HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro.Alert 3 Build 166 Release Candidate

    Changelog
    • IMPROVED: ROP mitigation
    • IMPROVED: LoadLib mitigation
    • IMPROVED: BadUSB mitigation
    • IMPROVED: Intruder detection in Safe Browsing
    • FIXED: Webcam Notifier enable/disable was broken
    • FIXED: BSOD caused by race condition in driver
    Download
    http://test.hitmanpro.com/hmpalert3b166.exe

    Please let me know how this version runs on your computer :thumb:
     
  2. guest

    guest Guest

    Nice,

    I'll give it a try.
     
  3. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I'm installing now. Will report back if I have any problems.

    Edited 3/10 @ 7:51: I installed HMPA as a new install. I did not update to build 166, and I installed to an image that had never had HMPA installed on it before.
     
    Last edited: Mar 10, 2015
  4. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    :thumb: Restarted and up and running great here, Erik.

    Thanks,
    Dave
     
  5. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Just so you know NOD 32 flagged the installation 3 times as a potentially unsafe application. Below is the log files from NOD 32.


    3/10/2015 6:42:57 PM Real-time file system protection file C:\Windows\system32\drivers\hmpnet.sys a variant of Win64/NetFilter.A potentially unsafe application WatchTower-5\achilles
    Event occurred on a new file created by the application: C:\Users\achilles\Downloads\hmpalert3b166.exe.

    3/10/2015 6:42:58 PM Real-time file system protection file C:\Windows\system32\drivers\hmpnet.sys a variant of Win64/NetFilter.A potentially unsafe application NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Online Armor\oasrv.exe.

    3/10/2015 6:43:00 PM Real-time file system protection file C:\Windows\TEMP\UDD10D.tmp a variant of Win64/NetFilter.A potentially unsafe application NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\Windows\System32\svchost.exe.
     
  6. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,750
    Location:
    EU
    Installed over the top of build 155. No issues so far, however after the restart the first time the tray icon was missing.
    Win7 64 Ult.

    edit: No beep from NOD32 AV on this machine.
     
  7. LagerX

    LagerX Registered Member

    Joined:
    Apr 16, 2008
    Posts:
    565
    Updated over 155 (W8.1 x64). No issues so far.

    Had strange BSOD's lately. Hope it's fixed/was caused by HMPA.
     
  8. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I tried to activate my license key instead of using the trial, and I keep getting a server error. The only entry I could find that might be related in window's event viewer said check for update failed. Try again in 120 minutes. This entry was recorded before I tried to activate my license though. Maybe you are having server issues, or maybe something else is going on. I'm using Windows 7x64 Ultimate.
     

    Attached Files:

    Last edited: Mar 10, 2015
  9. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    Installed over build 155 no issues so far..
     
  10. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I just clicked on Windows Media Player, and got the welcome screen you get when you run Windows Media Player for the fist time. I had to reconfigure all of my settings for Windows Media Player. I looked in Windows update history, and it did not list any update for Windows Media Player. Has anyone else experienced this after installing, or updating to the latest build? I'm using Windows 7x64 Ultimate.

    Edited 3/11 @2:31 am: I rolled my machine back to a time before ever installing HMPA. Windows Media Player still gave me the intro screen you get when you run Windows Media Player for the first time. We can eliminate HMPA as the cause now. It was just a coincidence. It had to have been caused by an update released by Microsoft since several other users are reporting the same thing.
     
    Last edited: Mar 11, 2015
  11. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I think there is definitely a conflict with this build, and Online Armor firewall. Right after installing this build Windows reported that my firewall was turned off. It also disabled Online Armor Program guard, and anti-keylogger guard. That could account for all the other odd behavior I just posted about above. I'm using Windows 7x64 Ultimate.

    I got this event when installing HMPA from NOD 32. According to NOD 32 HMPA was attempting to do something with OA service driver. I'm not sure if this has anything to do with it, but I thought I would mention it in case it did.

    3/10/2015 6:42:58 PM Real-time file system protection file C:\Windows\system32\drivers\hmpnet.sys a variant of Win64/NetFilter.A potentially unsafe application NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Online Armor\oasrv.exe.
     

    Attached Files:

  12. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I just had Firefox crash when closing it. Firefox crashes every time I close it now. My computer is going nuts since installing HMPA build 166. I think it is probably due to a conflict between HMPA, and Online Armor. I did not have any problems with build 155 though. Below is crash info from mozilla bug reporter.

