HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    3,097
    Location:
    the Netherlands
    Internet Explorer Lockdown
    when trying to access Properties in right-click context menu in Internet Explorer.

    N.B.
    Where I say access Properties in right-click context menu in Internet Explorer,
    I mean access Properties by right-clicking in some empty space in an open Internet Explorer tab, not access Properties by right-clicking an IE shortcut.


    For Windows Vista SP2 x86 IE9:
    Code:
    Mitigation   Lockdown
     
    Platform     6.0.6002/x86 06_17*
    PID          5696
    Application  C:\Program Files\Internet Explorer\iexplore.exe
    Description  Internet Explorer 9
     
     
    Process Trace
    1  C:\Program Files\Internet Explorer\iexplore.exe [5696]
       "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:5848 CREDAT:334176
     
    2  C:\Program Files\Internet Explorer\iexplore.exe [5848]
    3  C:\Windows\explorer.exe [5040]
    4  C:\Windows\System32\userinit.exe [5972]
    5  C:\Windows\System32\winlogon.exe [8408]
       winlogon.exe
     
    6  C:\Windows\System32\smss.exe [8288]
       \SystemRoot\System32\smss.exe 00000000 00000034
    
    For Windows 7 SP1 x64 IE11:
    Code:
    Mitigation   Lockdown
     
    Platform     6.1.7601/x64 06_25
    PID          4628
    Application  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
    Description  Internet Explorer 11
     
     
    Process Trace
    1  C:\Program Files (x86)\Internet Explorer\iexplore.exe [4628]
       "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2680 CREDAT:267521 /prefetch:2
     
    2  C:\Program Files\Internet Explorer\iexplore.exe [2680]
    3  C:\Windows\explorer.exe [512]
    4  C:\Windows\System32\userinit.exe [2704]
    
    Is this expected behavior, or a bug?

    I hope this is not expected behavior.
    I wouldn't like it to need to disable IE's Lockdown mitigation and restart the browser each time I need to access Properties in right-click context menu in Internet Explorer. Especially when I have multiple browser tabs open and I'm logged in at multiple websites.
    And of course this would be even more an issue for average/ non advanced users.

    Edit 1:
    Thanks to ropchain, I found out that there is an alternative to disabling IE's Lockdown mitigation and restarting the browser -
    that is (temporarily) disabling (all) Exploit mitigation, which doesn't demand restarting the browser.
    Nevertheless, I would like to know if the reported Internet Explorer Lockdown when accessing Properties is expected behavior, or a bug.

    Edit 2:
    I added the information that where I say access Properties in right-click context menu in Internet Explorer,
    I mean access Properties by right-clicking in some empty space in an open Internet Explorer tab, not access Properties by right-clicking an IE shortcut.
     
    Last edited: Apr 12, 2015
  2. Ooze

    Ooze Registered Member

    Joined:
    Apr 12, 2015
    Posts:
    6
  3. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,791
    On Wilders, I keep getting the blue fly-out for Plugin Container for Firefox. It happens at times which seem to be random, but is getting annoying. Sometimes when I browse a new thread, I get it. Sometimes just going to the next page in a thread triggers it. Also accessing the same thread may trigger it again, but not always. I even see it sometimes when posting a reply. Anyone know what keeps triggering this specific fly-out?
     
  4. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    The site for the particular film (the scene of the crash) is like this (This is not the actual string after"movieid= because I once posted a similar URL and unknowingly posted my password info:

    http://www.netflix.com/WiPlayer?mov...f871f2f-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    The URL you give takes me to my "home" page which includes "my list" and other films to browse

    Did not get the time last night but will reinstall and see what happens with IE11. I have my suspicions about the proper functioning of my FireFox plug-in container.
     
  5. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    I often get a script error message on Wilders if I try to copy some text. It freezes my browser and can only close it with task manager.
     
  6. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,791
    I'm not currently noticing the problem you describe with FF 37.01
     
  7. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,444
    Location:
    Among the gum trees
    Have a read of this thread.

    https://www.wilderssecurity.com/thre...h-player-starting-on-these-forums-now.373936/
     
  8. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,791
    I'm not having a problem with the flash fly-out - just the plugin container for the firefox fly-out. I set Safety Notification to Once per logon session and so far the blue fly-out has not reappeared. I would still be interested in knowing what triggers this. Erik?
     
    Last edited: Apr 12, 2015
  9. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Errr...one question....
    Is there a way to disable protection completely with single click?
     
  10. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I apologize if this has already been asked....

