Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #4601  
Old August 9th, 2012, 02:35 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
The lines in red explain why. Whitelisted.
FWIW, stdvcl32.dll is still appearing in the default scan.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4602  
Old August 10th, 2012, 07:30 PM
TomAZ TomAZ is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 358
Default Re: Hitman Pro Support and Discussion Thread

Can someone explain the "Private Cloud" at the bottom of the Proxy Tab in the new version 164? If checked, is it used in place of the standard cloud -- or in addition to the standard cloud? Also, what is supposed to go in the box directly to the right of the check box?
  #4603  
Old August 10th, 2012, 07:34 PM
markloman's Avatar
markloman markloman is offline
Developer
 
Join Date: Jan 2005
Posts: 71
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by TomAZ
Can someone explain the "Private Cloud" at the bottom of the Proxy Tab in the new version 164? If checked, is it used in place of the standard cloud -- or in addition to the standard cloud? Also, what is supposed to go in the box directly to the right of the check box?
Ssst! Hush hush It's a secret feature. Do not enter any data in the input field and leave the box unchecked. We'll reveal more about it later...
__________________
HitmanPro 3.7.5 Build 197 with Kickstart 2.2 | get.hitmanpro.com
  #4604  
Old August 10th, 2012, 08:43 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
You can upload suspicious or EWS items to VirusTotal. When a key is entered the VT-upload feature becomes available at the end of each row in the scan result view. Its a third-opinion.
This feature does not appear to be working for me on my XP box.
I entered my API key from VT and ran HMP 3.6.1 build 164 .
It once again flagged stdvcl32.dll (that was supposed to be whitelisted the other day), and although VirusTotal did appear as an option, when I clicked on it, nothing happened, and then HMP closed.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4605  
Old August 10th, 2012, 08:58 PM
TomAZ TomAZ is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 358
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
I entered my API key from VT and ran HMP 3.6.1 build 164 .
and although VirusTotal did appear as an option, when I clicked on it, nothing happened, and then HMP closed.

I've had this problem with VirusTotal as well on my XP machine. I've entered my API key too, but nothing happens.
  #4606  
Old August 10th, 2012, 09:01 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

I don't know if the problem exists also on W7 since I don't have that file on that box.
Maybe I should move it over there and test W7 too.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4607  
Old August 10th, 2012, 10:06 PM
TomAZ TomAZ is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 358
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
I don't know if the problem exists also on W7 since I don't have that file on that box.
Maybe I should move it over there and test W7 too.

My problem has not been specifically with that file, but rather in trying to use VT from within HMP on any file that has been flagged. It just doesn't seem to work for me.
  #4608  
Old August 10th, 2012, 10:18 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by TomAZ
My problem has not been specifically with that file, but rather in trying to use VT from within HMP on any file that has been flagged. It just doesn't seem to work for me.
I gotcha.
The only reason I mention that file is because it's the only one being flagged for me on two machines, so it's the only chance I've had to use the VT feature.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4609  
Old August 10th, 2012, 10:37 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
I don't know if the problem exists also on W7 since I don't have that file on that box.
Maybe I should move it over there and test W7 too.
I copied the same file to the Windows\System32 folder on my W7 machine and ran a scan.
HMP flagged it and the VT API key thing worked fine (the VT page opened).
So it looks like perhaps this is only happening on XP, SP3.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4610  
Old August 10th, 2012, 10:48 PM
TomAZ TomAZ is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 358
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
So it looks like perhaps this is only happening on XP, SP3.

That's exactly what I'm using -- XP SP3
  #4611  
Old August 11th, 2012, 02:45 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,153
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
This feature does not appear to be working for me on my XP box.
I entered my API key from VT and ran HMP 3.6.1 build 164 .
It once again flagged stdvcl32.dll (that was supposed to be whitelisted the other day), and although VirusTotal did appear as an option, when I clicked on it, nothing happened, and then HMP closed.
I've white listed it (it wasn't, thought I did ).

You saw HitmanPro close after clicking on VT ? Sounds like an issue. Can you reproduce is several times?
__________________
HitmanPro 3.7.6 Build 201 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4612  
Old August 11th, 2012, 09:58 AM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by erikloman
I've white listed it (it wasn't, thought I did ).

You saw HitmanPro close after clicking on VT ? Sounds like an issue. Can you reproduce is several times?
I reproduced it about 2-3 times last night before I posted about it.
I would be happy to try to reproduce it some more times as you have requested, but now that you have whitelisted that stdvcl32.dll file, nothing turns up on the scan anymore! What now? My machines are too clean. Maybe remove stdvcl32.dll from the whitelist?
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4613  
Old August 12th, 2012, 09:26 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,732
Default Re: Hitman Pro Support and Discussion Thread

Just updated to build 164.
  #4614  
Old August 13th, 2012, 03:47 PM
desert_by_night's Avatar
desert_by_night desert_by_night is offline
Infrequent Poster
 
Join Date: Apr 2012
Location: Portugal
Posts: 28
Default Re: Hitman Pro Support and Discussion Thread

Hi everybody
Another great test of Force Breach.

-http://www.youtube.com/user/Britec09-
  #4615  
Old August 13th, 2012, 06:18 PM
volvic volvic is offline
Regular Poster
 
Join Date: Aug 2009
Posts: 168
Default Re: Hitman Pro Support and Discussion Thread

Does anyone know of any promotions / discount coupon for hitman pro. Thanks. (PS Pls pm me too if poss)
  #4616  
Old August 14th, 2012, 01:56 PM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 834
Default Re: Hitman Pro Support and Discussion Thread

Hi Eric

Can you whiteliste the files

SHA256: b2302e61453bf32cfb5e886a13eb8780c6837c0b22e41b7750278f38e523ec8a
SHA1: 698a2d9f00ef2320d36e23774629b088a1388ae5
MD5: ff9578aad7acd2df58082bf5046f1b28
File size: 10.6 MB ( 11111424 bytes )
File name: ieframe.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:51:19 UTC ( 1 Minute ago )

SHA256: cde65b1225216feb00cacd7e26bb3cecc9b9d71d8b272665660e80cbb83d1e41
SHA1: 8d4bcd23af079c85936ecf7e868e61e335cdaca4
MD5: c0b2de7cdb7cbd4b99c89444bccb34a7
File size: 378.5 KB ( 387584 bytes )
File name: iedkcs32.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:53:36 UTC ( 0 Minuten ago )

SHA256: ed2bbd925758a5b23461ea8dfb845e0f34973c4c336634f507f1bf5e952b8ec4
SHA1: 7755917939b8efd9614b48a1bc9f4a171141d578
MD5: 09b57458e671a236ae528763c7cc3a08
File size: 170.0 KB ( 174080 bytes )
File name: ie4uinit.exe
File type: Win32 EXE
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:55:20 UTC ( 0 Minuten ago )
Attached Thumbnails
Click image for larger version

Name:	Hitman Pro 16.jpg
Views:	6
Size:	110.7 KB
ID:	234180  

  #4617  
Old August 14th, 2012, 02:05 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Page42
This feature does not appear to be working for me on my XP box.
I entered my API key from VT and ran HMP 3.6.1 build 164 .
It once again flagged stdvcl32.dll (that was supposed to be whitelisted the other day), and although VirusTotal did appear as an option, when I clicked on it, nothing happened, and then HMP closed.
Quote:
Originally Posted by erikloman
I've white listed it (it wasn't, thought I did ).

You saw HitmanPro close after clicking on VT ? Sounds like an issue. Can you reproduce is several times?
Quote:
Originally Posted by Page42
I reproduced it about 2-3 times last night before I posted about it.
I would be happy to try to reproduce it some more times as you have requested, but now that you have whitelisted that stdvcl32.dll file, nothing turns up on the scan anymore! What now? My machines are too clean. Maybe remove stdvcl32.dll from the whitelist?
I'm still happy to test but need something to test it with.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #4618  
Old August 14th, 2012, 04:22 PM
Adric Adric is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 408
Default Re: Hitman Pro Support and Discussion Thread

I believe this is a false positive also...
Attached Images
 
  #4619  
Old August 15th, 2012, 01:46 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 834
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Hi Eric

Can you whiteliste the files

SHA256: b2302e61453bf32cfb5e886a13eb8780c6837c0b22e41b7750278f38e523ec8a
SHA1: 698a2d9f00ef2320d36e23774629b088a1388ae5
MD5: ff9578aad7acd2df58082bf5046f1b28
File size: 10.6 MB ( 11111424 bytes )
File name: ieframe.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:51:19 UTC ( 1 Minute ago )

