HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. szepeviktor

    szepeviktor Registered Member

    Joined:
    Jan 10, 2017
    Posts:
    10
    Location:
    Budapest, HUNGARY
    Originally CCleaner, now Win10 control panel.
     
  2. lawdude

    lawdude Registered Member

    Joined:
    Sep 20, 2015
    Posts:
    41
    Thinking about cloning my HDD to an SSD. Will hmp.a work or will I need to have license updated?
     
  3. guest

    guest Guest

    Your license is tied to the hardware and it can happen that HMP.A is showing "your license is not valid anymore" after you have exchanged your HDD with an SSD.
    If your license is invalid, write to the support or send a PM to @erikloman
     
  4. lawdude

    lawdude Registered Member

    Joined:
    Sep 20, 2015
    Posts:
    41
    Thanks for replying mood. Yes, that was my concern. However, when I removed HDD and installed cloned Samsung SSD drive, hmp.a seems to function as before.
     
  5. Stef VDC

    Stef VDC Registered Member

    Joined:
    Jun 26, 2016
    Posts:
    1
    Location:
    Belgium
    @erikloman i tried to encrypt some documents with Kruptos 2 Professional but HitmanPro.Alert blocks it when only 2 or 3 files are done
    Mitigation CryptoGuard

    Platform 10.0.14393/x64 v574 06_3f
    PID 9248
    Application C:\Windows\explorer.exe
    Description Windows Verkenner 10

    Filename C:\Windows\explorer.exe

    C:\Users\Stef\Desktop\Nieuwe map\banded nissan.docx
    C:\Users\Stef\Desktop\Nieuwe map\AANKOOP PELLETS.xlsx
    C:\Users\Stef\Desktop\Nieuwe map\60 jaar getr.docx


    Process Trace
    1 C:\Windows\explorer.exe [9248]
    explorer.exe
    2 C:\Windows\System32\winlogon.exe [7704]
    C:\Windows\System32\WinLogon.exe -SpecialSession
    3 C:\Windows\System32\smss.exe [6272]
    \SystemRoot\System32\smss.exe 000000bc 0000007c C:\Windows\System32\WinLogon.exe -SpecialSession
    4 C:\Windows\System32\smss.exe [640]
    \SystemRoot\System32\smss.exe
    5 [4]

    Thumbprint
    20f00333e19359ac81a0ac9dd49f7dd31533f3379a6e57f78bada98b0b7c64cf
     
  6. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    That is the CryptoGuard feature doing its' job. You need to disable CryptoGuard before using your encrypting software, and then re-enable it when you're done :thumb:
     
  7. Fad

    Fad Registered Member

    Joined:
    Feb 25, 2009
    Posts:
    456
    Location:
    England
    I have 25MB of "stuff" in the Cryptoguard folder - will this folder be cleaned or emptied automatically at some point in the future ?

    I don`t know what the content of this folder is, I don`t encrypt anything and to my knowledge have had no alerts.
     
  8. Socio

    Socio Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    362
    FYI: I have found that it stops the error but also stops Hitman pro alert from functioning in the sandbox, no green box indicating encrypting while typing for example.

    If I enable software Hitman pro alert comparability then just hide the error message hitman pro alert functions normally, for now I wil live with the error message.
     
  9. guest

    guest Guest

    The Cryptoguard folder is part of the CryptoGuard feature. It can happen that files are placed in this folder even if you had no alerts.
    If this is the case and you see leftovers, you can clean the folder from time to time.
     
  10. Fad

    Fad Registered Member

    Joined:
    Feb 25, 2009
    Posts:
    456
    Location:
    England
    Thanks Mood, I`ll just add the folder to CCleaner for an occasional clear out.
     
  11. Paul R

    Paul R Registered Member

    Joined:
    Aug 5, 2014
    Posts:
    59
    Location:
    Bury, Lancashire
    Just installed an old game on Steam but I'm not able to run it, i keep getting the below, any ideas please?

    upload_2017-1-15_11-46-31.png
     
  12. guest

    guest Guest

    It seems that Steam is guarded (Mitigation Lockdown). Try to disable "Application Lockdown" for Steam.
    Edit: Steam dropped dxwebsetup.exe to the temporary directory and wanted to execute it. This was prevented from HMP.A (Application Lockdown)
     
    Last edited by a moderator: Jan 15, 2017
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Where are you getting the setup file from?
     
  14. Paul R

    Paul R Registered Member

    Joined:
    Aug 5, 2014
    Posts:
    59
    Location:
    Bury, Lancashire
    Nothing can run from temp without "admin priv" so i guess that doesn't help :) i cheated anyway and disabled HMPA while i played it .
     
  15. Telos

    Telos Registered Member

    Joined:
    Jul 26, 2016
    Posts:
    171
    Location:
    Frezhnacz
    HMP.A "Quickie" by cruelsister...
    https://youtu.be/mDQXK9U_8aE
     
  16. guest

    guest Guest

    According to the Process Trace (#2), the service of Steam executed a script "runasadmin.vdf", so with a high probability it tried to execute the file dxwebsetup.exe with admin rights in the next step.
    However, you already found a solution, problem solved :). But don't forget to enable HMP.A after playing ;)
     
  17. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    HitmanPro.Alert 3.6.3 Build 578 BETA

    Changelog (compared to 574)
    • Improved compatibility with third-party applications trying to modify our DLL in-memory
    • Improved compatibility with Turbo.net (or Spoon.net) applications
    • Improved Self Protection
    • Improved ROP exploit mitigation
    • Improved CryptoGuard
    • Added tamper protection to CryptoGuard minifilter
    • Added Hangul Word Processor to Software Radar
    • Fixed rare crash in Firefox caused by misaligned stack
    • Fixed compatibility with Trusteer Rapport on 32-bit browsers
    • Updated Network Filtering component
    • Updated Libpng library to latest version
    • Updated sqlite3 library to latest version
    Known Issues
    Overwatch still cannot start with this build. Please add Overwatch.exe to Exclude category in order to start Overwatch. We are still investigating.

    Notes

    This build is co-signed by Microsoft and is therefore suitable on Windows 10 with Secure Boot enabled.

    Download
    http://test.hitmanpro.com/hmpalert3b578.exe

    Please let me know how this build runs on your computer :thumb:
     
    Last edited: Jan 16, 2017
  18. @erikloman Does this Beta solve the loss of files as illustrated by the latest 'quickie' test by Cruel Sister?
     
  19. guest

    guest Guest

    The driver hmpnet.sys is not co-signed by Microsoft.
     
  20. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Oh crap. Thanks! Will solve it tomorrow.
     
  21. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Perhaps, we did make a few changes in CryptoGuard related to correlation ...
    While useful to some extend, the "quickie" test does not show how the samples get dropped on the system. The test merely tests a fraction of Alert's capabilities to prevent a system getting ransomed. CryptoGuard is the last line of defense. Exploit mitigations and Application Lockdown are earlier in an attack chain.
     
    Last edited: Jan 17, 2017
  22. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    I upgraded over 574 and after reboot 578 is running without issues (I have secure boot turned off) :thumb:
     
  23. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Is the beta build you posted co-signed or not? Time of the edit tells me you haven't yet. I'm just making sure. :)
     
  24. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    No, it's not.
    Expect a new build number, today.
    Be patient....
     
  25. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Thanks!
    He should have at least edited the post. But no harm done, as I read the later posts prior to the complete download of the installer. :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.