Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #4401  
Old June 14th, 2012, 08:49 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
No need. We automatically get them due to auto upload.


Thank you
  #4402  
Old June 14th, 2012, 08:50 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by lodore
Is there any possibility for hitman pro to add option to re enable task manager?
HitmanPro already repairs various policy settings, including the Task Manager policy (DisableTaskMgr). Are you referring to non-policy setting? We'll be more than happy to include it in the standard repair functions of HitmanPro.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4403  
Old June 14th, 2012, 08:58 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Hi Erik

I have another one for the withlisted

Need you the File for bcheck and for the analyse

SHA256: 31ca0250435a6df4f630765c1610afa433b421f598aca733f5f362121d3b1f17
SHA1: 650ed35900b667fba80071f33338fcfce52eb07e
MD5: 7782e143924e9688970a1df065693998
File size: 378.5 KB ( 387584 bytes )
File name: C:\Windows\System32\iedkcs32.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-06-14 12:56:44 UTC ( 1 Minute ago )
Attached Thumbnails
Click image for larger version

Name:	Glary utilitiesöklöklökl#öä#öä#öä#öklöklöklöklkl.jpg
Views:	2
Size:	146.9 KB
ID:	233310  

  #4404  
Old June 14th, 2012, 10:05 AM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
HitmanPro already repairs various policy settings, including the Task Manager policy (DisableTaskMgr). Are you referring to non-policy setting? We'll be more than happy to include it in the standard repair functions of HitmanPro.
Im not sure how it was disabled but hitman pro repaired regedit but didnt repair task manager on a computer I fixed.
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #4405  
Old June 14th, 2012, 10:07 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Hi Erik

I have another one for the withlisted

Need you the File for bcheck and for the analyse

SHA256: 31ca0250435a6df4f630765c1610afa433b421f598aca733f5f362121d3b1f17
SHA1: 650ed35900b667fba80071f33338fcfce52eb07e
MD5: 7782e143924e9688970a1df065693998
File size: 378.5 KB ( 387584 bytes )
File name: C:\Windows\System32\iedkcs32.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-06-14 12:56:44 UTC ( 1 Minute ago )
Done.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4406  
Old June 14th, 2012, 10:08 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by lodore
Im not sure how it was disabled but hitman pro repaired regedit but didnt repair task manager on a computer I fixed.
Hmm. Maybe next time we can have a remote look? If you send me a PM then I usually can have a remote look right away.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4407  
Old June 14th, 2012, 10:15 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 811
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
Done.

Thank you very much

Need you the File for check and for the analyse
  #4408  
Old June 14th, 2012, 10:54 AM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
Hmm. Maybe next time we can have a remote look? If you send me a PM then I usually can have a remote look right away.
Sure if it happerns again i can let you know.
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #4409  
Old June 15th, 2012, 09:07 PM
iammike's Avatar
iammike iammike is offline
Regular Poster
 
Join Date: Jun 2012
Location: SE Asia
Posts: 139
Default Re: Hitman Pro Support and Discussion Thread

All beta's running without problem on Win7 x64.

Just a feature request. I write my own programs and every time I run a scan Hitman Pro wants to upload them to the Scan Cloud. Is it possible to add an "ignore file" option, so on the next scan they are not detected anymore ?

Else, everything oke

Last edited by iammike : June 15th, 2012 at 10:47 PM.
  #4410  
Old June 16th, 2012, 09:52 AM
mrpink mrpink is offline
Frequent Poster
 
Join Date: Mar 2010
Posts: 348
Default Re: Hitman Pro Support and Discussion Thread

What's this?
Looks familiar lol
Attached Images
  
  #4411  
Old June 16th, 2012, 10:42 AM
mrtnptrs mrtnptrs is offline
Infrequent Poster
 
Join Date: May 2012
Location: The Netherlands
Posts: 25
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by mrpink
What's this?
Looks familiar lol
I think that this is a copy of HitmanPro to earn money.
Surfright has copyright, now you can use it!
  #4412  
Old June 16th, 2012, 01:30 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: Hitman Pro Support and Discussion Thread

A few more EWS) :
Attached Images
 
  #4413  
Old June 16th, 2012, 01:39 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by gerardwil
A few more EWS) :
EWS is not a scan you should run on regular basis.
That said, I'll whitelist these new files.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4414  
Old June 16th, 2012, 02:17 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
EWS is not a scan you should run on regular basis.
That said, I'll whitelist these new files.

I know but I felt I have to let you know these
  #4415  
Old June 18th, 2012, 06:09 PM
poison poison is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 144
Default Re: Hitman Pro Support and Discussion Thread

Hi, maybe somebody can help me.. I did a scan today with Hitman Pro and got the following infection:

Name:  SS_20120618_225419.jpg
Views: 439
Size:  169.6 KB

I have NOD32 and SUPERAntiSpyware Pro running real time along with Outpost Pro Firewall with Proactive Protection enabled and I have Malwarebytes Pro for on demand and none of those indicate I have an infection. I do have task manager replaced with Process Hacker, however, could that be the reason of the detection and it is a false positive or should I be worried?

It seems to be a registry key so I cannot get to the file to upload to Virus Total..

Thanks
  #4416  
Old June 18th, 2012, 06:32 PM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by poison
Hi, maybe somebody can help me.. I did a scan today with Hitman Pro and got the following infection:

Attachment 233399

I have NOD32 and SUPERAntiSpyware Pro running real time along with Outpost Pro Firewall with Proactive Protection enabled and I have Malwarebytes Pro for on demand and none of those indicate I have an infection. I do have task manager replaced with Process Hacker, however, could that be the reason of the detection and it is a false positive or should I be worried?

