kgameprotect.sys
kgameprotect.sys exposes FILE_ANY_ACCESS IOCTL 0x222048 through \\.\kgameprotect. The handler accepts a caller-selected PID and opens that process from KernelMode with PROCESS_TERMINATE before calling ZwTerminateProcess. It performs no caller, registered-client, or target-PID authorization on this IOCTL branch. The reviewed sample is version 2.7.1.7 and also registers a file-system minifilter, so correct minifilter installation is required. Static review confirms the process-termination path, but does not establish that unprivileged users can open the device or that protected processes can be terminated on every Windows configuration.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
kgameprotect.sysSample 1 · HVCI unknown
- MD5
cb1f1880aafd7d9bbdd70c54e56c9dd0- SHA1
86f3b8e26e80db804086f095dd6bee79980d810c- SHA256
6c1d596d18213e24f0c88d58ea7f3ca24114eded806b6198a8abc701251126ee- Imphash
4de3dfcde82ad8ff50165c62d0501064- Authentihash MD5
1bbaf5dc91831f9138f4ad266a5841d9- Authentihash SHA1
9f7d0ad9493857ea85e2074688df4244399e6ca6- Authentihash SHA256
abe670579d00b0dbc2c1fc477d8d6e41f3af642e48d60dcf558a171a819137e6- Machine
- AMD64
- Version
- 2.7.1.7
- Publisher
- Not recorded
Research & references
Acknowledgement: Shiroko @ShirokoLEET

