HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    Me and a lot of other people had this problem because of our custom DNS settings.
    If you are using OpenDNS, it is problematic.
    Use Google DNS, or just set your system and router at default DNS
     
  2. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    I just noticed that 3.6.5.592 is the latest release posted on the HitmanPro download website. HMPA already auto-updated to 3.6.6.593.
     
  3. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    I had to pull the plug on OpenDNS. Ever since switching to Google Public DNS [8.8.8.8] [8.8.4.4] have not had any issues ... https://developers.google.com/speed/public-dns/
     
  4. guest

    guest Guest

    The changelog is showing build 592, but the download is build 593. The changelog lags behind :)
     
  5. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Getting alert whenever I visit Flickr (photo sharing) with HMPA 3.6.7 602. Not sure if they have been hacked or F.P.
    Also noticed that since I emptied CryptoGuard folder (had 18 files) it has remained empty. CryptoGuard was re-enabled.
     

    Attached Files:

  6. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    That was it Tinstaafl! OpenDNS strikes again. After changing my router's DNS address to Google Public DNS addresses, no problems downloading from Hitmanpro.com. Thanks!
     
  7. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Glad to hear you got it sorted out. I have been on and off Google DNS a few times, but I have yet to find something that works better. Always end up back there!

    Kind of scary that OpenDNS has been having these issues for weeks now, considering that they are owned by Cisco now...
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,257
    Location:
    Among the gum trees
  9. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
  10. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Dear Erik,

    False Alert running wipe program:
    I got the following error with Wipe when doing a deletion file with Gutman method.
    Check the attached file

    It's safe : ~ Removed VirusTotal Results as per Policy ~
     

    Attached Files:

    Last edited by a moderator: Jun 8, 2017
  11. guest

    guest Guest

    This is no false alert and CryptoGuard is working as intended.
    Temporarily disable CryptoGuard before you are going to securely deleting files:
     
    Last edited by a moderator: Jun 8, 2017
  12. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    @Ashanta:
    Not a false alert, but expected behavior.
    Temporary disable crypto-gard, if you want to shred.
     
  13. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,870
    Location:
    the Netherlands
    Hi Ashanta,
    That was not a false positive, but a consequence of what WipeFile does and what CryptoGuard is meant to prevent.
    If you like to use WipeFile or similar to shred files or folders, first disable CryptoGuard, then shred what you like, and after that re-enable CryptoGuard.

    This is related to what Erik said, on April 1, 2015,
     
  14. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
  15. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    By the way, where is the path of the blocked files ?
     
  16. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    HMPA Cryptoguard drops things into C:\Windows\CryptoGuard
     
  17. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Thank you.

    What's the files with alphanumeric names on this folder ?
     
  18. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    CryptoGuard proactively makes backup copies of certain files, so that it can roll them back if a real crypto attack occurs. You can safely ignore them.
     
  19. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
  20. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    that's strange o_O...
    Erik, is this expected?
     
    Last edited: Jun 12, 2017
  21. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,221
    Location:
    USA
    Are you saying that HMPA blocks and the problem is only that it doesn't alert?
     
  22. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    too much imagination/free interpretation (imo)...
    No reaction = Alert seems to be blind (maybe PoC is not working properly or Alert interfer with its expected flow??)..
     
    Last edited: Jun 12, 2017
  23. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    Anybody here running HMP.A (and maybe other security measures) with no AV such as Kaspersky, Norton, etc.?
     
  24. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,386
    With Windows Defender enabled or disabled?
     
  25. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Not on my main computer. But I do have another PC without HMPA, that I mostly use for home entertainment, where I switch off the realtime AV. In that case just relying on VoodooShield and Malwarebytes Anti-Exploit to protect it. I use the AV there only as an on-demand scanner.

    Since I have been testing VoodooShield, and now that I "get it", I think that maybe something like that combined with HMPA could be all you need. Assuming that your PC was really clean to begin with. The concept of only allowing whitelisted executables to run seems bulletproof to me. Pure prevention! Plus with HMPA or something like that watching your back for anything sneaky you're probably ok! :thumbd:

    But YMMV, so assume at your own risk! :D
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.