HitmanPro.Alert BETA

Discussion in 'other anti-malware software' started by erikloman, May 30, 2017.

  1. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Yes, same issue, issue has been addressed, I expect a new RC early next week.
    For now disable CookieGuard (during browser startup).
     
  2. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    Naam van toepassing met fout: hmpalert.exe, versie: 3.8.24.957, tijdstempel: 0x64412bb3
    Naam van module met fout: ntdll.dll, versie: 10.0.19041.3570, tijdstempel: 0xf0fc3229
    Uitzonderingscode: 0xc000000d
    Foutmarge: 0x00104ac4
    Id van proces met fout: 0x784
    Starttijd van toepassing met fout: 0x01da065250971f3c
    Pad naar toepassing met fout: C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
    Pad naar module met fout: C:\WINDOWS\SYSTEM32\ntdll.dll
     
  3. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Did it record a minidump by any chance?
    C:\Windows\minidump or in C:\Users\<UserID>\AppData\Local\CrashDumps
     
  4. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    Negative.
     
  5. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    Another one (no minidump either):

    Naam van toepassing met fout: hmpalert.exe, versie: 3.8.24.957, tijdstempel: 0x64412bb3
    Naam van module met fout: webio.dll, versie: 10.0.19041.3031, tijdstempel: 0xc9c79e26
    Uitzonderingscode: 0xc0000409
    Foutmarge: 0x000522fd
    Id van proces met fout: 0x778
    Starttijd van toepassing met fout: 0x01d9be091607fdc3
    Pad naar toepassing met fout: C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
    Pad naar module met fout: C:\WINDOWS\SYSTEM32\webio.dll
     
  6. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
  7. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
  8. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Can you download this sysinternals tool http://live.sysinternals.com/procdump.exe
    Create a folder c:\dumps, place the procdump.exe in there, open an administrative command-box and execute the command below:

    c:\dumps\procdump -ma -i c:\dumps\

    then reproduce the issue, this should record a memory dump of the crashing process.

    If you want you can reset your Just in time debugger
    procdump -u
     
  9. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    Do you want me to revert to build 957 beta or the latest beta 967?
     
    Last edited: Nov 18, 2023
  10. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    just stay on 967 and see if it records crashes, it just sits in the background and only kicks in when the windows crash handler has something to do.
     
  11. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    Will report back if a crash occurs. I should check the logs daily…
     
  12. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    No luck yet. I’ll let procmon run a couple of days.
     
  13. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    I hope you installed procdump ;)
     
  14. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    No worries.
     
  15. Garf99

    Garf99 Registered Member

    Joined:
    Oct 14, 2016
    Posts:
    14
    Location:
    USA
    HitmanPro.Alert 3.8.25 build 967, Windows 11 23H2, Luminar Neo software (Skylum) will not launch unless C2 interceptor is disabled
    Is there a way to disable specific mitigations per specific software?

    Thanks
     
  16. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    HitmanPro.Alert 3.8.25 Build 971 (RC3)

    Changelog (compared to 967)
    • Fixed CookieGuard False positive on "chrome.dll"
    • Fixed KernelTrap compatibility issues with Kaspersky and GenshinImpact
    • Improved KeyboardGuard compatibility with ESET protected browsers
    • Improved HeapHeapProtect tweaked a few things to reduce FP's
    Beware this build is signed with a new code-signing certificate by Sophos LTD, this might take some 3rd party vendors to have "trust" issues as it's a rather fresh certificate.

    Download
    https://dl.surfright.nl/hmpalert3b971.exe

    Please let us know how this version runs on your machine :thumb:
    We're planning to promote this build to Stable if results are good in the coming week(s).
     
  17. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Can you try this:
    https://support.hitmanpro.com/hc/en...nPro-Alert-is-installed-how-can-I-solve-this-

    And can you provide a download link for that software so we can see if we can reproduce and/or improve something in this scenario.
     
  18. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,271
    No problems upgrading build 971. I'll report back if a crash should occur.
     
  19. Garf99

    Garf99 Registered Member

    Joined:
    Oct 14, 2016
    Posts:
    14
    Location:
    USA
    HitmanPro.Alert 3.8.25 build 965
    Download Link:
    https://skylum.com/luminar-download

    As for exclusions, I meant is it possible to exclude a specific mitigation (c2 in this case) per app,
    Also, if I try to exclude a UWP app, HMPA (just updated to 971) populates it with a very short partial list - not all my UWP apps (shows Windows settings and a few other Windows components)

    Thanks
     
  20. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    327
    2023-11-22_190202.jpg
    Is it so properly protected?
     
  21. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    If you open the logger then switch to the browser and start typing there, the keystrokes should show up scrambled bottom right in the orange bar around the browser.
    And in the logger they should not be clear text. Unless you have ESET installed then it's up to ESET to protect you on that.
     
  22. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Thanks we'll have a look as to why this happens.
    There are two scenario's, we trigger an alert on an application that one you can solve by using the suppressed alert (which is way tighter then just disabling the full protection against the offending application).
    BUT if there are application crashes/won't load issues there is no way to "disable" a protection for that application because that won't solve the problem, 99 out of 100 cases the application conflicts in such a way that even implementing that option won't work, so we'll have to put it on exclusions for now (or disable C2 globally) depending on your risk level. We'll see if we need to make a code change or that it gets put on the incompatible list.
     
  23. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,924
    Location:
    Outer space
    Autoupdated from 967 yesterday, everything fine so far :thumb:
     
  24. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    683
    Location:
    Planet Earth
    Can you confirm this has improved and/or fixed?
     
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,392
    Location:
    Among the gum trees
    I don't send many emails now days, but in my very limited testing I haven't seen the garbled text with the latest build.

    Thanks.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.