Emet 2.1 + Sandboxie, Software Updaters

Discussion in 'other anti-malware software' started by enemyofarsenic, Jul 29, 2011.

Thread Status:
Not open for further replies.
  1. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    Sorry, bad wording. There’s a Java.exe in the System32 folder that you should also add to EMET.
     
  2. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Is that .exe ever used?

    I also don't believe that EMET is able to force any programs in System32 to run with EMET.dll. Never worked on my computer.
     
  3. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    I don't know. But it's better to be safe than sorry. Look at this list here: -http://www.rationallyparanoid.com/articles/microsoft-emet-2.html-
     
  4. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Yes, I've read that =p I was just curious.

    Anyways, nothing in my System32 folder runs with EMET.dll. I've tried.
     
  5. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    Working here on Win7 32-bit. I just tested with Notepad.
     
  6. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    What's the path to notepad that you see in your running applications in the EMET GUI?
     
  7. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    C:\Windows\system32\notepad.exe
     
  8. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Oh, hm. Strange that it won't work for me.
     
  9. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    What OS are you running. Have you tried removing it from EMET and adding it again?
     
  10. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Hm. It seems that only some of them will run with EMET.dll. Notepad seems to. Going to see if the others will, I've reformatted recently.
     
  11. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    From my understaning of EMET it should run with any forced program system wide.
     
  12. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Some system files are protected. Restarting now to see if it's working.

    Some do some don't. svchost works. wininit does not. Just examples of some that aren't working. sppsvc, lsm, smss, csrss are not running with EMET.dll. Not that it's a big deal at all.
     
  13. JimboW

    JimboW Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    280
    Thanks for testing.:thumb: But as you say that’s no big deal. Those system files don’t need to be running under EMET anyway. Not much risk there. There wouldn’t be a problem with those running under maximum settings so there is still some protection as the main features DEP, SEHOP and ASLR are built in to the OS.
     
  14. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It's all good. I'm happy with EMET forcing what it does.
     
  15. dw426

    dw426 Registered Member

    Joined:
    Jan 3, 2007
    Posts:
    5,543
    That's where the x64 Java is installed to, the 32 is in Program Files (x86). On the EMET blog that was linked here, the recommended apps section shows both the 32 and 64 bit .exe files, which threw me off at first. If you only have the 32 version installed, nothing will be in system32.
     
  16. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    64bit Java is installed to Program Files. But I guess something might be dropped into system32 for 64bit java. Either way, it's running with EMET.
     
  17. dw426

    dw426 Registered Member

    Joined:
    Jan 3, 2007
    Posts:
    5,543
    Lol, yeah I screwed that up. Anyway, if you don't have the 64 version, there's no Java.exe in there. I only bothered with it when I was taking FF8 and Flash 11 Beta for a test drive. (great browser, terrible Flash, hehe)
     
  18. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Last edited: Aug 1, 2011
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.