HitmanPro Review 2026: Best Second-Opinion Scanner?
HitmanPro is an active, focused Windows cleanup scanner. Alert adds real-time defenses, but neither has current direct major-lab results.

Our verdict: HitmanPro is one of the better actively maintained Windows second-opinion scanners: download it, run it without a conventional installation, scan beside Microsoft Defender or another antivirus, and use the 30-day no-card trial for cleanup. Current build 346 shipped February 5, 2026 with Chromium PUA-extension removal, hardening and ARM fixes. It isn't continuous protection and shouldn't replace a primary antivirus. HitmanPro.Alert is the separate installed product; current build 2059 adds always-on anti-malware, CryptoGuard ransomware response and exploit/risk-reduction layers. Alert is distinctive, but no current direct result was found for either product in AV-TEST, AV-Comparatives or SE Labs. Buy the scanner only if you want recurring access after the trial; choose Alert only after a compatibility test. Editorial score: 7.0/10.
- Current 2026 scanner and Alert builds
- Runs beside an existing antivirus
- Small scanner can run without full installation
- 30-day trial without a credit card
- PUA, persistent malware and damaged-resource cleanup focus
- Alert adds distinctive CryptoGuard and exploit mitigations
- Regular HitmanPro has no real-time shield
- No current direct major-lab score found
- Official “four labs” copy names only SophosLabs
- One-PC licensing and separate product keys
- Alert can conflict with browsers, games or other security hooks
- Windows-only consumer products
HitmanPro and Alert are actively developed in 2026
HitmanPro isn't a dead SurfRight relic. Sophos still sells it under the HitmanPro name, hosts separate downloads/support and publishes engineering release notes. Scanner build 346 shipped February 5, 2026. Alert build 2059 shipped May 11, 2026 after two larger March/April updates.
SurfRight joined Sophos in 2015. The consumer products retain their own names and licenses, while current visuals/downloads increasingly use Sophos branding. The relevant status is active niche product, not legacy/EOL.
| Question | Verified answer | Decision impact |
|---|---|---|
| Latest scanner build found | 346 · Feb. 5, 2026 | Active maintenance and ARM/PUA fixes. |
| Latest Alert build found | 2059 · May 11, 2026 | Current always-on product; phased rollout possible. |
| Owner | Sophos (SurfRight joined 2015) | Official Sophos/HitmanPro channels only. |
| Platforms | Windows consumer products | No macOS, Android or iOS edition. |
| Direct current major-lab result | None found | Feature claims can't replace efficacy data. |
| Our score | 7.0/10, one editor | Strong niche utility with evidence limits. |
HitmanPro and HitmanPro.Alert are different products
HitmanPro is the on-demand scanner/cleaner. The official page describes a roughly 10 MB executable that can run after download without a conventional installation. You launch it when you want a second opinion or when an infection needs cleanup. It doesn't sit between the browser and every download.
HitmanPro.Alert installs because it continuously monitors activity. It includes HitmanPro scanning plus real-time anti-malware, CryptoGuard, exploit mitigation, web/banking, keystroke/webcam and risk-reduction layers. Alert has its own installer and license.
| Capability | HitmanPro | HitmanPro.Alert |
|---|---|---|
| Primary role | On-demand second opinion/cleanup | Always-on layered protection |
| Installation | Can run directly after download/USB | Requires installation/service/driver |
| HitmanPro malware scan | Yes | Included |
| Real-time anti-malware | No | Yes |
| CryptoGuard ransomware response | No | Yes |
| Exploit/risk reduction | No | Yes |
| Compatibility risk | Lower; active only during scans | Higher; hooks/monitors protected apps |
| License | HitmanPro key | Separate Alert key |
The old page called the scanner an “antivirus” without consistently separating roles. That creates bad buying and testing advice. A product can be an excellent second-opinion cleaner while being the wrong only defense.

Most users should try the scanner, not buy Alert blindly
If a Windows PC behaves suspiciously, run current Defender/Microsoft Safety Scanner or another maintained primary tool, then HitmanPro as an independent second opinion. Its no-card trial makes a one-time cleanup decision low-friction. Keep logs and verify detections before deleting business/system files.
Alert is for a narrower user: someone who values behavior-based ransomware rollback, exploit mitigation and browser/credential hardening enough to add another always-on security driver. It can make sense beside Defender, but adding it to an already feature-heavy Bitdefender/Norton/ESET stack can duplicate hooks and raise compatibility/false-positive risk.