It seems to be a registry key so I cannot get to the file to upload to Virus Total..

Thanks

I have just installed process hacker and used the option to replace task manager and I get the same FP. I then ran a scan with the task manager replacement option turned off and nothing detected.
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #4417  
Old June 19th, 2012, 04:58 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by lodore
I have just installed process hacker and used the option to replace task manager and I get the same FP. I then ran a scan with the task manager replacement option turned off and nothing detected.
We constantly fill the cloud with remnants. This one sneaked in. Solved the FP.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4418  
Old June 19th, 2012, 08:59 AM
poison poison is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 144
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by lodore
I have just installed process hacker and used the option to replace task manager and I get the same FP. I then ran a scan with the task manager replacement option turned off and nothing detected.
Quote:
Originally Posted by erikloman
We constantly fill the cloud with remnants. This one sneaked in. Solved the FP.

Thanks!
  #4419  
Old June 21st, 2012, 04:17 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

HitmanPro 3.6 Build 159 Released

Changelog
  • ADDED: Windows 8 Release Preview support.
  • ADDED: Detection and removal of XULRunner redirect scripts.
  • ADDED: /fb command line switch to perform Force Breach.
  • ADDED: HitmanPro switches the desktop to ensure visibility.
    Some Ransomware use a dedicated desktop to prevent applications from popping up.
  • IMPROVED: Force Breach to kill more processes.
  • IMPROVED: Force Breach now works under SYSTEM or SERVICE account.
  • IMPROVED: Detection and removal of ZeroAccess/Sirefef CLSID variant.
  • IMPROVED: Improved removal of MaxSS bootkit.
  • IMPROVED: Improved Volume Boot Record (VBR) handling.
  • FIXED: A problem where Default scheduled scan would not scan for cookies.
  • FIXED: SafeBoot Minimal was not working.
  • FIXED: Behavioral scoring on WOW64 uninstall keys.
  • FIXED: Compatibility issue with Dataplex caching software from NVELO.
  • UPDATED: Portugues language.
  • UPDATED: Internal white lists.
Users are automatically updated to the new version.

We've also released a new brochure for use in corporate environments here:
http://files.surfright.nl/hmp-brochure-en.pdf

Also the command line reference has been updated to reflect this version:
http://dl.surfright.nl/hmp-command-l...erence-1_5.pdf

Both documents can also be found here:
http://www.surfright.nl/en/downloads/business
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4420  
Old June 21st, 2012, 05:30 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Hitman Pro Support and Discussion Thread

I am not sure about this after I updated... Perhaps I should report in the WSA/Prevx forum.

Name:  ScreenShot_WSA_HMP_update3.6_Build159_01.jpg
Views: 232
Size:  75.8 KB
  #4421  
Old June 21st, 2012, 05:40 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Tarnak
I am not sure about this after I updated... Perhaps I should report in the WSA/Prevx forum.

Attachment 233425
I see a galore of threads in the HitmanPro.exe process writing in other process memory. This is NOT part of HitmanPro code so it must be malware doing this.

I addition I see HitmanPro is listing malware (red banner). The malware most likely injected itself in the HitmanPro.exe process and from there is injecting in other processes. That is what I can tell from the WSA event log.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4422  
Old June 21st, 2012, 05:50 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Hitman Pro Support and Discussion Thread

HMP scan is only picking up the same detection that I previously, reported, and ignored - http://www.wilderssecurity.com/showp...postcount=4390

The only thing going on is the numerous writes of NVT - SocketSentinal in WSA SecureAnywhere while running a HMP scan. I just don't get it.
  #4423  
Old June 21st, 2012, 06:03 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,135
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Tarnak
HMP scan is only picking up the same detection that I previously, reported, and ignored - http://www.wilderssecurity.com/showp...postcount=4390

The only thing going on is the numerous writes of NVT - SocketSentinal in WSA SecureAnywhere while running a HMP scan. I just don't get it.
Then I don't understand the log of WSA as that states that either HitmanPro.exe is writing in other process space or SocketSentinel is writing into HitmanPro.exe process space.
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4424  
Old June 21st, 2012, 06:22 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Hitman Pro Support and Discussion Thread

As you can see just prior to upgrading HMP, I had first shutdown WSA. I found this is better because I have noted that if I don't, I get freezing of my system, caused by interaction with WSA.

The screenshot below shows the restart of WSA after the HMP upgrade.

Perhaps, I should post in both the other developers' threads, with reference to my posts, here.

Click image for larger version

Name:	ScreenShot_WSA_HMP_update3.6_Build159_02.jpg
Views:	11
Size:	139.2 KB
ID:	233426
  #4425  
Old June 21st, 2012, 08:38 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,049
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Tarnak
As you can see just prior to upgrading HMP, I had first shutdown WSA. I found this is better because I have noted that if I don't, I get freezing of my system, caused by interaction with WSA.
WSA seems to affect alot legitimate programs (i had the same issue as you too) so i uninstalled WSA. it might ofer the best protection in the world but whats the point when you have to interact with it on a daily basis just to use your machine the way you want? anyway brilliant change-log eric

edit- i will giving away the 1 year WSA licence key. will send by PM to random members if my first PM gets no response.

re-edit= key given away
__________________
Active@ Disk Image | 10 On-Demand Scanners


Last edited by treehouse786 : June 21st, 2012 at 10:01 AM.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:57 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums