ELAM (Early Launch Antimalware) and AVs supporting it

Discussion in 'other anti-malware software' started by Minimalist, Oct 19, 2014.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,648
    Location:
    U.S.A.
    If Webroot, or any AV for that matter, is using an ELAM driver, it must be located in the Win drivers directory. Below is a screen shot of Eset's ELAM driver.

    Also, for an AV to be registered in MS Security Center, it must be using a MS signed ELAM driver.

    Eset_ELAM.png
     
  2. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,458
    Location:
    Ontario, Canada
    From the Webroot Log!

    Mon 2022-04-04 10:46:17.0556 ScriptShield active config: 2S(2) yes, SR(2) yes, SSH yes, FLR no, RUD yes, SDE(2) yes, DSR no, DQT 65536, MFS 100, USE yes, UNR no
    Mon 2022-04-04 10:46:17.0704 ELAM applicable: yes, driver present yes, driver registered yes, PPL: yes, PPL configured: yes, mandated: yes

    2022-04-04_12-34-56.png

    2022-04-04_15-42-46.png
     
    Last edited: Apr 4, 2022
  3. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,943
    Location:
    Outer space
    Yes.

    Interesting. So almost all AV's already use ELAM or they wouldn't be able to register as an AV.
     
  4. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
    Hello All:

    As I am not in the employ of Malwarebytes Corporation et al, therefore my non-authoritative contribution is:

    Malwarebytes for Windows Premium has employed Early Launch AntiMalware for approximately five years encompassing versions that first appeared in late MB3 and all of MB4 to present. Some of this feature is within the kernel driver filename MbamElam.sys and others.

    HTH
     
    Last edited: Apr 4, 2022
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice