Hitman Pro Support and Discussion Thread

Discussion in 'other anti-malware software' started by yashau, Mar 20, 2009.

  1. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Thanks and good to know!

    Cheers,

    Daniel
     
  2. Brandonn2010

    Brandonn2010 Registered Member

    Joined:
    Jan 10, 2011
    Posts:
    1,854
    Question. Tonight I cleaned a computer for someone.I ran TDSSKiller, and it found 2 Windows.Patched rootkits or something like that. It removed them, and didn't find anything after another scan, nor did Malwarebytes, yet HitmanPro found 4 ZeroAccess rootkits. However, 3 of them were in $Recycler.RecycleBin or something like that. Another was in the Windows Installer folder, yet manually looking for the folder turned up nothing. So my question is are the rootkits there, or is HitmanPro just detecting the already-deleted files that are just waiting to be written over, or what?
     
  3. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    ZeroAccess folders are derived from per-computer specific info. HitmanPro uses that exact same scheme to detect these folders and can therefor provide a much better cleanup.

    Note that ZeroAccess is notoriously known for hiding stuff in the recyclebin:
    https://nakedsecurity.sophos.com/20...lware-revisited-new-version-yet-more-devious/

    Hope this helps.
     
  4. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I just got around to running the latest beta. No problems. This in another snapshot in which I don't have HMP.A...;)

    ScreenShot_HMP_v3.7.9_bulid 233 beta_02.gif ScreenShot_HMP_v3.7.9_bulid 233 beta_03.gif
     
  5. Brandonn2010

    Brandonn2010 Registered Member

    Joined:
    Jan 10, 2011
    Posts:
    1,854
    Well crud. Guess he'll have to get a license for HMP since neither TDSSKiller nor Norton's TDSS removal tool detected them.
     
  6. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    ScreenShot_Kaspersy_TDSS Killers_v3.0.0.42_03.gif
    Talking about TDSSKiller, I just scanned the with latest version a short time ago...and I changed the scan parameters within, so to verify file signatures, which I don't bother with, usually.

    This time it came with [some] detections, because I did that change...but, all is good. I know what they are about, so no problem. Edit: one word was duplicated

    ScreenShot_Kaspersy_TDSS Killers_v3.0.0.42_02.gif
     
    Last edited: Dec 30, 2014
  7. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    I can't make any sense of this one. Erik?
    Scan.jpg
     
  8. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
  9. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
    Hi Erik and Hi Mark

    Any Infos for my post 6318

    With Best Regards
    Mops21
     
  10. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    You are aware that the EWS mode largely lists the files that arrived recently on the system? (it puts more weight on the a file's timestamp)
    EWS is only needed if you suspect the computer to be infected.
    It is highly unrecommended to continuously running in EWS. That is why you must be expert to know which files belong to Windows and which ones could be malware.

    That said, I've whitelisted the files.
     
  11. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany

    Hi Erik

    Thank you very much for your informations

    With Best Regards
    Mops21
     
  12. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro 3.7.9 Build 233 Released

    Changelog
    • IMPROVED: Detection and removal of new variant of Reveton ransomware.
    • FIXED: Issue with the Internet Explorer cookie enumerator causing the scan to never finish.
    • FIXED: Issue causing HitmanPro to stop working.
    Existing users are automatically updated.

    Please report any issues, if any. Thanks :thumb:
     
  13. WSFfan

    WSFfan Registered Member

    Joined:
    May 10, 2012
    Posts:
    374
    Location:
    The Earth
    Though automatic update is working fine,could you please update the download links with the latest build version?Thank you:)
     
  14. pimjoosten

    pimjoosten Registered Member

    Joined:
    Mar 28, 2014
    Posts:
    36
    Location:
    Amsterdam, The Netherlands
    My computer was just automatically updated to build 233, but it keeps crashing. Always at four seconds after the scan starts there is a Windows error "HitmanPro 3.7 stopped working" ("HitmanPro 3.7 werkt niet meer"). A computer restart does not solve the issue. The previous build worked perfectly.

    I am using Vista Ultimate 64-bit.
     
    Last edited: Jan 9, 2015
  15. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    No issues on Win7 Ult. (64)
     
  16. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Can you run HitmanPro from the command line:

    C:\Program Files\HitmanPro\HitmanPro.exe /debug:full

    And let it crash. Send me the dump erik@surfright.com via www.wetransfer.com
     
  17. pimjoosten

    pimjoosten Registered Member

    Joined:
    Mar 28, 2014
    Posts:
    36
    Location:
    Amsterdam, The Netherlands
    The dump is now being sent. You will receive it shortly.
     
  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    I've found the issue (thanks to your dump :thumb:).

    Build 234 is going out now as we speak. Sorry for the inconvenience.
     
  19. pimjoosten

    pimjoosten Registered Member

    Joined:
    Mar 28, 2014
    Posts:
    36
    Location:
    Amsterdam, The Netherlands
    I can confirm that the issue has been resolved in build 234. Thanks for fixing it this quickly! :)
     
  20. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,746
    Location:
    Germany
  21. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
  22. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Build 234 crashes when I download the hitmanpro.exe to desktop en run the file. When I put this file in
    C:\Program Files\HitmanPro it runs without a problem (Vista 32 bits).
     
  23. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    WERFBAE.tmp.mdmp sent by mail.
     
  24. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Uninstalled HitmanPro.Alert build 131 (conflict with Sandboxie and Vista 32 bits), restarted the computer and now HitmanPro build 234 works fine.
     
  25. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,304
    Location:
    Kent. UK by the sea
    Hi erikloman

    Many thanks to all the team at SurfRight.
    Build 234 working with no problems here. :thumb:

    Take Care
    TheQuest :cool:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.