Hitman Pro Support and Discussion Thread

Discussion in 'other anti-malware software' started by yashau, Mar 20, 2009.

  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    White listed. Thanks.
     
  2. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Build 174 belongs to the 3.6 branch. If you want to try Kickstart, uninstall 3.6 and install 3.7. Otherwise, keep 174 installed. It will be updated before the end of the week.
     
  3. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    A Side-kick CD is in the works. Probably will be released at the end of this week. The Side-kick CD works in conjunction with the USB flash drive (you have to use both).
     
  4. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Hi Erik

    Thank you very much

    And what is with the tmp file
     
    Last edited: Dec 18, 2012
  5. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Thanks!
     
  6. heikwith

    heikwith Registered Member

    Joined:
    Jul 29, 2002
    Posts:
    91
    On my system, booting from Kickstart USB flash drive v3.7.0.183 no longer resulted in blinking cursor.
     
  7. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro.Sidekick 1.1 Beta Available (ISO)

    HitmanPro.Sidekick is the HitmanPro.Kickstart companion CD-ROM for computers that are unable to boot from USB.

    Some old computers lack the ability to boot from USB. With the Sidekick CD-ROM, these older computers can now boot into their ransomed Windows environment were Kickstart starts HitmanPro.

    In order to use Sidekick you also need a Kickstart USB flash drive.

    How to use Sidekick

    1. Burn the ISO to a CD-R (use for example ImgBurn).
    2. Create a HitmanPro.Kickstart USB flash drive (see www.surfright.nl/kickstart#create).
    3. Power off the ransomed computer.
    4. Put both the CD-R and the Kickstart USB flash drive into the ransomed computer.
    5. Power on the ransomed computer and boot it from the CD-R.
    6. During boot you should see the HitmanPro.Sidekick 1.1 bootstrap loader.
    7. Press 1 (or 2) to continue booting (same like Kickstart).
    8. Let the computer boot and wait until Kickstart starts HitmanPro.

    Note: If HitmanPro is not starting, reset the computer and boot again from CD-R. Some systems have trouble recognizing a new USB flash drive.

    The ISO also has all Kickstart documentation (in three languages) and a how-to-use Sidekick text file (English only).

    Again, you only need Sidekick when your computer is unable to boot from USB.

    Download
    http://dl.surfright.nl/beta/KickstartSidekick.rar

    Please let me know how Sidekick is Kickstarting your system :thumb:
     
    Last edited: Dec 20, 2012
  8. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro 3.7.0 Build 184 Released

    Changelog
    • ADDED: Upgrade from version 3.6 to version 3.7.

    All existing users are now automatically updated to build 184, including the 3.6 branch.
     
  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Brand new day...brand new scan.;)

    ScreenShot_HMP_3.7.0_Build 184_06.jpg

    ScreenShot_HMP_3.7.0_Build 184_07.jpg

    ScreenShot_HMP_3.7.0_Build 184_08.jpg
     
  10. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  11. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  12. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Flagged as Suspicious. I pretty sure it's an FP. I've had this program for years.

    Al
     

    Attached Files:

  13. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    There will be an update later today addressing the incorrect flagging of files as Suspicious. Made a typo on my behalf.
     
  14. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    okay, thanks Erik. I wasn't sure if this case related to the previous posts, so I thought it would not hurt to post a screenshot to be on the safe side.

    Al
     
  15. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro 3.7.0 Build 185 Released

    Changelog
    • FIXED: Some applications were incorrectly classified as Suspicious.
    • UPDATED: Embedded white lists.
    Existing 3.6 and 3.7 users are automatically updated.

    Thanks to Tarnak and Adric for reporting the problem.

    Merry X-mas and a Happy New Year!
     
  16. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
  17. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Different snapshot...new scan, and back to normal, I think.:)

    ScreenShot_HMP_3.7.0-3_Build 185_01.jpg ScreenShot_HMP_3.7.0-3_Build 185_02.jpg

    ScreenShot_HMP_3.7.0-3_Build 185_03.jpg
     
  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  19. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I don't follow...
     
  20. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Sorry I mean't those A00* files that are listed by HitmanPro.
     
  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Just completed a fresh scan...all clear.

    ScreenShot_HMP_3.7.0-3_Build 185_04.jpg

    And now it is time to get some sleep.
     
  23. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Hi Erik

    I have another one FP see my picture into the red circle

    SHA256: 55c8c9d096769fee4e0f0cff30d3df36546e08f868388374e9cef34549549655
    SHA1: 341f0910844081d5ad66effb6b8f851dd35a49dd
    MD5: 9473f8dfbceae9d065f44d6d30a023a7
    File size: 282.2 KB ( 288974 bytes )
    File name: Au_.exe
    File type: Win32 EXE
    Detection ratio: 0 / 46
    Analysis date: 2012-12-22 15:59:03 UTC ( 0 Minuten ago )
     

    Attached Files:

  24. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Can you show the details? I think the file's certificate is invalid.
     
  25. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Here are the details from it

    Properties
    Name Au_.exe
    Location C:\Users\Alexander Robrecht\AppData\Local\Temp\~nsu.tmp
    Size 282 KB
    Time 19.1 days ago (2012-12-03 13:57:29)
    Needs Elevation Yes
    Entropy 7.8
    SHA-256 55C8C9D096769FEE4E0F0CFF30D3DF36546E08F868388374E9CEF34549549655

    Scoring (23.0)
    Program has no publisher information but prompts the user for permission elevation.
    Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
    Authors name is missing in version info. This is not common to most programs.
    Version control is missing. This file is probably created by an individual. This is not typical for most programs.
    Time indicates that the file appeared recently on this computer.

    References
    HKU\S-1-5-21-911542882-2029379874-2294310465-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\ALEXAN~1\AppData\Local\Temp\~nsu.tmp\Au_.exe
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.