HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. wasgij6

    wasgij6 Registered Member

    Joined:
    Mar 29, 2011
    Posts:
    321
    Thanks for the quick reply. ill try out the new version once its released.
     
  2. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    Thx but I talk about the windows 8 app Skype, which is not under any template.
     
  3. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Exploit mitigations on Metro apps are currently not yet supported.
     
  4. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    The prompt that notifies the user that HMPA is protecting Adobe Flash continuously prompts the user when navigating Wilders Security Forum. It prompts the user so often that it can be annoying.
     
  5. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
  6. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,244
    No problems with (un)sandboxed Firefox 36.0.1 (W7 64 bits/build 155).
     
  7. heikwith

    heikwith Registered Member

    Joined:
    Jul 29, 2002
    Posts:
    91
    I got a BSOD in my Dutch Vista 32bit with build 155.
    I am using Avast Free 10.2.2214.845 nl Final

    On Wed 04-03-2015 11:25:18 GMT your computer crashed
    crash dump file: C:\Windows\Minidump\Mini030415-01.dmp
    This was probably caused by the following module: hmpalert.sys (hmpalert+0xB7D9)
    Bugcheck code: 0x1000008E (0xFFFFFFFFC0000005, 0xFFFFFFFFAB40B7D9, 0xFFFFFFFFDE12962C, 0x0)
    Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M
    file path: C:\Windows\system32\drivers\hmpalert.sys
    product: HitmanPro.Alert
    company: SurfRight B.V.
    description: HitmanPro.Alert Support Driver
    Bug check description: This indicates that a kernel-mode program generated an exception which the error handler did not catch.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: hmpalert.sys (HitmanPro.Alert Support Driver, SurfRight B.V.).
    Google query: SurfRight B.V. KERNEL_MODE_EXCEPTION_NOT_HANDLED_M

    On Wed 04-03-2015 11:25:18 GMT your computer crashed
    crash dump file: C:\Windows\memory.dmp
    This was probably caused by the following module: hmpalert.sys (hmpalert+0xB779)
    Bugcheck code: 0x8E (0xFFFFFFFFC0000005, 0xFFFFFFFFAB40B7D9, 0xFFFFFFFFDE12962C, 0x0)
    Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED
    file path: C:\Windows\system32\drivers\hmpalert.sys
    product: HitmanPro.Alert
    company: SurfRight B.V.
    description: HitmanPro.Alert Support Driver
    Bug check description: This bug check indicates that a kernel-mode application generated an exception that the error handler did not catch.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: hmpalert.sys (HitmanPro.Alert Support Driver, SurfRight B.V.).
    Google query: SurfRight B.V. KERNEL_MODE_EXCEPTION_NOT_HANDLED
     

    Attached Files:

  8. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Can you send me the C:\Windows\memory.dmp file? Send it via www.wetransfer.com to erik(at]surfright.com.
     
  9. heikwith

    heikwith Registered Member

    Joined:
    Jul 29, 2002
    Posts:
    91
    Both transfered
     
  10. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
  11. heikwith

    heikwith Registered Member

    Joined:
    Jul 29, 2002
    Posts:
    91
    I got this at startup of download application Getright in my Dutch Vista 32bit with build 155.
    But this happens not always and I do not see why.
    Same problem with Avant browser, also not always.
    When this happens and after starting both in passive vaccination, these programs are running without problems in active vaccination.
    Getright False Positive.jpg
     
  12. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    When I try to 'scan' with HMPA, it comes up with 'Failed' now.

    Any idea?
     

    Attached Files:

  13. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    :eek:
     

    Attached Files:

    • dk.png
      dk.png
      File size:
      62.4 KB
      Views:
      45
  14. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    AppGuard activity reports numerous > Prevented process <Firefox> from writing to <c:\windows\cryptoguard\bcd6a129>

    Why does FF writing to cryptoguard require preventing. Is AppGuard blocking required communication between Firefox and HMPA
     
  15. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    If you get attacked by crypto-ransomware, CryptoGuard won't be able to help you as AppGuard is interfering with the rollback mechanism. Can you make an exclude to C:\Windows\CryptoGuard\ folder in AppGuard?
     
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    EDIT ~ #4315

    OK ~ just that AG Thread advises not to make exception.
    <<Unless something has stopped working as a result of AppGuard preventing Firefox from writing to the Cryptoguard folder (unlikely), it's probably best to ignore this and wait for it to be fixed in HMPA. Speaking personally, I wouldn't make folder exceptions for something that shouldn't be happening in the first place.>> #2920
    Hope Wilders does not see this as A v B
    So, C:\Windows\CryptoGuard\ will be added as an Exception folder in AppGuard
    *** Nice to find out no rollback because of AG.
     
    Last edited: Mar 7, 2015
  17. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Have you considered holding the CryptoGuard rollback data in an AppData folder instead of a Windows folder?

    AppGuard launch protection will be weakened if a Windows folder is listed as an exception folder within AppGuard.
     
  18. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    AppGuard assumes that application data will be held in AppData, not Windows system folders. Whilst a Windows folder can be listed as an exception folder within AppGuard, it can't also be included in the user-space definition, which would apply AppGuard launch protection. This creates a potential for a drive-by download. That said, any attempt to launch an executable would inherit the same permissions as Firefox and run guarded. Using AppData to hold application data avoids the issue altogether.

    You can create an exception folder via the Settings section of the Guarded Apps tab within the AppGuard GUI.

    EDIT: I've just checked this myself and somewhere down the line AppGuard has been changed to allow Windows folders to be included in the user-space definition, albeit with a recommendation not to do it. AppGuard used to prevent this with no option to override.

    What I would suggest you do then is to also include the CryptoGuard folder in the user-space definition within AppGuard. This is done via the User Space tab within the AppGuard GUI by listing the folder with the Include flag set to Yes. Making the CryptoGuard folder an exception folder and including it in the user-space definition effectively moves it from system-space to user-space. That way, you don't weaken AppGuard drive-by download protection.

    If you would like to discuss this further, let's continue in the AppGuard thread.
     
    Last edited: Mar 7, 2015
  19. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Interesting ... Hi pegr....yeah I edited when I recalled route for Exception. Now, though .... seems I loose no matter what. HMPA no rollback or weaken AG to drive by. :thumbd:
    EDIT ~~ OK see you over at AG
     
    Last edited: Mar 7, 2015
  20. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    Long known issue, but a specific exclusion in AppGuard ist all you need and both are running fine together.
    SOLUTION
     
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    CryptoGuard is a kernel mode feature. So rollback is done from kernel mode. The AppData folder is somewhat tricky to resolve on different systems (languages) from kernel mode.
     
  22. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    No help with this issue?
     
  23. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    See my edited reply in post #4318 above. AppGuard 4.2 beta allows Windows folders to be included in the user-space definition. I don't know when the change to allow this was made so not sure about AppGuard 4.1.
     
  24. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Thanks for the clarification. It looks like the latest beta version of AppGuard is now allowing Windows folders to effectively be moved from system-space to user-space. It didn't used to allow this. Adding the CryptoGuard folder to the user-space definition in addition to listing it as an exception folder within AppGuard will resolve this issue without weakening any AppGuard protection, so it looks like we have a solution.
     
  25. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    OK ... Please see AG #2921
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.