forgot I even had them so I deleted them.

WinKawaks.exe was a emulator. I have deleted it before with Hitmanpro, the file is now gone but after the rootboot the scan always says its there.

I think its showing a few false positives for me.

I am using Rollback RX so I assume that the Master Boot Record is to do with that.
Quote:
Originally Posted by Function
I am wondering if this is a problem between Hitman and Rollback RX snapshot system.
Switch into Compatible Disk Access (under Settings -> Advanced).

Rollback RX is NOT compatible with HitmanPro's Direct Disk Access because Rollback RX is hiding files from the operating system (= rootkit-like behavior).

Hope this helps.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4262  
Old April 18th, 2012, 05:07 PM
Function Function is offline
Regular Poster
 
Join Date: Feb 2012
Location: UK
Posts: 64
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
Switch into Compatible Disk Access (under Settings -> Advanced).

Rollback RX is NOT compatible with HitmanPro's Direct Disk Access because Rollback RX is hiding files from the operating system (= rootkit-like behavior).

Hope this helps.

Switch to Compatible Disk Access. Did the scan, nothing came up. All clean with this scan.

So should I always use Hitman Pro with Compatible Disk Access from now on?

Also I can't seem to find anyway to check for updates? Does it just automatically happen?
  #4263  
Old April 18th, 2012, 05:13 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Function
So should I always use Hitman Pro with Compatible Disk Access from now on?
Yes. For as long as you use Rollback RX.
Quote:
Originally Posted by Function
Also I can't seem to find anyway to check for updates? Does it just automatically happen?
HitmanPro is a behavioral scanner (local) and a cloud scanner (remote). The AV scanning is done remotely in cloud where the AVs are always up to date.

If there is a program update then HitmanPro will update automatically.

So you don't have to do anything. Just run it regularly or set a scan schedule under Settings -> Scan.

Hope this helps.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4264  
Old April 18th, 2012, 06:43 PM
jmonge's Avatar
jmonge jmonge is online now
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,770
Default Re: Hitman Pro Support and Discussion Thread

i am just running webroot with hitmanpro only this 2 and i feel alot faster now and secure if webroot missed some thing hitmanpro will nail it and destroy itthanks for making this wonderfull program is a very cool program to have always scaning in the system
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #4265  
Old April 19th, 2012, 02:37 AM
kardokristal's Avatar
kardokristal kardokristal is offline
Developer
 
Join Date: Jan 2012
Location: Estonia
Posts: 499
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by jmonge
i am just running webroot with hitmanpro only this 2 and i feel alot faster now and secure if webroot missed some thing hitmanpro will nail it and destroy itthanks for making this wonderfull program is a very cool program to have always scaning in the system

  #4266  
Old April 19th, 2012, 09:59 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

HitmanPro 3.6 Build 153 Released

Changelog
  • ADDED: Behavioral scan now detects spoofed memory mapped file names.
  • FIXED: Solved a time zone issue when validating the license.
  • IMPROVED: Several minor user interface issues.
  • UPDATED: Internal white lists.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4267  
Old April 19th, 2012, 10:18 AM
Amit's Avatar
Amit Amit is offline
Massive Poster
 
Join Date: May 2011
Location: Parallel Universe
Posts: 4,631
Default Re: Hitman Pro Support and Discussion Thread

updating automatically right now ......
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool.
✓Science is the belief in the ignorance of experts.
✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough.


-------Richard P. Feynman---------
  #4268  
Old April 19th, 2012, 11:01 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Volume Boot Record / VBR rootkits

HitmanPro 3.6 Build 154 BETA

Changelog
  • ADDED: Detection and removal of Volume Boot Record / VBR bootkits.
  • ADDED: Detection and removal Cidox, Mayachok, Rovnix bootkit.

An hour ago we've released build 153 to address time zone issues related to license activation. The problem was introduced in build 152, which is now fixed.

We now also release BETA build 154 (it has been in our source control system for a while now) which is dedicated to detecting and removing Volume Boot Record / VBR bootkits like Cidox, Mayachok, Rovnix, etc. These bootkits run on both 32-bit and 64-bit systems and work much like MBR bootkits.

First reports on VBR bootkits date back to July 2011:
http://news.drweb.com/?i=1772&c=23&lng=en&p=2
http://blog.eset.com/2011/08/23/hast...oiting-the-vbr

You can now use HitmanPro to cleanup these VBR infections.

Name:  Cidox.png
Views: 568
Size:  33.0 KB

BETA
32-bit http://dl.surfright.nl/HitmanPro36beta.exe
64-bit http://dl.surfright.nl/HitmanPro36beta_x64.exe
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4269  
Old April 19th, 2012, 11:39 AM
Amit's Avatar
Amit Amit is offline
Massive Poster
 
Join Date: May 2011
Location: Parallel Universe
Posts: 4,631
Default Re: Hitman Pro Support and Discussion Thread

updated to build 153....running smoothly here ........
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool.
✓Science is the belief in the ignorance of experts.
✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough.


-------Richard P. Feynman---------
  #4270  
Old April 19th, 2012, 11:51 AM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: Hitman Pro Support and Discussion Thread

....and 154 as well
  #4271  
Old April 19th, 2012, 12:03 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
HitmanPro 3.6 Build 153 Released
Excellent! Installed on 2 machines & scans run.
Thank you for the constant improvements.
You are making your tool indispensable, Erik.
And I'm very much looking forward to having Volume Boot Record/VBR bootkits detection capability in Build 154.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4272  
Old April 19th, 2012, 12:39 PM
RSpanky's Avatar
RSpanky RSpanky is offline
Frequent Poster
 
Join Date: Feb 2009
Location: Arizona, USA
Posts: 220
Default Re: Hitman Pro Support and Discussion Thread

Updated 153 and running great, AS ALWAYS
__________________
Webroot SecureAnywhere - Sandboxie - Malwarebytes Pro(RT) - OpenDNS


If it ain't broke, Then don't fix it. But if it does break I will come here to fix it
  #4273  
Old April 19th, 2012, 01:25 PM
carat
 
Posts: n/a
Default Re: Hitman Pro Support and Discussion Thread

Build 153 detects AVG as suspicous
  #4274  
Old April 19th, 2012, 02:12 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by tpro
Build 153 detects AVG as suspicous
What AVG suite are you using.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4275  
Old April 19th, 2012, 02:44 PM
carat
 
Posts: n/a
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
What AVG suite are you using.

AVG IS 2012
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:44 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums