App Review A Test of HitManPro Alert

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
cruelsister

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
849
Another program I bought in the past but now no longer use. I think ever since Sophos bought it it's gone downhill, plus I don't think the Lowman brothers work on Alert or Hitman Pro anymore. They were the main drivers behind surfright.nl and it's sad to see their products are not being developed to their full potential anymore.
 

Chuck57

Level 12
Verified
Top Poster
Well-known
Oct 22, 2018
590
I've used HMP as a second opinion for many years. I've always had a copy, either free or paid, on one of the computers I've had through the years. The software has always performed for me. This video shows a long standing weakness. Sophos apparently isn't interested in improving the product.
 

dinosaur07

Level 12
Verified
Top Poster
Well-known
Aug 5, 2012
577
Still, it offers strong protection for mixed malware. It is indeed very rare to run a lot of malware on a single machine. I am still believing in this solution onwards. I will try to avoid worms 🙃 or I (delusionally) hope that the other solution i use will defend my PC from getting infected with what HMPA might be circumvented.
 
F

ForgottenSeer 95367

Here is all the "Context" that you need to know:

HMPA does have a "library" of known malicious command lines. However, it trusts WScript and Java by default. Along came The Girl with the Microphone, and... Voila!!
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
However, it trusts WScript and Java by default
Actually, no, it does not. As can even be seen in the video HMPA does stop the malicious activity from the JAR ransomware run, and it will also detect malware coded as js or jse. But detection and proterction will vary depending on the mechanism which the malware uses, and the same is true for vbs malware.

If there was such a default allow for various extensions (which there is not) the product would be utterly worthless.
 
Last edited:
F

ForgottenSeer 95367

Actually, no, it does not. As can even be seen in the video HMPA does stop the malicious activity from the JAR ransomware run, and it will also detect malware coded as js or jse. But detection and proterction will vary depending on the mechanism which the malware uses, and the same is true for vbs malware.

If there was such a default allow for various extensions (which there is not) the product would be utterly worthless.
HMPA is a default-allow product. I didn't say it was default-allow by extension. Anything beyond its ability to detect sails right on by - playing with the mechanisms as it were - as you so aptly demonstrated.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top