We don't recommend regular HitmanPro as the only antivirus. We also don't call Alert a proven replacement for a current lab-tested full suite. The vendor says it can run with other security software; that positioning is the safer default.
HitmanPro is optimized for fast triage and persistent-malware cleanup
The scanner focuses on behaviors, reputation and suspicious objects rather than installing a complete local signature stack. The vendor says it can find malware attached to legitimate resources, repair damaged Windows resources and inspect critical system/boot areas for persistent threats.
Build 346 added detection/removal of Chromium-based browser PUA extensions. That's practical: malicious or unwanted extensions can survive simple browser resets, change search/new-tab behavior, inject ads or retain enterprise policies. The build also shows the active disk-access mode in the title bar and hardens the scanner.
“Run without installation” doesn't mean no system changes during cleanup. A remediation tool may quarantine/delete files, alter persistence and repair resources. Create a backup/restore path, keep the log and don't let any scanner automatically remove a business-critical file without verification.
A short scan isn't necessarily superficial because HitmanPro prioritizes locations/objects and cloud verdicts, but the vendor doesn't publish an object-by-object comparison with every full-disk scanner. Use it for its intended triage role, not as forensic proof that every byte is clean.
The current official claim is four security labs, including SophosLabs
HitmanPro's current product page says it leverages malware databases from four security labs, including SophosLabs. The current page doesn't identify the other three. Older material and community posts name Kaspersky or Bitdefender, but those historic integrations can't be asserted as the current engine mix without a current first-party source.
This matters for accuracy and sanctions/privacy decisions. “Multi-engine” isn't a permanent vendor roster. The correct 2026 wording is the vendor's limited four-lab claim, not a copied list from the SurfRight era.
Cloud reputation allows a small client to query current knowledge without downloading every signature. It also creates an internet dependency. Alert's anti-malware documentation says the module performs a cloud scan/verdict on an executable before launch; the release notes include failed-upload fixes on ARM, confirming that uploads are part of at least some suspicious-file workflows.
If the cloud is unreachable, don't assume a clean status. Alert release history includes an offline indicator, and a second-opinion scan on an isolated incident machine may have reduced classification capability until networking is restored safely.
No current direct AV-TEST, AV-Comparatives or SE Labs result was found
We checked current consumer test material from AV-TEST Home Windows, AV-Comparatives consumer tests and SE Labs reports and didn't find a direct HitmanPro or HitmanPro.Alert entry. That isn't a failure score; it's an evidence gap. We can't publish a current protection, false-positive or performance percentage.
| Evidence source checked | Current direct HitmanPro result | What we can conclude |
|---|---|---|
| AV-TEST consumer Windows | Not found | No current AV-TEST protection, performance or usability score can be assigned. |
| AV-Comparatives consumer tests | Not found | No current real-world protection, malware-protection or performance percentage can be assigned. |
| SE Labs home anti-malware | Not found | No current total-accuracy or legitimate-accuracy rating can be assigned. |
| Vendor release notes and support | Current builds and feature behavior documented | Useful for maintenance status and product operation, but not independent proof of protection efficacy. |
We also don't borrow Sophos Home or enterprise Intercept X results. Products may share cloud intelligence/components while differing in policy, modules, defaults, platform integration and version. Only a named product/build test supports a named product conclusion.
Several 2026 affiliate reviews use EICAR downloads. Interpret them by role: regular HitmanPro is on-demand, so failure to block a browser download before the user runs a scan doesn't contradict its design. Alert claims continuous anti-malware/web protection, so an Alert-specific miss is relevant—but a handful of EICAR URLs/files is still not a substitute for thousands of current malware samples, false-positive testing and reproducible configuration.
The absence of current broad testing is the main reason the family receives 7.0 instead of a top-tier score. Active engineering and distinctive mitigations are positives; independent efficacy validation is a different requirement.

Alert's strongest ideas are CryptoGuard and exploit/risk reduction
CryptoGuard watches encryption behavior. The vendor says it creates backups when it recognizes unauthorized encryption, stops/removes the ransomware and allows files to be reverted. Behavior-based response can catch a new family without a known signature, but it isn't a backup system. Maintain offline/versioned backups and test restoration.
