HitmanPro.Alert BETA

Discussion in 'other anti-malware software' started by erikloman, May 30, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Don't know. My license data was still good.
     
  2. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I believe so, but anyway it explains why my BadUSB was Enabled ... I reimported settings (doh). :rolleyes:

    For a clean install, advisable to export settings first.
     
  3. guest

    guest Guest

    The settings are stored in the registry and are deleted after HMP.A has been deinstalled.
     
  4. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Yes, the license info is preserved after uninstalling in my experience (including after using the removal tool).
     
  5. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    I assume you did not "import" previous settings?
     
  6. guest

    guest Guest

    The license info is probably stored there and is not deleted after a deinstall:
    Code:
    c:\ProgramData\HitmanPro\HitmanPro.key
    c:\ProgramData\HitmanPro\HitmanPro.lic
    Edit:
     
    Last edited by a moderator: Nov 7, 2017
  7. TheBear

    TheBear Registered Member

    Joined:
    May 7, 2006
    Posts:
    174
    Lately I have been noticing that when I have Hitmanpro.alert Beta OR released versions installed that my windows start menu icon does not work. Also, Notifications icon does not work.
    Nothing pops up when I click these icons with my mouse. I have to ctl-alt-del to restart.
    As soon as I uninstall hitmanpro.alert (beta or released) and reboot, the problem goes away.

    any one else seeing this?

    I am running win 10 pro fall creators update, Norton security, and VoodooShield beta 4.09b. on a 64 bit computer with lots of memory and plenty of disk space.
     
  8. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Logboeknaam: Application
    Bron: HitmanPro.Alert
    Datum: 7-11-2017 9:39:14
    Gebeurtenis-id:911
    Taakcategorie: Mitigation
    Niveau: Fout
    Trefwoorden: Klassiek
    Gebruiker: n.v.t.
    Computer: ****
    Beschrijving:
    Mitigation PrivGuard

    Platform 10.0.16299/x64 v721 06_17*
    PID 4208
    Application C:\Program Files\Mozilla Firefox\firefox.exe
    Description Firefox 56.0.2

    Sweep

    Code Injection
    00000241AF232000-00000241AF233000 4KB C:\Program Files\Mozilla Firefox\firefox.exe [964]
    00007FFC14570000-00007FFC14571000 4KB
    00007FFC14572000-00007FFC14573000 4KB
    00007FFC1456F000-00007FFC14570000 4KB
    00000000001C0000-00000000001C6000 24KB C:\Program Files\Sandboxie\SbieSvc.exe [3104]
    00000000001D0000-00000000001D1000 4KB
    00007FFC14549000-00007FFC1454A000 4KB
    1 C:\Program Files\Mozilla Firefox\firefox.exe [964]
    2 C:\Program Files\Sandboxie\Start.exe [7936]
    "C:\Program Files\Sandboxie\Start.exe" /env:00000000_SBIE_CURRENT_DIRECTORY="C:\Program Files\Mozilla Firefox" /env:=Refresh "C:\Users\Public\Desktop\Firefox 56.0.2.lnk"
    3 C:\Program Files\Sandboxie\SbieSvc.exe [3104]
    4 C:\Windows\System32\services.exe [716]
    5 C:\Windows\System32\wininit.exe [652]
    wininit.exe
    1 C:\Program Files\Sandboxie\SbieSvc.exe [3104]
    2 C:\Windows\System32\services.exe [716]
    3 C:\Windows\System32\wininit.exe [652]
    wininit.exe

    Process Trace
    1 C:\Program Files\Mozilla Firefox\firefox.exe [4208]
    "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="964.20.2105533856\1757480329" -childID 3 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120
    2 C:\Program Files\Mozilla Firefox\firefox.exe [964]
    3 C:\Program Files\Sandboxie\Start.exe [7936]
    "C:\Program Files\Sandboxie\Start.exe" /env:00000000_SBIE_CURRENT_DIRECTORY="C:\Program Files\Mozilla Firefox" /env:=Refresh "C:\Users\Public\Desktop\Firefox 56.0.2.lnk"
    4 C:\Program Files\Sandboxie\SbieSvc.exe [3104]
    5 C:\Windows\System32\services.exe [716]
    6 C:\Windows\System32\wininit.exe [652]
    wininit.exe
     
  9. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yes, I did reimport previous settings, that is why BadUSB was enabled, #727. :)
    I have also seen this, and there does seem to be some sort of interaction there, but I can't definitively ascribe HMP.A to being the the cause.

    See this thread: https://www.wilderssecurity.com/thr...ng-to-windows-10-fall-creators-update.397421/ esp. posts #34, #36, #71, #91.
     
  10. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    Does this still reproduce on build 721?
     
  11. SanyaIV

    SanyaIV Registered Member

    Joined:
    Oct 17, 2013
    Posts:
    278
    Yes, just tried again:
    Mitigation CodeCave

    Platform 10.0.16299/x64 v721 8f_01
    PID 256
    Application C:\Users\sanya\source\repos\F1\Debug\F1.exe
    Description F1.exe

    Process Protection / Code Cave Mitigation: Active code cave detected!

    Process Trace
    1 C:\Users\sanya\source\repos\F1\Debug\F1.exe [256]
    "C:\Users\sanya\source\repos\F1\Debug\F1.exe"
    2 C:\Windows\SysWOW64\cmd.exe [4308]
    "C:\WINDOWS\system32\cmd.exe" /c ""C:\Users\sanya\source\repos\F1\Debug\F1.exe" & pause"
    3 C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\Common7\IDE\devenv.exe [1428]
    4 C:\Windows\explorer.exe [6960]
    5 C:\Windows\System32\userinit.exe [6792]
    6 C:\Windows\System32\winlogon.exe [844]
    winlogon.exe

    Thumbprint
    0b502d5ab29ad00192ea36dc8ccad10dbd388a717a75df1716b367b79822abad

    I think it has to do with the project setting in the screenshot. When set to "Not set" it won't interfere, but when set to Console I get the CodeCave mitigation alert when trying to run it (CTRL + F5).
     

    Attached Files:

  12. Gapliin

    Gapliin Registered Member

    Joined:
    Feb 12, 2012
    Posts:
    81
    I've uninstalled HMP.A & HMP, deleted that folder, restarted the PC and after installing build 721 it was still licensed.
    Guess it's stored somewhere else or just computated with a HWID.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Ah yes I forgot it has gotten a Import/Export feature, no problems then, I'll just export the settings.
     
  14. ohgood

    ohgood Registered Member

    Joined:
    Apr 3, 2015
    Posts:
    39
    Location:
    cold upper midwest
    Howdy all!

    Erik, Mark & Ronnie, installed build 721 as instructed - removed previous v, deleted folder. All good, very light and smooth, you guys have been working very hard on another excellent release! I have not had the problems some had, but I also have minimal programs and few potentially conflicting security products.

    Win 10/64 on an old HP Notebook:
    Windows 10/64 Pro v. 1703, build 15063.674

    Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz 2.13 GHz
    4.00 GB (3.80 GB usable)

    Many thanks, again, for a terrific security product. I've tried SO many others, HPA has been the lightest, most secure and innovative. :D:p
     
  15. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    The RC version is running nicely over here, on Win 10 x64 fall creators, with Windows Defender, AppGuard and SpyShelter.
     
  16. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    I tried out HMPA RC together with Comodo Firewall (a rather ambitious combination) and initially had some conflicts, but they were resolved by disabling shellcode injection protection in Comodo. I accomplished this by making a global exception rule: C:\*
     
  17. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    Hi shmu26,

    That sounds rather drastic, can you elaborate a bit more about "some conflicts" there are more setups running HMP.A in combination with CFW and it should not be necessary to make such a system wide exclusion.
     
  18. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    Hi ohgood,

    Thanks for your feedback always welcomed, I'll pass the message to the team!
     
  19. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    1 Chrome started extremely slow
    2 Windows start button did not respond

    I personally don't consider it super drastic, because that particular protection of Comodo is probably superfluous when HMPA is running, and is also not really Comodo's main thing. It's just sort of an extra, a "it doesn't hurt" kind of thing. That's the way I look at it, anyway.
     
  20. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,857
    Location:
    the Netherlands
  21. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    True, but I did detect an apparent interaction there: https://www.wilderssecurity.com/thr...ll-creators-update.397421/page-2#post-2713647 ,
    but it could be a coincidence.

    It is an elusive problem, that one: https://www.wilderssecurity.com/thr...ll-creators-update.397421/page-6#post-2717947 :D
     
  22. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    These issues are sort of like "my head hurts". There could be a lot of reasons.
    But if you bang your head on the wall, and a second later it hurts, then you know what caused it.
    That's how it was with me: I installed HMPA on top of Comodo, and right away, my head hurt.
     
  23. hotlips69

    hotlips69 Registered Member

    Joined:
    Nov 3, 2005
    Posts:
    55
    Location:
    Sussex. UK
    build 721 works perfectly for me. Great job.
     
  24. Duotone

    Duotone Registered Member

    Joined:
    Jul 9, 2016
    Posts:
    142
    Location:
    Philippines
    Is it just me or HMP.A RC preventing windows update FCU?
     
  25. guest

    guest Guest

    Do you have removed the folder C:\ProgramData\HitmanPro.Alert before the installation of 721 RC?
    This should fix the Windows Update issue.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.