KfeCo10X64.sys
Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it's not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
KfeCo10X64.sysSample 1 · HVCI FALSE
- MD5
697f698b59f32f66cd8166e43a5c49c7- SHA1
f5d58452620b55c2931cba75eb701f4cde90a9e4- SHA256
b583414fcee280128788f7b39451c511376fe821f455d4f3702795e96d560704- Imphash
2df11474daf362b1b2fa3d3a89b6acbe- Authentihash MD5
9085c42a59541dbd2e05fec9c247a189- Authentihash SHA1
c46323ef4fd5f553003a92fdad0d3059564e481f- Authentihash SHA256
8bce4a327c9e77631c03057b0e45cdbb2e751194d42995c0310e3ccdd3d33b7c- Machine
- AMD64
- Version
- 9.7.4.11
- Publisher
- Rivet Networks, LLC.
Recorded command
sc.exe create KfeCo10X64.sys binPath=C:\windows\temp\KfeCo10X64.sys type=kernel && sc.exe start KfeCo10X64.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: zwclose zwclose