Exploit mitigations protect vulnerable applications such as browsers/Office against process injection, code reuse and other attack techniques. CookieGuard focuses on Chromium authentication cookies/credentials; keystroke encryption and webcam alerts address keylogging/privacy. Safe Browsing/web protection targets phishing/compromised sites.
2026 Process Protection additions include Vulnerable Driver Guard, intended to stop AV/EDR killers abusing legitimate vulnerable drivers, and ETWGuard, intended to prevent attackers manipulating Event Tracing for Windows. These are concrete, technically differentiated features—not generic “AI protection” copy.
Mitigations that inspect process behavior can also block unusual but legitimate software. Alert's event interface exposes technical detail, process trees, hashes/MITRE references and suppression. That's powerful for an informed user, intimidating for a novice.
The 2026 release notes show maintenance and compatibility work
| Product/build | Date | Notable changes |
|---|---|---|
| HitmanPro 346 | Feb. 5, 2026 | Chromium PUA extensions, disk-mode display, Sophos branding, hardening, ARM scan/upload fixes. |
| Alert 2043 | Mar. 13, 2026 | VulnDriverGuard, ETWGuard, ARM64 driver/Sophos Home/Bitdefender-Tor fixes. |
| Alert 2047 | Apr. 22, 2026 | HWB/VulnDriver/ETW/CookieGuard/event/game-detection improvements. |
| Alert 2059 | May 11, 2026 | Chromium Canary/Beta crash fix. |
The vendor uses phased rollout for Alert and says it can take several days for machines to receive the newest build. Before troubleshooting a “missing update,” compare the installed build, rollout note and release page; don't download an unofficial installer.
The release history also documents compatibility fixes. That's normal for low-level security software, but it means “works alongside everything” is an aspiration rather than a universal guarantee.

Both products have a 30-day trial without a credit card
The current HitmanPro scanner page and HitmanPro.Alert page advertise a 30-day free trial and say no credit card is required. That's ideal for incident cleanup: download from the official site, scan, review/remediate and decide whether recurring access is worth paying for without creating an automatic paid trial.
The official buy page sends purchases to Cleverbridge. On July 23, 2026 our Germany-localized browser checkout showed €19.95 including 19% VAT for one PC/one year of HitmanPro and €29.95 for Alert. The checkout also offered three-PC and three-year configurations.
Those are localized evidence, not universal prices. The U.S. or another country can show a different currency/tax/amount. Read the live checkout immediately before buying. We exclude Offer schema because one regional total shouldn't be advertised globally.
Alert includes HitmanPro features. Buying both separate keys is normally unnecessary. If the checkout/product names are confused, stop; official support has a specific article for users who bought a scanner key that can't activate Alert.
Licenses are per PC, separate by product and manually renewed
The checked entry plans cover one PC for one year. Official renewal support says Alert renewal is manual and the vendor doesn't auto-renew without express permission. Keep the Cleverbridge order/reference and product key email.
Don't activate a replacement key while an old license still has remaining days. The activation guide warns that remaining days aren't added to the new license. Wait until expiry unless support instructs otherwise.
HitmanPro and Alert keys aren't interchangeable. If activation reports that the license is unsuitable, verify which product you purchased rather than repeatedly reinstalling or buying a second key. Support can remedy an incorrect purchase when given both order references.
For a new PC/maximum-activation error, contact official support and request seat/license help. Community workarounds that modify licensing files are unsafe and may violate terms.
HitmanPro is Windows-only, with current ARM work
The official downloads page supplies 32-bit and 64-bit HitmanPro and lists Windows 11, 10, 8.1, 8, 7, Vista and XP. Alert lists Windows 11 through Windows 7 SP1. A product launching on an obsolete OS doesn't make that OS safe; Windows 7/Vista/XP lack current Microsoft security support.
Build 346 fixed scanning and failed uploads on ARM devices, while Alert 2043 fixed an ARM64 driver issue on Windows 10. That's meaningful current ARM attention, but ARM compatibility should be tested with the exact Windows build and other security drivers.
There's no consumer Mac, Android or iOS version. The official FAQ redirects Mac users to Sophos Home; evaluate that as a separate product with its own pricing/tests.
The scanner is lightweight by design; Alert's cost is continuous
We removed the page's unverified local scan/RAM numbers. The defensible claim is architectural: the regular scanner is a small executable that doesn't need a permanently installed real-time service. It consumes meaningful CPU/disk/network mainly while running and can coexist with a primary product.
