HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    You can add any application to Alert via the blue tile > Running Applications > click the application listed. Done.
     
  2. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    Not any, only applications that have an (active) window. So a "search for exe" function would be a very nice addition.
     
  3. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,220
    Location:
    USA
  4. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations,

    "You can add any application to Alert via the blue tile ..."
    "Not any, only applications that have an (active) window. So a "search for exe" function would be a very nice addition."

    Nice to know!

    Moose's World
     
  5. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    480
    @erikloman @markloman None of my autohotkey shortcuts are working in my browser. I have several shortcuts for text expansions and none of them are working inside the browser protected by HMPA.

    EDIT: I just found that keyboard encryption was causing the problem. After I disabled keyboard encryption, they work perfectly. Is there any option to exclude a program from keyboard encryption ?
     
  6. guest

    guest Guest

  7. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yeah, I googl'd after posting ... << The best way to protect a computer from a remote code execution vulnerability is to fix holes that allow an attacker to gain access. Microsoft often releases security patches addressing remote code execution vulnerabilities in its monthly Patch Tuesday fixes. >>
    Good info ~~ Thanks
     
  8. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Is it good to protect Cat Control Center CCC.EXE when Malware has been known to use CCC.EXE
     
  9. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yeah, had to google CCC :) Thanks
     
  10. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Hi Erik,

    I just experienced another black screen after booting. I sent you the Winlogon dump and log.
     
  11. guest

    guest Guest

    I suppose that enabling exploit mitigations for ccc.exe will not prevent malware from taking advantage of it. Although you still have hardening functions like Active Vaccination and Process Protection that might form an additional layer of protection.
     
  12. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yeah, I've had the black screen...didn't know it's related to Alert
     
  13. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    That's why I asked in a previous post, but nobody answered. I suspect it has to do with HMPA since it happens on different laptops running HMPA. It may well be unrelated, but Erik seemed interested to look into it, so I am sending him the crashes until he no longer needs the information.
     
  14. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Sorry, must have missed. What path in Event Viewer. What Event ID | OK ~ I've reviewed #3857. I'll check ~ Sorry, I missed your post. Event ID will be under Application or Administration ? How do you get from black screen to desktop ?
     
    Last edited: Feb 4, 2015
  15. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Not a problem. I'm glad I'm not the only one having this problem. Once you get the black screen, you can no longer get to the desktop. You have to hold down the power button until the PC shuts itself off. Once you get a good boot, you can then check the Administration event log.
    Winlogon.jpg
     
    Last edited: Feb 4, 2015
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Um...Event 1000 for me are all ISCTAgent and ApplicationError pointing to chrome ~ I'll keep looking.
     
    Last edited: Feb 4, 2015
  17. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    If the black screen you experienced did not happen recently, the event may already have been overwritten. If it happens again, you now know what to check.
     
  18. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Got them. Im analyzing them. Hopefully something turns up.
     
  19. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    Thank you. That is probably why I did not see the applications I wanted to add. (Seems I wasn't the only one.) So, I would thoroughly agree with you that being able to search for an EXE would be a good addition.
     
  20. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    Just installed RC 143. This is a really nice-looking application. Still getting interference with EMET though. I only mention this as an aside; I don't intend to keep EMET.

    alert_emet.png
     
  21. hotlips69

    hotlips69 Registered Member

    Joined:
    Nov 3, 2005
    Posts:
    55
    Location:
    Sussex. UK
    Three quick questions if I may:

    1) I've got the latest b143 installed & I ran the exploit tool & all the exploits were correctly stopped etc... but when I clicked to "Run a scan with Hitman Pro" it started up HMP 3.7.9 build 234 & did the scan correctly, but I've never installed HMP itself...only the HMP Alert?

    2) If I purchased HMP, would I get a seperate application to run a scan manually with updated signatures etc... as per MBAM?

    3) I've got two live test machines both running 24/7 which are purely for testing & often get re-imaged etc.....if I purchased a 1 PC licence, could I use that on both test machines simultaneously?
     
  22. guest

    guest Guest

    1. It will automatically download HMP in the background.
    2. HMP heavily depends on the scancloud for signatures and/or detection, but you can always download HMPA from the Surfright website.
    3. You'll run into issues if you perform regular imaging using the same license. A license can only be activated twice (good for one re-installation), you might want to contact Mark or Erik to correct this. iirc they have helped people before with the same issue.

    Regards,
    regenpijp
     
  23. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    Turns out you can't add services to exploit protection. I have one service I'd like to add. It's an atomic clock sync service that hits ntp.org, so I'm probably overdoing it on that one...
     
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Plugin container.JPG What's wrong with Plugin. Or, is that normal. 296 looked like Flash Icon afaik. Also, does Flash for Chrome show as running app so, I may add mitigation. I have NPAPI and PPAPI .305 installed and ran Chrome Flash (active window). All that shows while running Chrome Flash is Chrome. Is Chrome Flash embedded in Chrome. 305's in pic are syswow64 and system32. What am I missing ? Thanks
     
    Last edited: Feb 5, 2015
  25. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Flash is embedded in Chrome sandbox.
    Both flash from system32 and syswow64 are listed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.