Files signed by Microsoft Windows Early Launch Anti-malware Publisher

Microsoft Windows Early Launch Anti-malware Publisher

Microsoft Windows Early Launch Anti-malware Publisher is a digital signature publisher name observed in ThreatInfo records. This page groups 22 signed files and shows whether those files are currently classified as clean, undefined, or detected.

A digital signature can help identify a publisher, but it does not always prove that a file is safe. Certificates may be abused, stolen, expired, or attached to modified installers, so the file hash and detection status should be checked together.

qmbsecx64.sys 78f086e1c1eb383d2f2e7cf828948e0d Clean
qmbsec.sys 1678910dcc3405ac5109af09d0aa24d1 Clean
amselam.sys b3844014d965c15f8b6b8c3a8cf1e7ec Clean
amselam.sys 2c89a100c30bcff13fe0e6aab0e77f44 Clean
PCPElam64.sys 22c8b8ef9fc04d61e63ca7a0e0eb4886 Clean
PCPElam.sys 28600fd54b7c369a492a3724ea3d859f Clean
000200000006F8DD.copy 940d6dbf479ee8e9295141a78a8eeb0e Clean
psinelam.sys b099c83694fdb4a5d9fe8159f7d8b9ec Clean
protected_elam.sys c9c8eabfe8428423bdb397369247f48b Clean
protected_elam.sys 9bee915715ccabb945154f4706f49325 Clean
protected_elam.sys 9a21101f50d635ae4bb583489424676f Clean
protected_elam.sys 5326aa634bbcf39092ba9816a9428be6 Clean
mbamelam.sys 9e77c51e14fa9a323ee1635dc74ecc07 Clean
protected_elam.sys cf833a28b40ab93655f342a9d760d224 Clean
protected_elam.sys e9806e894443f95671064755f9663a18 Clean
WdBoot.sys d0c6e102636021c0e98dcce2bb2c477e Clean
psinelam.sys 24ed16161b26460a7e550d4b54dcaae8 Clean
bdelam.sys b25ab197292231bf7dec3085b93c12b9 Clean
PCPElam64.sys 0554719c4df9a5c2e3f2a4a814fd5395 Clean
PCPElam.sys d7b09dbfcc0ac036a1aa65d7600a5a38 Clean
rtp_elam.sys 6ea871dd0b0deef86dd814c09177f02b Clean
rtp_elam.sys 45b76cc2fff1be0e2c8aa7bd710d54f7 Clean

Certificate review summary

Use the file hashes to verify this signature

ThreatInfo groups the signed files above so you can compare exact hashes and detection labels. A signature name alone is not enough to decide whether a file is safe.

Recommended checks

  • Open any matching file report and compare the MD5 hash.
  • Confirm the file path and download source before trusting the binary.
  • Run a GridinSoft scan if the signed file appears unexpectedly.