Hitman Pro Support and Discussion Thread

Discussion in 'other anti-malware software' started by yashau, Mar 20, 2009.

  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Re: Beta Build 128

    Nope. They can run alongside.
     
  2. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    http://en.wikipedia.org/wiki/Fingerprint_(computing)
     
    Last edited: Aug 1, 2011
  3. darthsideous666

    darthsideous666 Registered Member

    Joined:
    Feb 9, 2007
    Posts:
    202
    Location:
    Secret Hideout on Coruscant
    I just ran a scan with Hitman Pro (Build 127) and it detected Webroot SecureAnywhere/Webroot Cloud AntiVirus as malware. This is obviously a false positive and related to the latest update of the Webroot Beta, because this was not the case before the update!
     
    Last edited: Aug 1, 2011
  4. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    I ran HitmanPro35beta.exe and it scanned my system. But it began uploading one file, which is part of Avidemux 2.6 experimental, called, avidemux3_qt4.exe.

    Why would Hitman upload avidemux3_qt4.exe?
     
  5. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    You apparently aren't willing to do any research on your own.
    The answer is available on the HMP website...

    HMP scan explanation.jpg
     
  6. getyyged

    getyyged Registered Member

    Joined:
    Aug 2, 2011
    Posts:
    2
    Hi!
    Im using EWS scan to test my system, (Windows 7 x64, hitman pro 3.5.9 (64-bit).I get a yellow message saying:
    "IRP_MJ_SCSI kernel-mode hook on nvstor.sys detected and bypassed"
    The device stack of the hard disk is referencing a hidden driver. This could affect the detection of malicious files."

    Is there a way to check if this hook and driver are benign and needed for correctly functioning of the system?
     
  7. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Uninstall Deamon Tools or more specifically the SPTD from DuplexSecure and reboot the computer. If the message is still there then you might have a rootkit on your system. But my guess is you have SPTD installed.
     
  8. getyyged

    getyyged Registered Member

    Joined:
    Aug 2, 2011
    Posts:
    2
    OK! It was SPTD, I deleted it and its message is not any more.
     
  9. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    I find that hard to believe that I am the only single human on earth that has Avidemux running and using Hitman Pro. Surely this file "avidemux3_qt4.exe" had been on other poeple's system who use Hitman Pro. Surely I am not the only human on Earth.
     
  10. Baserk

    Baserk Registered Member

    Joined:
    Apr 14, 2008
    Posts:
    1,321
    Location:
    AmstelodamUM
    You use a beta to scan an alpha. How on earth could you be the first...:rolleyes:
    I say; Vitamins.
    (However, if you were a troll, I'd say; It's at least an original one. For once)
     
    Last edited: Aug 2, 2011
  11. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    Looking forward to seeing an advanced install for this product. Then it's perfect.
     
  12. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    For sure, but someone had to be the first one, no. You said "experimental", it's not about the program it belongs to, it's about that specific file. You were the first HMP user to scan that experimental .exe, that's all.
     
  13. Ariadne22

    Ariadne22 Registered Member

    Joined:
    Jul 5, 2011
    Posts:
    29
    I got same message yesterday on a deep scan I ran b/c suddenly at 11 p.m. started getting just-in-time script popup, a message that firewall and updates were turned off, and immediately began experiencing redirects in Firefox (thought that bug was long gone - had that problem a year ago). Couldn't turn automatic updates on at all either in security panel or system panel, although I succeeded in restoring windows firewall.

    This image shows 'ignore', but when I told HMP to 'replace' and rebooted, problems remained. Did system restore to previous day and rootkit still came up on HMP as did just in time popup and browser link redirects, although the restore resolved the security center problems.

    Virus Trojan HMP Scan 8-2-2011.JPG

    Downloaded MBAM, but it wouldn't update. (Might have been b/c ESET was running realtime. Have since uninstalled MBAM and will turn off ESET and try again.)

    Then downloaded TDSSkiller which found the rootkit and deleted. All was well after that. No popup and no redirects. Subsequent HMP scans are clean as are TDSS.

    Running ESET NOD42 AV4 realtime. Did two full scans and it did not pick up this malware. Seems I'm vulnerable to this type of malware when I open IE. Usually use Firefox, but malware seems to appear within a couple of days of using IE7. Had different/worse antimalware problem a month ago which disabled HMP and required a safe boot before I could do a system restore. Thus installed ESET. Ha!! Still this crap gets through.:mad:

    Next moves - download Rkill and MBAM.

    Would Sandboxie or a different AV help prevent this malware getting through? I was up until after 2 a.m. cleaning up this mess.
     
    Last edited: Aug 3, 2011
  14. Kid Shamrock

    Kid Shamrock Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    229
    Sandboxie or DefenseWall are excellent against rootkits.
     
  15. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    indeed:thumb:
     
  16. andylau

    andylau Registered Member

    Joined:
    Jan 27, 2006
    Posts:
    698
    Erik,

    As I remember, you have said that a v3.6 beta version will be available at the end of July. But now is Aug, where is it?:D :p
     
  17. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    Last edited: Aug 4, 2011
  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Its coming. Just keep tuned in :D
     
  19. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    BETA Hitman Pro 3.5.9 build 129 (32-bit/64-bit)

    Changelog (compared to build 127)
    • Detects and removes latest ZeroAccess rootkit
    • Improved detection of Sinowall rootkit
    • Improved removal of 64-bit version of ZeroAccess rootkit
    • Improved kernel-mode guard to block code injection attacks on Hitman Pro scan and removal process.
    • Improved Cloud Assisted Miniport Hook Bypass to support detection of detours.
    • Improved Crusader's watchdog.
    • Added Romanian language.
    • ...

    32-bit: http://dl.surfright.nl/HitmanPro35beta.exe
    64-bit: http://dl.surfright.nl/HitmanPro35beta_x64.exe

    Please post any problems you may have with this build as we've made a few changes to the kernel-mode guard. Thanks!
     
  20. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Nice :)
    Seems fine on win7 x64.
     
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Thanks :thumb:
     
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I am still running v3.5.9.128. I was expecting it to update...automatically...but still waiting. That is the way I usually get the update. o_O
     
  23. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Beta's don't auto update. Only the stable releases. If you run build 128 (= previous beta) you should delete it and run this build instead (beta's don't install themselves).

    Hope this helps.
     
  24. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Hi

    I scan my pc today with Hitman pro and i have 2 false positives

    ~ VirusTotal Results Link Removed per Policy ~

    File name: OADriver.sys
    Submission date: 2011-08-07 16:01:02 (UTC)
    Current status: finished
    Result: 0/ 43 (0.0%)


    ~ VirusTotal Results Link Removed per Policy ~

    File name: oahlp32.sys
    Submission date: 2011-08-07 16:06:50 (UTC)
    Current status: finished
    Result: 0/ 43 (0.0%)
     

    Attached Files:

    Last edited by a moderator: Aug 7, 2011
  25. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    those files are detected by early warning scoring hence (6.0).
    if you run a scan without early warning scoring those files wont show as threats.
    you can still right click the files and use the option report as false positive.
    early warning scoring is used to help advanced users detect potentially unknown malware but can lead to false positives.
     
    Last edited: Aug 7, 2011
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.