Hitman Pro Support and Discussion Thread

Discussion in 'other anti-malware software' started by yashau, Mar 20, 2009.

  1. JEAM

    JEAM Registered Member

    Wow, I was not aware of this.
     
  2. Tinstaafl

    Tinstaafl Registered Member

    Just curious, did any AV effectively catch these particular "scriptors"?
     
  3. cruelsister

    cruelsister Registered Member

    Most are (as they are old) caught by a primary AV scanner when coded either as a script or an exe. The issue here is that HMP is not capable of detecting the malware when they already exist (got past the primary AV); and catching infections already extent on a system is the purpose of a 2nd opinion scanner.
     
  4. Tinstaafl

    Tinstaafl Registered Member

    Thanks. Agreed it would be nice to catch everything! It has always been my understanding that a primary AV scanner that uses signature files is the first line of defense, and that is why one uses 2nd, 3rd. etc. opinion scanners. Most of which are also signature based. I use 2nd & 3rd opinion on-demand scanners here.

    Also using HMP & HMPA to cover a different niche, as these are not signature based. I'm not exactly clear on how the HMP scanner detects potential "static" malware traces and/or cleans it. Although HMPA seems designed to catch bad "behavior" in the act, and terminate it.

    From the Hitman Pro website:
    "It scans for bad behavior

    A standard antivirus program misses stuff. It’s focused on finding malware signatures that virus firms have identified as malicious. But what about new, zero-day threats that haven’t been researched? That’s why HitmanPro looks at behaviors when scanning for trojans and other malware. Bad behavior is caught, with or without a malware signature."
     
  5. RonnyT

    RonnyT QA Engineer

    Last edited: Jun 1, 2022
  6. moredhelfinland

    moredhelfinland Registered Member

    What's this "Tarrash malware", can you provide a sample of it so i can test it against GData BEAST/DeepRay?
     
  7. RonnyT

    RonnyT QA Engineer

  8. moredhelfinland

    moredhelfinland Registered Member

    Thanks Ronny, added this HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TASK_NAME
    For my custom protected NVT registry guard rulebase.
     
  9. plat

    plat Registered Member

    This is a welcome change. Hopefully, this happens automatically, otherwise my entire system freezes and I have to unplug the computer and restart it. Very rare but can still happen on here. The Windows drive is an nvm-e.
     
  10. RonnyT

    RonnyT QA Engineer

    That's the intention of this change indeed, if a system freezes/bsod, scanner crash etc then it will auto-default to Compatible disk mode next time.
     
  11. Valdez

    Valdez Registered Member

    For RonnyT

    2Immagine.png
     
  12. RonnyT

    RonnyT QA Engineer

  13. Valdez

    Valdez Registered Member

    Thank you no longer appears :thumb:
     
  14. moredhelfinland

    moredhelfinland Registered Member

    @RonnyT
    Seems that HPA does not like custom .exe packers and automagically flags those as a malware? These are Demoscene products.
    Result
    Then, i'm using Resonic to play my audio files. It is legit software, but everytime i start Resonic, HMP says "Attack Intercepted".
     
  15. RonnyT

    RonnyT QA Engineer

    Can you send a scan log from HMP, and the alert details from HMPA to support@hitmanpro.com please
     
  16. moredhelfinland

    moredhelfinland Registered Member

  17. XIII

    XIII Registered Member

    Does Sophos Scan & Clean get a similar update?
     
  18. Krusty

    Krusty Registered Member

    After this FP I got this from HMP:
    Code:
    HitmanPro 3.8.30.326
    www.hitmanpro.com
    
       Computer name . . . . : DAVID-HP
       Windows . . . . . . . : 10.0.0.19045.X64/4
       User name . . . . . . : DAVID-HP\David
       UAC . . . . . . . . . : Enabled
       License . . . . . . . : Paid (425 days left)
    
       Scan date . . . . . . : 2022-10-30 12:00:16
       Scan mode . . . . . . : Quick
       Scan duration . . . . : 48s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : Internet
       Reboot  . . . . . . . : No
    
       Threats . . . . . . . : 1
       Traces  . . . . . . . : 2
    
       Objects scanned . . . : 5,673
       Files scanned . . . . : 5,673
       Remnants scanned  . . : 0 files / 0 keys
    
    Malware _____________________________________________________________________
    
       C:\Program Files (x86)\PrivaZer\PrivaZer.exe
          Size . . . . . . . : 20,652,072 bytes
          Age  . . . . . . . : 0.1 days (2022-10-30 10:17:38)
          Entropy  . . . . . : 6.7
          SHA-256  . . . . . : A9A4168ADB3C27E3FB9B6BF75799519B227FBCB034722ADC1FC7E67A20C00602
          Product  . . . . . : PrivaZer
          Publisher  . . . . : Goversoft LLC
          Description  . . . : PrivaZer
          Version  . . . . . : 4.0.56.0
          Copyright  . . . . : Goversoft
          RSA Key Size . . . : 2048
          LanguageID . . . . : 1033
          Authenticode . . . : Valid
        > SurfRight  . . . . : Mal/Behav-048
          Fuzzy  . . . . . . : 85.0
          Startup
             C:\WINDOWS\system32\Tasks\PrivaZer_SkipUAC
    
    
    
    
    I note that it is ONLY Sophos who detect this file on VirusTotal.

    Edit: "Google" is now detecting it too.
     
  19. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Hello @Krusty,
    Where do you see "Google"?
     
  20. anon

    anon Registered Member

    I saw that too, but now fixed (Google -> Sophos).

    SHA-256 . . . . . : A9A4168ADB3C27E3FB9B6BF75799519B227FBCB034722ADC1FC7E67A20C00602
     
  21. Krusty

    Krusty Registered Member

    Hi @The_PrivaZer_Team ,

    While I don't see it there now, when I scanned the installer at VirusTotal Google was listed as one of the vendors.
     
  22. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    OK.
    The problem is fixed with Hitman Pro flagging PrivaZer.
    We have contacted them and they have updated their virus definition.
     
  23. plat

    plat Registered Member

    Hmmm, had reported this glitch back in March here:

    https://www.wilderssecurity.com/thr...iscussion-thread.236732/page-341#post-3075718

    In a nutshell, if I left the scanner running while going into a game with old graphics style and screen resolution below 1920x1080, the HMP UI would turn out funny-looking. I'm simply reporting it again, this time with a different game. Sent to support with full details.

    Honestly, I don't expect anything to come out of it; just letting one know.

    hmp 11152022 l.PNG
     
  24. schemer

    schemer Registered Member

    Hi,
    I have been using HMP for years and now all of a sudden I got a message from VirusTotal saying I have been exceeding my total of 500 checks a day! What would cause this? Did someone hack my API that is used with hitmanpro?
    Thanks,
    Dave
     
  25. feerf56

    feerf56 Registered Member

    Norton should be officially notified. This only occurs with their latest database. It did not appear yesterday.

    2023-03-02_150454.jpg
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice