Strange EMET Behavior

Discussion in 'other anti-malware software' started by Fox Mulder, Jul 26, 2013.

Thread Status:
Not open for further replies.
  1. Fox Mulder

    Fox Mulder Registered Member

    Joined:
    Jun 2, 2011
    Posts:
    204
    OS: Windows 8 x64
    Software: EMET 4.0.4854.22470 (Beta), Java 7

    I installed Java for a one-time task a few days ago. Yesterday, EMET shut down Java. I wasn't using Java at the time so I don't know why it was running. Anyway, I uninstalled Java. The errors are below. Is this a problem with EMET 4 Beta or did I really have an infection that was mitigated?

    Code:
    Application Name: C:\Program Files (x86)\Java\jre7\bin\javaw.exe
    Execution flow simulation check failed:
      PID          : 0x1094/4244
      TID          : 19FC
      CodeAddress  : 0092D0BC
      CodeStackPtr : 2B4F4A8
      CalledAddress: 77CDE138
      API name     : ntdll.NtCreateFile
      StackPtr     : 02B4F408
      FramePtr     : 2B4F4F0
    Code:
    Fault bucket , type 0
    Event Name: EMET_40_Beta
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: javaw.exe
    P2: 7.0.250.17
    P3: javaw.exe
    P4: 7.0.250.17
    P5: 4.0.4854.22468
    P6: 7
    P7: 0
    P8: 
    P9: 
    P10: 
    Code:
    Faulting application name: javaw.exe, version: 7.0.250.17, time stamp: 0x51c4b3ff
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc000001d
    Fault offset: 0x00000000
    Faulting process id: 0x1094
    Faulting application start time: 0x01ce8a06acc38bb0
    Faulting application path: C:\Program Files (x86)\Java\jre7\bin\javaw.exe
    Faulting module path: unknown
    Report Id: f1c8e436-f5f9-11e2-beb9-50e549c54039
    Faulting package full name: 
    Faulting package-relative application ID: 
    Code:
    Fault bucket -620084721, type 1
    Event Name: APPCRASH
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: javaw.exe
    P2: 7.0.250.17
    P3: 51c4b3ff
    P4: StackHash_e122
    P5: 0.0.0.0
    P6: 00000000
    P7: c000001d
    P8: PCH_C4_FROM_ntdll+0x0002E1A4
    P9: 
    P10: 
     
  2. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Mine EMET is 4.0.4913.
    It's quite possible just incompatibility of the Java with "SimExecFlow" mitigation. Uncheck it for the Java.
    Did EMET popup when Java started? If yes then just uncheck the popup mitigations.
     
    Last edited: Jul 27, 2013
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,189
    Location:
    Texas
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.