HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Is this new? Do you have a firewall?
    The scan runs HitmanPro. The binary for HitmanPro is downloaded and then started from the temp (if HitmanPro is not installed).
     
  2. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    I have an extensive NGFW on the network, and that includes dual AV scanning, and deep packet inspection Layer 8 firewall. Why would it be blocking, right now I have outbound originations from the LAN on mostly a pass-through, and unless it's malware, or advertisements, it won't be blocked.

    Suggestions?
     
  3. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,540
    Hi,

    The free version of HitmanPro.Alert will alert us when the browser is being exploited, with the "Safe Browsing" feature enabled?

    Thanks
     
  4. guest

    guest Guest

    No,

    Safe browsing is will only indicate whether a MITB is being performed. You've to get to license in order to enable the exploit mitigations.
     
  5. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    It appears HMPA isn't compatible with Sophos Endpoint Security (managed by UTM 9x) in the slightest. I had to uninstall HMPA after installing SES. Totally locked up most processes, Chrome crashed and was locked into processes, etc.
     
  6. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,540
    Thanks.

    I thought the free version only alert us about an exploit, and the paid also mitigate the exploit...
     
  7. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,540
    I'm also interested to know this...

    Thanks
     
  8. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    We will have a look. Thanks for reporting.
     
  9. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    597
    I'm delighted to report that the same program recording was NOT blocked this week. In fact, the Hauppauge TV tuner is no longer listed under webcams in the Risk Reduction category.

    Thanks very much for the fix! :thumb:
     
  10. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,943
    Location:
    Outer space
    Trying to add Plex Home Theater(1.3.5) to Exploit protection, but it isn't listed under running applications :S
    (Latest Alert build 155 of course)
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    The developers will release more info when the final version is released, if I understood correctly. I'm not sure why this has never been explained clearly.

    Have you already looked at the "IE 11 getting terminated" problem when running sandboxed?
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    No, exploits are always mitigated and exploit protection is not offered in the Free version at all. In the free version you get "safe browsing" and some other features. So as soon your browser is infected with a banking trojan, HMPA will alert you not to use the browser, and will offer you to remove the malware with the HitmanPro 3 scanner.
     
  13. guest

    guest Guest

    Protecting against and mitigating can still be seen as the same thing. (sort of)
     
  14. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    Does this look right. Will Firefox be allowed to write to cryptoguard now ?
    cryptoguard read write.JPG
     
  15. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    Since, Firefox has to write to cryptoguard. How do I get sandbox'd FF data to cryptoguard folder.
    cryptoguard read write.JPG
     
    Last edited: Mar 8, 2015
  16. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
  17. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    OK... added c:\windows\cryptoguard\ to Direct File Access.

    * Now, what about the drive by hole I made by adding c:\windows\cryptoguard -- read write exception.

    I think I connected the dots enough to understand that cryptoguard holds backups if a roll back is required do to cryptolock ransomware. What still confuses is what does Firefox writing to cryptoguard have to do with Documents. c:\users\bjms\documents\myprivatefolder is still Private Deny Access by default in AG.

    * EDIT: Cryptoguard folder has 28 files. Does that mean I have 28 files that HMPA protects from crypto type ransomware ? Anyway to know what the cryptoguard files relate to...?
     
    Last edited: Mar 9, 2015
  18. guest

    guest Guest

  19. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,791
    I just noticed that when you install HMPA, it disables various tunneling interfaces used for connectivity using IPV6 transition technologies. I understand there is a security risk with this kind of tunneling, but I just hate it when apps decide it's better to disable stuff on your system without telling you about it. On top of that it leaves and error in device mananager that a certain interface is not working (error 10). I went on a wild goose chase trying to fix that. I normally just disable the IPHelper service which I understand needs to run for IPv6 transition technologies such as ISATAP, Teredo, and 6to4 to function on the computer, but it does not break anything in device manager. Adding the DisabledComponents to the registry if a tunneling adapter is already enabled gives the error below.

    tunnel.jpg
     
  20. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    @Adric Yes, thanks very much for that info :thumb: which seems to explain what I had a lot of trouble trying to figure out about a month back.
     
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Alert indeed disables Teredo. It has to be disabled because it can cause BSODs. Teredo is somewhat buggy. Google 'teredo bsod'.
    I will see if we can fix the error 10.
     
  22. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    @Adric,
    Thanks for your 'Teredo post'. Now I finally know what caused me so much trouble last February and I finally had to give up!
     
    Last edited: Mar 9, 2015
  23. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,444
    Location:
    Among the gum trees
    Ditto!

    I was thinking it was probably Norton.

    :thumb:
     
  24. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,696
    Location:
    USA
    Adric made a good point. HMPA should still inform the user what services it is disabling. It could cause problems for the user if they are using something that requires the services being disabled. HMPA should give a prompt informing the user what is being disabled.
     
  25. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Not the point, it seems like rdsu was a bit confused about the difference between safe browsing and anti-exploit, and of course it would not make sense to only alert about an exploit attack, that would be quite silly.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice