Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

HitmanPro.Alert CryptoGuard prevents files from being taken hostage


  • Please log in to reply
216 replies to this topic

#31 wcutler

wcutler

  •  Avatar image
  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 09:13 AM

wow - guess i should have waited some before posting.  This is a game changer the blocking of network shared drives on servers.

 

Is the event id always going to be 301?  We use kaseya and we could then monitor the event logs on the server for this id to notify us of an issue.

is anything be posted in the event logs on a workstation with this alert?



BC AdBot (Login to Remove)

 


#32 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 09:19 AM

got "Application failed to install. Error 0."  Also running Norton360 and CryptoPrevent....

 

What error is listed in the event log?



#33 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 09:21 AM

wow - guess i should have waited some before posting.  This is a game changer the blocking of network shared drives on servers.

 

Is the event id always going to be 301?  We use kaseya and we could then monitor the event logs on the server for this id to notify us of an issue.

is anything be posted in the event logs on a workstation with this alert?

 

Yes. The CryptoGuard Alert will always be 301.

 

Alert running on the server will only post and event on the server. It will not post anything in the event log of the infected workstation.


Edited by erikloman, 22 November 2013 - 09:31 AM.


#34 wcutler

wcutler

  •  Avatar image
  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 09:58 AM

so if alert is running on a workstation it will not post anything to the event log when an attack is happening?  If this is true it would be nice if you could get something to post to the event log so people could monitor it.  Some users are not always forth coming in contacting us when there is a problem.

 

When the alert gets release (no more beta) will there be more info on how to install silently and how to install with no start menu program list?  Since we use kaseya, i would create a script to install it silently on peoples pc.

 

Thanks for posting and the updates  



#35 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 10:20 AM

so if alert is running on a workstation it will not post anything to the event log when an attack is happening?  If this is true it would be nice if you could get something to post to the event log so people could monitor it.  Some users are not always forth coming in contacting us when there is a problem.

 

When the alert gets release (no more beta) will there be more info on how to install silently and how to install with no start menu program list?  Since we use kaseya, i would create a script to install it silently on peoples pc.

 

Thanks for posting and the updates  

 

Alert will post an event to the computer it is running on. Imagine a network with hundreds of endpoints and a file server. Just install Alert on the file server and Alert will report in the Event Log of the server which endpoint is infected.

 

There are command line switches. Typical switches are:
 

hmpalert.exe /install /quiet

 

Or for uninstall:

 

hmpalert.exe /uninstall



#36 Joe_BubbA

Joe_BubbA

  •  Avatar image
  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 10:23 AM

 

^^^ you didn't really answer his question.

 

Which of his three questions?

 

1. is this for browsers only?

The Intruder feature is only for web browsers.

The CryptoGuard feature protects all documents and files on the computer.

 

2. Its it protecting/checking when browsers are not open?

The Intruder only works when the browser is open. Intrusions happening while browser is open, will be detected and an alert will be displayed. Intrusion is not blocked.

 

3. if the person gets an email and launches the malware, will the alert stop it?

No. Alert  will not blocked the infection. But Alert will block crypto attacks on the documents and files on the computer. 

 

So, if the user has Alert installed but has no browsers open and then opens an infected attachment in outlook, Alert will not stop encryption of files?



#37 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 10:27 AM

So, if the user has Alert installed but has no browsers open and then opens an infected attachment in outlook, Alert will not stop encryption of files?

 

 

Alert's CryptoGuard is a system-wide real-time feature that will block encryption of files. Even when no browsers are open. In fact, browsers are totally unrelated to CryptoGuard.


Edited by erikloman, 22 November 2013 - 10:28 AM.


#38 Joe_BubbA

Joe_BubbA

  •  Avatar image
  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 10:32 AM

 

So, if the user has Alert installed but has no browsers open and then opens an infected attachment in outlook, Alert will not stop encryption of files?

 

 

Alert's CryptoGuard is a system-wide real-time feature that will block encryption of files. Even when no browsers are open. In fact, browsers are totally unrelated to CryptoGuard.

 

Perfect.  Thanks!


Edited by Joe_BubbA, 22 November 2013 - 10:33 AM.


#39 Joe_BubbA

Joe_BubbA

  •  Avatar image
  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 10:36 AM

 

got "Application failed to install. Error 0."  Also running Norton360 and CryptoPrevent....

 

What error is listed in the event log?

 

Event 201:  Application failed to install

Event 7009:  A timeout was reached (30000 milliseconds) while waiting for the HitmanPro.Alert Service service to connect.

Event 7000:  The HitmanPro.Alert Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion

 

Edit:  After a reboot, seems to be working...At least I got the banner message...


Edited by Joe_BubbA, 22 November 2013 - 10:43 AM.


#40 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 10:43 AM

 

 

got "Application failed to install. Error 0."  Also running Norton360 and CryptoPrevent....

 

What error is listed in the event log?

 

Event 201:  Application failed to install

Event 7009:  A timeout was reached (30000 milliseconds) while waiting for the HitmanPro.Alert Service service to connect.

Event 7000:  The HitmanPro.Alert Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion

 

 

Do you have a tool installed that is blocking the installation?



#41 Joe_BubbA

Joe_BubbA

  •  Avatar image
  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 November 2013 - 10:47 AM

 

 

 

got "Application failed to install. Error 0."  Also running Norton360 and CryptoPrevent....

 

What error is listed in the event log?

 

Event 201:  Application failed to install

Event 7009:  A timeout was reached (30000 milliseconds) while waiting for the HitmanPro.Alert Service service to connect.

Event 7000:  The HitmanPro.Alert Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion

 

 

Do you have a tool installed that is blocking the installation?

 

Just CryptoPrevent, but that would create an event in event log...


Edited by Joe_BubbA, 22 November 2013 - 10:48 AM.


#42 Fardooste

Fardooste

  •  Avatar image
  • Members
  • 108 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 22 November 2013 - 10:57 AM

Sweet tool thanks! 



#43 desertpenguin

desertpenguin

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:05:19 PM

Posted 22 November 2013 - 02:37 PM

thanks for this tool, I just tried it out, installs fine on local machines but when intsllating it on my Windows 2008R2 file server it caused a BSOD within 5 minutes (no reboot) so i had to uninstall it, will try some further testing later - do you have any details on how this actually works ? what defines a file as being 'encrypted'? what at the performance impacts of this on a file server?



#44 boopme

boopme

    To Insanity and Beyond


  •  Avatar image
  • Helper Emeritus
  • 85,296 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:19 AM

Posted 22 November 2013 - 02:47 PM

I see that CG supports Windows 8, XP, Vista and 7 (32-bit and 64-bit).
http://www.surfright.nl/en/cryptoguard
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#45 erikloman

erikloman

    Authorized SurfRight Rep

  • Topic Starter

  •  Avatar image
  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:19 AM

Posted 22 November 2013 - 02:49 PM

thanks for this tool, I just tried it out, installs fine on local machines but when intsllating it on my Windows 2008R2 file server it caused a BSOD within 5 minutes (no reboot) so i had to uninstall it, will try some further testing later - do you have any details on how this actually works ? what defines a file as being 'encrypted'? what at the performance impacts of this on a file server?


Oh that is unfortunate. Can you send me the minidump in C:\Windows\Minidump to erik(at]surfright.com ?




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users