mfeelamk.sys

SYSCORE

Microsoft Corporation

It runs as a Windows 64-bit kernel mode device driver named “McAfee Inc. mfeelamk”.
Publisher:
McAfee, Inc.  (signed by Microsoft Corporation)

Product:
SYSCORE

Description:
McAfee ELAM Driver

Version:
SYSCORE.15.1.0.668

MD5:
2d0378415ee29d01531e64b5052a37a6

SHA-1:
2beb2ffa58db64c72d00ccee43cd7237777c5d55

SHA-256:
db5a86e8a1117a80276a6556ef8251e5cfd4558179cd386b9a2026f7fb6dc202

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/23/2024 4:35:14 PM UTC  (today)

File size:
67.7 KB (69,352 bytes)

Copyright:
Copyright© 1995-2014 McAfee, Inc. All Rights Reserved.

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\mfeelamk.sys

Digital Signature
Authority:
Microsoft Corporation

Valid from:
9/24/2013 9:35:59 PM

Valid to:
12/24/2014 9:35:59 PM

Subject:
CN=Microsoft Windows Early Launch Anti-malware Publisher, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
33000000353AFBBA2861C70171000000000035

File PE Metadata
Compilation timestamp:
3/22/2014 12:57:08 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:9AAR677GN/wa60Nw9Ev/JuOO47nGEkf99Sa6WcqY33GTcmdZYCRsoFGxAnVXpKKm:aAR677GNTNw9Ev/A8G1d5cq6+1RxFKKm

Entry address:
0xE080

Entry point:
40, 53, 55, 57, 48, 83, EC, 20, 48, 8D, 05, A1, 41, FF, FF, 48, 8B, F9, BB, 9A, 00, 00, C0, 48, 89, 41, 68, 48, 8B, 05, 9E, C2, FF, FF, BD, 02, 00, 00, 00, 83, 38, 00, 74, 08, 39, 28, 0F, 85, BA, 01, 00, 00, BA, 68, 00, 00, 00, 33, C9, 41, B8, 6D, 66, 65, 78, FF, 15, 59, C2, FF, FF, 48, 85, C0, 48, 89, 05, E7, F1, FF, FF, 0F, 84, 97, 01, 00, 00, 89, 68, 08, 48, 8B, 05, D7, F1, FF, FF, 48, 8D, 15, 90, C4, FF, FF, 89, 68, 0C, 48, 8B, 05, C6, F1, FF, FF, C6, 40, 60, 00, 48, 8B, 05, BB, F1, FF, FF, C6, 40, 61...
 
[+]

Entropy:
6.2225

Code size:
41.8 KB (42,752 bytes)

Driver
Display name:
McAfee Inc. mfeelamk

Service name:
mfeelamk

Type:
Kernel device driver (KernelDriver)

Group:
Early-Launch