    1) Since I do not see the log in GUI, could the click on 'Number of alerts' show it?
    2) At 'Last Alert', the time of last alert would be a nice addition
     
  11. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    You can click on "Exploit mitigation" and select "Disabled".
     
  12. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Thanks! :)
    Maybe devs could make a 'Disable' option in tray icon menu?
     
  13. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area

    My problem appears to be definitely to be FireFox related or caused by Firefox.

    I'm not sure about the media player associated with IE 11, whether its Silverlight or not and whether it's built into the browser as opposed to being an plug-in, but had no issues with Netflix on IE11 with HMPA. I know Netflix requires Silverlight on FireFox.

    I had no issues with Flash on IE11 either.

    BUT a new problem arose with FireFox and HMPA. I was unable to change urls. This is what would happen when I had Flash enabled in FireFox. I had to disable Flash in FireFox for it to be useable. With Flash enabled in FireFox my browser would freeze if I viewed any site that had a Flash object on it. When this happened with Flash enabled I could only close it with Task Manager. (This of course may be caused by a conflict between HMPA and some other program on my particular PC)

    I had to do the same thing with Firefox and HMPA this AM. The problem started on the first page I viewed-New York Times. That page showed fine, but when I tried to go to a different URL the page would not change. The "loading page symbol" just kept spinning and there was a blank screen. I tried several URLs. The New York Times page had not given me any problems previously even when I had Flash enabled.

    Had to close FireFox with Task Manager. Then I could not reopen FF. Got two types of messages: "FF is already running" and "A piece/part of Firefox is missing". The "Firefox is already running" is not new. Sometimes when I force FF to close there is some background process of FF that remains listed in Task Manager, but does not appear to be actually "running." Sometimes several of these can build up. I have always been able to shut these background processes down with Task Manager, BUT with HMPA installed I was not able to close them and thus was unable to restart FireFox. After uninstalling HMPA, I had no problem closing the background FF process down with Task Manager and restarting FireFox.

    IMHO, there is some issue within Firefox that Mozilla has not acknowledged. NOT HMPA. For example, many (100's-1,000's-10,000's) of peeps can't use Flash in FF. It seems to be a random thing. Suggested Fixes from the FF forums work for some but not for others.

    For a number of reasons I much prefer FF over IE, mainly because of several extremely useful and time saving extensions I use in FF. Though I have been using IE11 more frequently because I need to use it to view Flash Content.

    Is anyone else having FireFox and or Silverlight issues with HMPA installed?

    I will try it again from time to time. I would really like to use HMPA, but at this point I am not willing to give up the conveniences FF gives me.


    Windows 8.1, FireFox 37.01 ( my Flash problem in FireFox started about two months ago with an earlier version.)
     
    Last edited: Apr 12, 2015
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    I've been having massive problems with the 37.x builds of Firefox regardless of HMPA. Interestingly most of the crashes are on this site.
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm I am bored now. HMP.Alert, just sits here and works. Again another well done from me to Erik and Mark
     
  16. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,423
    HMPA blocks Emsisoft Emergency Kit because of VM detection.

    I understand why, but shouldn't these kinds of programs from reputable sources be whitelisted? (for novice users?)
     
  17. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,236
    Location:
    The Netherlands
    Same here, well done, nothing to report...
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I just ran EEK and HMPA didn't bother it a bit.
     
  19. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,692
    Location:
    South Wales, UK
    Ditto here!
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I do wonder why some people still seem to get weird false positives, you would think that by now this would have been fixed, or perhaps something else on their system is triggering this? I also wonder if HMPA is perhaps a bit too strict when it comes to the anti-exploit part.
     
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I can understand your frustration, it's never fun when you're having serious problems. To be honest, I have read other posts where people had problems caused by "Active Vaccination" and "BadUSB", so personally I kept them disabled. It's also true that you might not ever encounter an exploit attack, especially when you're using less targeted software. But it's more a bit of an alarm system, for that one time you might get hit with an attack.
     
  22. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    There is a DEP issue with Silverlight. We are working on it. But so far we are unable to reproduce ourselves.
     
  23. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Wonder if some of the difference is Win 8.1 vs Win 7
     
  24. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    759
    Location:
    Earth
    Yep, same here running fine.

    Rules.
     
  25. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,423
    I tried to run EEK on Windows 7 (64 bits) when HPMA intercepted it. This was on the PC of a family member. I will try to reproduce it at home (later today).

    Another weird thing: I disabled the flyouts, but yet HMPA displayed one when I ran a portable App that had JRE included.
     
    Last edited: Apr 12, 2015
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.