mfeelamk.sys

SYSCORE

Microsoft Corporation

It runs as a Windows kernel mode device driver named “McAfee Inc. mfeelamk”.
Publisher:
McAfee, Inc.  (signed by Microsoft Corporation)

Product:
SYSCORE

Description:
McAfee ELAM Driver

Version:
SYSCORE.15.1.0.650

MD5:
df131e3fb4ba5d1750e0bdfac527dea9

SHA-1:
4e3a0a15e2f949b57914922952526ac451487a7b

SHA-256:
9898e37921ea3739fbd6e336940ff0f33cc836ca933297960e3be06281f69a0b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/25/2024 11:49:28 AM UTC  (today)

File size:
57 KB (58,336 bytes)

Copyright:
Copyright© 1995-2013 McAfee, Inc. All Rights Reserved.

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\mfeelamk.sys

Digital Signature
Authority:
Microsoft Corporation

Valid from:
9/24/2013 1:35:59 PM

Valid to:
12/24/2014 12:35:59 PM

Subject:
CN=Microsoft Windows Early Launch Anti-malware Publisher, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
33000000353AFBBA2861C70171000000000035

File PE Metadata
Compilation timestamp:
11/15/2013 8:23:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:hHF2vrcZZ4rlUZsSVYG/EJvast3tkM9r4dp8VwG9V8/t3e+I2G6Ij+h5puvKBW:b2zBlUKiYGsJvaK90dp4wgV8V3FDGvR

Entry address:
0xAAC0

Entry point:
55, 8B, EC, 8B, 45, 08, 83, EC, 0C, 53, 56, C7, 40, 34, E4, 1E, 40, 00, A1, 28, 85, 40, 00, 8B, 00, 57, 33, DB, 3B, C3, 6A, 02, BF, 9A, 00, 00, C0, 5E, 74, 08, 3B, C6, 0F, 85, 5F, 01, 00, 00, 68, 6D, 66, 65, 78, 6A, 3C, 53, FF, 15, 14, 85, 40, 00, 3B, C3, A3, D4, A7, 40, 00, 0F, 84, 44, 01, 00, 00, 89, 70, 04, A1, D4, A7, 40, 00, 89, 70, 08, A1, D4, A7, 40, 00, 88, 58, 34, A1, D4, A7, 40, 00, 88, 58, 35, A1, D4, A7, 40, 00, 89, 18, A1, D4, A7, 40, 00, 89, 70, 38, B8, C8, A7, 40, 00, 68, D4, 86, 40, 00, 6A...
 
[+]

Entropy:
6.4047

Developed / compiled with:
Microsoft Visual C++

Code size:
34.2 KB (35,008 bytes)

Driver
Display name:
McAfee Inc. mfeelamk

Service name:
mfeelamk

Type:
Kernel device driver (KernelDriver)

Group:
Early-Launch