← Back to driver explorer
Driver intelligenceVulnerableVerified

kgameprotect.sys

kgameprotect.sys exposes FILE_ANY_ACCESS IOCTL 0x222048 through \\.\kgameprotect. The handler accepts a caller-selected PID and opens that process from KernelMode with PROCESS_TERMINATE before calling ZwTerminateProcess. It performs no caller, registered-client, or target-PID authorization on this IOCTL branch. The reviewed sample is version 2.7.1.7 and also registers a file-system minifilter, so correct minifilter installation is required. Static review confirms the process-termination path, but does not establish that unprivileged users can open the device or that protected processes can be terminated on every Windows configuration.

UUID / a0006589-a811-4341-9be0-4512eae9febbADDED / 2026-09-11AUTHOR / Shiroko

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

kgameprotect.sysSample 1 · HVCI unknown
MD5
cb1f1880aafd7d9bbdd70c54e56c9dd0
SHA1
86f3b8e26e80db804086f095dd6bee79980d810c
SHA256
6c1d596d18213e24f0c88d58ea7f3ca24114eded806b6198a8abc701251126ee
Imphash
4de3dfcde82ad8ff50165c62d0501064
Authentihash MD5
1bbaf5dc91831f9138f4ad266a5841d9
Authentihash SHA1
9f7d0ad9493857ea85e2074688df4244399e6ca6
Authentihash SHA256
abe670579d00b0dbc2c1fc477d8d6e41f3af642e48d60dcf558a171a819137e6
Machine
AMD64
Version
2.7.1.7
Publisher
Not recorded

Research & references

Acknowledgement: Shiroko @ShirokoLEET