HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Whatelse are they running. I am noticing right now no encryption with FF. But to me it's just not that big a deal.
     
  2. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    Like I said....for me. I can wait. My friend runs Comcast Norton Security Suite. My friend likes to see Alert.3 working. The absence of FF encrypting creates doubt for my friend regarding Alert.3.
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm. Since I use comcast I've been offered that free Suite. You do indeed get what you pay for. I am more careful about recommending stuff to friends then I am about malware. Good luck.

    Pete
     
  4. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    Well, since I only suggested a Trial and I was in good favor until FF no encrypting. I can sure use all the luck you offer. ;)
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    1. I am sure Erik will deal with this

    2. Since the Encryption really deals with keyloggers, if the rest of the system protection is adequate, a keylogger shouldn't get on your system or be able to run,
     
  6. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    I know that and you know that....now, how do I convince my friend that's convinced legal and illegal are logging every keystroke. Just Because You're Paranoid Doesn't Mean They Aren't After You :D
     
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I would stay from advising some folks about their security software. It's a lose lose
     
  8. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    True, its not like any of us would ever be guilty of doing such a thing. :thumbd:
     
  9. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    The solution for the paranoid is easy; just intercept all your traffic and check for abnormal patterns.
     
  10. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    why is there no green border around my IE but there is with Chrome using HPA.
     
  11. Abdallah

    Abdallah Registered Member

    Joined:
    Oct 28, 2013
    Posts:
    124
    Location:
    N/A
    Does the test tool still exist and work ? because I downloaded a ~ctp4.zip from their website and HMP.Alert didn't intercept two of the tests ( I didn't run all the tests ) , and I think it is in URLMon section (64 and 32 bit)

    Any idea ?
     
  12. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    Look here for the latest testtool version, which is working fine for me.

    http://www.surfright.nl/en/downloads/
     
  13. Abdallah

    Abdallah Registered Member

    Joined:
    Oct 28, 2013
    Posts:
    124
    Location:
    N/A
    I didn't think that it will be there !

    Anyway , just tested it , all URLMon exploits in 32-bit exe intercepted , but the only URLMon exploit in 64-bit exe crashing the testing tool , don't know why

    Abdullah
     
  14. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    Confirmed, I re-tested the hmpalert testtool 64bit, URLmon with hmpalert187 (my previous test was some time ago) and it failed.

    URLMon_Testtool_mpa b187.jpg
     
  15. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    ok but what about my question. I mean this is a HPA support thread isn't it?
     
  16. jd97

    jd97 Registered Member

    Joined:
    Apr 27, 2015
    Posts:
    28
    Question for the developers:

    I recently had an incident where HitmanPro.Alert v 3.0.41 build 187 was installed and all mitigations was enabled. despite this, A malicious site was encountered that hosted multiple exploits. I got the alert which briefly displayed. It appears that the exploit bypassed all built in browser sandboxing. The browser and all process associated with it were closed, it closed explorer.exe and one other Windows service.

    Does this mean that the exploit was completely mitigated and it saved me or did HitmanPro.Alert fail?

    System Specs:
    Windows 7 SP1 up-to-date 64-bit
    ESET Smart Security v8
    Adobe Flash 17.0.0.169
    No Java
    Office 2013 was up to date

    I can't disclose too many details because it has been reported to the vendor.

    Also, HitmanPro.Alert keeps showing up in the Windows Problem Reports and Solutions Center showing that is crashed (nearly on a daily basis). All are BEX errors.

    On another note, How can we pull Windows Error Reports when these things happen (the dump files)?

    Thank you!
     
  17. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    I sent you a DM!
     
  18. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    We're overhauling the Exploit Test Tools a bit as some anti-exploit solutions inadvertently block some of the tests with an unintended mitigation (e.g. block the technique on sellcode instead of the specific technique), as some of you noticed. The most current Exploit Test Tools are available from our website (scroll down): http://www.surfright.nl/en/downloads/
     
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,443
    Location:
    Among the gum trees
    Erik and Mark,

    I've got some good news for you, bad news for me. I temporarily uninstalled Norton Security with Backup v22.2 on one machine ready to install their latest beta but before I installed the beta I opened Firefox 37.0.2 and checked the Keystroke Encryption. Guess what? Without Norton (or any other AV) installed the Keystroke Encryption was working as expected again. Apparently there is a conflict with Norton and HMP.A. :(

    I hope that helps.

    Cheers.
     
  20. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Can someone make a dump of the browser process that has malfunctioning keystroke encryption? Just use Task Manager and right-click on for example firefox.exe and choose dump.
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,443
    Location:
    Among the gum trees
    I'm on it. I'll PM you shortly.
     
  22. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,295
    Via www.wetransfer.com a zip (containing a IE11-dmp). I see a fly out but no green border with IE11 (W7 64 bits/build 187).
     
  23. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    Do you mean NO actual keystroke encryption done and/or NO keystroke encryption flyouts?
     
  24. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    The same for me. I have keystroke encryption issue also.

     
  25. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,237
    Location:
    USA
    Spyshelter Premium has a keystroke encryption feature; is it enabled?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.