Hitman pro fasle positives again?

Status
Not open for further replies.

siles

New Member
Thread author
Apr 2, 2017
1
Hitmanpro detects these keys as trojan/fakeAV
Malware remnants ____________________________________________________________

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)

But after delete and a restart from Hitman, these are still present/redetected
Bitdefender Total Security, Malware Bytes Premium, ESET and Kaspersky detect nothing!
Also Hitmanpro doesn't detect anything in safe mode or in quick scan mode
Please help!
 

Attachments

  • HitmanPro_20170402_2012.log
    5.1 KB · Views: 397

Rodger Dodger

New Member
May 21, 2017
1
I've been a very happy Hitman Pro user for 6-7 years. Perhaps longer. Never had a single issue using it as my secondary malware protection tool. Then about two weeks ago I started having problems with several completely safe, licensed commercial products I also run on my 64 bit, Windows 10 PC. System Mechanic won't stay resident; nor would Win Patrol (been using this product for 15 years!). Then yesterday I started looking closely at what Hitman Pro (I was running the latest available version) was diagnosing as malware. I immediately noticed a false positive message on my latest Hitman Pro scan list about Heimdal Pro, my primary malware protection tool after Windows Defender. Hitman Pro arbitrarily deleted one Heimdal Pro executable file and marked other files for deletion next reboot. Despite my desire to override. I had not looked at Hitman Pro scan results for along time, probably years. Mainly out of complete trust of the company who built it, Surfright. They saved my bacon several times!

But now Sophos owns the product and things seem to have changed. The issues I was having were all traced to actions recorded in Hitman Pro history log. I've since reinstalled System Mechanic, Win Patrol and Heimdal Pro and uninstalled Hitman Pro. Though I have 3 years left on my license. I've also opened a Sophos support ticket though in candor, I'm not holding my breath.

I'm wondering whether others have had similar experience lately? Has Sophos been responsive?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top