SHA256: cde65b1225216feb00cacd7e26bb3cecc9b9d71d8b272665660e80cbb83d1e41
SHA1: 8d4bcd23af079c85936ecf7e868e61e335cdaca4
MD5: c0b2de7cdb7cbd4b99c89444bccb34a7
File size: 378.5 KB ( 387584 bytes )
File name: iedkcs32.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:53:36 UTC ( 0 Minuten ago )

SHA256: ed2bbd925758a5b23461ea8dfb845e0f34973c4c336634f507f1bf5e952b8ec4
SHA1: 7755917939b8efd9614b48a1bc9f4a171141d578
MD5: 09b57458e671a236ae528763c7cc3a08
File size: 170.0 KB ( 174080 bytes )
File name: ie4uinit.exe
File type: Win32 EXE
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:55:20 UTC ( 0 Minuten ago )

Hi Eric

Any infos about it
  #4620  
Old August 16th, 2012, 01:46 AM
Mops21 Mops21 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 834
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Hi Eric

Can you whiteliste the files

SHA256: b2302e61453bf32cfb5e886a13eb8780c6837c0b22e41b7750278f38e523ec8a
SHA1: 698a2d9f00ef2320d36e23774629b088a1388ae5
MD5: ff9578aad7acd2df58082bf5046f1b28
File size: 10.6 MB ( 11111424 bytes )
File name: ieframe.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:51:19 UTC ( 1 Minute ago )

SHA256: cde65b1225216feb00cacd7e26bb3cecc9b9d71d8b272665660e80cbb83d1e41
SHA1: 8d4bcd23af079c85936ecf7e868e61e335cdaca4
MD5: c0b2de7cdb7cbd4b99c89444bccb34a7
File size: 378.5 KB ( 387584 bytes )
File name: iedkcs32.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:53:36 UTC ( 0 Minuten ago )

SHA256: ed2bbd925758a5b23461ea8dfb845e0f34973c4c336634f507f1bf5e952b8ec4
SHA1: 7755917939b8efd9614b48a1bc9f4a171141d578
MD5: 09b57458e671a236ae528763c7cc3a08
File size: 170.0 KB ( 174080 bytes )
File name: ie4uinit.exe
File type: Win32 EXE
Detection ratio: 0 / 42
Analysis date: 2012-08-14 17:55:20 UTC ( 0 Minuten ago )

Hi Eric

Any infos about it
  #4621  
Old August 16th, 2012, 02:42 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,153
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Mops21
Hi Eric

Any infos about it
EWS is showing files that got recently deployed/updated. This way you can find malware that was recently deployed. But you should ONLY run EWS when you are an expert AND suspect malware infection. If you don't suspect infection, don't run with EWS.

The above files belong to Internet Explorer and are most likely recently updated. If you choose More Information at the end of each row you'll see why they are listed.

Hope this helps.
__________________
HitmanPro 3.7.6 Build 201 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4622  
Old August 16th, 2012, 05:12 AM
Adric Adric is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 408
Default Re: Hitman Pro Support and Discussion Thread

Erik

RegfromApp gets flagged during a normal scan. I don't understand why so many AV products have problems with stuff that comes from Nirsoft. a-squared is one such product.

Al
  #4623  
Old August 16th, 2012, 05:19 AM
Adric Adric is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 408
Default Re: Hitman Pro Support and Discussion Thread

deleted
  #4624  
Old August 16th, 2012, 05:41 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,153
Default Re: Hitman Pro Support and Discussion Thread

Quote:
Originally Posted by Adric
Erik

RegfromApp gets flagged during a normal scan. I don't understand why so many AV products have problems with stuff that comes from Nirsoft. a-squared is one such product.

Al
Google SafeBrowsing has a problem with it as well.
Click image for larger version

Name:	RegFromApp.png
Views:	3
Size:	81.0 KB
ID:	234192
Every software publisher that treats itself seriously should digitally sign its publications.

I've white listed the file.
__________________
HitmanPro 3.7.6 Build 201 with Kickstart 2.2 | Info | Blog | Shop | Download | Support
  #4625  
Old August 16th, 2012, 10:07 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,854
Default Re: Hitman Pro Support and Discussion Thread

very true
__________________
Kaspersky Internet Security 2013
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:26 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums