HitmanPro.Alert BETA

Discussion in 'other anti-malware software' started by erikloman, May 30, 2017.

  1. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,857
    Location:
    the Netherlands
    Completely clear. Thanks very much. :thumb:
     
  2. TheBear

    TheBear Registered Member

    Joined:
    May 7, 2006
    Posts:
    174
    HitmanPro 3.7.0 build 721 Release Candidate working fine here.
     
  3. plat1098

    plat1098 Guest

    Removed Alert 720 plus the ProgramData folder and installed 721. The Block Untrusted Fonts tile isn't even there any more but had to manually enable BadUSB, and set Vaccination to active for now. Left Credential Theft Protection disabled (at default) for now. Works fine so far w/Sandboxie 5.22 release and IE11. The only thing is being unable to get the HMP scanner to show separately by clicking on the scanner tile, it just shows that little menu. The only feedback you get then is a "scan complete" and green or red on the Alert tile. It would be nice to see the scanner separately in real time. :)
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Did a complete uninstall and installed 721. Looks good so far. Scan was fine and fast .
     
    Last edited: Nov 3, 2017
  5. newyorkjet

    newyorkjet Registered Member

    Joined:
    Jan 17, 2013
    Posts:
    63
    Location:
    UK
    Followed instructions for installing 721. Left settings on standard as left factory. All is fine. PC boots to Macrium reflect USB unlike 718 and 720.
    Thank you.
     
  6. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    No problems installing (after also deleting Programdata folder). Win 10 Pro x64 v1709 16299.19.

    Surprised to see No. of alerts is not zeroised though, must be getting that data from elsewhere (Event Viewer?). Can one manually zeroise it?
     
    Last edited: Nov 4, 2017
  7. markloman

    markloman Developer

    Joined:
    Jan 25, 2005
    Posts:
    581
    Location:
    Hengelo
    The alerts are read from the Application log, part of the Windows Event Log. If you want to set the counters to zero, you can clean the Windows Event Log.
     
  8. SanyaIV

    SanyaIV Registered Member

    Joined:
    Oct 17, 2013
    Posts:
    278
    It still triggers an alert:
    Mitigation CodeCave

    Platform 10.0.16299/x64 v721 8f_01
    PID 8292
    Application C:\Users\sanya\AppData\Local\Temp\is-2VQ9O.tmp\astah-professional-7_2_0-1ff236-jre-64bit-setup.tmp
    Description Setup/Uninstall

    Intersectional control flow detected!

    Process Trace
    1 C:\Users\sanya\AppData\Local\Temp\is-2VQ9O.tmp\astah-professional-7_2_0-1ff236-jre-64bit-setup.tmp [8292]
    "C:\Users\sanya\AppData\Local\Temp\is-2VQ9O.tmp\astah-professional-7_2_0-1ff236-jre-64bit-setup.tmp" /SL5="$608D2,92158849,569856,C:\Users\sanya\Downloads\astah-professional-7_2_0-1ff236-jre-64bit-setup.exe"
    2 C:\Users\sanya\Downloads\astah-professional-7_2_0-1ff236-jre-64bit-setup.exe [14332]
    3 C:\Windows\explorer.exe [7504]

    Thumbprint
    37a1c59855a4c83de118d54424ab6cf74b1bf93f6de08b0a37bff1e7659618d2

    However if I disable CodeCave I can install the program, and once installed I can enable CodeCave and launch the application without issue.

    Another CodeCave situation: Visual Studio Community 2017 -> Create a new Windows Console Application (C++) and just make a simple Hello World application. Now do CTRL + F5 to run it, causes:
    Mitigation CodeCave

    Platform 10.0.16299/x64 v721 8f_01
    PID 15328
    Application C:\Users\sanya\source\repos\TestCodeCave\Debug\TestCodeCave.exe
    Description TestCodeCave.exe

    Process Protection / Code Cave Mitigation: Active code cave detected!

    Process Trace
    1 C:\Users\sanya\source\repos\TestCodeCave\Debug\TestCodeCave.exe [15328]
    "C:\Users\sanya\source\repos\TestCodeCave\Debug\TestCodeCave.exe"
    2 C:\Windows\SysWOW64\cmd.exe [2880]
    "C:\WINDOWS\system32\cmd.exe" /c ""C:\Users\sanya\source\repos\TestCodeCave\Debug\TestCodeCave.exe" & pause"
    3 C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\Common7\IDE\devenv.exe [9408]
    4 C:\Windows\explorer.exe [7504]

    Thumbprint
    e6d903dc8fe081f7dc79ecf91e6fe6cb164431777269e2db654e99e00d5757c4
     
  9. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Completely uninstalled 720, installed 721, and enabled badUSB. No problems so far.
     
