Hitman Pro Support and Discussion Thread

Discussion in 'other anti-malware software' started by yashau, Mar 20, 2009.

  1. moonriver

    moonriver Registered Member

    Joined:
    Dec 31, 2008
    Posts:
    26
  2. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Last edited: Jun 24, 2011
  3. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    I'm getting two false positives from the current HMP. Looks like old Prevx detections. VirusTotal results:

    PELZOOM.DLL
    2011-06-25 11:30:59 (UTC)
    0/ 42 (0.0%)
    MD5 : 59cb3a8d913a93e33a62bf132d0fbdfa
    SHA1 : 85aed8f859d06e0da48e43bef92790b609bcfc43
    SHA256: 85b0e9bda6acb922693149692f0baa812a3f6b203bf4c565f1b6abff8e3655ff

    MO28KC.dll
    2011-06-25 11:27:59 (UTC)
    0/ 42 (0.0%)
    MD5 : d3d7837370f4a2da22ed64ffa0dc29ac
    SHA1 : 4d681f156052ed1d44d96a4d3b64520206182165
    SHA256: b9b079679809c8241da0fb3c9eee10f04b661166bacc4a13dc716774de194492

    I'll leave them there (ignore) and see if they disappear. :D

    Al
     

    Attached Files:

  4. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Hi

    Can you check this

    On picture 2 stand Build 125 but i download it and it Build 124

    On picture 1 stand Build 124 its 125 outside

    Into the circle i download it and its 3.5.5.98 can you check it
     

    Attached Files:

  5. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Problem I'm experiencing: I scan my computer, and Hitman identifies a recent skype.exe update as suspicious, tries to upload it (it's above 20 mb) but freezes at aprox. 66% uploaded and eventually times out.

    Untitled.png
     
    Last edited: Jun 25, 2011
  6. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I never download from Softonic, they require you to install their program just to do that.
    I don't know why SurfRight links there, but it's not a good idea (unless money is involved).
     
  7. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Something kind of similar used to happen on my computer when I was using
    a real time antivirus, after dropping the antivirus, it has not happened again.

    Bo
     
  8. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    What you say appears to be the case.
    I ran two quick tests, one on each computer, and with VIPRE turned off, there was no hang at 99%.
    (And the scan was done in ¼ of the time.)
    With VIPRE turned back on, the hang returned.
    (And the longer scan time returned as well.)
    Bo knows! ;)
     
  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I only know that I have Vipre going since forever...and I have never turned it off when running HMP. YMMV.;)
     
  10. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany

    Thank you very much for your info
     
  11. treehouse786

    treehouse786 Registered Member

    Joined:
    Jun 6, 2010
    Posts:
    1,411
    Location:
    Lancashire
    anyone know how to check for the atapi.sys warning?
     

    Attached Files:

  12. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Run with EWS if you are an malware expert and suspect infection only. Only use the Default Scan for regular scans.

    This message is displayed when the IRP_MJ_SCSI miniport driver function points to kernel memory that cannot be related to a driver. This is typical rootkit behavior.

    We found one 'legit' driver that does this as well and that is SPTD. If you have SPTD installed then you can ignore the yellow sticky.

    You may run aswMBR as well to confirm. Its alarm bells will go off as well. But again, might be SPTD.
     
  13. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  14. syk69

    syk69 Registered Member

    Joined:
    Feb 7, 2010
    Posts:
    183
    Force breach mode isn't working on latest rogue av (windows 7 antivirus 2012). computer has windows 7 64 bit. When trying force breach the fake firewall alert pops up instead of killing all processes.
     
  15. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Rename HitmanPro35.exe to HitmanPro35.pif en start the .pif.
     
  16. syk69

    syk69 Registered Member

    Joined:
    Feb 7, 2010
    Posts:
    183
    Alright went back to users login and did rename to .pif and ran it with EWS and found the exe of the rogue. The scan hanged at 99% though so had to cancel it and then remove. Thanks. Hopefully you can get force breach mode back working again.
     
    Last edited: Jun 27, 2011
  17. sly53

    sly53 Registered Member

    Joined:
    Jun 28, 2011
    Posts:
    15
    New here and have an installation question. When you click to do the default scan the screen that comes up gives an option to install a copy of HMP to the computer or do a one time scan. Does install a copy mean a install of a program in the usual sence or is it just going to put some links? I selected the one time option, can I do this everytime and it will work as the other option? What is the difference in these two option as far as how HMP will work? I am including a photo to show what I am asking. Thanks
     

    Attached Files:

  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Yes - Copies the executable to the 'Program Files\Hitman Pro' folder and adds uninstall entries to the registry and adds shortcut entries to the Start Menu.

    No - Doesn't do the above.

    Note: Currently, if you choose either mode, Hitman Pro will create the 'Hitman Pro' folder in LocalAppData to store the license and banner (if you run the free/trial version). Currently, uninstall will leave this folder on the system to preserve the license between different installs.

    Hope this helps.
     
  19. sly53

    sly53 Registered Member

    Joined:
    Jun 28, 2011
    Posts:
    15
    OK, so if I select yes I would then have it listed in the windows uninstall programs? If I select no it would not be listed and I would just delete the download file to remove it? Am I understanding this correctly?
     
  20. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Correct.
     
  21. sly53

    sly53 Registered Member

    Joined:
    Jun 28, 2011
    Posts:
    15
    Thanks for your quick reply. Just one last thing, I assume then that there would be NO difference in the malware removal if it does find something, is this correct? Or is there some advantage I would be missing by not doing the copy when saying yes?
     
  22. sly53

    sly53 Registered Member

    Joined:
    Jun 28, 2011
    Posts:
    15
    I should add I am talking about stuff like putting items into quarantine along with the removal. I just want to be sure I do not miss out on something if I decide to select no and make no copy to the computer. I hope I am making clear what I want to know, so I can decide what I would prefer. Thanks
     
  23. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Trojan Popureb.E

    We just released a BETA version of Hitman Pro 3.5.9 build 126 that is able to detect and clean Trojan Popureb.E.

    Early this week Microsoft advised Windows users to reinstall the operating system to get rid of the trojan.The new build of Hitman Pro allows to remove the trojan withing a few minutes.

    We also wrote a blog post upon the matter here.

    The BETA can be download here:

    32-bit: http://dl.surfright.nl/HitmanPro35beta.exe
    64-bit: http://dl.surfright.nl/HitmanPro35beta_x64.exe
     
  24. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Re: Trojan Popureb.E

    Downloaded and ran 32-bit version. No problems here.
     
  25. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.