Alert is different. It installs services/drivers and monitors process, file, browser and exploit activity. Its value depends on being continuous, so measure boot/login, browser launch, Office, games, developer tools, large file operations, sleep/resume and VPN use during the trial.
Cloud lookup makes network quality relevant. A quick scan can reflect prioritized object selection and cloud verdicts; it isn't comparable to another vendor's full-disk scan solely by elapsed time. Don't choose a scanner because its progress bar ends first.
Suspicious and PUA results require context before removal
HitmanPro can flag admin tools, remote-control software, game files, unsigned utilities, temporary installers and PUA/browser extensions. Recent community posts show Steam/War Thunder, OneDrive or Sysinternals-style tools causing confusion. These anecdotes don't prove a high false-positive rate; they show why detection labels matter.
Don't treat “suspicious,” “trace,” “tracking cookie” and confirmed malware as equivalent. Verify the path, publisher/signature, source and hash. A signed Microsoft PsExec binary in an official Sysinternals package is different from a renamed copy dropped in a user's temp directory by an attacker.
Official scanner false-positive support says to scan again, save the log and email it with an explanation. Alert exposes technical details/process tree and lets a sure user suppress an event. Preserve evidence before suppression; never whitelist by filename alone.

“Runs alongside antivirus” still needs a trial on your stack
Regular HitmanPro is low-conflict because it's on-demand. Some installed antivirus products may still block/remove secondary scanners during setup or scan the same files simultaneously. Pause scheduled scans—not real-time protection—while troubleshooting resource contention, then restore the primary schedule.
Alert's low-level mitigations are more likely to collide with browser security, games/anti-cheat, VPNs, other anti-ransomware or exploit modules. Official support maintains application-crash/incompatibility articles, and 2026 release notes include Bitdefender/Tor, Sophos Home, Chromium and game fixes.
Use the no-card trial. Create a restore point/image, install Alert, update/restart if requested and exercise your real applications. Don't stack Alert, another exploit-protection tool and several real-time antivirus engines because “more layers” sounds safer.
How to use HitmanPro in an infection response
- Disconnect the machine from untrusted networks if accounts/data may be actively stolen; don't delete logs/evidence needed for business response.
- From a clean device, download the correct signed HitmanPro build from the official downloads page and verify the publisher signature.
- Run the primary antivirus/Defender Offline where appropriate, then run HitmanPro as an additional opinion. Save logs before removal.
- Review suspicious/PUA/system detections. Quarantine/remediate confirmed malware; don't restore an unknown file because an app breaks.
- Restart and rescan with both tools. Patch Windows, browsers and exposed applications.
- From a known-clean device, change affected credentials, revoke sessions and contact financial/IT support when theft is plausible.
- For ransomware, boot/rootkit, repeated detections or high-value systems, prefer a known-good rebuild/restore and professional forensics over endless cleaners.
A clean second-opinion result is reassuring, not an attestation that no credential was stolen or persistence exists. Scanners can't reverse data exfiltration.
Cloud scanning needs a confidentiality decision
The product depends on cloud verdicts and release notes explicitly mention fixing failed uploads on ARM. The public marketing page says HitmanPro doesn't sell user information or install unwanted apps/toolbars/advertising programs. That's useful but not a granular file-submission specification.
For confidential source code, legal/medical documents or unreleased binaries, inspect the Sophos privacy notice/product settings and organizational policy before scanning. Hash/reputation queries and suspicious-sample uploads have different confidentiality consequences; the current public product page doesn't enumerate every trigger/retention path.
Don't upload confidential detections to VirusTotal merely to get another opinion; its sharing model may expose samples to partners. Use an approved private analysis channel or support case with authorization.
Support is practical but some articles are old
The dedicated support center covers activation, product-key recovery, alerts, false positives and incompatibilities. Release pages are more current than several FAQ articles dated 2021; use release notes for version/feature state and support articles for workflows.
If a scanner freezes, official guidance says disk indexing corruption is a common cause: run `chkdsk /f`, then `sfc /scannow`; if it continues, switch Advanced → Disk mode from Direct to Compatible. Back up first and treat repeated freezes/disk errors as possible storage-health issues, not just an antivirus bug.
For an Alert event, preserve Technical Details, the process tree and hash. Contact `[email protected]` when unsure. Don't suppress a mitigation only to make a game/business app launch without understanding the event.
