EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    @fearlessscientist. That would make since. I'm Not using the built-in Administrator account, I'm using the unevaluated administrator user account with UAC in default state. You would think it'll be reversed where.. when using the built-in Administrator account with UAC in default state wouldn't be likely to cause the EMET UI alerts. I think the relating code in EMET is incorrectly reversed. :D
     
  2. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    I noticed that Microsoft's ruleset in EMET v4.1 doesn't cover the java.exe, javaw.exe, and javaws.exe that are in my system folder (in my case syswow64). I manually added them.

    ---

    I also noticed that Microsoft has a new v4.1 download digitally signed Nov. 25, 2013, but it's the same v4.1.5064.16886 when installed. I'm not sure why Microsoft did this.
     
  3. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hi MrBrian.

    Here are the original package MD5 hashes...

    e350385cf8113be4a1d5abefc2b0f04c EMET_Agent.exe
    fdef7dc7b75c57ba5a60904835703c9a EMET_GUI.exe
    655e17161216f678598ad4314e3519d1 EMET64.dll
    0184fb8638aa66f66541171a28c96b13 EMET.dll
     
  4. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    Thanks :).

    Those hashes are unchanged in the newest download. The new download is smaller than the older v4.1 download.
     
  5. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Well, I PM'ed you the rest of the MD5 hashes.
     
  6. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Don't the *\java.exe rules already cover them?
     
  7. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    Not the ones that Microsoft provides.
     
  8. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    Thanks :). All of the md5 hashes in the EMET folder are unchanged from the old v4.1 download to the new v4.1 download. The timestamps changed on most of the files though. Also, the new download is ~900,000 bytes smaller than the old download.
     
    Last edited: Dec 3, 2013
  9. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Must've been my imported rules after checking the default XML's. EMET mislead me by bolding those entries. :cautious:
     
  10. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
  11. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    484
    Great news. :thumb:
     
  12. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    See the new manual for configuration information on ASR and EAF+.
    They need to be configured through registry editor as there is no GUI for that. Keep in mind that EAF+ is only configured for Internet Explorer by default.

    The information is in chapters 1.2.9 and 1.2.10.
     
  13. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Does it install in a separate directory? Did you uninstall the previous version before installing and if so, does that preserve current rules?
     
  14. Export your settings before an 'over the top' install of 5.0 over 4.1

    Tried it briefly, errors with IE11 when closing. Back to 4.1, did had not any problems with other tech previews.
     

    Attached Files:

  15. AdvancedSetup

    AdvancedSetup Security Expert

    Joined:
    May 8, 2008
    Posts:
    144
    Location:
    USA
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thanks for the info:thumb:
     
  17. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  18. harshisthere

    harshisthere Registered Member

    Joined:
    Aug 8, 2011
    Posts:
    84
    The bypass was done after making disabling ASLR and also remember that the recent flash exploit did not execute itself if they found EMET running in the system.
     
  19. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
    -http://www.youtube.com/watch?feature=player_embedded&v=lP9Vtg1FvEQ-
     
  20. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Ah didn't notice the export option.

    I exported, uninstalled, installed 5.0 and imported my rules. All went well and no app issues so far. No errors with IE11 or Chrome, lucky me. :)
     
  21. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    It gives mistake report at installation. During install I have Avast shields disabled and OA HIPS disabled no SRP and AppLocker. What should I do?
     

    Attached Files:

  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I also installed EMET 5.0TP on one of my new machines. Running as well as 4.1 did.

    Pete
     
  23. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    so do i.

    Anyway i don't know if 5.0TP really fixes the problems highlighted in the study of Bromium even if EAF+ seems to go in that direction...
     
    Last edited: Feb 27, 2014
  24. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    484
    5.0 working great so far..
     
  25. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I just returned to a previous snapshot by time machine Eaz-Fix. Installed 5.0 on the top of 4.1. Checked the last mitigation for all apps. Disabled Deep Hooks as all extensions of Dragon crashed. After this it's going smooth so far.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.