HitmanPro.Alert BETA

Discussion in 'other anti-malware software' started by erikloman, May 30, 2017.

  1. guest

    guest Guest

    the on-scanner seems to be launched from temp folder, if something block temp folder, so he won't run and show "failed".
     
  2. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    They're saying it is an OpenDNS issue. However, I am not using OpenDNS. Also, I tried ISP, Google and other DNS - so I am fairly confident is saying the quirk I am seeing on this one particular system has nothing to do with DNS.
     
  3. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    I've tried my ISP and Mullvad DNS. Outcome is the same - 'failed'!
     
  4. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    For some reason the Windows startup tone only plays on system restart, not cold start. Fast Startup disabled.
     
  5. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    L0L... Mullvad client never works for me so I always return to IVPN.

    Are you using Emsisoft ? There are some reported issues between Emsisoft and HMP.A.
     
  6. _CyberGhosT_

    _CyberGhosT_ Registered Member

    Joined:
    Mar 2, 2015
    Posts:
    457
    Location:
    MalwareTips "Your Security Advisor"
    I have noticed as well, that for some reason on my system, if I set the scheduled scan to "Quick Scan"
    instead of the full scan. I get zero errors (alerts). and that's with credguard on too.
    So for now that's what mine is set at.
    Also: no issues with my VPN (AirVPN) and HMP.A, or with AdGuard DNS :thumb:
     
    Last edited: Jun 12, 2017
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Do you have hitman pro alert as an Appguard power app. Thats what I needed to do. Also I have no conflict with EIS. Win 7 x64 pro. Scanning right no
     
  8. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    No. I don't have anything else on the HMP.A test systems.
     
  9. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    No, I'm not using Emsisoft. I'm using ReHIPS and HMPA only. :) I disabled Windows Defender since HMPA blocks all malware I throw at it with the real time scanner (it works perfectly for me. It's just the on-demand scanner that 'fails').
     
  10. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Is that with 710 CTP4 Peter? And do you have any mutual exclusions between EIS and HMPA?
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Actually it is 710 now, and I don't have any mutual exclusions What I do have is WIn 7x64 pro
     
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Thanks Peter.

    710 CTP4 installed over 603 beta and running without issues, including scan, on my primary machine (see sig).

    Edit: But I do have EAM and HMPA mutually excluded.
     
  13. guest

    guest Guest

    After clicking on "Anti-Malware" you can can see Enable/Disable. This is part the real-time protection which can be enabled/disabled.
    And you can see "Scan Computer":
    If you have HitmanPro installed, clicking on this button should launch your installed HitmanPro and it is doing a scan on-demand
    If HitmanPro is not installed, HMP.A is downloading HitmanPro to a temporary directory and is launching it.
    But if the download of the file is failing, then i would better install HitmanPro. Now HMP.A doesn't need to download it every time.

    HMP.A is using the HitmanPro-Cloud for the real-time AV protection ("Real-time protection against prevalent malicious files")
    Files which are detected from HitmanPro (on-demand), should be detected from HMP.A too (real-time)
    You can copy/read/write/move/delete detected files without problems. Only the execution is blocked.
    I don't think it is preventing other installed AV-solutions from doing its work.

    The real-time protection of HMP.A relies solely on the cloud.
     
  14. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    The newest beta has real time detection - it's still using HMP for scanning. Regarding the problem of the scan failing when trying to start it from HMPA, there is apparently more than one cause; OpenDNS is one, but no one said it was the only one. :)
     
  15. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Correct. OpenDNS is definitely not the cause for me. When I first install HMPA CTP4 it works. But after the first reboot and there after it 'fails' when trying to do an on-demand scan without HMP installed.
     
  16. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    A few days ago I installed HMP.A CTP4 on my office machine.
    Had no issues so far, but today I ran into one.
    A weekly task is scheduled running an executable, created by myself,
    but I got a red flyout, that a malicious threat was blocked....
    There seems to be no option, to create an exception.

    @erikloman:
    How to exclude this task, or executable?
     
  17. guest

    guest Guest

    You can't exclude executables. But this is in preparation:
     
  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Can you make a log with Process Monitor and send it via PM? I already received one from another Wilders member, but would like another.
     
  19. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    You currently cant exclude anything yet, but this is coming. Stay tuned!
     
  20. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Yep!
     
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Nice find. We'll have a look at whitelisting options. There should have been something in the Event Log though. We'll have a look at IFW. Thank you all for reporting, your diligent work and your patience!
     
  22. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    @erikloman

    Spoke too soon.

    Had to revert to 3.6.7 build 603 beta because Macrium Reflect backups (full, differential or incremental) would not work with 710 CTP4.

    Macrium gives message 'Backup aborted! - Unable to read from disk - Error Code 5 - Access is denied.'

    Retested to make sure it is due to 710 CTP4 and indeed it is. But I am back on image with 603 beta now so don't have the logs or any more info now.

    It may be something similar to what @Peter2150 and @puff-m-d experienced with IFW?
     
    Last edited: Jun 13, 2017
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Now also getting this on build 603:

    Mitigation Anti-VM

    Platform 10.0.15063/x64 v603 06_45
    PID 9220
    Application C:\Pumpernickel\Tools\Tray.exe
    Description Tray.exe

    VMware
    Thumbprint
    928984701761a8b191227e27d5b086455becd0a920be029d79299354778f78a6
     
  24. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    I did not have a problem with Macrium Reflect backups on CTP3 or on CTP4
     
  25. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I hadn't seen any other reports of this either.

    CTP4 is the first time I tried build 710. I can replicate the issue, but don't have much appetite for flipping images at the moment.

    Edit: This is with MR v6 paid, latest btw.
     
    Last edited: Jun 13, 2017
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.