Solved Where did Strip My Rights come from?

Migotop

Member
Member
Messages
70
I like the idea of lowering my browser's write capability with a restricted token, but that's what I have Simple Software Restriction Policy and EMET for. I never intentionally downloaded or installed StripMyRights.exe, which is in C:\Windows, and Malwarebytes Premium is flagging the registry keys and values written by it as a "Security Hijack", specifically (HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\FIREFOX.EXE|Debugger) for example ( there are 4 keys and 4 values in total) Is this put here by EMET or Simple Software Restriction Policy? How can I check that my browser is actually operating under a restricted token rather than a (maliciously) elevated one? Thanks!
 

My Computer

System One

  • OS
    windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    ASUS
    Browser
    firefox
    Antivirus
    avast

My Computer

System One

  • OS
    Windows 8.1 full version
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom built Intel system
    CPU
    Intel 4790k
    Motherboard
    Asus Z-97 AR
    Memory
    8 (2 x 4) GB Gskill Ares 1600 mghz
    Graphics Card(s)
    Asus Strix GTX 970
    Sound Card
    Onboard
    Monitor(s) Displays
    Still working out the details
    Hard Drives
    Samsung 840 Evo 120 GB. 2 Seagate Barracuda 1 TB HDd
    PSU
    EVGA 750W 80+ Gold Certified Fully-Modular ATX
    Case
    Raidmax Vampire full tower (black)
    Cooling
    Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
This is what I found on a google search.

StripMyRights - Based on DropMyRights

Thanks! Somehow I missed that one when I was Googling. Also, I ran into a post at the Malwarebytes Forum where someone had run into a similar problem, and it turned to be EMET that was throwing a flag with Malwarebytes. I consider this solved, but would still appreciate if someone knows how to check on the restricted browser token (that it's restricted and not elevated). Thanks Griffscavern!
 

My Computer

System One

  • OS
    windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    ASUS
    Browser
    firefox
    Antivirus
    avast
This is what I found on a google search.

StripMyRights - Based on DropMyRights

Thanks! Somehow I missed that one when I was Googling. Also, I ran into a post at the Malwarebytes Forum where someone had run into a similar problem, and it turned to be EMET that was throwing a flag with Malwarebytes. I consider this solved, but would still appreciate if someone knows how to check on the restricted browser token (that it's restricted and not elevated). Thanks Griffscavern!

Restricted User also covered in that link, I just missed it on the first read through/skim. Solved.
 

My Computer

System One

  • OS
    windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    ASUS
    Browser
    firefox
    Antivirus
    avast
This is what I found on a google search.

StripMyRights - Based on DropMyRights

Thanks! Somehow I missed that one when I was Googling. Also, I ran into a post at the Malwarebytes Forum where someone had run into a similar problem, and it turned to be EMET that was throwing a flag with Malwarebytes. I consider this solved, but would still appreciate if someone knows how to check on the restricted browser token (that it's restricted and not elevated). Thanks Griffscavern!

Restricted User also covered in that link, I just missed it on the first read through/skim. Solved.

You're welcome. Glad I could help.
 

My Computer

System One

  • OS
    Windows 8.1 full version
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom built Intel system
    CPU
    Intel 4790k
    Motherboard
    Asus Z-97 AR
    Memory
    8 (2 x 4) GB Gskill Ares 1600 mghz
    Graphics Card(s)
    Asus Strix GTX 970
    Sound Card
    Onboard
    Monitor(s) Displays
    Still working out the details
    Hard Drives
    Samsung 840 Evo 120 GB. 2 Seagate Barracuda 1 TB HDd
    PSU
    EVGA 750W 80+ Gold Certified Fully-Modular ATX
    Case
    Raidmax Vampire full tower (black)
    Cooling
    Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Back
Top