<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; hitman pro</title> <atom:link href="http://www.ghacks.net/tag/hitman-pro/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Hitman Pro Review and Giveaway [Ghacks Christmas Giveaway]</title><link>http://www.ghacks.net/2010/12/14/hitman-pro-review-and-giveaway-ghacks-christmas-giveaway/</link> <comments>http://www.ghacks.net/2010/12/14/hitman-pro-review-and-giveaway-ghacks-christmas-giveaway/#comments</comments> <pubDate>Tue, 14 Dec 2010 07:25:58 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[ghacks Christmas giveaway]]></category> <category><![CDATA[hitman pro]]></category> <category><![CDATA[malware scanner]]></category> <category><![CDATA[windows software]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37935</guid> <description><![CDATA[There is no perfect security software on the market. If you look at reviews and tests of security software you may notice that the tests come to the conclusion that security software a manages to eliminate or stop 99.9% of all malware and spam. Guess what, that means that every 1000th attack slips right through [...]]]></description> <content:encoded><![CDATA[<p>There is no perfect security software on the market. If you look at reviews and tests of security software you may notice that the tests come to the conclusion that security software a manages to eliminate or stop 99.9% of all malware and spam. Guess what, that means that every 1000th attack slips right through the defenses.</p><p>What&#8217;s the best way to protect the system then? Making sure that security solutions stack up to protect the system, and of course to avoid unnecessary risks on the Internet.</p><p><a
href="http://www.surfright.nl/en/hitmanpro/">Hitman Pro</a> is a program that comes into play when you want to test that defense, or suspect that your computer has been infected with malicious software but your regular antivirus solution cannot find it. Even better, Hitman Pro is compatible with any security solution already installed which cannot be said automatically for running two antivirus apps side by side.</p><h2>Hitman Pro Review</h2><p>Hitman Pro offers two options during installation. It is possible to install the program normally on the PC to use it on a regular basis or perform a one-time scan of the system that does not require installation at all. Very handy to quickly check an already infected system.</p><p>Hitman Pro does not run in the background all the time even if it is installed. The security software runs a scan of the system, reports the results and closes down after everything has been handled. The scan itself takes a few minutes the most, depending on the speed of the hard drive and the overall performance of the computer. A typical scan on my fast solid state drive took less than a minute to complete.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/hitman-pro-550x436.jpg" alt="hitman pro" title="hitman pro" width="550" height="436" class="alignnone size-medium wp-image-37936" /></p><p>Hitman Pro combines a behavioral scan with cloud computing. Suspicious programs found during the scan are automatically submitted to the cloud where they are tested with five different antivirus engines. The engines used are<br
/> by the companies Dr.Web, Ikarus, Emsisoft, Prevx and G Data.</p><p>The cloud then reports back to the computer with the results of the scan. Hitman Pro can remove viruses and other malicious software from the system. Each item and the user&#8217;s action is recorded in the History with options to remove them completely or restore them if needed.</p><p>The program is super-easy to use, simplicity by design one could say. The first screen offers to perform a scan, close the program or open the settings. A quick scan and standard scan is available, and a click on the little down icon next to the Next button will reveal the selection.</p><p>The settings can be used to configure some aspects of the program. Here it is possible to configure a daily scan on computer startup (postponed until the hard disk activity nears the idle state), enable a Scan with Hitman Pro entry in Windows Explorer, configure connection and proxy settings and enter the license code if the program has been purchased or won.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/hitman-pro-review-550x436.jpg" alt="hitman pro review" title="hitman pro review" width="550" height="436" class="alignnone size-medium wp-image-37937" /></p><p>The Hitman Pro download weights in under 7 Megabytes which is small compared to other antivirus solutions which nowadays come near or over of 100 Megabytes easily.</p><p>But how does Hitman Pro handle infections in detail? That depends on the infected file. Non-critical files that are infected are marked for deletion right away, while critical files like core Windows files are handled differently.</p><p>First, Hitman Pro tries to find an uninfected copy of the file on the system. If it finds one it exchanges the file with the infected one on reboot and cleans the infected file from the system. If no safe copy of an infected file is found Hitman Pro asks the user to insert a Windows CD or DVD to replace it. This means you will never end up with a non-booting copy of Windows because a core system file has been removed by the antivirus solution.</p><blockquote><p>When the file is classified as malicious by the Scan Cloud, the Hitman Pro client is placing the infection into quarantine. Various techniques ensure that all infections are completely removed without false positives.</p><p> Close handles (e.g. unload DLL from winlogon)<br
/> Close processes (e.g. winlogon stays)<br
/> Remove object from disk<br
/> Schedule object removal using PendingFileRenameOperations<br
/> Remove references like shortcuts and registry entries<br
/> Restore standard registry keys to default values (e.g. Userinit)<br
/> Disable service drivers<br
/> Deploy native NT bootdelete to remove resilient disk objects<br
/> After reboot retry removal and rescan to ensure complete removal</p><p>White Listing</p><p>It is a huge problem when anti virus programs remove legitmate files from the computer (false positives). Especially in the case of Windows system files, it could lead to parts of the computer to malfunction. Most anti virus vendors have experience with such a horror scenario. To prevent this, Hitman Pro 3 contains a large white list with &#8220;Hashes&#8221; of these legitimate files. Hitman Pro 3 has a white list of standard installations of Windows 2000 to Windows 7, Office 2000 to 2007 and all updates and services packs.</p></blockquote><h3>Hitman Pro Video Review</h3><p><iframe
title="YouTube video player" class="youtube-player" type="text/html" width="500" height="405" src="http://www.youtube.com/embed/WmPQOjra244" frameborder="0"></iframe></p><h3>Hitman Pro Verdict</h3><p>Everyone can use Hitman Pro. That&#8217;s excellent, especially combined with the fact that the application can be run without having to be installed first. It is ideal for those cases where a family member of friend calls you to help with a virus infection on a computer.</p><p>Hitman Pro offers additional security next to standard antivirus software that runs all the time on the computer system. The software is lightweight and uses five different antivirus engines to verify suspicious files in the cloud.</p><p>The &#8220;second opinion malware scanner&#8221; is available as a 32-bit and 64-bit edition for Windows operating systems. It supports all Windows versions from Windows XP up to Windows 7.</p><h3>Hitman Pro Giveaway</h3><p>We have ten Hitman Pro licenses to giveaway. Please post your current security setup in the comments for a chance to win one of the licenses. Users who want to test their system right away with Hitman Pro can download a fully functional version from <a
href="http://resellers.hitmanpro.com/7804777/HitmanPro35.exe">here</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/14/hitman-pro-review-and-giveaway-ghacks-christmas-giveaway/feed/</wfw:commentRss> <slash:comments>209</slash:comments> </item> <item><title>How To Detect A 64-bit Alureon Rootkit Infection</title><link>http://www.ghacks.net/2010/09/01/how-to-detect-a-64-bit-alureon-rootkit-infection/</link> <comments>http://www.ghacks.net/2010/09/01/how-to-detect-a-64-bit-alureon-rootkit-infection/#comments</comments> <pubDate>Wed, 01 Sep 2010 09:23:59 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[hitman pro]]></category> <category><![CDATA[rootkit]]></category> <category><![CDATA[tdl]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=33799</guid> <description><![CDATA[Alureon, or TDL, TLD3 and Tidserv, is the first rootkit that can infect 64-bit Windows PCs. Before that, only 32-bit systems were affected by rootkits, and many Windows users realized that in February, when Microsoft patch MS10-015 caused infected machines to display a blue screen. It obviously was not Microsoft&#8217;s fault back then, which was [...]]]></description> <content:encoded><![CDATA[<p>Alureon, or TDL, TLD3 and Tidserv, is the first rootkit that can infect 64-bit Windows PCs. Before that, only 32-bit systems were affected by rootkits, and many Windows users realized that in February, when Microsoft patch MS10-015 caused infected machines to display a blue screen. It obviously was not Microsoft&#8217;s fault back then, which was first assumed by professionals and users alike. It turned out after some research that the TLD3 rootkit was responsible for that behavior.</p><p>The developers of the rootkit have improved it considerably since then, and managed to add the ability to infect 64-bit Windows systems. That&#8217;s a first, and security vendors are alarmed about that trend.</p><blockquote><p>However, the authors of these attacks have not been resting. Just under a month ago, we became aware of a new variant of Alureon that infects the Master Boot Record (MBR) instead of an infected driver.  While this new variant did not affect 64-bit machines, it had an inert file called ldr64 as part of its virtual file system.  More recently, we discovered an updated variant that successfully infected 64-bit machines running Windows Vista or higher, while rendering 64-bit Windows XP and Server 2003 machines unbootable.</p></blockquote><p>Many security companies have already added detection of the 64-bit variant to their security applications, Microsoft for instance added signatures to Microsoft Security Essentials in the beginning of August.</p><p>Still, Windows 64-bit owners may want to verify for themselves that the rootkit is not installed on their operating system. As the information above suggest, Windows XP and Windows Server 2003 owners will immediately notice that something is wrong, as their operating system will fail to boot. Windows Vista or Windows 7 64-bit users should read on.</p><p>There are at least two options to do that, all with tools already included in the operating system:</p><blockquote><p>Open a command prompt, with Windows-R, entering cmd and enter.</p><p>Use the command <strong>diskpart</strong> to open Diskpart in a new command line window.</p><p>Enter <strong>lis dis</strong> in the new prompt, if it remains empty the computer is infected with the rootkit. If the disks display, it is not.</p></blockquote><p><strong>Good</strong></p><div
