HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. guest

    guest Guest

    @erikloman/markloman

    Is there any difference in the 'level of protection' offered by the hardware assisted CFI on different generations of Intel CPU's? (For example: Sandy Bridge vs. Haswell)

    Why would anyone run both tools? o_O
     
  2. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    No difference. Haswell does support a new mode but Alert 3.0 does not yet use it.
     
  3. guest

    guest Guest

    Okay, thnx. That saves me quite some time.
     
  4. guest

    guest Guest

    Has this verion been tested with WSA? have you heard about any incompatibility with WSA?
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I was just trying to figure out if it's right to draw the conclusion that MBAE can not protect against certain attacks, "exotic" or not. But personally I also think that MBAE and HMPA are both great tools. And I'm sorry to hear you lost your "30 minute" post, I also hate it when this happens. I think Firefox has an extension which let's you save your forum posts, but I'm not sure.

    LOL, I do wonder, shouldn't security tools be able to protect their own processes against DLL injection?

    To clarify, I'm not blaming the developers of MBAE/HMPA/EMET, it's something that you should expect, just like when you run 2 AV's or 2 behavior blockers, it's asking for trouble.
     
  6. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,304
    Location:
    Kent. UK by the sea
    Hi erikloman

    Many thanks to all the team at SurfRight.
    Build 131 RC working without problems here. :thumb:

    Take Care
    TheQuest :cool:
     
  7. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Well, I'm running build 131 right now with WSA with no obvious problems :thumb: It's a good idea after updating to check through WSA and make sure HMPA is being "allowed" everywhere and not denied or monitored.
     
  8. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    Why is the "Check for update" button grey even though I have 129 and 131 is out already? I want to always check for an update with that button and get an answer wether there is an update or not :/

    Thanks
     
  9. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Another person speaking as if those tools are somehow equivalent, when that's not always the case: https://www.wilderssecurity.com/threads/emet-mbae-and-hmp-a.370363/

    It's like questioning why we layer security programs.
     
  10. Erik,

    Does it has to be specifically i3, i5 or i7 or are processors of same familly (e.g. ivvy bridge or haswell) with virtualization instruction set enabed processors also capable of running CFI?

    I think it is noble of you to adopt HPMA to run with MBAE, but I think it may be wiser to say don't run two simular programs at the same time (when they are not mutaully excluding protecting different software)?
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Totally Agree
     
  12. pablozi

    pablozi Registered Member

    Joined:
    Oct 24, 2010
    Posts:
    215
    Location:
    nowhere
    Just upgraded from previous build and all seems to be fine.
    Win 8.1 Update 1 x64, Google Chrome x64 stable.
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    You misunderstood me. I'm not saying that you shouldn't combine them, I'm saying: don't be surprised if they will start to malfunction at some point, or become incompatible after some update. And to clarify, I'm speaking specifically about HMPA's "exploit protection" and "safe browsing" features. If these 2 are turned off, HMPA should in theory not interfere with MBAE. But I believe that HMPA always injects code into monitored processes whether these features are turned on or not, which may cause problems.
     
  14. guest

    guest Guest

    They offer roughly the same mitigation capabilities. Although EMETs EAF+ is king in killing memory leaks, but EMET is also slow as hell...
    But in general I think that HMPA is more user friendly, is better understandable and has the most useful features.
     
  15. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    @Rasheed187: Safe browsing interferes with MBAE and EMET? How?

    @regenpijp: Yes, but the free version doesn't offer similar mitigation capabilities.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    No sympathy. Don't Erik and Mark deserve to eat, as does Mbam infact.
     
  17. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Being on par with EMET is good, but it sounds like being on par with HMP.A for Intel would be better.:D Is there some other security I should add to make up the difference, or does what's in my signature have me covered?

    I'm having a problem with the Taskbar sliding open on mouse-over at the edge of the screen when Chrome is full-screen. It happens whenever the green border is showing for a few seconds, but sometimes even when the border isn't showing. Then I have to move the window from full-screen to get to the Taskbar.
     
    Last edited: Dec 22, 2014
  18. brihy1

    brihy1 Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    199
    Location:
    usa
    Does the check for updates work?I hit check for updates and it does nothing but grays out and says no update available?Still on 129
     
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Thanks Mark! :thumb:
     
  20. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Why? I restored my machine from a backup. Why would I ask if I knew?

    I really don't understand why you are so concerned about this. Why do these companies even offer a free version then?
     
  21. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I'm quite certain that attitude will get you customers. :rolleyes:

    Thank goodness the Loman brothers and MBAM know better and are doing well because of that.
     
  22. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Build 31 up and running nicely on one machine so far. :)

    :thumb: Great work guys!
     
  23. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I concur, it's really exciting seeing all these new technologies bear fruit.
     
  24. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Erik & Mark,

    I think I've found a way to avoid having Firefox not opening but showing in Task Manager.

    Before anyone points the finger at MBAE, I have had this happen even with MBAE disabled.

    https://www.wilderssecurity.com/thre...iscussion-thread.324841/page-121#post-2435668

    What seems to help is if I hover over the Firefox icon in the Task Bar and wait until the words "Mozilla Firefox" appear before clicking the icon to open FF, Firefox does open (so far anyway). If I am too quick and click on the Firefox icon on the Task Bar sometimes FF will not open but shows it is running in the Task Manager. I have noticed it more often when my machine has been idol.

    PS: The very early issue of HMP.A not showing the green border around Firefox while Norton Security v22 beta was installed has been resolved, thank you.

    Edit: Just to confirm, I am using HMP.A 3 RC Build 131 unactivated (so free version). This has not happened using HMP.A 2.
     
    Last edited: Dec 22, 2014
  25. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
    Added System Explorer 6.1 (SE) to template OTHER (build 131/W7 64 bits). When I minimize SE to the traybar the blue border remains active. See picture of desktop.
     

    Attached Files:

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.