HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Sent dump by email be patient, to big to email, so uploading and will send link
     
    Last edited: May 12, 2015
  2. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
  3. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Is zip okay....my dump is >500mb
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I zipped mine. 829mb before 201 after.
     
  5. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    The OP didn't even confirm what version of HMPA he had installed. The only useful info is the malware itself; maybe Erik can get a sample and have a look at it?

    http://www.bleepingcomputer.com/for...version-released-that-uses-the-exx-extension/

    http://www.bleepingcomputer.com/virus-removal/teslacrypt-alphacrypt-ransomware-information
     
    Last edited: May 12, 2015
  6. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    okay ~ zip <200mb ~~ OneDrive
     
    Last edited: May 12, 2015
  7. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    No problems with Firefox 38.0. Also no problems with flash 17.0.0.188 (W7 64 bits/build 187).
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Yes, Keystroke Encryption is working again now I've upgraded to FF 38.0. :thumb:
     
  9. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    HitmanPro.Alert 3.0 has _NO_ problem with TeslaCrypt. The encryption is blocked without loss of any data.

    For example, this latest variant: http://www.bleepingcomputer.com/for...version-released-that-uses-the-exx-extension/
    Sample: https://www.virustotal.com/en/file/...3ae3f09229de55c8913b66da/analysis/1431445133/

    Even before Alert's CryptoGuard is triggered, the Process Protection mitigation from Alert intercepts the threat:

    TeslaCrypt-Process_Protection.jpg

    When the user would disable Process Protection mitigation, CryptoGuard will intercept the attack:

    TeslaCrypt-CryptoGuard.jpg

    It is important to point out that the malware may be allowed to run on the machine but the data is always safe. HitmanPro.Alert is malware-agnostic and simply stops malicious operations. This approach stops way more crypto-ransomware attacks than what anti-malware or anti-virus solutions can offer.

    If the user had Alert v2 from last year than yes, the documents on the machine will get encrypted by TeslaCrypt without intervention by Alert.
    For solid protection against crypto-ransomware users need HitmanPro.Alert 3.0.
     
    Last edited: May 12, 2015
  10. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,857
    Location:
    the Netherlands
    Kyle124, the OP in the Malwarebytes thread, wrote "I am using latest version 3 with updated build to latest version so thats not the problem and everything is enabled."
     
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    FF38 = NO encrypting :( ~~ Flash 17.0.0.188 okay :)
    Thanks
     
    Last edited: May 12, 2015
  12. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    Maybe his License was expired or he forgot to activate his purchase. I just checked the CryptoGuard protection against TeslaCrypt and it's working fine.
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I wonder what he did wrong then, perhaps a configuration error? I also noticed that CryptoMonitor could stop it, at least according to BleepingComputer. Does it work differently? And BTW, when you have the time, perhaps you can respond to my PM.
     
  14. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    No problems with Adobe reader 11.0.11 (W7 64 bits/build 187).
     
  15. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,857
    Location:
    the Netherlands
    I hadn't thought of that.
    I wonder if Kyle124 thought of that.
    Although, he did write "everything is enabled."
    Anyhow, I think it would be much better if Kyle124 would contact SurfRight, or post in this thread, instead of posting at Malwarebytes forums.
     
  16. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Thanks for pointing out that Kyle124 was using the latest verion of HMPA - I missed that. Still, we don't for sure what happened. Was HMPA installed correctly and fully enabled? He says MBAM detected the malware but he doesn't know the name. His data was encrypted, but he doesn't remember for certain what file extension the ransomware appended to his data files. Then he reset the OS so there's no way to go back and look at what happened.
     
    Last edited: May 12, 2015
  17. Aura

    Aura Registered Member

    Joined:
    Mar 19, 2015
    Posts:
    107
    Location:
    -
    Hi markloman,

    I sent a PM to erik on BleepingComputer to tell him about this thread when it got posted, but he didn't read it yet (and he's been MIA for a few weeks now, maybe on vacation or else). Kyle124 posted a malwr.com link to the sample that infected him, and there's a download link for it. The malware is the newest variant of Tesla Crypt, which encrypts the files with a .exx extension, not .ecc, and not .ezz (Alpha Crypt). Is it possible that CryptoGuard is just not equipped to block this variant yet? If you want the malwr.com link to download and test the sample against CryptoGuard, let me know and I'll send you it via PM.
     
  18. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    I also tested the sample that Kyle124 posted - I got it from malwr.com.
    CryptoGuard inside HitmanPro.Alert 3 has no problem intercepting it:

    CryptoGuard.jpg

    @erikloman is on a well deserved R&R. He'll be back next week.
     
  19. jd97

    jd97 Registered Member

    Joined:
    Apr 27, 2015
    Posts:
    28
  20. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Well that didn't last long. Keystroke Encryption has stopped working in FF once again. :thumbd:
     
  21. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    I can't find the message in this thread at the moment, but someone said they isolated the Keystroke Encryption issue to a conflict with Norton Security.
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Nope, I am seeing a problem with encryption and no Norton here
     
  23. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    OK - not so simple then. Thanks!
     
  24. Aura

    Aura Registered Member

    Joined:
    Mar 19, 2015
    Posts:
    107
    Location:
    -
    Thank you for the update mark. And that's what I thought as well, I doubt erik would leave the CryptoGuard thread on BleepingComputer unattended without assigning someone else to take over it or else.
     
  25. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    No problems with Sandboxie beta 4.17.5 (W7 64 bits/build 187).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.