id="attachment_33800" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/windows-64-bit-rootkit-detection.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/windows-64-bit-rootkit-detection-500x252.png" alt="windows 64 bit rootkit detection" title="windows 64 bit rootkit detection" width="500" height="252" class="size-medium wp-image-33800" /></a><p
class="wp-caption-text">windows 64 bit rootkit detection</p></div><p><strong>Bad</strong></p><div
id="attachment_33801" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/diskpart.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/diskpart-500x255.png" alt="diskpart" title="diskpart" width="500" height="255" class="size-medium wp-image-33801" /></a><p
class="wp-caption-text">diskpart</p></div><blockquote><p>The second option to detect the 64-bit rootkit is the following: Launch Disk Management from the Computer Management pane.</p><p>If it does not show disks, it means the system is infected with the rootkit. If it shows disks, everything is fine.</p></blockquote><p><strong>Infected System</strong></p><div
id="attachment_33802" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/al64-2.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/al64-2-500x355.png" alt="al64-2" title="al64-2" width="500" height="355" class="size-medium wp-image-33802" /></a><p
class="wp-caption-text">al64-2</p></div><p>Additional information are available at <a
href="http://blogs.technet.com/b/mmpc/archive/2010/08/27/alureon-evolves-to-64-bit.aspx">Technet</a> and <a
href="http://www.symantec.com/connect/blogs/tidserv-s-boot-methods">Symantec</a>.</p><p><strong>How to Remove the Rootkit if the system is infected:</strong></p><p>Several programs are able to remove the rootkit and repair the MBR so that the system boots normally after the repair.</p><p>Hitman Pro Beta 112 and later can do it for instance.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/01/how-to-detect-a-64-bit-alureon-rootkit-infection/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>Run Multiple Anti-Spyware Tools With Hitman Pro</title><link>http://www.ghacks.net/2008/09/17/run-multiple-anti-spyware-tools-with-hitman-pro/</link> <comments>http://www.ghacks.net/2008/09/17/run-multiple-anti-spyware-tools-with-hitman-pro/#comments</comments> <pubDate>Wed, 17 Sep 2008 19:54:44 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[antivirus]]></category> <category><![CDATA[hitman pro]]></category> <category><![CDATA[scan pc]]></category> <category><![CDATA[software program]]></category> <category><![CDATA[Spyware]]></category> <category><![CDATA[spyware scan]]></category> <category><![CDATA[virustotal]]></category> <category><![CDATA[windows scan]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7054</guid> <description><![CDATA[Virustotal is a great online service that provides access to more than 30 antivirus engines that can scan a file uploaded by the user. This gives the user a much deeper understanding if a file is malicious or not. Hitman Pro is a similar application with the difference that it is a local software program [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.virustotal.com">Virustotal</a> is a great online service that provides access to more than 30 antivirus engines that can scan a file uploaded by the user. This gives the user a much deeper understanding if a file is malicious or not. <a
href="http://www.surfright.nl/en/hitmanpro">Hitman Pro</a> is a similar application with the difference that it is a local software program that makes use of various anti-spyware programs which it downloads automatically to scan a computer.</p><p>Hitman Pro is making use of eight spyware scanning engines. It&#8217;s a mixture of free and trial versions. Among the software programs are popular spyware cleaners like Spybot Search and Destroy, Ad-aware and Webroot Spysweeper. Each application can be selected to be included in the system scan or excluded from it. Besides those eight engines can include the commercial antivirus applications TrendMicro Sysclean and McAfee Virusscan if the user has a license for those applications.</p><p>The options contain several additional interesting features that require some explanation. The user can select to use the Browser security plugins that is offered by some of the anti-spyware applications, install security updates and configure least user access levels for his web browser.</p><p><span
id="more-7054"></span><img
src="http://www.ghacks.net/wp-content/uploads/2008/09/hitman_pro-500x377.jpg" alt="hitman pro" title="hitman pro" width="500" height="377" class="alignnone size-medium wp-image-7055" /></p><p>The first run takes a bit longer than the future ones because all selected applications will be downloaded from the Internet. Hitman Pro is installing the automatically on the user system with minimal to no user input required. Once the applications have been downloaded the system scan begins. Each application is run after the other and the results are visible in the application itself and in Hitman Pro at the end.</p><p>This process can slow down the computer quite a bit and it is probably a good idea to let the scans run automatically and do something different in the meantime. One aspect that is not optimal is the fact that most of these anti-spyware tools run a permanent process even if the main application is not running.</p><p>This can create quite some noise in the background and experienced users might prefer to install and uninstall the applications manually instead. The idea itself is great however and it would have been really nice if Hitman would be able to use the scanning engines and definitions without having to install the software programs itself. That&#8217;s probably wishful thinking though.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/09/17/run-multiple-anti-spyware-tools-with-hitman-pro/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
