Announcement Banner
UNSOLVED

joe53

updated

11 years ago

J

joe53

5 Journeyman

•

5772 Posts

•

17269 Points

0

226616

May 25th, 2015 12:00

HitmanPro.Alert 3.x Review

I have previously reviewed hereabouts the free HitmanPro.Alert (HMPA) 2.0, and must say that after almost 2 years it has given me no grief on my Win 7 system. No slowdowns, no conflicts. Just to recap, it is a free tool that checks the browser integrity and alerts users when secure online banking and shopping is no longer guaranteed. At that time (2013), there were reports of possible conflicts with MBAE, and/or EMET, resulting in various problems, but as I don't use those programs, I did not see these glitches. Suffice it to say that I generally use security programs until they cause me grief - and version 2.0 never did.

It was with some trepidation that I decided to try out version 3.x. I was persuaded to do so because of a report from MRG Effitas (March, 2015) where HMPA 3.x compared favorably to both EMET and MBAE in preventing drive-by exploits and zero-day exploits. I would note that
1) these tests were sponsored by SurfRight, the vendor of HMPA 3, and
2) the paid version of HMPA only was evaluated.
www.mrg-effitas.com/.../MRG_Effitas_Real_world_exploit_prevention_test.pdf

That said, HMPA 3 is still available in a free version. It purports to offer protection that exceeds HMPA 2.  A comparison list between v2 and v3 can be seen here (including what is excluded in the free v3):
www.wilderssecurity.com/.../hmpa-version-comparison-png.246705

The free v3 adds
-keystroke encryption
- webcam notification of secret access
- network lockdown
- blocks malicious USB devices

The free v3 removes the CryptoGuard Ransomware protection present in v2.
Also excluded in the free version are:
- Exploit mitigations
- Process Protection
- Active system Vaccination
- On-demand Malware Detection and remediation

I tested v3 on a Win 7 sp1 Home Premium x64 desktop, fully up-to-date from MS and 3rd parties. I first uninstalled HMPA 2 (uneventfully) using the surfright uninstall tool from:
dl.surfright.nl/hmpalert-uninstall_x64.exe
Restarted the system.

Results:

1)Download: 3.87 MB, for version 3.0.41.187

2) Installation:

No bundled junkware to un-check.

Tried to decline the 30 day trial license -in essence I did not want to activate it, so as to experience the free version only. I was only offered the options to enter my license key, or to purchase. Well I had not been given a key, and I sure as heck wasn't going to purchase, so I closed the wizard, and restarted the PC.

Lo and behold, there the HMPA icon was in my notification tray. So it looks like I got the full trial monty after all. At least for the next 29 days, after which presumably it reverts to the free version, sans bells and whistles.

The first thing I try is to open IE 11. It opens promptly, with the familiar green fly-out tab from HMPA telling me all is well.

Next, I try to open Firefox 38.0.1. No joy!

An alert pops up to say FF was terminated to prevent execution of malicious code, and that I should scan my computer for malware. A first time for me! Asks me to scan with HitmanPro (HMP). At this point I am unsure which version of HMP this will run: the on-demand free scanner I already have, or the paid scanner built into HMPA 3 that might automatically delete whatever it finds? So I waffle, and open Opera. Seems ok.

Scans by MBAM Premium, Panda Free AV,  and Emsisoft are all clean. So I ran HitmanPro Free, from my taskbar. It found nothing. I ran it again from within HMPA. Again, nothing. But I note that my HitmanPro AV 30 day trial, which I had never activated before (waiting for the proverbial rainy day when something might actually be detected that would need deleting) was now activated, and counting down. Looks like I've wasted my (HMP) ammo.

And I still cannot get Firefox to open, even after a reboot. (Firefox is not my default browser, and I use very few extensions, apart from "NoScript" and "Ad-block plus". It has never failed to open in the past.

So I start disabling HMPA settings, to find the culprit. Turns out it is one of the 12 options in the "Exploit mitigation-Firefox" module. To be more specific, the "Enforce DEP" option, under "Memory Mitigations". Which is all Greek to me. And I can no longer sign in to to the Dell forums - I get an "incorrect credentials" message when I try using Firefox.

Other than that, HMPA 3 has had no discernable effect on my system. Nothing was added to my start menu, and only
the HMPA service "HITMANPRO.ALE" was added. No effect on my CPU usage, which remains at ~1%, and my "FreeCell" (perhaps the best arbiter of my system's performance) remains as snappy as ever. Opening/navigating  financial websites is not a problem.

That said, HMPA 3 has trashed my Firefox. I can still use it, but its home page is foreign to me. My few extensions are gone. I can't even access "about Firefox" to confirm my version.

I would add that SurfRight has no user-to-user forum as such to troubleshoot problems with HMP and HMPA. Just 2  incredibly long threads over at Wilders, which really is bush league. One gets the impression the developer is using this as a sort of beta venue for feedback. 

As always, I cannot vouch for the efficacy of this product in preventing exploits. Maybe it is great - but all I can document is the grief.

When my 30 day trial is over, I will be re-installing HMPA 2. (Or maybe not).