Who should use HitmanPro?
| Scenario | Recommendation | Why |
|---|---|---|
| Suspicious/infected Windows PC | Use the scanner trial | Focused second opinion and cleanup without card. |
| Periodic reassurance on clean PC | Optional | Useful, but free maintained scanners may be enough. |
| Only antivirus | Don't use regular HitmanPro alone | No continuous protection. |
| Defender user wanting anti-ransomware/exploit layer | Trial Alert carefully | Distinct mitigations; direct lab gap/compatibility. |
| Already running full paid suite | Scanner yes; Alert often unnecessary | Alert may duplicate hooks/features. |
| Business/forensic incident | Use approved incident tooling | Consumer scanner isn't a forensic/EDR platform. |
HitmanPro alternatives depend on the job
Malwarebytes offers a widely used free on-demand cleanup mode and a separate paid real-time product. Emsisoft Emergency Kit is a portable/on-demand alternative useful for an incident USB toolkit. ESET Online Scanner and Microsoft Safety Scanner are additional vendor-specific opinions.
Norton Power Eraser is more aggressive and better reserved for last-resort suspicious systems with careful result review. Microsoft Defender Offline can scan outside normal Windows execution and is already available to Defender users.
For primary protection, choose a current, directly lab-tested product such as Bitdefender, Norton or ESET, or keep the built-in Microsoft Defender properly configured. HitmanPro complements that decision; it doesn't replace it.
Frequently asked questions
Is HitmanPro still active in 2026?
Yes. HitmanPro scanner build 346 shipped February 5, 2026, and HitmanPro.Alert build 2059 shipped May 11, 2026 after larger March and April updates. Sophos still sells, downloads and supports both products under the HitmanPro brand.
Can HitmanPro replace my antivirus?
Regular HitmanPro shouldn't. It's an on-demand scanner/cleaner with no continuous real-time shield. Use it beside Microsoft Defender or another supported antivirus. HitmanPro.Alert adds always-on protection but still lacks current direct major-lab results and is positioned as a layer that can coexist with another product.
What is the difference between HitmanPro and HitmanPro.Alert?
HitmanPro is the small run-on-demand second-opinion scanner. Alert is installed and includes HitmanPro plus real-time cloud anti-malware, CryptoGuard ransomware response, exploit/risk reduction, web/banking, keystroke and webcam protections. They use different product keys; Alert includes the scanner.
Is the HitmanPro 30-day trial really free?
The official pages advertise a 30-day trial with no credit card required for both products. That makes it suitable for a one-time scan/cleanup or compatibility evaluation. Download only from HitmanPro/Sophos and verify what the trial enables in the current build before remediation.
Which antivirus engines does HitmanPro use?
The current official page says HitmanPro uses malware databases from four security labs, including SophosLabs. It doesn't name the other three. Historic Kaspersky or Bitdefender references shouldn't be treated as the current roster without a current first-party statement.
Does HitmanPro work with Microsoft Defender?
Yes by design: the regular scanner can run alongside another security product. Alert is also marketed for coexistence, but its continuous exploit/ransomware/browser hooks need a real compatibility trial with Defender or any third-party suite, games, VPN and business apps.
Does HitmanPro auto-renew?
Official Alert support says renewal is manual and licenses aren't auto-renewed without express permission. Don't activate a new key early because remaining days on the old license won't be added. Keep the Cleverbridge order and verify the current checkout terms.
What should I do if HitmanPro flags a legitimate file?
Don't delete or suppress it blindly. Verify path, publisher/signature, source and hash; scan again, save the HitmanPro log and send it with context to official support. For Alert, preserve Technical Details/process tree before suppressing a confirmed false positive. Never whitelist by filename alone.
Final verdict: excellent supporting actor, not the lead
HitmanPro earns its place in a Windows incident toolkit. It's actively maintained, small, easy to run beside an existing antivirus and focused on the exact moment a second opinion matters. The no-card trial is consumer-friendly, and build 346 addresses real current PUA/ARM/hardening work.
Alert is more ambitious. CryptoGuard, exploit mitigation, CookieGuard, VulnDriverGuard and ETWGuard are technically distinctive. Its 2026 cadence shows serious engineering—but the same low-level reach raises compatibility questions, and direct current lab validation is missing.
Our editorial score is 7.0/10. Use regular HitmanPro for triage/cleanup, not as your only antivirus. Trial Alert only when you can name the gap it fills and test the actual software stack. Keep current primary protection and versioned backups either way.