HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,221
    Location:
    USA
    Because the MS Office apps are actually using ROP. The quick fix is to turn off the "control flow integrity" code mitigation for the Office apps. Hopefully down the road a workaround can be implemented (white list maybe?) so that settings don't have to be changed in HMPA.
     
  2. AdamP

    AdamP Registered Member

    Joined:
    Apr 12, 2016
    Posts:
    2
    Is there a way to script or change this behavior at installation? What is the best way to make this change across multiple devices short of manually logging in to make the change?
     
  3. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,221
    Location:
    USA
    Not that I'm aware of, but perhaps others will chime in.
     
  4. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    We have noticed a ROP being triggered in Office since a recent update of Office. You may retry starting the Office application to resolve (it seems that the ROP is not triggered in some occasions). If it does not help, temporarily disable Control Flow Integrity on Word or Excel. Meanwhile we are looking at the issue. We are trying to resolve from either the cloud or via an update. In Alert 3.5 there are whitelisting options so that in the future this can be resolved automatically. Sorry for the inconvenience.

    Erik
     
  5. CeeBee

    CeeBee Registered Member

    Joined:
    Nov 20, 2015
    Posts:
    60
    As noted elsewhere, I'm running HitmanPro.Alert 2.6.5.77 for reasons of my choice. I also have a paid 3 PCs license for HMP 3.x (including HMPA), so, please don't suggest to upgrade to that version.

    Question: as of yesterday, when starting Firefox, I'm getting a forced upgrade attempt from the free HPA 2.6.5.77 to HPA 3.1.9.363. This happens both on my legacy XP computer and a laptop running Windows 7. In the case of the XP, the installation fails .. but, that's not the issue here. On my W7 laptop, the setup was messed up and I had to do some re-installs. Thanks guys! o_O

    What is this? A new policy of Sophos-Surfright to force-upgrade (silently) people still using the free version 2 to the paid for version 3? Again, I have a paid license for version 3 however use version 2 for reasons of my choice. Any way to stop/control this behavior? TIA.
     

    Attached Files:

    Last edited: Apr 13, 2016
  6. guest

    guest Guest

    a nice feature would be to add an "exclude" button on the alert pop-up.
     
  7. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    This is a mistake! :eek::'(

    The 2.x binary was replaced by the 363 binary on the update server by a colleague. I have personally corrected the problem but already a few people were updated to 3.x build. Sadly the 2.x branch has no way to suppress the updater while the 3.x branch does have the /noupdate command line switch and NoUpdate registry key.

    My sincere apologies.

    Erik
     
  8. CeeBee

    CeeBee Registered Member

    Joined:
    Nov 20, 2015
    Posts:
    60
    Apology accepted! But, I do hope that the correction is in place next time I fire up my W7 laptop. I'm sure I'll do the upgrade to 3.x later on, but on my whim .. not by force. Thanks.
     
  9. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    CVE-2016-1019 (April 2016) vs HitmanPro.Alert 3.0 (April 2015)

    https://www.youtube.com/watch?v=l270kRf7Iv4

    :thumb:

     
  10. JohnBurns

    JohnBurns Registered Member

    Joined:
    Jul 4, 2004
    Posts:
    778
    Location:
    Oklahoma City
    OK - I went ahead and manually updated HitmanPro Alert from 363 to 364. It seems to be running ok except I now am getting Event Viewer Warnings like the attached regularly. Something seems wrong and needs to be corrected. Can anyone tell me how to stop this short of uninstalling HMP Alert?
     

    Attached Files:

  11. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Today HMP.A auto-updated on 12 out of 14 machines, from build 360 to build 363.
    It failed on one machine, where auto-update failed several times before, on previous builds, for unknown reason.
    HMP.A was still installed, but not running. When manually started, it showed degraded UI, missing all mitigations and licence.
    I installed build 364 over defective build 360, an now it's fine again...
    This particular machine has different software installed and running. For example a Go1984 client, that often caused trouble in the past.

    One machine hasn't updated yet, but shows no signs of failed update.
    I will not force update, nor manually install the latest build (364), maybe this machine wasn't rebooted for a while...
     
    Last edited: Apr 13, 2016
  12. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    This is normal behavior, and does mean that there is now update available/rolled out yet.

    Build 363 ist the latest build, that is deployed over auto-update.
     
  13. JohnBurns

    JohnBurns Registered Member

    Joined:
    Jul 4, 2004
    Posts:
    778
    Location:
    Oklahoma City
    Thank you for that explanation - that relieves my concerns. I appreciate your post.
     
  14. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Under what circumstances does HMPA put files in \Windows\CryptoGuard and when do these files get purged?

    I have about 41 files there right now and some are a few weeks old. One example of files being placed there is when I install Shadow Defender. The eula.rtf ends up there and I'm curious as to why.
    Code:
    (FOLDER) C:\Windows\CryptoGuard
      (+)(FILE) 3F89E6E4 = 3/21/2016 23:45, 10131 bytes, A
    
     
  15. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Files are put there when an existing file is being opened for write. They should be deleted automatically.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm, I have 181 files in that folder. May delete them and see what happens.
     
  17. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    Just checked -- I have 4,090 items in that folder :eek: and they're all dated 6/6/2015. o_O
     
  18. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,245
    Here 117 items, latest 13-8-2014.
     
  19. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Checked mine. There's nothing else except 3 files in a folder created because of a Cryptoguard action against a shady program which happened almost 2 months ago.
     
  20. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    Build 363. Two 7x64 computers. Zero files in the CryptoGuard folder on one PC, four files on the other PC.
    Files are from Feb and April of this year.
     
  21. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    I'm guessing it must be safe to delete such old files.
     
  22. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yikes. Just checked mine - 90,312 files, 12.3GB all from 2016-01-04!
    Not sure what caused that, not aware that I was possibly hit by ransomware.
    Taking some time to delete :)
     
    Last edited: Apr 15, 2016
  23. hotlips69

    hotlips69 Registered Member

    Joined:
    Nov 3, 2005
    Posts:
    55
    Location:
    Sussex. UK
    I've got 429 files in this folder dating back to July 2014 to the present week.

    I've also got about a dozen sub-folders all starting with "reverted_"

    Can I delete them all safely?
     
  24. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I have 12 files all less than 1 mb
     
  25. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    yes, you can (delete it safely)...
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.