    AdapterDeviceID: 0x6719
    AdapterDriverVersion: 14.501.1003.0
    AdapterSubsysID: 0b001002
    AdapterVendorID: 0x1002
    Add-ons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20131118,fiddlerhook%40fiddler2.com:2.4.9.7,calomelsslvalidation%40calomel.org:0.74,%7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.9.17,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:36.0.1,%7Bd10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d%7D:2.6.7,%7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:5.0.12,firefox%40ghostery.com:5.4.3
    AvailablePageFile: 14791012352
    AvailablePhysicalMemory: 6533427200
    AvailableVirtualMemory: 3641425920
    BIOS_Manufacturer: American Megatrends Inc.
    BlockedDllList:
    BreakpadReserveAddress: 235864064
    BreakpadReserveSize: 67108864
    BuildID: 20150305021524
    CrashTime: 1426030400
    EMCheckCompatibility: true
    FramePoisonBase: 00000000f0de0000
    FramePoisonSize: 65536
    InstallTime: 1425914891
    Notes: AdapterVendorID: 0x1002, AdapterDeviceID: 0x6719, AdapterSubsysID: 0b001002, AdapterDriverVersion: 14.501.1003.0
    D2D? D2D1.1? D2D1.1+ D2D+ DWrite? DWrite+ D3D11 Layers? D3D11 Layers+
    ProductID: {ec8030f7-c20a-464f-9b0e-13a3a9e97384}
    ProductName: Firefox
    ReleaseChannel: release
    SecondsSinceLastCrash: 217
    ShutdownProgress: quit-application
    StartupTime: 1426030206
    SystemMemoryUsePercentage: 23
    Theme: classic/1.0
    Throttleable: 1
    TotalPageFile: 17159340032
    TotalPhysicalMemory: 8580620288
    TotalVirtualMemory: 4294836224
    URL: https://www.wilderssecurity.com/
    User32BeforeBlocklist: 1
    Vendor: Mozilla
    Version: 36.0.1
    Winsock_LSP: MSAFD Tcpip [TCP/IP] : 2 : 1 : %SystemRoot%\system32\mswsock.dll
    MSAFD Tcpip [UDP/IP] : 2 : 2 :
    MSAFD Tcpip [RAW/IP] : 2 : 3 : %SystemRoot%\system32\mswsock.dll
    MSAFD Tcpip [TCP/IPv6] : 2 : 1 :
    MSAFD Tcpip [UDP/IPv6] : 2 : 2 : %SystemRoot%\system32\mswsock.dll
    MSAFD Tcpip [RAW/IPv6] : 2 : 3 :
    RSVP TCPv6 Service Provider : 2 : 1 : %SystemRoot%\system32\mswsock.dll
    RSVP TCP Service Provider : 2 : 1 :
    RSVP UDPv6 Service Provider : 2 : 2 : %SystemRoot%\system32\mswsock.dll
    RSVP UDP Service Provider : 2 : 2 :
    useragent_locale: en-US

    This report also contains technical information about the state of the application when it crashed.
     

    Attached Files:

  13. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Yep, had that too!
     
  14. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I'm glad i'm not the only one. When your the only one experiencing problems it makes it look like your computer is the problem. It should make it easier to discover the problem.
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I just reboot for a third time, and Online Armor firewall is working again now. Online Armor Program Guard, and anti-Keylogger guard is working again also. Firefox has also stopped crashing when closing it.

    Edit: Btw.. I installed HMPA as a new install. I did not update, and I installed to an image that had never had HMPA installed on it before.
     
  16. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  17. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    Same here...
     
  18. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    The link you posted is no good. I checked my update history from today's updates, and I did not find anything listed for Windows Media Player.
     
  19. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Firefox is no longer crashing for me, but maybe it will start again later. It did not happen until installing build 166. I did not have any problems with build 155 other than the blue protection border not disappearing around Media Player Classic. The Firefox crash could have something to do with the Online Armor, and HMPA conflict I experienced when installing this build. I had a serious conflict between the two as described in my previous post. Online Armor, and HMPA both inject into Firefox. Online Armor injects into almost everything, and HMPA injects into quite a bit also.
     
  20. Cactus5

    Cactus5 Registered Member

    Joined:
    Jan 17, 2015
    Posts:
    28
    Location:
    Southwest USA
    This WMP problem can't be related to the new HMP.A. I haven't updated to build 166 yet and I just opened WMP and got the Welcome Screen and it took me though things like it was the first time I used it. Same behavior on all 3 of my Win7 x64 computers running HMP.A b155. There must have been something in the updates from MS today.
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Woops!

    I just got this DEP alert when I closed Firefox 36.0.1.

    Code:
    Log Name:      Application
    Source:        HitmanPro.Alert
    Date:          11/03/2015 12:25:03 PM
    Event ID:      911
    Task Category: (9)
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      Dave-PC
    Description:
    Mitigation   DEP
    
    Platform     6.1.7601/x64 06_25
    PID          352
    Application  C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Description  Firefox 36.0.1
    
    IP = 00000000,
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="HitmanPro.Alert" />
        <EventID Qualifiers="0">911</EventID>
        <Level>2</Level>
        <Task>9</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2015-03-11T01:25:03.000000000Z" />
        <EventRecordID>6900</EventRecordID>
        <Channel>Application</Channel>
        <Computer>Dave-PC</Computer>
        <Security />
      </System>
      <EventData>
        <Data>C:\Program Files (x86)\Mozilla Firefox\firefox.exe</Data>
        <Data>DEP</Data>
        <Data>Mitigation   DEP
    
    Platform     6.1.7601/x64 06_25
    PID          352
    Application  C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Description  Firefox 36.0.1
    
    IP = 00000000,</Data>
      </EventData>
    </Event>
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I had a bit of a start. Did my typical upgrade, and it seemed fine. Rebooted as normal, and then tried a scan. It failed. Tried several times. Then looked at the event viewer..nothing. Appcrash... nothing. So I rebooted, and then the scan went fine.
     
  23. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    Any word if it's compatible with Sophos Endpoint Security yet?

    Before it was unusable with it! I'm afraid to test it as it caused severe system instability.
     

    Attached Files:

  24. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I'm still unable to activate my product key. I still get the same server error message I reported in post 4358.
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Just curious. Don't you take any system images. That would solve any instability problems.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.