Certain apps, such as the Finder and the SystemUIServer, are encrypted and this kernel extension will only decrypt the executable pages if it considers your Mac to be genuine (consulting the TPM, I believe).

The TPM was used briefly at the beginning of the Intel mac days, but hasn't been used since. The decryption is now done through dsmos.kext in software.