  10. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Win 10 Pro x64 v1709 16299.19, HMP.A build 721 beta.

    Mitigation ROP

    Platform 10.0.16299/x64 v721 06_45
    PID 8120
    Application C:\Program Files\Mozilla Firefox\firefox.exe
    Description Firefox 56.0.2

    Callee Type LoadLibrary

    Stack Trace
    # Address Module Location
    -- ---------------- ------------------------ ----------------------------------------
    1 00007FF841D9966D KernelBase.dll
    2 00007FF844AF8508 ntdll.dll
    3 00007FF844AE0F56 ntdll.dll __C_specific_handler +0x96
    4 00007FF844AF4C3D ntdll.dll __chkstk +0x11d
    5 00007FF844A6D1B8 ntdll.dll
    6 00007FF844AF3B6E ntdll.dll KiUserExceptionDispatcher +0x2e

    7 00007FF8027AAA01 xul.dll
    cc INT 3

    8 00007FF802EFCAAA xul.dll
    9 00007FF802EE5F62 xul.dll
    10 00007FF802C37D1E xul.dll

    Code Injection
    000002723EE4D000-000002723EE4E000 4KB C:\Program Files\Mozilla Firefox\firefox.exe [14032]
    00007FF844AF0000-00007FF844AF1000 4KB
    00007FF844AF2000-00007FF844AF3000 4KB
    00007FF844AEF000-00007FF844AF0000 4KB
    1 C:\Program Files\Mozilla Firefox\firefox.exe [14032]
    2 C:\Program Files\Mozilla Firefox\firefox.exe [16456]
    3 C:\Windows\explorer.exe [4104]
    4 C:\Windows\System32\userinit.exe [4676]

    Process Trace
    1 C:\Program Files\Mozilla Firefox\firefox.exe [8120]
    "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="14032.3.511104922\1068371946" -childID 1 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120
    2 C:\Program Files\Mozilla Firefox\firefox.exe [14032]
    3 C:\Program Files\Mozilla Firefox\firefox.exe [16456]
    4 C:\Windows\explorer.exe [4104]
    5 C:\Windows\System32\userinit.exe [4676]

    Thumbprint
    65b08153b6f661f989e3612ad52cf5c1192ecd4df327f9082c26b98b91b224b3
     
  11. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    When you run the scan the HitmanPro icon is in the "tray" though it may be hidden. If you double click the icon the usual HitmanPro window with the list of detections will open.
     
  12. plat1098

    plat1098 Guest

    Yes, got it. Actually, this was brought up before, I guess it's just the way it is. You can double-click the scanner tile on the release and get the HMP interface while it's running. Just not in the beta, it seems. No biggie.
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I get a Scanning icon in the tray in 721. But all my tray icons are visible. Win 7 x64
     
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    From a technical point of view HMPA is superior, but I also feel it causes too many problems, that's why I decided not to install. But for some it won't cause any problems, it also depends on apps and other security tools that are used. But I'm not willing it to risk anything.
     
  15. Sand

    Sand Registered Member

    Joined:
    Apr 28, 2016
    Posts:
    26
    Installed RC 721, upgrade over previous one "720" and clean install.

    I see both zam and cyberghost working fine now.


    I instead obtain a Error Starting Application for C:\Windows\System32\PrintDisp.exe

    that is installed with https://www.iceni.com/infix.htm a PDF Editor,

    looking at the properties of that PE looks like miss any Mitigation Exploit feature, and I added it to exclusion, so far not obtaining any error starting anymore, means that Hitman try to protect it but fail because has no way to protect it,

    Am I wrong?
     

    Attached Files:

  16. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Thus far no problems here (Windows 7 Pro SP1 x64).
     
  17. L10090

    L10090 Registered Member

    Joined:
    Feb 13, 2015
    Posts:
    302
    Location:
    Netherlands
    W7-x64 Professional: De-installed Build 720 completely, Installed build 721 RC, no issues what so ever!
     
  18. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    I also noticed that BadUSB was off when I installed 721; I wonder if that's by default?
     
  19. guest

    guest Guest

    It is a default since 3.1.1 Build 350:
     
  20. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Where have I been? LOL Thanks for clarifying :thumb:
     
  21. guest

    guest Guest

    No problem :)
     
  22. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    Installed 721 RC, on Win 10 x64 pro fall creators update.
    Chrome starts up slowly and fitfully, and some of the extensions crash.
     
    Last edited: Nov 5, 2017
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    That is strange, because I uninstalled 720 and deleted Programdata, rebooted, installed 721, rebooted - and BadUSB is Enabled.
     
  24. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    If you uninstall HMP.A and delete the folder in Program Data, will that also delete preferences?
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Disabled here. Indeed strange
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.